Cava Guard collects nothing about you. This page is short because there is little to say.
Nothing. Cava Guard has no account system, no analytics, no advertising, no crash reporting and no third-party SDKs of any kind. We do not receive your temperature readings, your device identifiers, your location or your usage of the app, because there is no server of ours for them to be sent to.
Cava Guard is a client for a server you run. Temperature readings travel from the sensor in your fridge, to the Raspberry Pi on your own network, to your phone. We are not in that path at any point.
| Server addresses and names | The addresses you enter, and the name each server reports for itself. Held in the app's own preferences. |
|---|---|
| Access tokens | Held in the iOS Keychain, not in preferences, and marked so that they are never migrated to a new device and are unavailable while the phone is locked. |
| Last-contact timestamps | When each server was last reachable, so the app can warn you if one goes quiet. |
All of it is removed when you delete the app.
To receive alerts, your phone obtains a push token from Apple and the app gives it to your server. Your server uses it to ask Apple to deliver a notification to your phone. Apple therefore handles the delivery, as it does for every iOS app; Apple's own privacy policy governs that step. The notification carries only what your server puts in it — typically a sensor name and a temperature.
The app connects only to the server addresses you configure. It contacts no other host. If you enable remote access, the connection to your own server runs over Tailscale, whose privacy policy applies to that service.
Cava Guard is not directed at children and collects no personal information from anyone.
If this policy ever changes, the revised version will be posted here with a new date. Since the app collects nothing, a change would most likely mean a new capability — and we would rather say so plainly than quietly widen a sentence.