Privacy Policy

Hue Remote for Watch

Last updated: August 15, 2026

Overview

This policy explains how Hue Remote for Watch handles information in its iPhone app, Apple Watch app, and optional remote-access service. Hue Remote does not use advertising, behavioral or third-party product analytics, or cross-app tracking, and the developer does not sell personal data.

Local Network and On-Device Storage

The app uses the local network to find and control Hue Bridges. Bridge credentials and remote sessions are stored in Keychain on iPhone and Apple Watch.

On-device settings may include the selected language, active and paired bridges, room and light order, device icon choices, and saved or hidden quick colors. To make the app load reliably, a cached copy of Hue home information—such as room, zone, entertainment-area, and light names, capabilities, and recent states—may be stored on the device for up to seven days. This local cache is removed when it expires, when the related bridge is removed, or when the app is deleted.

Hue Account and Remote Access

If you connect a Hue account, Signify handles sign-in. Hue Remote uses a backend service to exchange and refresh authorization, store Hue tokens in encrypted form, and forward only supported Hue control requests. Signify processes Hue account and service requests under its privacy notice.

The remote-access service stores encrypted authorization tokens, an opaque Hue route identifier, random device and session identifiers, device type, expiry times, and security counters. Light commands and Hue responses are processed to deliver the requested action and are not retained as an activity history. Successful status responses may be held briefly in memory to reduce duplicate requests.

Service Provider and Operational Logs

The remote-access service runs on Cloudflare Workers and Durable Objects. Cloudflare processes the service data described above on the developer's behalf. Sampled operational logs may contain network and request metadata, such as IP address, request timing, response status, and service errors. These logs are used only for service reliability, security, and troubleshooting—not for advertising, tracking, or behavioral analytics—and are retained according to the configured Cloudflare service limits. For more information, see Cloudflare's Privacy Policy.

Retention and Control

Remote-access sessions normally expire after 90 days and may be securely rotated while the service remains in use. Signing out removes all of the app's remote sessions and stored Hue authorization from the service. If you stop using remote access without signing out, the account record is deleted after all device sessions expire. You can also revoke the app from your Hue account settings.

Your Choices and Privacy Requests

You can use local Hue Bridge control without connecting a Hue account. You can remove a paired bridge from the app, sign out to delete remote authorization, revoke Hue Remote in your Hue account settings, and delete the app to remove its on-device data.

The independent developer of Hue Remote for Watch is responsible for the backend data described in this policy. To ask a privacy question or request access to or deletion of backend information associated with your Hue Remote use, contact edman.build@gmail.com. The developer may need limited information to verify and locate the relevant record.