Privacy Policy
Last updated: July 27, 2026
Overview
IoT Parrot ("we", "our", "the app") is operated by Lurawood Labs LLC. This policy explains exactly what data we collect, why we collect it, who else receives it, and how you can delete it. We collect only what the service needs to work — there is no advertising, analytics, attribution, or crash-reporting SDK in the app.
Data We Collect
- Account information: Your email address; your name, if the sign-in provider returns one (Sign in with Apple asks for your name and email, and you can decline either); and the account identifier returned by Google or Apple if you sign in with one of those providers. Authentication is handled by Firebase Authentication; if you use an email/password account, your password is stored by Firebase in hashed form and is never visible to us.
- Device, broker, and dashboard configuration: The MQTT broker connection details (host, port, TLS settings, username), device names and topics, dashboard layouts, schedules, NFC automations, and alert rules you create. This is the data the app exists to store.
- MQTT broker passwords: Stored encrypted at rest using Google Cloud KMS. They are decrypted only when the app or one of our server-side functions needs to open a connection on your behalf. See Dashboard sharing for an important exception about who else can receive them.
- Push notification tokens: On iOS and Android we store a Firebase Cloud Messaging registration token per installed device so alerts can reach you. Firebase also assigns an installation identifier to the app on your device. The web app does not register for push and does not create these.
- Support tickets: When you contact us from the app we store your message, the category you chose, your user ID, your email address, and any image you attach. Attachments are stored in Firebase Cloud Storage.
- Sharing recipients: When you share a dashboard, the recipient's email address that you enter is stored on the share record and is visible to you and to the recipient.
- Alert history: When an alert rule fires we record the rule name, the time, the delivery outcome, and up to the first 256 characters of the MQTT payload that triggered it. History is capped: we keep your most recent 100 fire events on Maker and 500 on Pro, and older events are deleted automatically as new ones arrive.
- Data streams (Pro): If you explicitly create a data stream, values published to the topic you selected are sampled and stored so you can chart them. Nothing is logged unless you create a stream. Stored values are automatically deleted after 30 days.
- Billing identifiers: If you subscribe, we store the Stripe customer and subscription identifiers, your tier, and the renewal state. Card numbers never reach the app or our servers — checkout runs on Stripe's hosted pages.
- Server logs: Our cloud infrastructure records standard request logs (timestamps, user IDs, IP addresses, error messages) for operating and debugging the service. These are not used for profiling or advertising.
Data We Do Not Collect
- The app contains no advertising, analytics, attribution, or crash-reporting SDK. We do not display ads, we do not read your device's advertising identifier (IDFA / Android Advertising ID), and we do not track you across other companies' apps or websites.
- We do not sell, rent, or share your personal data with third parties for marketing purposes.
- We do not collect your phone's location. The app requests no location permission. Map widgets plot the coordinates your own IoT devices publish over MQTT — see Maps and address lookup.
- We never use your camera. The app has no photo- or video-capture feature. We access your photo library only at the moment you pick an existing image to attach to a support ticket.
- We do not read or analyze your IoT data beyond the specific, user-initiated cases described in the next section.
Your MQTT messages
If you use your own ("bring your own") MQTT broker, messages travel directly between your hardware, the app, and your broker. We are not in that path and we do not receive or store those messages. There are four exceptions, all of which follow from features you choose to turn on:
- The IoT Parrot Managed Broker. If you use the managed broker instead of your own, the broker is infrastructure we operate — your messages pass through our systems in order to be delivered.
- Alerts (Maker and Pro). Our alerts service subscribes to the topics your alert rules name and evaluates each message against your conditions. Payloads are evaluated in memory; only the truncated snapshot described above is stored when a rule fires.
- Data streams (Pro). Values from a topic you explicitly select are sampled and stored for charting, then deleted after 30 days.
- Schedules. Our scheduler publishes the payloads you configured to your broker at the times you configured.
