Privacy

What happens to your data

reMaestro runs on a box in your house. Most questions about where your data goes have the answer it didn't go anywhere. This page is the rest of the answer: what the software writes down, how long it keeps it, and every outside company that ever receives anything.

This is not a privacy policy, and it is not written as one. A privacy policy is a set of legal commitments — who is answerable for your data, which law applies, what you can compel anybody to do about it. Those are claims about a business, not facts about software, and writing them here would be inventing them. What this page does instead is describe what the software actually does, which is checkable. There is a longer and more technical version of all of it in the documentation.

Last reviewed 15 August 2026 · describes the software as it currently ships

The short version

Six things can be written down. Four of them live on your own hub and never leave it. Two of them only exist if you decide to use the optional hosted service.

WhatWhere it livesOn by default?How long
A conversation you're having Your hub, in memoryYes 5 minutes after you stop talking; 2 hours for the assistant on a screen
The live feed of events and commands Your hub, in memoryYes The last 400 events and 500 commands, gone when it restarts
Counts, costs and timings of AI calls Your hub, on diskYes 2 years
What was actually said Your hub, on diskNo 90 days by default; you choose anything from 7 days to forever
Counts, costs and timings of gateway calls reMaestro CloudOnly if you use the cloud AI gateway 30 days per call; 24 months as hourly totals
Your backups reMaestro CloudOnly if you switch it on Until you delete them — encrypted, unless you turned that off

The row most people don't expect is the third one. A hub keeps a two-year record of how much AI it used and who asked for it, out of the box, whether or not you ever touch reMaestro Cloud. It contains no words — that is enforced by tests rather than promised — but it is a record of activity per person, and it is on without anybody being asked. You are told about it on the page where you create the first account, and it is described in full in the hub documentation.

The box in your house

The hub is your machine. Nothing described in this section is sent to reMaestro, and most of it is not sent anywhere at all.

Out of the box, it keeps no record of anything anybody said

That is the shipped state, not a suggestion. Writing down conversations is a switch, it is off until somebody turns it on, and the code checks whether it is on before every single write rather than reading it once when it starts. If reading that setting fails, the answer is off — the failure mode of a privacy switch has to be "kept nothing", never "kept everything because the disk was busy".

What it keeps anyway

  • The conversation you're in the middle of, in memory, so that "no, the other one" works. Five minutes after the last thing said for voice, two hours for the assistant on a screen. Then it's gone, and none of it touched the disk.
  • A live feed of what the house is doing — the last 400 events and 500 commands, in memory, lost on restart. It no longer carries the words: an event says that an exchange happened, in which room, and whether it worked.
  • Counts, costs and timings of every AI call, on disk, for two years. How many calls, how many worked, tokens and seconds of audio, what it cost where the hub could know, how long it took, and who or what asked. No prompt, no transcript, no reply, no filename, no room name. This exists because your hub is the only thing that can see all of your AI spend, including calls made straight to a provider on your own key that never touch any service of ours.

If you switch conversation logging on

Then the hub starts writing down what was said, what was typed, what came back, which tools the assistant called and which commands actually reached a device — so you can read a conversation afterwards instead of inferring it from a chart. Ninety days by default; 7 days, 30, 90, a year or keep everything are the choices, and keep everything is a labelled option on a dropdown rather than a box you can leave blank. Turning the switch back off asks whether you want to keep what's there or delete it, and takes neither on its own.

The uncomfortable part, stated rather than buried: any admin account on your hub can read every conversation on it, including ones they were not part of. Everybody else reads only conversations carrying their own account id, which in practice means the assistant on a screen and nothing else. The reason is that a microphone is not a person — a handset on a coffee table has no session and no sign-in, so the hub genuinely does not know whose words those are, and attributing them to whoever was last signed in somewhere else would be a claim nothing in the house could support.

Your AI key is yours, and the words go where you point them

The assistant is off until you give it a model to talk to. If you point it at a provider on your own key, your conversations go to that provider and to nobody else — nothing is copied to us on the way past, because there is no route by which it could be. If you'd rather nothing left the house at all, the hub will talk to a model running on a machine of your own.

The three things your hub sends us

One happens on a timer. The other two happen when you open one particular page, and never otherwise.

It checks for updates

Unless you turn that off in Settings → Updates, your hub asks releases.remaestro.app on a timer whether there's a newer release, and fetches the manifest and its signature.

That request carries three things and no more: your internet address, because every HTTP request carries one; which channel you follow, because it's in the URL (stable.json or beta.json); and the version you're running, because the hub puts it in the browser-identification header (remaestro/1.2.3). There is no hub identifier, no account, no device list and no usage figure in it, and nothing reports back afterwards — installing an update is still a button somebody presses.

