Mando TV

Privacy policy

Privacy Policy

Last updated: 23 August 2026

Short version

Mando TV does not collect, store or transmit any personal information. It talks only to your television, over your own local network. The one exception is entirely in your hands: if something breaks, you can choose to send a diagnostic report. You see the whole thing first and you pick where it goes. See Sending a diagnostic report.

What the app does with data

The app handles three kinds of information, all of it on your phone only:

None of this leaves the device. There is no account, no cloud sync and no backup to our servers, because there are no servers.

Sending a diagnostic report

If something goes wrong, the app can produce a report to help fix it. This is the only way anything ever leaves your phone, and it happens only because you chose to send it.

The report contains the app and Android version, your phone's model, which kind of connection the phone is on (Wi-Fi, mobile data, none — not which network, and never its name), and a log of what the app did — which includes the name of your TV and the addresses of your TV and this phone on your local network. Local addresses like 192.168.1.42 mean nothing outside your own network. When you open the report, the app also asks the network once who else is there and lists any other televisions that answer, by address and by the description they broadcast — this is how a report about a TV the app cannot control can say what it is instead of saying nothing. Only televisions are listed: anything identifying itself as a router, a printer or another kind of device is left out, and so is your Wi-Fi's name. The report never contains your pairing code, the secret derived from it, your TV's hardware address, or any part of the private key. The log it draws on is kept in memory only, is limited to the most recent few hundred lines, and is discarded when the app closes. It is never written to storage.

The app reads that connection type outside the report too, to tell you when the phone is on mobile data and so cannot reach a television at all. It is read on the phone, shown on the phone, and stored nowhere.

What the app does not do

Network access

The app declares the INTERNET permission because Android requires it for any network socket, including one that only ever reaches your local network. The app does not connect to any host outside your local network. It also declares ACCESS_NETWORK_STATE, so it can tell you when you are not on Wi-Fi rather than silently finding no TVs.

CHANGE_WIFI_MULTICAST_STATE lets the app ask your Wi-Fi hardware to stop discarding multicast traffic while it looks for a television. Wi-Fi chips drop that traffic when idle to save power, and some televisions are only found that way. It grants no access to your data and none to any network beyond your own.

ACCESS_LOCAL_NETWORK is what Android 16 requires of any app that talks to devices in your home rather than to the internet, which is all this app does.

Some televisions offer only a volume control and no pairing of any kind. For those the app stores nothing at all — there is no credential to keep — and the commands travel across your network unencrypted, because that is the only thing those sets accept. It also means anyone else already on your network could change their volume, with or without this app. Nothing leaves your network either way.

On Android 16 and later, Android may ask you to allow that one the first time the app looks for a television — whether it asks depends on the phone. Where the system does require it, no television can be found until you allow it. It is the only permission this app will ever ask you about, and the app searches either way rather than waiting for an answer.

Those are the only permissions the app asks of you, and none gives access to your location, contacts, camera, microphone or files. A build also contains a permission React Native generates for its own internal use, named after this app's package and usable by nothing else; it grants no access to your device.

Data deletion

Uninstalling the app, or clearing its data from Android Settings, permanently destroys the private key and every stored pairing. Nothing is retained anywhere else, so there is nothing further to request the deletion of. If you sent a diagnostic report by email, ask at the address you sent it to and it will be deleted. You may also want to remove the pairing from the TV's own settings.

Children

The app collects no data from anyone, including children.

Changes

Any change to this policy will be recorded in this file and in the project's CHANGELOG.

Contact

Questions about this policy: write to felipesmsoto@gmail.com, or on WhatsApp at +56 9 6292 7020.

← Back to Mando TV