Ziggy is a local-first AI smart-home assistant. A Ziggy hub — a small computer running in your home alongside Home Assistant — handles voice commands, automations, and device control locally wherever it can. Some features (remote access from outside your home, account and billing, optional cloud AI fallback, and scheduled backups) are provided by Ziggy Cloud. This policy explains what data we handle, where it lives, who it is shared with, and the choices you have.
Ziggy Home is operated by the team behind ziggy-home.com. For any privacy question, data request, or complaint, contact us at hello@ziggy-home.com. We are the data controller for the account, cloud and website data described below.
The first time you visit, a banner asks whether we may measure how the site is used. Your choice is
stored in your browser (ziggy-consent) so we do not ask again; you can change it at any time
with the Privacy settings link in the footer.
| Service | Before you accept | After you accept |
|---|---|---|
| Google Analytics 4 (Google Ireland) | Consent Mode v2 with every storage type set to denied: no cookies, no advertising personalisation; at most cookieless, aggregated pings. | Analytics and ads storage granted. Page views, clicks and “Define your home” steps are sent with a random anonymous id. Google Ads may count a lead as a conversion. |
| PostHog (hosted in the EU, Frankfurt) | Runs memory-only: nothing is written to your device, no session replay, no automatic capture. Events are anonymous and cannot be linked across visits. | The anonymous id is stored in your browser so visits can be linked, and session replay may record how the page is used (typed text in forms is masked). |
What is measured: which pages and sections you view, which buttons you click, the language you chose,
your steps through “Define your home” (room types, chosen packs, totals — never the free-text wish),
and how you arrived (campaign parameters such as utm_*, gclid, fbclid, and the
referring site). Attribution is kept in your browser (ziggy-attr) and attached to a lead only
if you submit a form. Your email address, name and free text are never sent to Google or PostHog.
Identifiers: a random anonymous id (ziggy-aid, stored only after consent or after you submit a
form) and a per-tab session id. Retention: GA4 event data 14 months; PostHog event data 12 months and
session recordings 30 days; both are then deleted automatically.
After you accept the banner we load Sentry (Functional Software, Inc., EU data region) to capture JavaScript errors on the site: the error message, stack trace, browser type and page. We turn off Sentry's personal-data collection and do not send your IP address, cookies or any identifier. Error reports are kept for 90 days.
Submitting a form is a request to us, so it does not depend on the analytics banner. We store your email address and the options you chose (the kit you were interested in, and for “Define your home” the room types, packs, total price, your two research answers and — only if you ticked the box — the free-text wish) together with how you found us (campaign parameters, referring site, landing page) and the anonymous id and session id above, so we can recognise your visit. These go to:
| Where | What | Why |
|---|---|---|
| Ziggy Desk — our own system on Fly.io, Frankfurt (EU) | The lead record above; the Desk assigns it an internal lead id and hashes your IP address with a daily salt for abuse control only | Keeping track of who asked for a kit, and answering you |
| HubSpot (CRM, EU data centre) | Email, chosen options, attribution, lead stage | Managing the conversation with you about your kit |
| Brevo (email, EU) | Email and lead id | Sending you what you asked for. Marketing news is sent only if you ticked the marketing-consent box; otherwise you are stored as opted-out and receive at most one double-opt-in email asking whether you want news. |
| Jeff — our internal assistant | Email and a one-line summary | Notifying the founder so a person replies to you |
Google Analytics and PostHog receive a “lead created” event carrying the internal lead id only — never the email address. If the Desk is unavailable, the same email and summary are sent to Jeff directly so your request is not lost.
Sections 3–10 below describe the Ziggy Home app and Ziggy Cloud.
| Data | Why | Where it lives |
|---|---|---|
| Account email | Sign-in, support, service notices | Ziggy Cloud (EU) |
| Subscription & billing status (plan, status, invoice timestamps) | Managing your subscription | Ziggy Cloud + Stripe |
| Home & device data (room names, devices, scenes, automations) | Running your home | Your hub, in your home |
| Voice (push-to-talk only) | Turning speech into commands | Your hub; see §4 |
| Push token (FCM / APNs) | Delivering notifications | Ziggy Cloud |
| Approximate / precise location (optional) | Presence & geofence automations, only if you enable them | Your hub, in your home |
| Crash logs (optional, OS-level) | Diagnosing app crashes | Google Play / Apple, if you opt in at the OS level |
We do not collect your name, phone number, contacts, photos, message history, browsing history, advertising ID, or device fingerprints. We do not have an advertising or analytics SDK in the app; website analytics are described in §2.
Voice capture is push-to-talk only — audio is captured only while you actively hold the microphone button. There is no wake-word listening. Speech-to-text runs locally on your hub first. If local transcription is unavailable for a request, that single audio clip is sent over an encrypted connection to OpenAI's speech-to-text service for that request and is not stored by us. You can choose not to use voice at all.
We share data only with operational service providers that are necessary to run Ziggy, each under their own terms. We do not share data for advertising or marketing.
| Provider | What | Purpose |
|---|---|---|
| Stripe | Payment & subscription metadata (card details are handled by Stripe, never by us) | Billing |
| OpenAI | A voice clip or transcript, only on fallback (see §4) | Speech-to-text / assistant fallback |
| Cloudflare | Encrypted tunnel traffic (content is not readable by Cloudflare) | Secure remote access |
| Fly.io | Account & home metadata | Ziggy Cloud hosting (EU) |
| Backblaze B2 | Encrypted backup blobs (we hold the key) | Backups, if enabled |
| Google / Apple | Push token + notification payload | Delivering notifications |
Data in transit is encrypted using TLS 1.2 or higher, and remote access to your home runs through an encrypted tunnel. Backups are encrypted before they leave your home.
You can delete your account and associated cloud data at any time from the app: Settings → Account → Delete Account. Cloud-side data is purged within 30 days and we confirm by email when complete. Data that lives only on your hub is yours — you can wipe it yourself at any time. You may also email hello@ziggy-home.com to request access to, correction of, or deletion of your data.
Ziggy is intended for adults (18+) managing their own home. It is not directed at children and we do not knowingly collect data from children.
We may update this policy as Ziggy evolves. Material changes will be reflected here with a new "last updated" date, and where appropriate we will notify you in the app or by email.
Questions or requests: hello@ziggy-home.com.