Last updated: August 10, 2026
Chameleon Lighting ("us", "we", or "our") operates the Chameleon Lighting mobile application, the web app at app.chameleon.lighting, and the lighting controllers they connect to (together, the "Service").
This page explains what we collect, why, who else sees it, and how to get rid of it. The short version: we collect what the Service needs in order to run your lights — an account, the content you make, and the state of your controllers. We do not use analytics, advertising, or tracking software of any kind, and we do not sell your data.
You can open the app as a guest and browse the community catalog without signing up. In guest mode nothing is sent to us: no account is created, no email or name is collected, and nothing you do is written to our servers. Our content delivery network will see your IP address and browser type as part of serving you the catalog file, as it would for any website.
Account details. Your email address, your name, a username you choose, and your password. Passwords are handled by Amazon Cognito and are never visible to us. Optionally, a profile photo — either one you upload or one you pick from our stock library.
Location. At sign-up you type a city and state. This is used to work out sunrise and sunset where you are, so schedules built around "at dusk" fire at the right time. If you use the "use my location" button instead, the app asks your device for a deliberately coarse reading, once, at that moment — we do not track your location in the background and the app never watches your position over time. That reading is rounded to about a kilometre on your device, before it is sent anywhere: sunrise and sunset are the only thing a location is used for, and that is all the precision it takes. We never receive your street address, and neither does anyone we pass a location to.
The content you create. Playlists, patterns, palettes, events and your calendar, including any names or artwork you attach to them.
Your controllers. For each Chameleon controller you pair, we store what it reports and what you configure: the name you give it, its settings and zones, its schedule, its time zone and location, and which content is playing. The controller also reports diagnostics — signal strength, free memory, temperature, firmware version, its address on your local network, and the name of the Wi-Fi network it is joined to. We use these to keep the device online and to help you when something goes wrong. We do not receive your Wi-Fi password.
Household members and sharing. If you invite someone to your household, or grant them guest access to a device, we store the email address you invite. Everyone in a household can see the email addresses of the other members.
We do not sell your data or share it for advertising. Data reaches other companies only where it is needed to run the Service:
We may also disclose information if we are legally required to, or where it is necessary to protect our rights or someone's safety.
Publishing is optional and off by default. If you choose to publish a collection or share content to the community catalog, that content becomes publicly readable on the internet — the catalog is a public file, not a members-only area — and it carries the publisher name shown alongside it. Do not put anything in a name, description or image that you would not want published. Un-publishing removes it from the catalog going forward; copies other households already made are theirs and remain with them.
The app keeps a local copy of your profile, your content and the community catalog so it starts quickly and works with a poor connection. On the web app this lives in your browser's local storage. Signing out or clearing your browser data removes it. We do not use cookies for advertising or tracking.
We keep your account information and content for as long as your account exists. Controller diagnostics are kept in an operational log so we can investigate faults; this log is keyed to the controller rather than to you.
Depending on where you live, you may have the right to see a copy of your data, correct it, or have it deleted. Deletion is built into the app. For anything else, email us at the address below and we will respond.
Accounts are protected by Amazon Cognito. Traffic between the app, our servers and your controllers is encrypted, and controllers authenticate to our systems with their own certificates. No system is perfectly secure, and we cannot guarantee absolute security, but we take reasonable measures to protect your information.
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us information, contact us and we will delete it.
We may update this policy from time to time. Changes take effect when posted on this page, and the "Last updated" date above will change. Please review it periodically.
If you have any questions about this Privacy Policy, please contact us: