Wevival — Privacy Policy
Effective date: July 20, 2026 Version: privacy-v1-2026-07-20 Operated by: IHS Web Design LLC, doing business as Teagles Consulting, operating wevival.app
Short version: you can use Wevival without an account, and we never see what you switch on and off. If you do create an account, we collect the least we can get away with, we don’t sell anything, we don’t run ad trackers, and you can delete all of it whenever you want.
The long version follows, because a privacy policy should actually describe what happens.
1. There are two ways to use Wevival, and they are very different
This is the most important section of this policy. Read this one even if you skip the rest.
Local-only mode — no account, and we never see your home
You can use Wevival without creating an account at all. In this mode the app talks directly to your plugs on your own Wi-Fi network.
In local-only mode:
- We hold no account for you. No email address, no display name, no sign-in.
- What you switch on and off, when, and what you named things — we never see any of it. Your plug names, your on/off history, and your schedules stay on your phone and your network.
- There is no account for us to sell, lose, or hand over.
Two things do leave your device, though, and we would rather tell you than have you find them.
1. An update check. On startup the app asks wevival.app whether a newer version exists. It is a bare request with no payload — it does not even tell us which version you are running. We see a public IP address and a timestamp, the same as any website visit. There is no identifier of any kind attached, so we genuinely cannot tell one install from another from one launch to the next.
2. A check on which plugs are already claimed. When the app scans your network and finds Wemo devices, it sends us the hardware serial numbers (UDNs) of those plugs and asks which ones are already claimed by an existing Wevival home. We answer yes or no for each — never whose home, never any detail. This exists so that a phone cannot wander into range and start controlling a neighbour’s plugs.
We do not store those serial numbers. Answering the question is a single lookup — we check them, reply, and keep nothing. No record of the request is written, no link between you and those serials is created anywhere, and the serials never appear in our logs. The only thing that briefly exists is a counter in memory that stops anyone hammering the endpoint, and it holds a number, not your serials. It is gone within minutes.
This check runs only while you are signed out. Once you sign in, the app uses the authenticated path instead.
What never reaches us in local-only mode: what you switch on or off, when you do it, what you named anything, your schedules, or anything else about your home. A phone that has never signed in creates no record on our servers at all.
Device details are stored only when a signed-in user deliberately adds a plug to a home — that is the product working as intended, and it’s described in the next section.
If you would rather neither of these happen, you can block wevival.app at your router and the app will keep controlling your plugs locally. You will stop being told when updates exist, which we do not recommend — some of them fix safety problems.
The trade-off is that local-only mode works only while you are on your home network. You cannot control your plugs remotely, you cannot share access with family members, and you cannot use schedules that run while you’re away.
If privacy matters more to you than remote access, use local-only mode. It is a complete, supported way to use this app, not a crippled trial.
Connected mode — with an account
If you want remote control, sharing with family, or schedules that run while you’re away, you create an account. That requires us to hold some information on our servers, because remote control is fundamentally a matter of us relaying your instruction to your home.
Everything in the rest of this policy describes connected mode only.
2. What we collect (connected mode only)
Your account
- Your email address
- A display name, if you choose to add one
- The date and time you confirmed your account
- Sign-in tokens
We use emailed magic links to sign you in. We never collect or store a password, because we don’t use them.
Your homes and devices
For each home you create: the name you gave it.
For each plug or switch you add:
- The device’s UDN (its built-in unique identifier, similar to a serial number)
- The friendly name you gave it
- The device type
-
Its local network address and port — a private address on your own network, such as
192.168.1.xor10.x.x.x. This is not a public internet address and cannot be used to locate you. - Its current on/off state and brightness
- Timestamps for the state you last requested
Your bridge phone
- The name you gave the phone
- A device identifier
- The app version it’s running
- When it was last seen, and whether it’s currently online
- A public key and pairing code, used to establish a secure link between the phone and our server
- Which plugs that phone can physically reach on your network
Sharing
- Which people have which roles in which homes, and any expiry date on that access
Technical logs
Like any web server, we log basic request metadata. We also read your IP address — as passed to us by Cloudflare — for one purpose: rate-limiting sign-in attempts so people can’t abuse the magic-link system.