It asks for the plugin list, when you open the Marketplace

A plugin is a driver somebody else wrote, for a device this hub didn't ship knowing about. Open Plugins → Marketplace and your hub asks extensions.remaestro.app for the signed list of them; pressing Install on one asks for that plugin's own signed document. The plugin itself is then downloaded from wherever its publisher keeps it, which is usually not us.

It shows you the list it saved last time straight away and asks for a fresh one behind that, so the page is never waiting on us — but the request is the same request either way, and it happens because you opened the page.

Plugins → Installed asks us nothing at all. That page lists what is on your hub, and everything on it is already on your hub. Opening it, reading it, or removing a plugin from it makes no request to anybody.

Those requests carry your internet address, and which plugin you asked about, because it is in the URL. That is all. There is no hub identifier, no account, and no list of what you have installed — and unlike the update check, not even the version you're running: the hub fetches the whole list and works out at home which of it will run here.

Nothing here is on a timer. Your hub never fetches this on its own, so if you never open that page, it is never asked for. And installing a plugin from a link somebody gave you involves us not at all, which is deliberate and permanent: the registry is a place plugins are easier to find, never how they are installed.

It asks what people thought of those plugins, on the same page

Plugins can be rated out of five. Those ratings can't live in the signed plugin list — that list is a set of files we sign when we publish them, and a number that changes every time somebody clicks would mean re-signing the lot each time, which would turn the signature from "we published this" into "this was true at two o'clock". So the ratings come from cloud.remaestro.app instead, and opening Plugins → Marketplace asks for them straight after asking for the list.

This is the one request that goes to a machine of ours rather than to a file host, so be exact about what is in it. It carries your internet address, because every request does, and nothing else at all — no account, no hub identifier, no version, and not which plugin you are looking at: it is one request for every rating there is, and your hub matches them up at home. We keep no record of it.

Rating one does need an account, and that is the point of asking for one: it ties a rating to something that costs a little to make and that can be taken away. If you have linked this hub to a reMaestro Cloud account, the star buttons appear and pressing one sends which plugin and how many stars, under your hub's token. One rating per plugin per account, changeable, and withdrawing one deletes it rather than hiding it. There are no written reviews — there is nowhere to type one, and no field in the database that could hold one.

If you have not linked an account, none of that appears and nothing is sent but the read above. The ratings still show, because they are decoration on a shelf rather than a feature you buy. And if that request fails — no internet, or the service is down — the page says so in one quiet line and carries on: browsing and installing are entirely unaffected, and a plugin with no rating shown reads as "no ratings yet" rather than as nought stars.

So the phrase "nothing phones home" needs one qualification, and this is it. Nothing about your house is reported to us. The box does open outbound connections: those three, and then whatever you point it at — your own AI provider, your media server, a TV guide source, a light bridge. Switch off automatic checks and the update request stops too; you then check by hand when you feel like it.

reMaestro Cloud, if you use it

Optional, and the hub must never need it. Every feature it fronts has a local equivalent that keeps working if the service is switched off, unreachable, or shut down for good. If you have not linked a hub to an account, nothing in this section applies to you and nothing about your house exists on any machine of ours.

One thing on that host is not part of this and does not need an account: reading the plugin ratings, described above. An unlinked hub asks for them when somebody opens the Marketplace, that request carries nothing but the internet address every request carries, and no record of it is kept — so there is no account here for a hub that has never made one.

Two separate things can send bytes to it, with two separate switches: the AI gateway, and cloud backup. You can use either without the other.

What it knows about you as a customer

In full: your email address, an account id we minted, a hash of your password, when you signed up, when you last signed in, which plan you're on, and the hubs you've linked — for each one, a name you chose and a hash of its token, never the token itself. Nothing about the devices in your house, and nothing that could be used to control them.

Signing in is the only thing your address is used for. The service has no way to send you email — there is no mail sender anywhere in it — so there is no mailing list, and there cannot be one until somebody writes code that does not currently exist.

The AI gateway

The gateway exists so you don't have to bring your own key. It is a metered proxy: a request arrives from your hub, we forward it upstream, and we count what it cost.

Be clear about this before switching it on. If you point your hub's reasoning at the gateway, then the conversation — what somebody said, plus the block of context your hub builds about your house, which includes your device names and your room descriptions — is in the request that reaches us, and we forward it on. That is what a gateway is. And if you point transcription at it, the audio clip goes the same way — the recording itself, not a transcript of it. Who all of that goes to is named below, and the alternatives are on the same settings page: your own key straight to a vendor, or a model on a machine in your own house. The setup we'd recommend is a mixture — a cloud model doing the thinking and a Whisper server of your own doing the listening, so the words leave and the audio doesn't.

