Privacy Policy
Last updated: 23 July 2026
- No analytics, advertising, or tracking.
- No account with the developer and no background collection of your data.
- Feedback is sent only when you explicitly submit it.
- Your Wi-Fi password goes only to your pump — never to the developer or to Kamoer.
- Backups live in your own iCloud or on your device, and are deleted separately from the rest of the app's data.
Rheon ("the app", "we", "us") is an independent, unofficial controller for the D-D H2Ocean P1+ dosing pump (also sold under the Kamoer brand). It is not affiliated with, endorsed by, or operated by D-D The Aquarium Solution or Kamoer Fluid Technology ("Kamoer"). This policy explains how the app handles information. It applies to the Rheon app on iOS and iPadOS.
1. No accounts, analytics, advertising, or tracking
Rheon has no user accounts or general-purpose backend, and it does not automatically send the developer your information, usage data, diagnostics, or location. There is no analytics, advertising, attribution, tracking, or crash-reporting software in the app. The only developer-operated network service is the optional feedback relay described in section 7.
The app offers a one-off in-app purchase that unlocks some features. Purchases are sold and processed by Apple, and the app checks your entitlement through Apple's StoreKit on your device. The developer receives no payment details, no Apple Account identifier, and nothing else that identifies you personally.
2. Information stored on your device
To work, the app stores the following locally on your device. Sensitive items are kept in the system Keychain. None of it is transmitted to the developer.
- Kamoer sign-in session — the authentication token returned when you log in with your Kamoer account (Keychain).
- Remembered logins — the email address or phone number you choose to have the app remember (Keychain).
- Device credentials — secrets used to receive live updates from your pump, such as MQTT credentials and per-device secrets (Keychain).
- App data — your settings, volume-alert configuration, and a cache of recent device state, stored in the app's local storage.
- Widget data — a snapshot of your pumps' recent state (name, online status, container level, dosing progress, next scheduled dose) kept in a storage area shared with Rheon's own widgets so they can draw without launching the app. It holds no account details. See section 6.
- Saved sign-in details, if you choose — Rheon supports iOS Password AutoFill and declares an association with rheon.app, so iOS can offer to save your Kamoer password and fill it in later. Anything you save that way is held by iOS in your keychain — and in iCloud Keychain if you have that turned on — under your control rather than the app's. The developer never receives it.
- Backups — any device backups you create, stored on your device and, when it is available, in the app's own iCloud container. See section 5.
Wi-Fi credentials are handled differently: when you set up a pump, the network password you type is held only in memory for as long as the setup flow needs it, is sent only to the pump, and is never written to storage. See section 4.
You can remove the rest at any time using Settings → Clear App Data in the app, which clears the app's stored data and signs you out. Deleting the app removes its local storage; run Clear App Data before deleting if you also want its Keychain items removed, as iOS may otherwise retain them for a later reinstall. Backups are deliberately excluded from both — delete those on the Backup screen (see section 5).
3. Information sent to Kamoer's cloud (Cloud mode)
The pump's standard, internet-based control runs through Kamoer's cloud service. When you use the app in Cloud mode, it signs in with your Kamoer account and sends commands to, and reads status from, that service over an encrypted connection. This typically involves your Kamoer account identifier, authentication tokens, your pump's identifiers, and the dosing commands and device state you view or change.
The app also carries out account management against the same service. If you create a Kamoer account from within Rheon, the email address or phone number, password, verification code, and captcha response you enter are sent to Kamoer to open that account. The same applies to resetting your password, and to deleting your account — which the app can request on your behalf, and which is irreversible. In every case the account is held by Kamoer and these details go to Kamoer, never to the developer.
Kamoer Fluid Technology operates this cloud service (on Alibaba Cloud / Aliyun infrastructure) and is the party that collects and processes that information. Their handling of it is governed by Kamoer's own documents, not by this policy:
Kamoer's cloud runs on Alibaba Cloud (Aliyun) infrastructure, so using Cloud mode means your data is processed by Kamoer outside the United Kingdom and the EEA, in China. That transfer is made by you and Kamoer under Kamoer's own policies; the developer is not the controller of that data and does not carry out the transfer.
Rheon is an independent client for that service and has no control over, and takes no responsibility for, Kamoer's data practices.
4. Bluetooth mode and pump setup
When you use the app's Bluetooth mode, it connects directly to a nearby pump over Bluetooth Low Energy. In this mode no internet connection is used, nothing is sent to Kamoer's cloud or anywhere else, and no data leaves your device and pump.
