Pi-Tool — Datenschutzerklärung

Stand: 26. Juli 2026. Diese App ist ein inoffizielles Community-Tool und steht in keiner Verbindung zum evcc-Projekt. Nutzung auf eigene Gefahr — keine Haftung für Schäden an System, Daten oder Hardware (MIT-Lizenz, „AS IS").

Verantwortlicher (Art. 13 DSGVO)

KYTH. Systems UG (haftungsbeschränkt)
Prof.-Mederer-Straße 4, 92348 Berg, Deutschland
E-Mail: datenschutz@kyth.systems
Vollständige Anbieterangaben im Impressum.

Kurzfassung

Pi-Tool sammelt keine personenbezogenen Daten, hat kein Konto, keine Werbung und kein Tracking. Deine Zugangsdaten bleiben verschlüsselt auf deinem Gerät.

Welche Daten und wo

Netzwerkzugriffe

Health-Alerts über ntfy (optional, standardmäßig aus)

Richtest du „Health-Alerts" ein, installiert die App über deine SSH-Verbindung einen systemd-Timer auf deinem Pi. Dieser prüft alle 30 Minuten den Zustand des Geräts und schickt bei einem Problem eine Push-Nachricht an einen ntfy-Server. Voreingestellt ist der öffentliche Dienst ntfy.sh (Drittanbieter); im selben Dialog kannst du jeden anderen — auch einen selbst gehosteten — ntfy-Server eintragen.

Berechtigungen der App

Die App enthält keine Analyse-, Werbe- oder Tracking-Bibliotheken und fordert keine Berechtigungen für Standort, Kontakte, Kamera oder Mikrofon an. Einen Android-Dienst, der im Hintergrund selbsttätig Aufgaben ausführt, gibt es bewusst nicht — Automatik läuft als Timer auf dem Pi.

Löschung

Deinstallieren der App entfernt alle lokal gespeicherten Daten.

Rechtsgrundlage

Die lokal verarbeiteten Verbindungsdaten dienen ausschließlich der von dir ausgelösten Aktion (Art. 6 Abs. 1 lit. b/f DSGVO). Außer dem oben genannten Update-Check bei GitHub (USA) und — nur wenn du die Health-Alerts einrichtest — den Statusmeldungen deines Pi an den von dir gewählten ntfy-Server werden keine Daten an Dritte übermittelt. An uns selbst übermittelt die App nichts.

Pro-Kauf über Google Play

Die einmalige Pro-Freischaltung kaufst du über Google Play. Vertragspartner des Kaufs (Merchant of Record) ist die im Bestellvorgang genannte Google-Gesellschaft (Google Commerce Limited); die Zahlungsabwicklung erfolgt durch Google, es gelten die Datenschutzerklärung von Google und die Google-Play-Nutzungsbedingungen. Wir erhalten von Google keine Zahlungsdaten und in der Regel keinen Namen, sondern nur Transaktionsdaten der Bestellung (Bestellnummer, Produkt, Zeitpunkt, Land/Steuerregion, Kauf-/Erstattungsstatus, Kauf-Token zur Freischaltungsprüfung auf deinem Gerät). Diese verarbeiten wir zur Vertragserfüllung, für Support und Erstattungen (Art. 6 Abs. 1 lit. b DSGVO) sowie zur Erfüllung handels- und steuerrechtlicher Aufbewahrungspflichten (Art. 6 Abs. 1 lit. c DSGVO i. V. m. § 147 AO, § 257 HGB — 8 bzw. 10 Jahre). Die Prüfung der Freischaltung erfolgt ausschließlich auf deinem Gerät; wir betreiben keinen eigenen Server.

Speicherdauer

Die App speichert Daten ausschließlich lokal auf deinem Gerät; die Deinstallation löscht sie. Bei uns selbst fallen keine Nutzungsdaten an. E-Mail-Korrespondenz löschen wir, sobald sie für die Bearbeitung nicht mehr erforderlich ist. Kaufbelege unterliegen den o. g. gesetzlichen Aufbewahrungsfristen. Eine automatisierte Entscheidungsfindung einschließlich Profiling findet nicht statt.

Hosting dieser Seiten

Impressum und Datenschutzerklärung werden über GitHub Pages (GitHub Inc., USA) bereitgestellt. Beim Aufruf erhält GitHub technisch bedingt deine IP-Adresse in Server-Logs (Empfänger in einem Drittland; GitHub ist nach dem EU-U.S. Data Privacy Framework zertifiziert). Rechtsgrundlage ist unser berechtigtes Interesse an einer sicheren, verfügbaren Bereitstellung (Art. 6 Abs. 1 lit. f DSGVO). Wir setzen keine Cookies und kein Tracking ein.