How We Use Your Data
Your data is used solely to:
- Provide and maintain the IoT Parrot service
- Authenticate your account and enforce your subscription tier's limits
- Execute scheduled MQTT actions, evaluate alert rules, and deliver alert notifications by push and email
- Process subscription payments
- Respond to support requests
- Diagnose faults and protect the service from abuse
Third-Party Services
IoT Parrot uses the following third-party services:
- Google Firebase and Google Cloud: Authentication, Firestore database, Cloud Storage (support attachments), Cloud Functions and Cloud Run (server-side logic), Cloud KMS (broker-password encryption), and Firebase Cloud Messaging (push notifications). Subject to Google's Privacy Policy.
- Stripe: Processing subscription payments. Checkout and the billing portal are hosted by Stripe; we receive only the subscription state and identifiers, never card details. Subject to Stripe's Privacy Policy.
- Google Maps Geocoding API: Used server-side to turn coordinates published by your devices into a human-readable address for map widgets. Only the coordinates are sent — no account identifier accompanies the request — and results are cached to reduce repeat lookups. Subject to Google's Privacy Policy.
- OpenStreetMap: Map widgets fetch map tiles directly from OpenStreetMap's tile servers. Those requests come from your device or browser, so OpenStreetMap receives your IP address and the map coordinates being viewed. Subject to the OpenStreetMap Foundation Privacy Policy.
- Resend: Delivering alert notification emails. Subject to Resend's Privacy Policy.
- Google Workspace (Gmail SMTP): Delivering support replies and account/subscription notices. Subject to Google's Privacy Policy.
- Sign in with Google / Sign in with Apple: Only if you choose one of those sign-in methods. Subject to Google's and Apple's privacy policies.
Maps and address lookup
Map widgets display coordinates that your devices publish over MQTT — not your phone's location. Two things leave your account when you view one: the tile requests your device makes to OpenStreetMap (which expose your IP address and the area you are viewing), and, on tiers with the address readout, a server-side reverse-geocode request containing your device's coordinates to Google's Geocoding API.
Dashboard sharing
When you share a dashboard with another IoT Parrot user, they receive read access to that dashboard, to the devices its widgets reference, and to the connection details for the broker(s) those devices use — including the broker username and password, which their app needs in order to connect. Anyone you share with can therefore reach other topics on that same broker, and revoking the share does not invalidate credentials they have already received. If you need to fully withdraw access, change the password on your broker. Only share dashboards with people you trust.
Data Storage and Security
Your data is stored on Google Cloud infrastructure, and our server-side services run in the United States. All connections to our services use TLS. Access to your documents is enforced by Firebase Authentication and per-user Firestore security rules, and MQTT broker passwords are encrypted at rest with Google Cloud KMS rather than stored in plain text. No system is perfectly secure, but we design for least privilege and store as little as the features allow.
Data Retention and Deletion
Your data is retained for as long as your account is active, except where a shorter limit is stated above: alert history is capped at your most recent 100 fire events on Maker and 500 on Pro, and data-stream values are deleted after 30 days. You can delete your account yourself, at any time, from Settings → Delete Account in the app. Doing so permanently deletes your user record and everything under it — brokers, devices, dashboards, schedules, NFC automations, alert rules, alert history, data streams, and push tokens — plus the shares and schedules that reference you, and your sign-in record. If you have a managed broker, its credentials are deprovisioned at the same time. Any active subscription is cancelled.
Two things intentionally survive account deletion:
- Support tickets and their attachments, so an open request is not lost along with the account that raised it. These contain the email address and message you supplied. Both are automatically deleted 12 months after the ticket is created — the ticket by a Firestore time-to-live policy, and any attached image by a Cloud Storage lifecycle rule on the
support_attachments/folder. - Billing records held by Stripe, which Stripe retains for its own legal, tax, and anti-fraud obligations.
If you want a support ticket removed sooner, email support@iotparrot.com and we will delete it.
Your Rights
Depending on where you live, you may have the right to access, correct, export, or delete the personal data we hold about you, and to object to certain processing. Most of your data is directly visible and editable in the app, and account deletion is self-service as described above. For anything else, contact support@iotparrot.com and we will respond within a reasonable period.
Children's Privacy
IoT Parrot is not intended for children under 13. We do not knowingly collect data from children under 13. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to This Policy
We may update this policy from time to time. We will notify users of significant changes through the app or by email.
Contact Us
If you have questions about this privacy policy, contact us at support@iotparrot.com.