Bedside — Privacy Policy
The short version
- Bedside has no accounts. We add no analytics or tracking SDK of our own — Firebase Analytics is not in the App. The only advertising is a short video you can choose to watch to earn more listening sessions: never while you are monitoring, and never if you own Bedside Household.
- Sound and video go from one phone on your Wi‑Fi to the other. We do not upload them. There is no Bedside server.
- Android only: you can turn on crash reports in the app. They are off unless you turn them on, and they never include sound, video, room names, or codes.
- The room name you type is stored only on that phone.
- This is not a medical or life‑safety device.
This policy explains how HMB Software LLC (“HMB Software,” “we”) handles information in the Bedside apps for iPhone and Android (the “App”). By using the App you agree to this policy and to our Terms of Use.
1. Who we are
Bedside is published by HMB Software LLC. Privacy questions: privacy@hmb-software.com.
2. What the App does
Bedside is a local two‑phone monitor. One phone (“This Room”) captures microphone audio and, if you allow it, camera frames. The other phone (“I Listen”) plays that audio and shows those frames. Both phones must be on the same Wi‑Fi network. Discovery uses Bonjour / local DNS‑SD. The stream is a direct TCP connection on your LAN, unlocked with a 6‑digit code shown on the room phone. You can type that code or scan the QR next to it; scanning uses the listen phone’s camera on that device only.
The 6‑digit code is not a password for the internet. Anyone on your Wi‑Fi who can see the room phone and type the code can connect. Use a network you trust. Leave is the way to stop the session and pick a new code.
3. Information the App handles
Microphone and camera
With your permission, This Room reads the microphone (required) and camera (optional). That audio and those JPEG frames are sent only to the paired listener on your local network. They are not sent to HMB Software. They are not stored by us. When the session ends, the in‑memory stream ends. You can deny camera access and still use audio only. The listener microphone stays off until you hold Hold to talk.
I Listen may also use the camera on that phone, on‑device only, to read the pairing code shown on This Room. Those frames never leave the listen phone and are never sent on the LAN. You can deny that permission and still type the code.
Local network
The App uses local network / nearby Wi‑Fi access so the two phones can find each other. It does not use your location. It does not need the public internet to work.
Room name
The display name you type (for example “Bedroom”) is stored in on‑device preferences (UserDefaults / SharedPreferences) so the next launch remembers it. It is also advertised on the local network as the Bonjour service name and a TXT record so the other phone can label the room. It is not sent to us.
Device name
When you connect, the App may send the phone’s existing device name (the name already set in system settings) to the other phone so the UI can say who connected. That stays on the two phones.
App settings check (both platforms)
Each time the App starts it asks Google Firebase Remote Config for a small settings file. That file is how we turn the rewarded video described in section 4 on or off without shipping an update. To make that request, Firebase gives your installation of the App a random identifier (a Firebase installation ID) and sends it with the request, so Google receives that identifier and your device’s network address, as it would for any request to a server.
That identifier is generated by Firebase, is specific to this installation, and is reset if you uninstall the App or clear its data. It is not your advertising identifier, and it is not linked to any account, because there are none. The request contains no room name, no 6‑digit code, no address of the other phone, and no audio or camera data. Nothing about you is sent to us — we receive no report from it, and the settings file travels one way, from Google to your phone.
This happens on iPhone and on Android, and it does not depend on the crash‑report switch below.
Crash reports (Android, optional)
The Android app can send crash reports through Google Firebase Crashlytics. This is off when you install the App. It only starts if you turn on Send crash reports on the Bedside home screen, and turning it back off stops further collection.
When it is on and the App crashes, the report includes the technical stack trace, the screen you were on and whether a session was running, and the standard diagnostic details Crashlytics attaches: your Android version, device model, app version, memory and storage state, and an identifier Crashlytics generates for the installation. Google receives the upload and therefore your device’s network address, as it would for any request to a server.
Crash reports never contain microphone audio, camera frames, your room name, the 6‑digit code, the address of the other phone, your advertising identifier, or any account of yours — we do not have one. Google processes these reports for us as a service provider; see Firebase’s privacy information.
What we do not collect
- No account, email, or phone number
- No analytics or tracking SDK added by us — Firebase Analytics is not in the App at all
- No Android advertising identifier — the App removes that permission (section 4)
- No crash reports unless you switch them on (Android only; iOS has none). iPhone still makes the settings check described above.
