Privacy
Privacy policy — SmartHome
Valid from 7 October 2026
This policy covers the SmartHome app for Android, iPhone and iPad — the app that opens your property's gate when you arrive, shows the property's cameras and UPS, and tells you when the gate was left open. In short: the app works with your own property's devices, your position is read on the phone and used for the gate alone, and there are no ads, no analytics and no third parties.
Who we are
MagicWeb.org eOOD, Sofia, Bulgaria, makes the SmartHome app, runs this website and runs the servers at magicweb.org the app signs in to. We are the controller of the data this policy describes. You reach us at the address under Contact.
Your account
You sign in with an e-mail address and a password. The account is created on this website (ISUPortal.com) or on MagicWeb.org and is kept by our identity server at magicweb.org (Keycloak); the app has no registration of its own. On our side the account is your e-mail address, your name and a hash of the password.
After the sign-in the phone keeps a refresh token — a key that lets the app stay signed in and fetch a fresh access token at every start and every few minutes. The password itself is never stored on the phone. Signing out removes the key; a password change or a session we revoke invalidates it, and the app returns to the Login screen.
Face ID, Touch ID, a fingerprint or the app PIN unlock the kept session on the phone. The phone's operating system tells the app only whether it recognised you; the app never sees your face or your fingerprint.
What the app keeps on your phone
The app keeps its data in its own settings on the phone, and nowhere else:
- your settings — the switches, the units, the active hours, the minutes after which a gate left open is reported;
- the property's gate: its address on the home network and the relay address, its access token, its coordinates, and the gate's last known state;
- the geofence radius you set;
- the app PIN as a salted hash — never the PIN itself;
- the account's e-mail address and name, and the refresh token described above;
- the addresses of the property's cameras (with their credentials, as the property configured them), of its UPS and of its RSIHome computers;
- a journal of what the app did — an arrival, a departure, a pulse to the gate — up to 500 lines.
Uninstalling the app deletes all of it.
Location and the geofence
The app uses the phone's location — also in the background — for one purpose: to open the gate automatically when you arrive within the radius you set (and, if you switch it on, to close it when you leave), and to show your distance to the gate. The position is read on the phone and compared with the gate's coordinates there; the decision to open or close is made on the phone.
Your location is never used for advertising and never handed to a third party. Your last position fix, your distance to the gate and your speed are part of the status report the app sends to your property's own RSIHome computer (see Reports to your property's computer) — to nobody else, and we keep none of it.
You can switch the geofence off under Settings › Gate perimeter; the app then uses no location at all, and you open the gate by hand. You can also take the location permission away in the phone's settings; the manual controls keep working.
Notifications
With your permission the app shows notifications on the phone: the gate opened or closed automatically on your arrival or departure, and the gate left open — "still open — open for 15 min — close it?" with a Close action that closes it. They are local notifications, made on the phone; no push service of a third party is involved.
When the gate stands open past your minutes and your app is not running, our relay sends one e-mail to your account's address with a link to a page that closes the gate. Settings › General › Notifications turns the notices off; the minutes under Settings › Gate perimeter › Notify when left open set to Off turn the e-mail off.
Cameras and the UPS
The app shows the property's own cameras and UPS, over your account. At home it plays the cameras' streams directly over the local network. Away, it fetches single pictures through our relay (see below); the pictures pass through the relay on their way to your phone and are not kept there. The app records and stores nothing of the streams.
The relay — how the gate commands travel
At home the app talks to the gate's controller over the local network. Away, its commands travel over RSI's own relay at magicweb.org: the request goes to our server, which hands it to RSI's agent inside your property's network and returns the answer. No service of a third party is between the phone and the gate.
Each request carries your account's e-mail address and the gate's token, so the gate knows who pressed. The relay remembers who pressed last, when, and whether that person's app is running — the facts the left-open notice is built on — and keeps nothing else of a request: no command history, no location.
Reports to your property's computer
While it runs, the app reports its status every few seconds to the RSIHome computers of your property — the household's own desktop app, on the property's own network: the device's name and model, the app's version, the last position fix, the distance to the gate, whether you are inside the radius, the gate's state and the app's journal. The report lets the household see its devices on one screen.
At home the report goes over the local network. Away, it goes through our relay, which passes it on and keeps nothing. These reports stay on your property's own computer; we do not receive them.
Permissions and why
On Android the app asks for exactly these permissions:
- Location — precise, approximate and in the background — for the geofence described above. "In the background" is what lets the gate open while the phone is in your pocket.
- Notifications — for the notices described above.
- Internet and network state — to reach the gate, the cameras, the UPS, the sign-in and the relay, and to know whether the phone is on a network.
- Install packages, and update without a second confirmation — the app updates itself from your property's own update server (an RSIHome computer on the home network); the download's checksum is verified before Android's installer is asked. You start every update yourself.
- Display over other apps — so the installer's dialog and the update's progress can appear in front of the running app.
The app asks for no Bluetooth, no camera, no microphone, no contacts and no storage permission.
On iPhone and iPad the app asks for Location (While Using and Always — the background mode is Location), Face ID, the local network (to talk to the gate's controller at home) and Notifications.
Retention and deletion
On your phone the data stays as long as the app is installed; uninstalling the app deletes it. On our side we keep your account — e-mail address, name, password hash — at the identity server for as long as the account exists, and the relay's note of who pressed last; no command history and no location.
Write to the address under Contact from the account's e-mail address and within 30 days we delete your account and everything stored under it, unless a law obliges us to keep a record longer.
No third parties
We hand your data to no one. No advertising network, no analytics service, no crash reporter and no third-party SDK is part of the app. Besides your property's own devices, the only servers the app talks to are ours at magicweb.org, rented in the European Union (Germany).
This website
ISUPortal.com keeps your language choice, the last page you opened and whether you accepted the cookie notice in your browser's storage. Signing in here uses the same account. The contact form sends what you typed to our mailbox and nowhere else.
Contact
Questions, access to your data, a correction or a deletion: info@magicweb.org
Changes
When this policy changes, the new version appears here with a new date.