3. What we do not collect
We want to be specific, because it’s a short list of things people reasonably worry about:
- No passwords — we don’t use them
- No advertising or analytics trackers. No Google Analytics, no Meta pixel, no Firebase, no Crashlytics, no ad network, no analytics SDK of any kind. The app does not include Google Play Services.
- No location data — and the app holds no location permission at all. There is no GPS or location code in it. Device discovery works by ordinary network traffic on the Wi-Fi you have already joined, not by scanning for Wi-Fi networks, so it never needs the location permission that scanning would require.
- No contacts, no photos, no microphone. The app can use your camera, for one purpose only: scanning a pairing QR code. Nothing is stored, and no image is ever transmitted.
- No payment information — the service is free and we have no payment system
- No browsing history or activity outside Wevival
4. How we use it
Only to run the service:
- Sign you in and keep you signed in
- Store the on/off state you want your devices in, and relay it to your bridge phone
- Show you your homes and devices, and who has access to them
- Send you the transactional emails the service needs to work (magic links, account confirmation)
- Prevent abuse and keep the service secure and available
- Diagnose problems
That’s the whole list. We do not use your information for advertising, profiling, or marketing, and we do not send marketing email.
5. We do not sell or share your data
We do not sell your personal information. We have never sold it and we have no plans to. We do not share it with advertisers, data brokers, analytics companies, or any third party for their own purposes.
The only companies that touch your data are the infrastructure providers we need to run the service at all:
| Provider | What it does | What it sees |
|---|---|---|
| Our VPS host | Runs the server and database | Everything stored above |
| Cloudflare | Sits in front of the site for security and DDoS protection | Request metadata and IP addresses |
| Brevo | Delivers our transactional email | Your email address and the contents of magic-link emails |
One flow we don’t control, and think you should know about anyway. When you install Wevival or one of its updates, Android’s built-in Google Play Protect scans the app, which means the app file or its fingerprint goes to Google. This is Android doing what Android does on every installed app — we don’t trigger it, we don’t receive the result, and we have no way to switch it off for you. We mention it because it happens during our install and you may see a Google prompt, and we would rather you knew where it came from. For what it’s worth, Wevival passes cleanly.
We may also disclose information if we are legally required to — a valid court order, subpoena, or other lawful demand — or where we believe in good faith it is necessary to prevent imminent physical harm or to protect the security of the service. We do not have a formal transparency report; we are one small business.
6. What we send off your network, and what we don’t
Worth being clear, because this is a local-network product:
Your bridge phone talks to your plugs directly on your own network. The commands themselves — the actual “turn on” instruction — travel from our server to your bridge phone, and then locally to the plug. The plug itself never talks to us, and never talks to Belkin.
What reaches our servers in connected mode is the desired state (on/off, brightness) and the device identifiers described above. We do not receive a stream of your household activity, we do not build a behavioural profile from your switching patterns, and we do not analyse that data for any purpose beyond operating the service.
We want to be careful about one thing here. In connected mode we necessarily hold the on/off state of things in your home, and timestamps for when you asked for them. That is enough raw material to infer patterns — when a house is occupied, when someone wakes up — if anyone chose to analyse it. We do not, and we will not. We use it to do what you asked and nothing else. If that ever changes, it would be a material change to this policy and we would tell you before it took effect, not after.
7. How long we keep it
We would rather describe what we actually do than promise a schedule we haven’t built.
- Your account and configuration — kept as long as your account exists. Delete your account and it goes.
- Inactive accounts — we do not currently delete accounts for inactivity. If your account sits unused, it stays until you delete it.
- Technical logs — our server keeps ordinary request logs. We have not yet set a fixed retention period for them, so they persist according to our server’s defaults. We intend to set a defined limit, and we will state the number here once it is real.
- Deleted data — removed from our live systems immediately and permanently when you delete your account. There is no soft-delete, no deactivated-account state, and no tombstone record left behind. We do take routine database backups, and a deleted account may persist in an older backup until that backup ages out; we have not yet set a fixed backup retention period, and we will state it here when we do.
