Legal
Smart Home Codes stores the pairing codes for your Matter smart-home accessories, so you can throw the paper labels away. Everything it holds stays on your device and in your own iCloud account, and the codes themselves are encrypted. There is no Arnstad Holding server in the picture, and nothing you put into the app reaches us.
This policy covers the iOS app Smart Home Codes, which appears as "Home Codes" on your device (bundle identifier com.arnstad.MatterCodes), published by Arnstad Holding AS. Our other products are covered by the general privacy policy.
The app is somewhere to keep the pairing codes for your own Matter accessories. It reads your accessory list from Apple's Home app so you do not have to type out an inventory, and you attach a code to an accessory by scanning the QR code on its label or entering the digits by hand.
That is all it does. The app cannot pair with an accessory, control one, or send it a command — not as a matter of policy, but because the capability is not built into it.
Nothing.
There are no accounts, no analytics, no crash reporting, no advertising and no third-party SDKs. We run no server for this app, so there is nowhere for your information to be sent even in principle.
On your device, and in your own private iCloud database (CloudKit) under your Apple Account. Apple handles syncing between your devices. We are not a party to any of it: we cannot see that database and hold no copy of what is in it.
Before anything is written to storage, on the device or in iCloud, the app encrypts it with AES-GCM. That covers:
The key is generated on your device and kept in the keychain. It travels to your other devices through iCloud Keychain and by no other route. It never reaches us.
Accessory names, rooms, manufacturers and model names are stored as plain text, so that search can work without decrypting every record first.
This is a deliberate trade rather than an oversight. Those details already exist in HomeKit and are visible to Apple through it, so they are not secrets. The pairing code — the part that would actually matter if someone else saw it — is always encrypted.
The app asks for HomeKit access so it can read the list of accessories in your home and show them to you. That is the extent of it: it issues no commands, and nothing it reads leaves your device.
Camera access exists so the app can scan the QR code printed on an accessory label. Frames are processed on your device while you hold it over the label and then discarded — not saved, not sent anywhere. The one exception is a label photo you deliberately choose to keep, which is encrypted along with everything else.
Delete a code in the app and it is gone. To remove everything, delete the app and then clear its iCloud data from the Settings app, under your Apple Account → iCloud → Manage Account Storage.
After that, no copy survives anywhere. There is nothing left for us to delete, because we never had it.
Arnstad Holding AS is a Norwegian company, so the GDPR applies to us. It gives you the right to see the personal data a company holds about you, to correct it, and to have it erased. Those rights are simple to satisfy here: this app gives us no personal data about you, so there is nothing for us to disclose, correct or erase. If you would like that confirmed in writing, write to privacy@arnstad.com and we will confirm it.
The app collects nothing from anyone, children included. There are no age-gated features because there is nothing to gate.
If the app changes in a way that affects this policy, we will update this page and change the date at the top.
Arnstad Holding AS
Akersbakken 23C, 0172 Oslo, Norway
For questions about this policy or about how the app handles your data, write to privacy@arnstad.com. For help using the app, see our support page or write to support@arnstad.com.
One note that concerns arnstad.com rather than the app: this site uses Simple Analytics to count page views. It sets no cookies, records no personal data and does not follow visitors between sites. The app itself contains no analytics of any kind.