Privacy Policy
Status Board collects nothing. There are no accounts, no sign-up, no analytics, no tracking, no advertising, and no third-party SDKs. The developer operates no server and has no way to see your data.
What we collect
Nothing. Status Board has no backend of any kind. No information about you, your devices, or your dashboards is ever transmitted to us, and we have no mechanism by which we could receive it.
Where your data lives
- On your device. Dashboards, panel settings, cached panel values, board images and the widget cache are stored in the app's own container.
- In your private iCloud database. If you enable iCloud sync, dashboard layouts and settings are synchronised between your own devices using CloudKit's private database. Calendar and non-camera HomeKit panels also sync their latest rendered value by default so unsupported screens can display it. A Health panel does so only if you explicitly turn that option on. That database belongs to your Apple Account; the developer has no access to it.
- In the system Keychain. Web clip passwords, Nest sign-ins and K12 credentials are device-only Keychain items. Some connector addresses and tokens entered directly in a panel are also part of that panel's settings and therefore follow the board through private iCloud when sync is enabled.
Services you connect
Status Board can show data from services you choose to configure — among them Canvas / Instructure, K12 OLS, GitHub, App Store Connect, Supabase, Tessie, RSS feeds, web server logs, MCP servers and weather. When you configure one, your device talks to that service directly. Nothing is proxied through, relayed by, or copied to the developer. Your relationship with each of those services is governed by that service's own privacy policy, not this one.
Vehicle location and speed limits
A Tesla panel reads your vehicle's state from Tessie using an API key you provide. That includes its location, which the panel can draw on a map. The map is rendered by Apple Maps on your own device.
Neither Tesla nor Tessie publishes the posted speed limit for the road a car is on. When — and only when — a Tesla panel is configured to show speed and the vehicle is moving, the app looks the limit up in OpenStreetMap by sending the vehicle's coordinates to overpass-api.de. Nothing else is sent: no API key, no VIN, no vehicle name, and no identifier of any kind. No request is made while the car is parked, and results are reused rather than re-queried while the car stays on the same stretch of road. Remove the Speed field from the panel and no request is ever made.
Your location
A weather panel can be set to follow this device. When it is — and only then — the app asks the system for your location, uses it to fetch a forecast, and keeps the last position on the device so the panel still has something to show before the next fix arrives. The coordinates are sent to the forecast service only as the latitude and longitude of the request. They are never sent to the developer, never attached to an identifier, and never stored anywhere other than on your own device. Every other way of choosing a location — a city, an address, a station, or coordinates typed in by hand — needs no location access at all, and you can revoke access at any time in Settings.
Searching for a city or an address sends what you typed to Apple's geocoder and to Open-Meteo's place index in order to turn it into coordinates. The answer is cached on the device so the same search is not repeated on every refresh.
Weather stations
A weather panel pointed at a public observation station reads it from that network's own public API — the US National Weather Service, or NOAA's aviation weather service — with no account and no key. A panel pointed at your own weather station reads it at the address you give, which is normally a machine on your own network; that request never leaves your network and never passes through anything the developer runs.
Background images
If you give a board or a panel an image URL, your device downloads that image directly from the address you entered and caches it locally. The built-in wallpapers are drawn by the app itself and fetch nothing.
Calendar and Health data
Calendar panels read upcoming events with your permission. Their latest rendered event feed — including displayed titles and start times — syncs through your private iCloud database by default so Apple TV can show it. You can turn this off for each panel.
Health panels read a small set of values (steps, active energy, exercise minutes, heart rate) from HealthKit, with your permission, in order to display them. The app requests read-only access and never writes to HealthKit. Health stays on the reading device by default. If you explicitly enable cross-device value sync for a Health panel, only that panel's latest rendered value or aggregate is copied to your private iCloud database; raw samples and history are not. You can revoke access at any time in the Health app.
Your home
HomeKit access is read-only. Status Board never controls an accessory or records a camera stream. A HomeKit panel's latest rendered sensor or thermostat value syncs through your private iCloud database by default so a Mac without HomeKit access can show it; you can turn this off per panel. Camera frames and thermostat history are never written to iCloud.
Web clips
Web clip panels render pages you specify inside a sandboxed web view on your device. Content blocking based on the open EasyList and EasyPrivacy filter lists is enabled by default, which blocks common advertising and tracking requests. Cookies belong to the app's own web data store and are not shared with Safari or with us. If you save a site's sign-in details for automatic login, they go into the Keychain on your device.
Local network
The macOS app can act as a bridge that relays dashboard values to your other devices over your local network, discovered with Bonjour. That traffic stays on your network. It does not pass through the internet or through any server we operate. Board definitions sent by the bridge, and JSON files you explicitly share, omit connector tokens, private keys, MCP headers and recognisable credentials in URLs.
Children
Status Board is not directed at children and collects no data from anyone, including children.
Changes
If this policy ever changes, the revised version will be posted at this address with a new date.
Contact
Questions about privacy: i@am.guru