Privacy Policy
TV Remote – Smart Control (Android)
Last updated: 8 August 2026
1. Who we are
This app is operated by ASO Positive, s. r. o., registered at Rovniankova 11, 851 02 Bratislava, Slovakia, company ID (IČO) 57393630, VAT ID (IČ DPH) SK2122694486 ("we", "us"). We are the data controller for the limited processing described below.
This policy covers the Android application TV Remote – Smart Control (package eu.utilitynest.remote.control.stick.universal.smart.tv), distributed through Google Play.
Questions, or to exercise your rights: multibusinesseu@gmail.com
2. The short version
- There is no account and no sign-up. We never ask for your name, e-mail address or any other identity.
- Everything the app does with your TV happens on your own Wi-Fi. Commands go straight from your phone to your TV.
- We operate no servers and receive no data from the app. We cannot see which TV you own or what you watch.
- Data is collected by the services that make a free app possible: Google AdMob (ads), Firebase Analytics (anonymous usage statistics), and Google Play Billing / RevenueCat (subscriptions).
- In the EEA, the UK and Switzerland you are asked for advertising consent the first time the app opens, and you can change it at any time in Settings → Ad privacy settings.
3. What is stored on your phone
The following is written to your phone's private app storage. It is never transmitted to us:
- Your saved TVs — the name the TV reports about itself, its local IP address and port, model, platform (Roku or Android TV), whether it has been paired, and when it was last connected.
- Android TV pairing credential — a client certificate and private key generated on your phone during pairing, kept in a PKCS#12 keystore inside the app's private storage. This is what your TV recognises as "this phone"; it never leaves the device.
- Preferences — haptic feedback on/off, D-Pad or touchpad mode, and whether you have completed onboarding.
- Rating-prompt counters — the date of first launch, how many successful connections you have made, and how many times you have been asked to rate the app. These exist only so the app does not nag you.
- Your advertising consent choice — stored on the device by Google's User Messaging Platform SDK.
All of it is removed when you uninstall the app or clear its data in Android Settings.
4. Your local network
- To find TVs, the app probes addresses on your phone's own local subnet on the Roku control port (8060), and listens for Android TV devices announcing themselves over mDNS.
- The app requests no location permission, does not read your Wi-Fi network name, and does not scan for Bluetooth devices.
- Remote-control key presses, launched apps and typed text go directly from your phone to your TV. Nothing is routed through us or through any third party.
- Typing. Text you type on the "Type on TV" screen is sent only to your TV. An Android TV device can report back the contents of the text field it currently has focused, so the app can mirror what is on screen. That text is held in memory for the duration of the session only — it is never saved to disk and never transmitted anywhere.
5. What third-party services collect
These are the only parties that receive any data from the app. Each acts as an independent controller or as our processor for the purposes shown.
Service Data Purpose
Google AdMob
Google Ireland Ltd. / Google LLC Advertising ID (AD_ID), IP address (from which approximate location such as country is derived), device and OS information, ad interactions (impressions, clicks), app identifier Serving ads, capping how often you see the same ad, fraud prevention, measurement and payout. Ads are personalised only if you consented.
Google User Messaging Platform (UMP) Your consent answer, stored on the device as an IAB TCF consent string Collecting, storing and re-displaying your advertising consent choice
Firebase Analytics
Google Ireland Ltd. / Google LLC A resettable, first-party app instance ID, device model, OS and app version, and country derived from IP. Only Firebase's automatic events are collected: first_open, session_start, app_update, app_remove, os_update, user_engagement, in_app_purchase and app_exception. Knowing roughly how many people use the app and whether it crashes. The app defines no custom events — nothing about which TV you own, which buttons you press or what you watch is recorded. app_exception records only that a crash occurred, with no stack trace and no content.
RevenueCat, Inc.
United States A randomly generated anonymous app user ID, the purchase receipt issued by Google Play, subscription status, platform and country Determining whether your Premium subscription is active, and restoring it on a new device
Google Play Billing Handled entirely by Google. Google is the seller of the subscription. Taking payment. We never receive your card details, billing address or any payment data — only whether the subscription is active.
