Privacy Policy

Last updated: 16 February 2026

Who we are

Dwellsee is a free monitoring service for Samsung EHS heat pumps. For any privacy-related questions, contact us at contact@dwellsee.com.

For the purposes of the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018, the data controller is Dwellsee, contactable at the email address above.

What data we collect

Account information

When you create an account, we collect your email address and store a securely hashed password. Your email is used for authentication and to contact you about your account if necessary.

SmartThings connection

When you link your SmartThings account, we store OAuth tokens that allow us to read your heat pump data. Refresh tokens are encrypted using AWS Key Management Service (KMS). We also store your SmartThings device identifiers, device names, and device model information.

Heat pump telemetry

We poll your heat pump approximately every minute and store operational data including flow and return temperatures, outdoor temperature, compressor frequency, flow rate, energy consumption, and operating mode. This data is retained for one year and then automatically deleted.

Schedules and preferences

If you set up DHW or weather compensation schedules, we store the schedule configuration including days, times, target temperatures, and your timezone.

Feedback and waitlist

If you submit feedback or join our waitlist, we store your email address, the message you provided, and basic metadata (the page you were on and your browser type).

Notifications

We generate in-app notifications (for example, short-cycling alerts). These are stored for 90 days and then automatically deleted.

Application monitoring

We use AWS CloudWatch Real User Monitoring (RUM) to track application errors, page load performance, and API response times. This collects your browser type and pages visited, but does not use cookies. Server-side logs (such as API request logs) are retained for 7 to 30 days.

Why we collect it (lawful basis)

DataLawful basis
Account informationContract — necessary to provide the service
SmartThings tokens & device dataContract — necessary to poll your heat pump
Heat pump telemetryContract — the core service you signed up for
Schedules & preferencesContract — features you have chosen to use
Feedback & waitlistLegitimate interest — improving the service
Application monitoringLegitimate interest — maintaining service reliability and fixing errors

How long we keep it

DataRetention
Account & device informationUntil you request account deletion
Heat pump telemetry1 year (automatically deleted)
Notifications90 days (automatically deleted)
Server logs7–30 days (automatically deleted)
Debug data (if enabled)30 days (automatically deleted)

Who we share it with

We do not sell your data or share it with third parties for marketing purposes. Your data is processed by:

  • Amazon Web Services (AWS) — our infrastructure provider, which hosts and processes all data. AWS acts as a data processor under their Data Processing Addendum. All data is stored in the EU (eu-west-1, Ireland).
  • Samsung SmartThings — we send API requests to SmartThings on your behalf to read your heat pump data. This uses the OAuth connection you authorise.

If you use the share feature to create a public snapshot of your device data, that snapshot is accessible to anyone with the link until it expires.

Cookies and local storage

Dwellsee does not use cookies. We store the following in your browser's local storage, all of which are strictly necessary to provide the service:

  • Authentication tokens (to keep you signed in)
  • Theme preference (light/dark mode)
  • UI preferences (selected time range, device selection)

How we protect your data

  • All data is transmitted over HTTPS (TLS encryption in transit)
  • All data is encrypted at rest in AWS
  • SmartThings refresh tokens are additionally encrypted with a dedicated AWS KMS key
  • Access to infrastructure is restricted and requires authenticated AWS credentials

Your rights

Under the UK GDPR, you have the right to:

  • Access — request a copy of all personal data we hold about you
  • Rectification — ask us to correct inaccurate data
  • Erasure — ask us to delete your account and all associated data
  • Portability — receive your data in a machine-readable format
  • Object — object to processing based on legitimate interest
  • Restrict processing — ask us to limit how we use your data

To exercise any of these rights, email contact@dwellsee.com. We will respond within one month.

If you are unhappy with how we handle your data, you have the right to lodge a complaint with the Information Commissioner's Office (ICO).

Account deletion

To close your account and delete all associated data, email contact@dwellsee.com. Upon request, we will delete your account, all device data, telemetry history, schedules, and any other personal data we hold. Data subject to automatic retention (such as telemetry with a TTL) will be deleted immediately rather than waiting for expiry.

Changes to this policy

We may update this policy from time to time. If we make significant changes, we will notify you by email or through a notice on the site. The “last updated” date at the top of this page shows when the policy was last revised.

Questions? Contact us at contact@dwellsee.com.

About Dwellsee