Two things stay behind that you might expect to travel. Deciding which device to touch happens entirely on your hub — the gateway never learns which light was dimmed or what was sent to it; it sees a conversation and returns an answer. And nothing in the request is written down: the service keeps one row per call and then hourly totals, and those rows have no field capable of holding a prompt, a transcript, a reply, a filename or an IP address. That is not a promise about what we choose to store — the type that holds every word in that record has a private constructor, the only values it can contain are compiled into one file, and four separate tests fail the build if any of that stops being true.

Per-call rows are deleted after 30 days; the hourly totals after 24 months. Both horizons are enforced by actually deleting rows, and the tests check that rows go rather than that a constant says the right number.

Cloud backup

Each backup gets a fresh random key, the backup is encrypted with it, and that key is then wrapped separately by each unlock method you have — your hub's own key, and a recovery code shown to you once. The server stores the encrypted bytes and the wrapped keys, and never the key itself: enough to store a backup, and never enough to open one. What it can see either way is the size, the timing, the count and which account they belong to.

The recovery code is the one thing you have to keep, and that is the honest cost of the server not being able to read your backups. You may instead choose unencrypted backups — no code, nothing to lose — and if you do, reMaestro can read the contents, which are a credential dump: device keys, your AI key, a TLS private key, whatever anybody configured your plugins with. The settings screen says exactly that, in those words. Encrypted is the default.

Two things on your hub are excluded from a backup by name, so they cannot reach the service even inside a sealed blob: the conversation log, and the hub's own usage history. That exclusion is enforced in both directions, including on restore.

Your sealed backups sit on the service's own disk. There is no third-party storage provider involved, and naming one that does not exist would be as wrong as omitting one that does.

Everyone outside reMaestro who receives anything

This is the list people actually want, so here it is in one table rather than scattered through the prose. If you self-host and never create a cloud account, only the last two rows can ever apply to you — and the last one only when you visit this website.

WhoWhat reaches themWhen
OpenRouter Your conversation with the assistant, and the context your hub builds about your house — device names, room names, activities. OpenRouter forwards it to whichever model vendor answers. Only if you point your hub's reasoning at the reMaestro Cloud gateway. Never if you use your own key, or a model on your own machine.
OpenAI The audio of anything you say to the assistant, as a clip, plus the language you told it to expect. Not the rest of the conversation, and nothing about your devices. Only if you point your hub's transcription at the reMaestro Cloud gateway, and only for the models served that way.
OpenRouter (audio) The same clip, where the model you're using is served through OpenRouter instead. It forwards it to whichever speech-to-text vendor answers. Only if you point your hub's transcription at the reMaestro Cloud gateway, and only for the models served that way.
GitHub Your internet address, the release channel you follow, and the version you're on — nothing else. GitHub serves the release manifest your hub asks for, serves the plugin list when you ask for one, and serves this website. The plugin list is the one request of the three that doesn't carry your version. Every automatic update check, unless you switch them off; every time you open the Marketplace or install a plugin from it; and every visit to this site.
Google Your internet address and browser, because this site loads its typefaces from Google Fonts. Nothing from your hub ever reaches them. Every visit to a page on remaestro.app, including the documentation.

Audio is the row to read twice. Which of the two transcription rows applies to a given clip depends on the model your hub is set to use, not on some deployment-wide choice — the service's price list records, per model, which upstream serves it. So on one day some clips can go to OpenAI and others through OpenRouter. A third destination is possible and is not in the table because it is not an outside party at all: a Whisper server run on the operator's own machines, where the audio reaches no third company. You cannot tell which from the outside, and if that distinction matters to you, the reliable answer is to transcribe on a machine of your own rather than through the gateway.

Otherwise that is the whole list. Not on it, deliberately and checkably: no analytics, no advertising or tracking pixels, no error-reporting service, no chat widget, no customer-messaging tool, no email provider, and no third-party storage or backup provider. Outside the two font requests this website makes, the only external addresses anywhere in the hosted service's source code are the AI upstreams above.

Where the service itself runs

reMaestro Cloud runs on hardware the operator controls, and your sealed backups sit on that hardware's own disks. Nobody is handed readable data in order to host it: what is on those disks is the ciphertext of your backups and a database of counts and costs, and the key that would open a backup is not there and never was.

Where that hardware physically sits may change, and this page does not commit to a location or to a hosting company — because committing to one would be a claim we'd have to keep true through the next machine move rather than a fact about the software. What does not change is the sentence above it: if the day comes that a hosting provider is between you and the service, they go in the table above as a named recipient, because that is where a company that can reach the disk belongs. The cost of that flexibility is stated as a gap rather than left for you to notice.

