Version 1.0 · Last updated 16 May 2026
Homie is a self-hosted AI home assistant. The bulk of the personal data it processes — household members, calendars, messages, voice transcripts — stays on your own device. A small amount passes through our Cloudflare infrastructure so household members can sign up and so authentication tokens can be exchanged. This policy explains what we collect, where it lives, and what your rights are under the GDPR.
Homie ("Homie," "we," "our," "us") is operated by Jonas and Stefan, based in Stockholm, Sweden. We are the data controller for the personal data described below.
For privacy questions or to exercise your rights, contact us via the contact form on heyhomie.tech.
This policy applies when you:
It does not cover personal data held by third-party services you choose to connect (Google, Spotify, Twilio, OpenAI, Anthropic, Home Assistant, and others). Those providers act as their own controllers or as separate processors for you, under their own terms. The services we currently integrate with are listed in §6.
Homie is designed so that almost all personal data sits in a local SQLite database on the device that runs Homie (typically at ~/.config/Klaus/db/klaus.db or Klaus/db/klaus.db). We do not have access to this database.
Depending on which features you enable, this local database may contain:
This data stays on your device. We have no copy and no access. Its security depends on your operating system, your disk encryption, your backups, and who can reach the device.
To enable household signup and to coordinate authentication, a small amount of data passes through a Cloudflare Worker (auth.hihomie.app) and a Cloudflare KV namespace (homie_tokens):
We process this data on the legal bases of performance of a contract with you (GDPR Article 6(1)(b) — operating the service you asked for) and our legitimate interest in running the authentication system securely (Article 6(1)(f)).
heyhomie.tech and welcome.hihomie.app are static pages hosted on Cloudflare. They do not use analytics, advertising, or tracking cookies.
Cloudflare itself receives standard HTTP request information (IP address, user-agent, requested URL) as part of operating the network. We do not access individual visitor logs. See Cloudflare's privacy policy.
When you submit an invite link at welcome.hihomie.app, the data you enter (name, avatar, calendar preference) is stored as described in §3.2.
| Data | Location | Retention |
|---|---|---|
| Household secret (HMAC) | Cloudflare KV | While the household is active. Deleted on request. |
| OAuth tokens | Cloudflare KV | Maximum 1 hour, or deleted on pickup |
| Member signup settings | Cloudflare KV | Maximum 1 hour, or deleted on pickup |
| Open-invite claims | Cloudflare KV | Default 24 hours, maximum 30 days |
| Conversation logs, messages, LLM logs, memory | Your local device | Indefinite by default. You control deletion. |
Local data on your own device is yours. We have no copy and cannot delete it for you. We recommend periodically reviewing what your local database stores, and deleting the SQLite file if you uninstall Homie.
You have the right to:
Because most of Homie's data sits on your own device, you exercise most of these rights directly by editing or deleting local files. For the small amount of data held in our Cloudflare KV, email us via the contact form on heyhomie.tech and we will respond within 30 days.
You also have the right to lodge a complaint with the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY) at imy.se.
When Homie communicates with the following services, personal data is sent to them and is governed by their own privacy policies. We list them here for transparency.
| Service | Purpose | Location | Policy |
|---|---|---|---|
| Cloudflare, Inc. | Web hosting, Workers, KV, DNS | Global edge | link |
| Anthropic, PBC | LLM (Claude) for assistant reasoning | USA | link |
| OpenAI, LLC | Realtime voice and text-to-speech | USA | link |
| Google LLC | Calendar, optionally Drive (OAuth) | USA / global | link |
| Spotify AB | Music playback (optional) | EU / USA | link |
| Twilio, Inc. | SMS and voice (optional) | USA | link |
| Open-Meteo | Weather forecasts (no personal data sent) | EU | link |
| SMHI | Swedish weather data (no personal data sent) | EU | link |
Transfers to processors located outside the European Economic Area (Anthropic, OpenAI, Twilio, and parts of Google and Cloudflare) are protected by the European Commission's Standard Contractual Clauses, and additional safeguards where applicable.
Homie is designed for use by households and may be configured by adult household members to include children. We do not knowingly collect personal data from children under 13 without parental involvement. If you believe a child's data is being processed without appropriate consent, contact us via the contact form on heyhomie.tech and we will assist.
All daemon-to-Worker communication is authenticated with HMAC-SHA256 signatures using the household secret. OAuth tokens stored in Cloudflare KV are short-lived and deleted on pickup. Local data security depends on your own operating system, disk encryption, and backup choices.
No system is perfectly secure. If you discover a vulnerability, please report it to us via the contact form on heyhomie.tech.
We may update this policy. Material changes will be reflected by the "Last updated" date at the top of this page and, where feasible, by a notice on heyhomie.tech.
Email: us via the contact form on heyhomie.tech