Overview
Availight Duo is designed as a local-first availability display. Core setup, local control, and device-to-device operation should continue to work without an Availight Cloud account.
Availight Cloud is optional for connected features such as account-backed device registration, Google Calendar, iCalendar, Microsoft Teams, cloud diagnostics, and remote management as the product evolves.
Information We Collect
- Account information such as email address, account identifier, and session metadata needed to keep accounts secure.
- Device information such as Controller install ID, product type, room name, firmware version, protocol version, local portal address when reported, cloud polling state, pending delivery count, and basic online/offline state.
- Smart Display connector information such as server-side OAuth tokens, iCalendar feed URLs, selected calendar IDs, connector preferences, normalized event windows, connector health, last sync time, token expiry metadata, webhook/watch channel state, and error state.
- Mobile app and local device information such as local Controller sessions, Availight Cloud account sessions, user preferences, and temporary validation data while the app is open.
Information We Avoid Collecting
- Wi-Fi passwords in Availight Cloud.
- Controller setup codes in Availight Cloud.
- Firmware signing private keys.
- Raw OAuth tokens in the mobile app, Controller, or Door Unit.
- Provider access tokens, refresh tokens, or feed URLs in Controller or Door Unit firmware.
- Meeting attendees, full descriptions, conference links, or raw provider payloads in device firmware.
How We Use Information
- Authenticate users and help users claim and manage Controllers.
- Deliver normalized availability updates to a claimed Controller.
- Keep Smart Display sources refreshed and clear stale events safely.
- Show device and connector health in the mobile app.
- Support troubleshooting with privacy-safe diagnostics.
- Improve product reliability and security.
Calendar And Presence Data
Availight Cloud should convert provider data into compact availability signals, such as Busy, Focus, or Available. The Controller and Door Unit should receive only the normalized result, source, timing, priority, and a limited reason or title when needed for the user-facing Auto Mode screen.
Google Calendar and Microsoft Teams tokens remain server-side. iCalendar feed URLs remain server-side after cloud setup. Disconnecting a connector should clear that source and stop future polling or token use for that connector.
Sharing
Availight does not sell personal information. Data may be processed by infrastructure providers needed to run the service, such as Supabase, Google Calendar APIs, Microsoft Graph APIs, app platform services, hosting providers, and email/support tools.
Security
Availight production services should use HTTPS. Provider tokens should be protected server-side and should not be returned through public diagnostics. Controller delivery tokens should be rotatable and revocable. Production builds should not include local development secrets.
User Choices
- Use local setup and local control without an Availight Cloud account.
- Disconnect Google Calendar, Microsoft Teams, or iCalendar independently.
- Unclaim a Controller from an Availight Cloud account.
- Sign out of the mobile app.
- Request account or device data deletion through support.
Icon Attribution
Icons created and provided by Flaticon: https://www.flaticon.com/free-icons/
Contact
- Email: support@availight.com
- Website: https://www.availight.com
