Privacy
Last updated October 7, 2026
WiFi Doorman lets the owner of a home network approve or block new devices on a UniFi network, usually with help from the installer who set the network up. This page explains what we collect, why, and what you can ask us to do with it. In short: we keep only what the service needs, we don't sell anything, and we don't show ads or use tracking.
WiFi Doorman is run by an individual based in New York, USA ("we", "us"). Questions: support@wifidoorman.com.
What we collect
Your account
- Your email address, and your name if you sign in with Google.
- A sign-in cookie (
wd_session) so you stay signed in. It's the only cookie we set, and it's needed for the service to work. - Your role at each home or installer company (owner, family, staff).
Your network
To do its job, WiFi Doorman checks your UniFi controller about every 15 seconds and keeps:
- For each device on the network: its hardware (MAC) address, the name it reports or that you gave it, its maker, IP address, the WiFi network and access point it used, and when it was last seen.
- Your lists of allowed, blocked and waiting devices, your settings, and an activity history (what was allowed, blocked or forgotten, when, and by whom).
- For installers: the controller's address and its API key. The key is stored encrypted and never shown to anyone, including you, after it's saved.
Notifications
If you turn notifications on, we store your browser's push address and keys, and the type of browser, so we can send alerts to that device. Signing out removes them for that device.
Payments
Payments are handled by Stripe. Your card details go to Stripe, never to us or your installer. We keep the Stripe customer and subscription references and what each home is entitled to (trial, monthly or one-time).
Server logs
Our web server keeps short-lived logs of requests (including IP addresses) to keep the service secure and working.
Who else handles data
- Google Cloud (USA) hosts the service and its nightly backups.
- Stripe processes payments, and pays installers who set their own prices.
- Resend sends our emails: sign-in links, invites and plan reminders.
- Google or Apple deliver push notifications to your phone, as your browser requires.
- Google Fonts serves the app's typeface, so your browser contacts Google when it loads it.
- Your installer can see the homes they manage: devices, settings, activity and plan status.
We don't sell or rent personal information, and we don't share it for advertising.
How long we keep it
- Account and network data: while your account or home is active. Devices you forget are removed from your lists.
- Backups: up to 30 days.
- Demo homes: deleted automatically after 24 hours.
- Payment records: as long as tax and accounting rules require.
Your choices
- See and change your data in the app: devices, people, settings and notifications.
- Leave a home, or ask the owner or installer to remove you.
- Ask us for a copy of your data, to correct it, or to delete your account: email support@wifidoorman.com. We'll answer within 30 days.
- Installers can remove a controller at any time; deleting the API key in UniFi also cuts our access straight away.
Security
Connections are encrypted (HTTPS). API keys are stored encrypted. Sign-in and invite codes are single-use and stored only as one-way hashes. Our server only talks to controllers from one fixed address, so installers can allow just that address.
Children
WiFi Doorman isn't meant for children under 13, and we don't knowingly collect their information. A home's devices may belong to children; their device names are kept only as part of that home's lists.
Changes
If we change this page in a way that matters, we'll update the date above and tell account holders by email or in the app.