Google Play In-App Review A request to display the rating dialog Asking for a rating. Google deliberately never tells us whether the dialog appeared, whether you rated, or what you said.
We do not sell your personal data, and we do not share it with data brokers.
6. Advertising consent and personalisation
If you are in the EEA, the UK or Switzerland, a Google consent form appears the first time you open the app, before any ad is requested and before the ads SDK starts. Your answer is passed to Google as Consent Mode v2 signals:
- ad_storage, ad_user_data and ad_personalization are set from your answer. Refusing means your advertising ID is not used for ads.
- analytics_storage stays enabled. It governs only the first-party, resettable app instance ID that the anonymous usage statistics in section 5 rely on; it is not an advertising identifier and is not shared for advertising.
If you refuse, you still see ads — they are simply non-personalised. Google still processes your IP address and limited technical data for those ads, in order to cap frequency, prevent fraud and report on them.
You can change your answer at any time in Settings → Ad privacy settings, or via the "Ad Privacy Options" link shown under the banner. You can also reset or delete your advertising ID entirely in Android Settings → Privacy → Ads.
Outside those regions Google reports that no consent form is required, and ads are served under Google's rules for your region.
7. Legal bases (GDPR Article 6)
- Consent — Art. 6(1)(a): personalised advertising, and storing or reading the advertising identifier on your device. You may withdraw it at any time, as described above.
- Performance of a contract — Art. 6(1)(b): processing your purchase and keeping Premium unlocked on your devices.
- Legitimate interests — Art. 6(1)(f): non-personalised advertising, which funds a free app; aggregate usage and crash statistics, to find and fix problems; security and fraud prevention.
- Legal obligation — Art. 6(1)(c): transaction records that Google and RevenueCat must retain for tax and accounting purposes.
8. Transfers outside the EEA
Google LLC and RevenueCat, Inc. are established in the United States. Transfers to them are covered by the European Commission's Standard Contractual Clauses and, where the recipient is certified, by the EU–U.S. Data Privacy Framework. You may ask us for details of the safeguards in place.
9. How long data is kept
- On your phone — until you uninstall the app or clear its data.
- Firebase Analytics — Google retains event data for the retention period configured in Firebase, after which it is deleted or aggregated.
- AdMob — according to Google's own retention policy for advertising data.
- RevenueCat / Google Play — for as long as your subscription exists, and afterwards for the statutory accounting and tax periods.
10. Your rights
Under the GDPR you have the right to:
- access the personal data held about you, and receive a copy;
- have inaccurate data corrected;
- have data erased;
- restrict or object to processing, including profiling for advertising;
- data portability;
- withdraw consent at any time, without affecting processing carried out before you withdrew it.
To exercise any of these, write to multibusinesseu@gmail.com.
One practical limitation, stated honestly. Because the app has no accounts, we hold nothing that identifies you and normally cannot connect a request to a person. If your request concerns advertising or analytics data, please include your advertising ID (or, for a purchase, the Google Play order number) — or contact Google directly, since Google is the controller for that data. We will always help where we can.
You also have the right to lodge a complaint with the Slovak supervisory authority: Úrad na ochranu osobných údajov Slovenskej republiky, Hraničná 12, 820 07 Bratislava, dataprotection.gov.sk — or with the authority in your own country of residence.
11. Children
The app is not directed at children. Its Google Play target audience is 13 years and older, it is not declared as child-directed to Google's advertising SDKs, and ad content is capped at a "PG" rating. We do not knowingly collect data from children under 13.
12. Security
- We hold no personal data on our side, so there is nothing of yours for us to lose.
- The Android TV pairing key is generated on your phone and never leaves it.
- Traffic between your phone and your TV stays inside your own network. Android TV connections are encrypted with TLS using your paired certificate. Roku's control protocol is unencrypted HTTP — that is how Roku designed it, and it applies to every Roku remote app, so treat it as you would any other device on your home network.
13. Changes to this policy
If this policy changes, the "last updated" date at the top changes with it. Material changes will also be announced in the app or in the Google Play listing.
14. Contact
ASO Positive, s. r. o.
Rovniankova 11, 851 02 Bratislava, Slovakia
IČO: 57393630 · IČ DPH: SK2122694486
multibusinesseu@gmail.com