Par Home Assistant Privacy Policy
This privacy policy applies to the Par Home Assistant Alexa skill. The skill is a private smart-home integration intended for authorized members of the skill owner's household in Canada.
Information processed
The skill uses account linking to authenticate an authorized Home Assistant user. To provide smart-home control, it may process:
- OAuth access and refresh tokens issued by Home Assistant;
- Home Assistant device identifiers, names, capabilities, and current states;
- Alexa smart-home directives, such as requests to turn a light on or off; and
- Operational metadata and error details needed to diagnose failures.
How information is used
Information is used only to authenticate the linked account, discover approved Home Assistant entities, carry out authorized smart-home commands, report device state to Alexa, and maintain the reliability and security of the integration.
Credentials and account linking
Home Assistant login credentials are entered directly on the Home Assistant authorization page. The Alexa skill and its AWS Lambda relay do not store the user's Home Assistant password. The skill relies on OAuth tokens issued by Home Assistant after the user approves account linking.
Sharing and service providers
Data needed to operate the skill may pass through Amazon Alexa, AWS Lambda, Cloudflare, and the linked Home Assistant installation. These services may process data according to their own privacy policies and service terms. The skill owner does not sell personal information and does not use it for advertising or marketing.
Retention
The skill does not maintain a separate user-profile database. OAuth tokens remain usable until they expire or are revoked. Limited operational logs may be retained by AWS, Home Assistant, or Cloudflare according to the configuration and retention settings of those services.
Security
Communications between Alexa, AWS Lambda, Cloudflare, and Home Assistant use HTTPS. Access is restricted through account linking and by an explicit Home Assistant entity allowlist.
User choices and deletion
An authorized user can stop future processing by disabling or unlinking the skill in the Alexa app and revoking the associated Home Assistant token. Operational logs can be removed by the skill owner from the relevant AWS or Home Assistant systems.
Children
This skill is not directed to children under 13.
Changes to this policy
This policy may be updated when the skill's functionality or service providers change. The effective date at the top of this page will be updated when material changes are made.
Contact
Questions about this policy may be directed to the administrator of the linked Home Assistant installation.