If a specific number matters to you, email [email protected] and ask — we will tell you the truth rather than point at a policy.
8. Your rights — all of them, for everyone
Some privacy laws grant rights only to residents of particular places. We think that’s a silly way to run a free service, so we extend these rights to every user, everywhere, regardless of where you live:
- Access — get a copy of what we hold about you
- Correction — fix anything that’s wrong
- Deletion — delete your account and everything attached to it
- Portability — get your data in a machine-readable format
- Objection — tell us to stop processing your data (in practice, this means closing your account, since we only process what the service needs)
We will never discriminate against you for exercising any of these. There’s nothing to discriminate with — the service is free.
Deleting your account
You can delete your account from inside the app, yourself, at any time. You don’t have to ask us, give a reason, or wait. If you’d rather not use the app — or can’t get into it — email [email protected] from your account’s address and we’ll do it for you within 7 days.
Deletion is immediate and permanent. It cannot be undone. It removes your account, your sign-in tokens, your device records, your bridge-phone registrations, and your memberships.
Homes you share with someone else stay put. If another administrator shares a home with you, we remove you from it rather than delete something other people are still using to control equipment in a house that may not even be yours. A home where you are the only administrator is deleted outright, along with its devices, rooms, scenes and schedules — leaving it standing would strand a home nobody can administer.
Your bridge phone is unregistered everywhere, including from any home that survives. Once you’re gone, your phone stops relaying for anyone.
The one honest caveat: we take routine database backups, and a deleted account may persist in an older backup until that backup ages out. See Section 7.
To exercise any other right, email [email protected]. We’ll respond within 30 days.
9. Children
Wevival is not directed to children, and you must be at least 18 to create an account. We do not knowingly collect personal information from anyone under 13.
If you believe a child under 13 has given us information, email [email protected] and we will delete it.
We recognize that a home-automation product ends up in households with children. Nothing in the service is designed for or marketed to them.
10. Security
- All traffic to the site and app is encrypted in transit (HTTPS/TLS)
- Your bridge phone connects out to us over an encrypted TLS connection and authenticates with your account’s own sign-in token. We allow it to relay only for homes you are actually a member of.
- Nothing listens for inbound connections to your home, and no ports are opened on your router. The connection is always your phone reaching out to us, never us reaching in.
- We store no passwords, which removes an entire category of breach risk
- Sign-in attempts are rate-limited
- Access to production systems is limited to the operator
Being honest about the limits: no security measure is absolute, and we are a small free service without a dedicated security team. The plugs themselves are discontinued hardware that no longer receives firmware or security updates from Belkin — that is outside our control and worth factoring into what you connect.
If we become aware of a breach affecting your personal information, we will notify you as required by applicable law.
Found a security problem? Email [email protected]. We’d genuinely rather hear from you than not.
11. Where your data is
Our servers are in the United States. If you use Wevival from outside the US, your information is transferred to and stored in the US, which may have different data-protection laws than your country. By using the service you understand this.
12. Cookies, tracking, and Do Not Track
We use essential cookies only — the ones that keep you signed in and keep the site secure. We do not use advertising cookies, tracking cookies, or third-party analytics cookies. There is no cookie banner because there is nothing to consent to beyond what the site needs to function.
No third party collects information about you through Wevival. We allow no advertising networks, analytics providers, or other third parties to collect personally identifiable information about your online activities over time or across different websites or services, either through our website or through our app.
Do Not Track. Some browsers can send a “Do Not Track” signal. There is no industry consensus on what a service should do in response, so we do not respond to Do Not Track signals — but only because there is nothing for us to stop doing. We do not track you across other websites or services in the first place, whether or not you send the signal.
Reviewing and changing your information. You can review and update your display name and the names of your homes and devices at any time from inside the app, and you can delete your account there too. To review or correct anything else we hold, or to request a copy, email [email protected] — see Section 8.
13. Changes to this policy
If we change this policy, we’ll post the new version at https://wevival.app/privacy with a new effective date and version string. For material changes, we’ll notify you by email or in-app notice before they take effect.
14. Contact
IHS Web Design LLC, doing business as Teagles Consulting Ottawa County, Michigan, USA