1. Who we are
Tilo is a Wi‑Fi remote control app for smart TVs, published under the Inovy brand (“we”, “us”). The controller of the personal data described here is Oğuzhan Aktay (individual developer, brand: Inovy), Türkiye. Postal address: Cumhuriyet Mah., Diyar Sk. No: 5, 16400 İnegöl, Bursa, Türkiye. Privacy contact: privacy@inovy.dev.
2. The short version
- No account.Tilo never asks you to sign up or sign in. It uses a random, anonymous ID.
- TV control stays at home.Your iPhone talks to your TV over your own Wi‑Fi. None of it passes through our servers.
- Voice stays on your iPhone.Speech is recognised on the device. The audio and the words never reach us.
- Typing goes only to your TV.What you type is sent to the TV and is never logged, by us or anyone we work with.
We do not sell your personal data.
3. Data we process
- Anonymous ID. On first launch Tilo signs in anonymously to our backend (Supabase, EU, Ireland) and receives a random user ID. With it we keep a small profile: your device’s language and region setting (for example “en-US”) and when the profile was created. We do not collect your name, email address or phone number, and there is no sign-up or sign-in.
- Local network access and your TVs. iOS asks whether Tilo may find devices on your local network. Tilo uses this only to discover TVs on the same Wi‑Fi (Bonjour/mDNS and SSDP) and to send them commands directly. TV control never leaves your local network and never goes through our servers. The TVs you save (the name you give them, the model, the platform, the IP address and, when available, the MAC address used to wake the TV) are kept only on your iPhone.
- Pairing keys. When you pair a TV, its pairing credential (a client key on LG webOS, a token on Samsung Tizen, a client certificate that Tilo creates and your Android TV approves; Roku needs none) is stored in the iOS Keychain on your iPhone, together with the TV’s security fingerprint where the TV uses one. None of it is sent to us. Forgetting a TV in Tilo deletes that TV’s key or token and its fingerprint. On Android TV, Tilo’s own client certificate is shared by all your Android TVs and stays in the Keychain until you delete Tilo (see section 7).
- Voice (Tilo Pro). The first time you tap the microphone, iOS asks for microphone and speech recognition permission. Tilo uses Apple’s on-device speech recognition only and does not fall back to Apple’s servers; if on-device recognition is not available for your language, voice control is not available. Audio is not recorded or saved. Simple commands such as “volume up” become key presses, and anything else is sent to your TV as search text. Audio and recognised text are never sent to us and never appear in analytics, crash reports or session replay.
- Keyboard (Tilo Pro). Text you type in Tilo’s keyboard is sent only to your TV, over your local network. It is never logged or stored by us and never appears in analytics, crash reports or session replay.
- Volume buttons. If this setting is on, Tilo reacts to your iPhone’s volume buttons while the remote is open and changes the TV’s volume instead. No audio is recorded.
- Analytics. Mixpanel (EU data residency) receives product events such as onboarding steps, permission answers, paywall views, purchases, the TV platforms found, pairing results (with an error reason when it fails), Pro feature use, connection drops and reconnect times. Events carry your anonymous ID and basic device and app details. They never contain what you type or say, TV names or your TVs’ IP addresses.
- Crash reports. Sentry (EU, Germany) receives crash and error reports with technical details: device model, iOS and app version, error codes and stack traces. Free-form text is removed before a report leaves your iPhone, and no personal data is sent.
- Session replay. Microsoft Clarity records how Tilo’s screens are used (taps, scrolling and layouts) so we can find confusing spots. It starts after the privacy prompts that follow your first TV connection. Text fields are masked, and recording pauses completely on the Keyboard and Voice screens, so what you type or say for your TV is never recorded.
- Advertising attribution. The Meta SDK (Meta Platforms) receives install and app events so we can measure our advertising, but only if you allow tracking in Apple’s App Tracking Transparency prompt. We show that prompt after your first successful TV connection, not at launch.
- Google consent tool. After your first TV connection, Tilo runs Google’s User Messaging Platform (UMP) for everyone, even while ads are turned off. It checks whether consent is needed where you live and, in the EEA and the UK, shows the consent form the law requires. Your answer decides whether ads may be requested and personalised; if you decline, we do not show Apple’s tracking prompt and Meta attribution stays off. Google receives technical device data to make this check.
- Ads (currently turned off). Tilo includes Google AdMob, but ads are switched off today, and AdMob loads and shows ads only while they are turned on. When they are on, the free version may show full-screen ads when you move between sections of the app, for example when you switch tabs or TVs, or open and leave Devices or Settings. Ads never appear during setup or pairing and never in response to a remote button press, and Tilo Pro has no ads. The free version may also offer an optional rewarded ad that unlocks Tilo Pro for 2 hours. Ads are personalised only if you allow tracking and, where Google’s consent form is shown, you also agree to personalised ads there; otherwise only non-personalised ads are requested. AdMob receives device data such as the advertising identifier (only when allowed), IP address and ad interactions. For a rewarded ad, AdMob sends our server a signed confirmation with your anonymous ID and a transaction ID, and we record the temporary Pro period.
