# Privacy · TV Night Guard 0.1.0-beta.4 source candidate This document describes the 0.1.0-beta.4 cross-platform testing source candidate, not a released or hardware-validated build. It follows the cross-platform beta.3 candidate; the supplied website/installed build remains Windows 0.1.0-beta.2. Beta.4 has not been released, and no expiry behavior is claimed for existing beta.2 binaries. TV Night Guard works on your local network. It has no account, analytics, advertising, viewing-history collection, or automatic support upload. There is no cloud TV-control service or automatic update check in this beta. The app sends discovery queries on local IPv4 network interfaces when you click Search. Pairing, connection checks, off tests, and scheduled checks contact TV addresses you select. Automatic control requires a paired device, your physical off-test confirmation, and an enabled schedule. Stored on this computer: - TV names, private IP addresses, platform, model, and device identity/certificate fingerprint. - Quiet hours, weekdays, selected computer options, and per-TV test confirmation. - Pairing tokens and Sony pre-shared keys encrypted with the operating system’s credential protection through Electron safeStorage. Windows uses DPAPI for the signed-in user; Linux requires a secure desktop keyring, and the insecure `basic_text` backend is refused. Other software running as the same user may be able to decrypt credentials. - The last 200 local activity events, including room names and status changes. Credentials are never intentionally logged. - For builds identified as alpha, beta, rc, test, or dev, a local `testing-build-state.json` record of build/version/time information used by the testing-build expiry check. It is not uploaded. Data is stored on Windows in `%APPDATA%\TV Night Guard Beta`; on macOS in `~/Library/Application Support/TV Night Guard Beta`; and on Linux in `app.getPath('appData')/TV Night Guard Beta` (normally `$XDG_CONFIG_HOME/TV Night Guard Beta` if `XDG_CONFIG_HOME` is absolute, otherwise `~/.config/TV Night Guard Beta`). The Windows portable executable also stores settings there. Pairing credentials are not carried inside the executable. ## Testing-build expiry Alpha, beta, rc, test, and dev builds with testing-build metadata expire 30 days after the UTC BUILD timestamp embedded in that build. The deadline is not calculated from installation or first launch, and deleting or reinstalling the local state file does not extend it. Stable non-testing releases do not expire. This does not make any claim that existing beta.2 binaries expire. The expiry date is shown in the app UI. Expiry is enforced locally; there is no server entitlement or cloud upload of the state record. A local last-seen time plus monotonic runtime helps detect clock rollback (five-minute skew tolerance). Invalid metadata or state, or failure to persist state, fails closed. Expiry disables the guard, stops TV commands, and releases the keep-awake request. Diagnostics export and inspecting/removing saved TVs remain available, as does explicitly disabling startup/wake settings. Expiry does not automatically request administrator authorization or clean up privileges; an existing native wake task may remain until the user disables the setting in Settings. Expiry does not delete saved app data. Testing builds are free during testing; download a newer testing build to continue testing. This is not a server-side entitlement, user tracking, anti-debug, or tamper-proofing system. **Save anonymous diagnostics** creates a file only where you choose. It contains app version, operating system/architecture, timezone, quiet-hours schedule, TV models/platforms, test/enable flags, and coarse status. It excludes room names, IP addresses, unique device identities, credentials, and activity text. Review before sharing. The app does not upload it. Remove a TV in the app to delete its saved credential and configuration. Old activity events may retain its room name until they age out of the 200-event limit. Uninstalling alone retains local settings for a possible reinstall. Before uninstalling or moving the app, disable the guard and startup/wake options in Settings and **Save**. Deleting the app binary alone does not delete the app-owned wake integration or local data. Use your OS/package's normal uninstall process; this document does not provide manual cleanup commands. Startup and optional wake integrations are created only when selected and saved. Windows launches in the existing signed-in session; macOS uses an Electron login item and an app-owned privileged wake integration; Linux uses XDG autostart and can use a systemd wake timer with administrator authorization. The Linux wake integration requires systemd and a supported RTC wake alarm. These platform integrations may persist if the app binary alone is removed. For beta privacy questions, contact the person who provided your copy. No support address or external data recipient is configured in this build.