Setting up a new pump also happens over Bluetooth. So the pump can join your network, the app asks the pump which Wi-Fi networks it can see, shows you that list, and then sends the network name and password you choose to the pump over Bluetooth. Those credentials travel only from your device to your pump. The app does not save them, and neither the developer nor Kamoer's cloud ever receives them.
One consequence is worth knowing: the names of the Wi-Fi networks near your pump, and the name of the one you pick, are written to the app's diagnostic log. Wi-Fi passwords never are. That log stays on your device unless you choose to attach it to a feedback submission, so if you would rather not share nearby network names, leave the log attachment off (see section 7).
5. Backups and iCloud
If you create a device backup, the app writes a file describing that pump's configuration — its identifier, name, serial number and firmware version, dosing plans, and volume-alert settings. Backups contain no passwords, no Kamoer sign-in token, and no Wi-Fi credentials.
When iCloud Drive is available on your device, backups are written to the app's own iCloud container so they survive reinstalling the app and appear on your other devices; otherwise they are kept on the device only. The Backup screen labels each backup with where it lives. This uses your own iCloud storage under your Apple Account: the developer operates no server in this and has no access to your backups. Apple's handling of iCloud data is governed by Apple's own privacy policy.
Backups are not erased by Settings → Clear App Data, and backups already written to iCloud are not necessarily removed when you delete the app. To remove them, delete them individually on the Backup screen, or remove the app's iCloud data from Settings → [your name] → iCloud on your device.
6. Notifications, widgets, and Live Activities
If you enable volume alerts, the app schedules local notifications on your device to warn you about low or depleted dosing containers. These are generated and delivered on-device and are not sent through any server.
Rheon also offers Home Screen and Lock Screen widgets, and a Live Activity that tracks a dose while it runs. These read the shared snapshot described in section 2, which the app writes as your pump data changes. Everything here is produced and displayed on your device: Rheon uses no push notifications, registers for no push token, and sends nothing to any server for these features. The snapshot is removed together with the rest of the app's data when you use Settings → Clear App Data or sign out.
7. Optional feedback
Rheon includes a Send Feedback form. Nothing is sent unless you choose to submit that form.
A submission contains the category you pick, the subject and message you enter, and — when you file a bug report — the three further fields describing what you were trying to do, what happened, and what you expected.
Every submission also carries a short block of technical context, added automatically: the app version and build number, your iOS version, your device model (for example `iPhone16,1`), your device language, and your time zone. This describes the software and hardware a problem occurred on, not you. It contains no account details, no device identifier unique to you, and no location.
A submission may also contain a screenshot and diagnostic logs, but only when you explicitly choose to attach them. Note that diagnostic logs can include the names of Wi-Fi networks near your pump (see section 4). Review the form and remove anything you do not want to share before sending. Do not include passwords, authentication codes, or account tokens.
The submission is sent over an encrypted connection to a Cloudflare Worker operated for Rheon. Cloudflare Email relays it to the developer at [email protected]. The information is used only to respond to your request, investigate problems, and improve the app. Feedback messages and attachments are deleted within 90 days. They are not used for advertising or tracking and are not sold.
If you want a feedback submission deleted sooner, contact [email protected] from the same email address or provide enough information to identify the submission.
8. Third-party components
The app includes the open-source library PhoneNumberKit to format and validate phone numbers for login. It runs entirely on your device and makes no network connections. The app contains no advertising, analytics, or tracking SDKs.
9. Children
Rheon is a tool for aquarium hardware and is not directed at children, and we do not knowingly collect information from anyone, including children.
10. Your choices
- Erase the app's local and Keychain data via Settings → Clear App Data (see section 2 for what uninstalling alone does not cover).
- Delete backups individually on the Backup screen, including the copies held in your iCloud.
- Delete your Kamoer account from Settings → Delete Account in the app, or manage it and the data Kamoer holds through Kamoer's own services and policies.
- Choose whether to submit feedback and whether to attach a screenshot or diagnostic logs.
- Decline the in-app purchase — the app's pump control works without it.
11. Your data protection rights
Apart from feedback you voluntarily submit, the developer holds no data about you. The app's local data can be erased via Settings → Clear App Data or by deleting the app, and backups are deleted separately on the Backup screen (see sections 2 and 5). To ask about or request deletion of submitted feedback, contact [email protected].
For any personal data held by Kamoer's cloud, Kamoer is the controller, so UK and EU data-protection rights — such as access, correction, deletion, portability, and objection — are exercised through Kamoer under its own policies. If you are in the UK or EU and have a concern, you may also complain to your data-protection authority; in the UK this is the Information Commissioner's Office (ICO).
12. Changes to this policy
If this policy changes, the updated version will be posted on this page with a new "Last updated" date.
13. Contact
Questions about this policy? Contact [email protected].