Once a request leaves us, it is out of our hands

What a model vendor does with a conversation after it has been forwarded to them is governed by their terms and not by anything on this page. Nothing described here reaches into it. If that matters to you, the answer is not to use the gateway: point your hub at a provider on your own key, or at a model running in your own house. Both are supported and neither is a downgrade.

This website

It is a handful of static files on GitHub Pages, so GitHub's servers see the ordinary things a web server sees — your address, the page you asked for, your browser's identification. There are no cookies, no analytics and no tracking of any kind on it, which you can confirm by reading the page source; there is nothing to opt out of because nothing is collected.

The one exception is worth naming rather than glossing: the typefaces come from Google Fonts, which means your browser makes a request to Google when a page loads. That is a real third party on an otherwise self-contained site, and it applies to the documentation as well as to these pages.

If you'd rather none of that happened

Every item above has a control, and none of them costs you the product.

Don't create a cloud account The whole of reMaestro Cloud becomes irrelevant. The hub does not need it and does not degrade without it.
Bring your own AI key Your conversations go straight from your hub to the provider you chose. Nothing passes through us, because there is no path by which it could.
Run the model in your own house Point the hub at a model on a machine of your own, and a Whisper server for the listening, and neither the words nor the audio leave your network.
Leave conversation logging off It is off until you turn it on. Left alone, your hub never writes down a word anybody said.
Turn off automatic update checks Then the hub makes no outbound request to us on its own at all, and you check for a release when it suits you. The only other one it can make is the plugin list, and that happens when you open the Marketplace — never on a schedule, and never from any other page.
Keep your backups encrypted The default. Keep the recovery code somewhere safe and the server cannot open them, however much anybody would like it to.

What's enforced, what's merely true, and what isn't covered

Some of what's above is enforced by a test that fails the build. Some of it is a default nobody has changed. Some of it is nothing at all. Those are three different kinds of statement, and running them together is how a page like this turns into reassurance instead of information — so they're marked apart, the same way the documentation marks them.

Guaranteed

Enforced in code. A change that broke it would fail the build.

  • No prompt, transcript, reply, filename or IP address can enter the counts-and-costs record — on your hub or in the cloud.
  • The conversation log cannot enter a backup, in either direction, including on restore.
  • Conversation logging is off until somebody turns it on, and a failure to read that setting is answered "off".
  • Retention horizons are enforced by deleting rows, and the tests check that rows actually go.
  • The server cannot open an encrypted backup: it never holds the key.
  • Your hub cannot record a cost for a gateway call, so it can't invent a figure about somebody else's price list.

Merely likely

True today, because of a default or a judgement. Nothing would notice if it changed.

  • That you keep your recovery code. Nothing can help if you don't — that is the design.
  • That an unencrypted backup was chosen deliberately rather than clicked past. The screen says what it costs; nothing makes anybody read it.
  • That the two-year horizon on the counts record is one you want. It is the only thing here you are told about rather than asked about, and that is a weaker thing.
  • That deleting is keeping up. It runs on the read and write paths; if the database refuses, rows sit past their horizon until it succeeds. Nothing reads them, and it is logged.

Unguarded

Nothing in the product addresses this. Named anyway, because the alternative is you find out.

  • What a model vendor does with a request after it leaves us. Their retention is theirs.
  • Where the service physically runs, and therefore which country's law it sits under. This page does not state it and does not commit to it. The hardware is the operator's, and where it sits may change; nothing here promises it will be one place or another.
  • Which upstream transcribed a given clip. It depends on the model, and you can't see it from your side. Transcribe on your own machine if you need to know.
  • Ordinary server logs. Anything answering HTTP has an operator, and infrastructure logging is not the analytics record and is not covered by the guarantees on the left.
  • A conversation while it's still open. For five minutes, anyone signed in to your hub — or anything holding a read-scoped API key — can read the live conversation, whichever way the logging switch is set. The phone app depends on it.
  • Anything you build on top. A rule or a webhook that fires when somebody speaks can send those words wherever you pointed it, and nothing here constrains that.
  • A plugin you installed, and the household names it is handed. A plugin is an ordinary program with your hub's own privileges — no sandbox, no permission prompt, and no packaging or signing choice changes that. Configuring one hands it what you typed and the name your account goes by, so it can address you by name; it may log that, keep it, or send it anywhere, and nothing here notices. It is the one party on this page we cannot name in advance, because you choose it.

Everything on this page describes the software as it ships. Where it and the documentation ever disagree, the documentation is the longer answer and the source code is the actual one.