Boss Bot Nest Privacy Policy

Effective October 9, 2026

Boss Bot Nest ("the app") is a private, personal-use application operated by Steve Reich. Its only user is Steve Reich, who uses it so his own AI assistant can read and adjust his own Google Nest thermostats. This policy explains how the app accesses, uses, stores, and shares Google user data.

1. Data the app accesses

With the user's consent through Google's authorization screen, the app uses the Smart Device Management API scope https://www.googleapis.com/auth/sdm.service to access the Nest devices and structures the user chooses to share: device and room names, current ambient temperature and humidity, thermostat mode, HVAC status, temperature setpoints, eco settings, and connectivity status. The app does not access camera video, doorbell events, email, contacts, location history, or any other Google account data.

2. How the data is used

The data is used only to provide the app's user-facing features: reporting the current thermostat status to the user and changing thermostat settings when the user asks. It is not used for advertising, profiling, analytics resale, credit or lending decisions, or to train generalized AI or machine-learning models.

3. Storage and security

OAuth access and refresh tokens are stored privately on infrastructure controlled by the operator, with access restricted to the operator and his assistant. They are not published or shared. Thermostat readings may be kept briefly in private logs to confirm that a requested change took effect. Data is transmitted to and from Google only over HTTPS.

4. Sharing

Google user data is not sold, rented, or transferred to third parties, including advertising platforms, data brokers, or information resellers. Data is disclosed only if required by law, or as needed to protect against security threats or abuse.

5. Limited Use disclosure

Boss Bot Nest's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Retention and deletion

Tokens are kept only while the user wants the integration to work. You can revoke the app's access at any time at myaccount.google.com/permissions or in the Nest app's Works with Google / Device Access settings (nestservices.google.com/partnerconnections). After access is revoked or the integration is retired, stored tokens and logs are deleted. Deletion requests can also be sent to the contact below.

7. Changes

If this policy changes, the updated version will be posted on this page with a new effective date.

8. Contact

Steve Reich — tzviray21@gmail.com

Home