- No cloud backup of audio or video
- No sale of personal information
4. Rewarded video and Bedside Household
The only advertising in Bedside is a video you choose to watch. Being the room is always free and never limited. Listening is free too, with a set number of sessions to start. If you run out you can watch a short video to earn more, buy Bedside Household once to remove the limit, or simply keep listening anyway — running out never stops you monitoring a room.
There are no banner ads, no full‑screen ads between screens, and no ads that start on their own. No ad is requested or shown while you are listening to a room, or while this phone is acting as This Room. If you own Bedside Household you are never offered one.
When — and only when — you choose to watch a video, the App starts the Google Mobile Ads SDK (AdMob) and requests one ad. Google receives the technical information it needs to serve and measure that video, such as device and app characteristics, app interactions, and an approximate region derived from your network address. Bedside does not send Google your room name, your 6‑digit code, the other phone’s address, any audio, or any camera frames. See Google’s privacy policy.
Before the first ad request in regions that require it, the App asks for your choice using Google’s User Messaging Platform. On Android, Bedside removes the advertising‑ID permission from the App; that is Google Play’s documented way to opt out of advertising‑ID collection, and on Android 13 and later the system returns a zeroed value to an app that does not declare it. The ads SDK identifies the installation with the App Set ID instead, which is scoped to us and needs no permission. On iPhone, Bedside never asks for permission to track you across other companies’ apps, and does not do so.
Bedside Household is a one‑time purchase handled entirely by the App Store or Google Play. We never see your payment details. Your purchase is confirmed with the store you bought it from and remembered on that device, so it keeps working offline. There is no Bedside account, and the two stores are separate — buying on one platform does not unlock the other.
5. Children
Bedside is for caregivers. The person who installs and operates the App should be an adult. The App is not directed at children under 13 as users, and we do not knowingly collect personal information from children. A child who happens to be in a room that is being monitored is not creating an account with us; we never receive that audio or video.
6. Retention and deletion
We do not hold a copy of your sessions. Uninstalling the App removes the locally stored room name. Ending a session (Leave) drops the live connection. There is no “download my data” pack because we do not have your data.
7. Your rights
If you believe we hold personal information about you, email privacy@hmb-software.com. For this App the usual answer is that we do not. You can also revoke microphone, camera, or local‑network permission in system settings, which stops those features.
8. Third parties
The App uses operating‑system APIs (camera, microphone, Bonjour / Network Service Discovery, notifications). Those are governed by Apple’s and Google’s own policies. HMB Software does not insert a third‑party analytics or tracking SDK. The App does include the Google Mobile Ads SDK and Google’s User Messaging Platform for the rewarded video described in section 4. Neither is started when the App launches, and neither is started while this phone is acting as This Room.
Both apps include Google Firebase Remote Config, and the Firebase Installations library it depends on, for the settings check described in section 3. That one runs at every launch on both platforms. Firebase Analytics is not in either app.
The Android app also includes Google Firebase Crashlytics for the optional crash reporting described in section 3, along with the sessions and data‑transport libraries it depends on. Those stay dormant unless you turn crash reports on. The Firebase Cloud Messaging library is also present in the Android build, but Bedside registers no push token and we operate no server that could send you a push message.
9. Apple Privacy Nutrition Labels and Google Play Data safety
The App accesses UserDefaults / local preferences only to remember the room name you typed (CA92.1 on iOS). Microphone, camera, and local network are used on‑device and on your LAN as described above, not as data we collect.
The Android Data safety form declares Crash logs — App functionality and Diagnostics, optional, not shared, collected only with your consent — for the opt‑in crash reporting in section 3. It also declares what the Google Mobile Ads SDK collects if you choose to watch a rewarded video: approximate location derived from your network address, app interactions, diagnostics and crash logs, and device or other IDs, for advertising, analytics, and fraud prevention. The advertising‑ID box is not ticked, because the App removes that permission. Device or other IDs also covers the Firebase installation ID sent by the settings check in section 3, which happens at every launch rather than only around a video. The Play listing declares that the App contains ads and a one‑time in‑app purchase. iOS has no crash reporting; the same rewarded‑video collection applies on iPhone if you choose to watch a video, and the settings check applies there too.
10. Not a medical device
Bedside is a consumer convenience for hearing another room on your Wi‑Fi. It is not a medical device, not a substitute for in‑person care, and not a dedicated life‑safety pager. Phones sleep, radios drop, and apps get killed. If someone in that room needs reliable overnight monitoring, use a purpose‑built device and a person who can respond.
11. Changes
If we update this policy we will change the date above. The current version lives at https://www.hmb-software.com/bedside/privacy.
12. Contact
HMB Software LLC
Email: privacy@hmb-software.com
Site: https://www.hmb-software.com