liutimo

Homa Privacy Policy

Effective Date: August 9, 2026
Last Updated: August 9, 2026

This Privacy Policy explains how LiuZheng, the developer of Homa (“Homa,” the “App,” “we,” “us,” or “our”), handles information when you use Homa.

Homa is designed primarily as a local client for servers and NAS devices that you choose. Homa does not require a Homa account and does not use a developer-operated cloud backend to store your server credentials, terminal content, or server data. Some features, however, communicate directly with servers and third-party services selected by you, and limited public resources may be fetched as described below.

1. Scope

This Policy applies to Homa. It does not govern a server, NAS, website, API, AI provider, app marketplace, content delivery network, or other third-party service that you access through Homa. Those services process information under their own policies.

2. Information Stored on Your Device

Depending on the features you use, Homa may store the following locally:

Sensitive secrets are stored using the Apple Keychain with device-only accessibility where supported. Other configuration and preferences may be stored in the App’s local container, including UserDefaults. Device-only Keychain items are not intended to sync through iCloud.

We do not receive this locally stored information merely because you use Homa.

3. Connections to Your Servers and Services

When you connect to a server or integration, Homa communicates from your device directly with the destination you configured. Information transmitted may include:

The server or service operator—including you, your organization, or a third party—determines how that destination logs, retains, and uses the information. Homa does not route these connections through a developer-operated relay.

You are responsible for choosing trusted destinations and for configuring secure transport. If you choose an unencrypted protocol, an HTTP endpoint, a server with an unverified host key, or an otherwise insecure configuration, information may be exposed in transit.

You assume the risks associated with each destination and connection you configure. Homa cannot determine whether you are authorized to access particular data, whether a destination is trustworthy, or whether its operator will protect information appropriately.

4. Optional AI Features

Homa’s AI-assisted features are optional. When you configure and use an AI provider, Homa sends requests directly from your device to the provider endpoint you select. Depending on the feature, a request may include:

Homa also sends the API key or authorization headers required by the selected provider. API keys are stored locally in Keychain, but the selected provider necessarily receives credentials when authenticating a request.

Do not send secrets, personal information, confidential logs, or regulated data to an AI provider unless you are authorized to do so. The provider may log, retain, use, or transfer request and response data according to its own terms and privacy policy. Your selection may cause data to be processed in another country or region. We do not control the provider’s practices.

Homa may include presets for providers such as OpenAI, Anthropic, OpenRouter, or DeepSeek, and may allow a custom or self-hosted endpoint. A preset is a convenience and does not mean that the provider sponsors or operates Homa.

5. Public Assets and Update Requests

To display operating-system or application icons, Homa may request public metadata or image assets from services such as GitHub-hosted content and jsDelivr. Development or preview builds may also request update information from a developer-operated website. These services may receive standard network information automatically included in an internet request, such as your IP address, request time, requested URL, and user-agent or device networking information.

Opening an external link or website causes your device to connect to that destination under its privacy policy.

6. Purchases

If Homa offers paid features, purchases and subscriptions are processed by the app marketplace, such as Apple’s App Store. We do not receive your full payment card number or bank credentials. The marketplace may provide purchase status, product entitlement, transaction identifiers, region, and related information needed to provide or restore a purchase. The marketplace handles this information under its own privacy policy.

7. Information We Do Not Collect for Our Own Purposes

In the current version of Homa:

This does not mean that destinations you choose—including servers, AI providers, websites, content delivery networks, and marketplaces—collect no data. Their processing is separate from ours.

To the extent we process personal information, we do so to:

Where applicable law requires a legal basis, processing is based on performing our agreement with you, your consent or instructions, our legitimate interests in providing and securing Homa, and compliance with law, as appropriate. You may withdraw consent for optional features by stopping their use or removing their configuration.

9. Retention and Deletion

Local configuration remains on your device until you remove it in Homa, erase applicable app data, or the operating system removes it. You can delete individual servers, SSH keys, provider profiles, and integration settings within the App where those controls are available.

For the most complete deletion, remove sensitive configurations in Homa before uninstalling it. Apple’s operating system controls uninstall behavior, and some Keychain items may persist after an app is deleted. Information already sent to a server or third-party provider must be deleted through that destination, subject to its policy and retention rules.

If you email us for support, we may retain the correspondence as reasonably necessary to respond, maintain records, prevent abuse, and comply with law. Do not include passwords, private keys, API keys, or unnecessary server output in support messages.

10. Security

We use platform security features and design measures intended to protect locally stored credentials, including Apple Keychain storage for supported secrets and SSH host-key verification. No method of storage, transmission, or software security is guaranteed to be completely secure.

You are solely responsible for securing your device, server, accounts, credentials, backups, network, SSH and API configuration, and for using least-privilege credentials. You are also responsible for reviewing host-key warnings, restricting physical and remote access to your device, installing updates, and responding to suspected compromise. Homa cannot protect information after it reaches a destination you selected and does not guarantee that local storage or any connection will prevent unauthorized access, interception, disclosure, deletion, or loss.

11. Children’s Privacy

Homa is a technical server administration utility and is not directed to children. We do not knowingly collect personal information from children through a Homa account or developer-operated backend. A minor should use Homa only with the involvement and permission of a parent or legal guardian and only where permitted by applicable law.

If you believe a child has provided personal information directly to us, contact us so we can review and, where appropriate, delete it.

12. International Data Transfers

We do not centrally transfer your locally stored server data. However, when you connect to a server, AI provider, content delivery network, website, or other endpoint in another country or region, your device sends information to that destination. You are responsible for selecting the destination and ensuring that any transfer is lawful. The destination’s safeguards and privacy policy apply.

13. Your Data-Protection Responsibilities

When you use Homa to access, view, transmit, or otherwise process information belonging to another person, you—not the developer—determine the destination, purpose, content, credentials, commands, and manner of that processing. To the extent applicable, you or the organization on whose behalf you act are responsible for acting as the data controller or business and for:

Homa is a user-directed technical tool and does not independently determine these purposes. The developer assumes no responsibility for your handling of third-party data or for the practices of a server or provider you select, except to the extent responsibility cannot be excluded under applicable law. The disclaimers and limitations in the Homa Terms of Use also apply to your use of Homa.

14. Your Privacy Rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to certain processing of personal information, receive a portable copy, withdraw consent, or complain to a privacy regulator.

Most Homa information is stored only on your device or sent directly to a destination you select, so we may not possess or be able to identify it. Use the App’s controls or contact the relevant server or service provider for that information. For information you have provided directly to us, you may contact us using the details below. We may need to verify your request and may retain information where permitted or required by law.

Homa does not sell personal information or share it for cross-context behavioral advertising as those terms are commonly defined in applicable U.S. state privacy laws.

15. Changes to This Policy

We may update this Policy to reflect changes to Homa, our practices, or legal requirements. We will publish the updated Policy and revise the date above. Where required, we will provide additional notice or request consent.

16. Contact Us

For questions, privacy requests, or concerns, contact: