Effective date: 4 September 2026.
Rimami Oy provides KinoLight, an app that synchronizes compatible smart lights with the colors on your TV. Rimami Oy is responsible for the personal information we process to provide KinoLight. Contact us at support@rimami.com or visit rimami.com.
KinoLight normally analyzes camera frames on your Android device. If you enable Online TV detection, selected still images are also sent to our online detection service. You do not need a KinoLight account. We do not show advertisements, sell personal information, or track you across other companies’ apps and websites.
Camera processing and optional online detection
The camera detects your TV and analyzes its colors to control your lights. Continuous color analysis takes place on your device. KinoLight does not record camera video or save camera frames to your photo or media library. It does not capture audio.
Online TV detection is off by default. When you enable it, KinoLight can send a compressed still image to help find or check the screen boundary. It normally crops the image around a candidate TV area, including some surrounding space. If local detection cannot find a suitable candidate, Android can send a resized image of the full camera frame. An uploaded image can therefore include your room, people, objects, and visible TV content.
Images are sent over encrypted internet connections to Rimami’s detection service. Fly.io hosts the service, and fal.ai analyzes the images to identify the screen boundary. The result is returned to the app. The service receives selected still images rather than a continuous video stream. An upload can also include coordinates for the candidate screen area and a counter that associates the response with the current camera operation.
Rimami processes these images in memory for the detection request. We do not save the images or detection results as a dataset, and we do not use your camera images to train models. We send fal requests with input/output storage disabled, using the control described in fal’s data-retention documentation. We send image data directly with the request rather than uploading it to a file-sharing CDN.
You can disable Online TV detection in KinoLight’s settings to stop further image uploads. Local detection remains available. Turning the setting off does not recall a request already sent.
Request limits and technical information
KinoLight creates a random installation identifier and stores it in the app’s local preferences. When online detection is enabled, the app sends it to our relay with detection requests and service-availability checks. This identifier is separate from purchase identifiers and from identifiers used for local light protocols. It is not an advertising identifier. Our relay does not forward it to fal.
The relay uses a hashed version of this identifier for request limits and a short cooldown. The hash and its quota information stay in server memory. The daily quota records are scheduled to clear at the next midnight UTC, or earlier when the server process restarts. They are not written to the relay’s quota file. The file holds only the current UTC date and the service-wide request total, so the overall cost limit survives a restart.
Our relay application does not write individual online-detection requests, outcomes, images, installation identifiers, or upstream request identifiers to its access or operational logs. It keeps aggregate service counters in memory. Network providers necessarily process connection information: Fly receives the connecting IP address and request metadata, while fal receives the relay’s connection and service-request metadata. fal retains service-request metadata such as request identifiers, status, timestamps, and processing duration. Providers may also retain operational, security, and billing records under their own policies. Disabling application request logs does not disable those independent provider records.
Other information and services
- App settings and paired lights. Preferences, calibration values, layouts, device names, local network addresses, device identifiers, and pairing keys are stored on your device. The app discovers and controls compatible Hue, Nanoleaf, WLED, LIFX, WiZ, Govee, and Tuya devices on your network. Local light commands are not routed through Rimami’s server.
- Local protocol identifiers. WiZ uses a separate, persistent random client identifier stored in the app’s preferences. It is sent to local lights without encryption for registration and control acknowledgements. Registration messages can also include your device’s local IP address and may be broadcast across the local subnet. It is separate from the online-detection identifier and is not sent to Rimami.
- Tuya account connection, when used. You can provide your own Tuya developer API credentials to retrieve devices from Tuya’s regional cloud API. These credentials are encrypted using Android Keystore and stored on your device. Rimami does not receive them. Tuya handles the cloud requests under its own privacy policy.
- Purchases. Google processes payments through Google Play Billing. RevenueCat manages purchase and subscription status using a generated app-user identifier, purchase records, and relevant device/app information such as platform, app version, and country. A generated identifier is not a guarantee of anonymity. Rimami does not receive your payment-card details. See RevenueCat’s privacy policy. Free-trial state is tracked locally on the device.
- Ratings and reviews. KinoLight may ask Google Play to display its rating and review prompt. Google handles any submission under its own terms and privacy policy.
- Casting and calibration video. Google Cast communicates with your selected receiver. During calibration, KinoLight can temporarily serve the supplied calibration video over your local network or obtain it from Bunny’s CDN. Google and Bunny may process device/session or download metadata, including IP addresses, as part of their services. The calibration-video server does not serve your camera images.
- App configuration and sports features. Downloads of online configuration and, when used, sports information contact Rimami services. Sports connections carry selected match/subscription information and ordinary network metadata. Those connections do not carry camera images. Non-detection service logs may include request or connection identifiers for operating and troubleshooting the service.
- Support. If you email us, we receive your email address and the information you choose to send so we can respond.
Google, Tuya, and Bunny also describe their own handling of information in their privacy notices. Cloud-detection provider information is available in Fly’s privacy statement and fal’s privacy policy.
Permissions and your controls
KinoLight requests camera permission for screen detection and calibration and uses network access to communicate with your selected devices and online services. You can deny or revoke camera permission in Android Settings; camera-based features will then stop working. Local detection does not require online detection to be enabled.
You can remove local preferences, pairing information, the local cloud-detection identifier, and stored Tuya credentials by clearing KinoLight’s app data in Android Settings, or by uninstalling the app. Device backup and restore settings can affect whether app data is restored later. There is no KinoLight account to delete.
Retention, legal bases, and international processing
Online-detection image handling and quota retention are described above. Other relay operational records use rotating logs that overwrite the oldest records when configured size limits are reached; this is based on log volume, not a fixed number of days. Fly’s hosted application-log search currently retains logs for seven days. That period does not establish a limit for every separate provider security or billing record. Purchase records remain for entitlement management, applicable accounting requirements, and the providers’ retention purposes. Support correspondence is kept as needed to handle the request and related obligations or disputes.
Where the GDPR applies, we rely on your consent for optional online-detection image processing. You can withdraw it by disabling the feature; withdrawal does not affect the lawfulness of earlier processing. We rely on legitimate interests to protect service availability, limit misuse and costs, and troubleshoot technical problems. Purchase and requested-service processing relies on performing our agreement with you, and applicable legal obligations cover records we must retain.
Our detection relay currently operates in the United States. Our providers may process information outside your country and the European Economic Area (EEA). fal’s Data Processing Addendum includes contractual transfer safeguards where applicable. Fly’s privacy statement describes its participation in the EU–US Data Privacy Framework, a framework for protecting personal information transferred to participating US companies.
Your privacy rights
Depending on the applicable law and processing basis, you may request access, correction, deletion, restriction, or portability of personal information, and object to processing based on legitimate interests. You may also withdraw consent as described above. Contact support@rimami.com. We may need enough information to locate the relevant records; we do not keep a permanent online-detection user profile. We can assist with requests concerning RevenueCat records.
You may complain to your local data protection authority, including Finland’s Office of the Data Protection Ombudsman.
Children and policy changes
KinoLight is not directed to children under 13. If you believe a child has provided personal information through the app, contact us.
We will publish material changes at this policy’s existing URL and update its effective date. If we introduce a new optional use that requires consent, we will seek that consent before starting it.