At Home Dashboard Privacy Policy
Last updated: October 2, 2026
Scope
This policy describes the private At Home Dashboard application and its Google Calendar and optional OneDrive integrations. It does not replace the privacy notices for Google, Microsoft, GoDaddy, or the public website's contact form and reCAPTCHA services.
Public information website
The public information pages are hosted on Cloudflare Pages. Requests to view them are processed by Cloudflare and may include ordinary connection information such as IP address and browser headers, subject to Cloudflare’s privacy policy. These pages have no account sign-in, dashboard data, advertising, or analytics scripts. The separate contoto.com contact form uses its own hosting and anti-spam services.
Information accessed and used
Google Calendar: after authorization, the application reads the connected account's calendar list, calendar identifiers and colors, and events from calendars selected by the owner. Display data includes event titles, dates, times, all-day status and locations when available. This information is used to show the household's schedule. The application does not modify Google calendars or events.
OneDrive: if connected, the application reads folder and file information to let the owner browse and choose photo folders. It downloads supported photos from selected folders and creates resized local display copies. Microsoft's Files.Read permission is broader than the selected folders; the folder selection is enforced by the application's behavior, not a folder-specific Microsoft permission. Cloud originals are not modified or deleted.
The application stores authorization tokens and account-connection settings to refresh these connections without requiring a new sign-in for every update. Passwords are entered into the provider's sign-in pages, not stored by the dashboard.
Storage and security
Credentials and settings are stored on the Raspberry Pi in files restricted to the connection service and system administrators. They are protected by filesystem permissions, but are not encrypted at rest by the application. Cached appointment data and resized photo copies are stored locally for display and continued operation during temporary internet outages.
The installed setup service listens only on the Pi's local interface. Remote setup uses an SSH tunnel. The display receives appointment data and photo copies, not authorization tokens. Anyone who can see the household display can see its selected content. Device administrators and people with access to its storage may also be able to access stored information.
Sharing and permitted use
The application communicates with Google and Microsoft to obtain authorized content. It does not upload calendar data or photos to this public website, sell them, use them for advertising, or use them to train artificial-intelligence models. The application does not include an analytics service for connected calendar or photo content.
At Home Dashboard's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Retention and removal
The application refreshes a rolling cache of upcoming appointments and a limited photo collection. Last successful cached content may remain on the Pi when the internet is unavailable or an update fails. Tokens remain locally until replaced or removed.
The owner can change selected calendars or folders in setup and revoke application access through the connected Google or Microsoft account. Revoking access stops future authorized retrieval but does not itself erase previously cached files or locally stored credentials. The device owner must also remove those local files when retiring, transferring, or clearing the dashboard. Contact the owner for help with local removal.
Household use and contact
The app is configured by the household owner and does not offer public sign-ups or collect information directly from children. For questions or removal requests, use the contact form at contoto.com and identify the request as relating to At Home Dashboard. Do not send passwords or authorization tokens.
This policy will be updated if the application's data practices change.