- Purchases. Tilo Pro is bought through the Apple App Store; we never see your payment details. Adapty manages subscriptions and receives your anonymous ID (to link the subscription to it), purchase receipts and technical device data through its SDK. Our backend stores your Pro status: the product, the expiry date and whether it is a trial.
- Coupon codes. If you redeem a Tilo code, our backend checks it against stored hashes (codes are not kept in plain text) and records the redemption with your anonymous ID, the time and your new Pro end date. Failed attempts are stored with a timestamp so codes cannot be guessed. The code is never sent to analytics. Apple offer codes are redeemed in Apple’s own sheet.
- Feedback. If you use Help & feedback, we receive the category, your message and, only if you add it, your email address. If “Include technical info” is on, we also receive the app version and build, iOS version, device model and language, never anything you typed for your TV. Feedback is stored with your anonymous ID.
- Reminder notifications. Reminders, such as a nudge to connect your TV or a note the day before a free trial ends, are local notifications scheduled on your iPhone. They never include a TV name, an IP address or anything you typed. We do not use push notifications and do not collect a push token.
- Email. If you write to us, we receive your email address and what you write.
4. How we use it, and why we may
We use this data to run Tilo (finding, pairing and controlling your TVs, Tilo Pro, coupons and rewarded Pro), to understand how the app is used and improve it, to find and fix crashes, to show and measure advertising where it is enabled and you have agreed, to send the reminders you allow, and to answer your messages.
Our legal bases are: the contract with you for the app, subscriptions, coupons and feedback; your consent for tracking, Meta attribution and personalised ads; and our legitimate interest in understanding and improving Tilo (analytics and session replay), keeping it stable (crash reports) and preventing abuse (rate limits).
5. Who processes it for us
- Supabase (EU, Ireland): anonymous sign-in, database and server functions.
- Apple: App Store payments, on-device speech recognition, local notifications.
- Adapty: subscription management.
- Mixpanel (EU): product analytics.
- Sentry (EU, Germany): crash reports.
- Microsoft Clarity: masked session replay.
- Meta Platforms: advertising attribution, only after you allow tracking.
- Google: the User Messaging Platform (the consent check after your first TV connection, for everyone) and AdMob, only while ads are turned on.
Commands go straight from your iPhone to your TV. What your TV does with them is covered by its manufacturer’s own privacy policy.
6. Your choices
You can turn off Local Network, Microphone and Speech Recognition access for Tilo in iOS Settings at any time (Tilo cannot find or control TVs without local network access). Tracking stays off unless you allow it; change it in iOS Settings → Privacy & Security → Tracking. Where consent is required, Google’s consent form lets you make your choices. The Reminders and Phone volume buttons switches are in Tilo’s Settings, and notifications can also be turned off in iOS Settings. iOS may deliver reminders quietly to Notification Centre before you are ever asked; you can keep them or turn them off there. Forget a TV to delete its pairing key.
7. Retention and deleting your data
On your iPhone. Your saved TVs, settings and Tilo’s anonymous session are stored in the app and are removed when you delete Tilo. Pairing keys live in the iOS Keychain; forget a TV in Tilo to remove its key. iOS can keep Keychain items after an app is deleted; they stay on your iPhone and are never sent to us. If you reinstall Tilo, it starts with a new anonymous ID.
On our servers. Data linked to your anonymous ID (your profile, Pro status, coupon redemptions, rewarded Pro records and feedback) is kept while you use Tilo and until you ask us to delete it.
Asking us to delete it. Tilo has no account, so we can only find your data through your anonymous ID. The surest way: before you delete the app, open Settings → Help & feedback in Tilo and send “Delete my data”. The message reaches us linked to your anonymous ID, and we delete everything stored with that ID. You can also email privacy@inovy.dev with the subject Tilo data deletion; tell us roughly when you used Tilo and, if you subscribed, the purchase date (please do not send receipts or card details). We delete what we can match and reply within 30 days.
Purchase records held by Apple and Adapty, and analytics, crash and replay data already received by Mixpanel, Sentry, Microsoft Clarity, Meta and Google, stay with those providers under their own retention periods. Deleting your data does not cancel a subscription: cancel it in your Apple ID’s subscription settings.
8. International transfers
Our database is in the EU (Ireland), and Mixpanel and Sentry process data in the EU. Some providers, such as Adapty, Microsoft, Meta and Google, may process data in the United States or other countries. Where a transfer needs safeguards, we rely on Standard Contractual Clauses or another lawful transfer mechanism.
9. Your rights
Depending on where you live, including under the GDPR and Türkiye’s KVKK, you can ask for access to your data, a copy of it, correction, deletion or restriction, object to processing, and withdraw consent at any time without affecting earlier processing. Write to privacy@inovy.dev; because Tilo has no account, we may ask you to send the request from the app so we can match it to your anonymous ID. You can also complain to your local data protection authority.
10. Children
Tilo is not directed to children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has given us personal data, contact privacy@inovy.dev and we will delete it.
11. Changes
If we change this policy, we update the effective date above and, for important changes, tell you in the app.
12. Contact
Privacy questions and requests: privacy@inovy.dev. Help with the app: support@inovy.dev.