Deine Rechte (Art. 15–21 DSGVO)

Du hast das Recht auf Auskunft (Art. 15), Berichtigung (Art. 16), Löschung (Art. 17), Einschränkung der Verarbeitung (Art. 18), Datenübertragbarkeit (Art. 20) sowie Widerspruch gegen Verarbeitungen auf Grundlage von Art. 6 Abs. 1 lit. f DSGVO (Art. 21). Da die App keine Daten an uns überträgt, liegen uns in der Regel keine Daten zu dir vor — außer du kaufst die Pro-Version (siehe oben) oder kontaktierst uns per E-Mail. Du hast außerdem das Recht, dich bei einer Aufsichtsbehörde zu beschweren (Art. 77 DSGVO), z. B. beim für uns zuständigen Bayerischen Landesamt für Datenschutzaufsicht (BayLDA), Promenade 18, 91522 Ansbach.

Kontakt

Datenschutz-Anfragen an datenschutz@kyth.systems; sonstige Anliegen auch über die GitHub-Issues des Projekts.


Pi-Tool — Privacy Policy (English)

Pi-Tool collects no personal data, has no account, no ads and no tracking. Connection details you enter (host, port, username, password) are stored only locally and encrypted on your device (Android Keystore). They are never transmitted to the developer or any third party. Your password is sent only over your own SSH connection to your own server to perform the action you trigger, and is filtered from logs. The app calls GitHub's public API on launch to check for app updates, and after connecting it fetches evcc's release notes (evcc-io/evcc) and — only if Home Assistant is detected on your Pi — its latest version tag (home-assistant/core); no account, usage or credential data is sent, but GitHub Inc. (USA) unavoidably receives your device's IP address as a recipient in a third country (legal basis: our legitimate interest in update checks, Art. 6(1)(f) GDPR). It makes a read-only HTTP call to your own evcc web API (/api/state) when you open the live status, and — only when you tap "find Pi" — probes the SSH port of devices on your own local Wi-Fi (local connection attempts only; no data is sent to us or any third party). Uninstalling the app deletes all stored data. This is an unofficial community tool, not affiliated with the mentioned projects.

Health alerts via ntfy (optional, off by default): if you set them up, the app installs a systemd timer on your Pi that checks the device every 30 minutes and pushes a message to an ntfy server when something is wrong — by default the public service ntfy.sh (a third party); you may enter any other, including a self-hosted one. What leaves your Pi (not your phone): the topic you chose and the message text — disk usage, temperature, read-only-filesystem/SD-card errors, the names of services that are not running (e.g. evcc, Pi-hole) and the number of available updates. No credentials, no account or usage data; the server receives your connection's IP address as the sender. ntfy.sh states that published messages are cached temporarily (default: 12 hours) and IP addresses may be logged for rate limiting (ntfy privacy notes). Note that an ntfy topic is effectively a password: topics are reachable without an account, so anyone who knows or guesses the name can read your messages — which is why the app suggests a long random topic and warns about guessable ones. Legal basis: performing the function you triggered (Art. 6(1)(b)/(f) GDPR); switch it off in the same dialog and the timer is removed from the Pi.

Permissions: INTERNET for the SSH connection and the calls above; USE_BIOMETRIC only for the optional app lock (Android performs the check — the app receives "confirmed"/"cancelled" and no biometric data); POST_NOTIFICATIONS so Android may show the foreground service's ongoing notification (local only — no push service, no push tokens, no Firebase); and FOREGROUND_SERVICE/FOREGROUND_SERVICE_DATA_SYNC so a long SSH action keeps running while the app is in the background. No analytics, ad or tracking libraries; no location, contacts, camera or microphone permissions.

Pro purchase: the one-time Pro unlock is bought via Google Play. The seller (merchant of record) is the Google entity named at checkout (Google Commerce Limited); payment is handled by Google under Google's privacy policy and Play terms. We receive no payment data and generally no name — only order/transaction data (order ID, product, time, country/tax region, purchase/refund status, a purchase token used to verify the unlock on your device), processed to perform the contract and for support/refunds (Art. 6(1)(b) GDPR) and to meet statutory retention duties (Art. 6(1)(c) GDPR). Entitlement is verified only on your device; we run no server.

Your rights (Art. 15–21 GDPR): access, rectification, erasure, restriction, data portability and objection; and the right to lodge a complaint with a supervisory authority (Art. 77 GDPR), e.g. the Bavarian DPA (BayLDA), Promenade 18, 91522 Ansbach. Since the app sends us no data, we normally hold none about you unless you buy Pro or email us. These pages are hosted on GitHub Pages (GitHub Inc., USA; EU-U.S. Data Privacy Framework certified), which receives your IP in server logs (Art. 6(1)(f) GDPR); no cookies, no tracking.

Controller: KYTH. Systems UG (haftungsbeschränkt), Prof.-Mederer-Straße 4, 92348 Berg, Germany — datenschutz@kyth.systems (see the Impressum). Contact also via GitHub Issues.