Smart Green Indoor Air Privacy Policy
Effective date: 23 June 2026
Overview
Smart Green Indoor Air is a research prototype app for indoor air quality in residential settings. It was developed by Kheybar Mammadnaghiyev as part of a PhD research project at Liverpool John Moores University (LJMU).
The app is intended only for agreed research participants who have been given an indoor air quality sensor and app access details for their assigned sensor.
This policy explains what app data may be collected, how it is used, who may receive it, how long it may be kept, and how to contact the researcher.
The app does not use personal user accounts. Participants access the app using their assigned sensor ID and passcode. App data is linked to the assigned sensor, and a hashed sensor identifier is used for app requests and stored app records where possible.
For questions about this policy, the app, or app-related data, contact:
Kheybar Mammadnaghiyev
PhD researcher and app developer
K.Mammadnaghiyev@2025.ljmu.ac.uk
The research project is carried out in an LJMU academic research context. Research records, participant information, and study administration are also governed by the relevant approved study materials, University research governance processes, and applicable data protection law.
Key Points
- The app uses assigned sensor identifiers and sensor-linked app data.
- The app and backend use a hashed sensor identifier where possible.
- The app does not ask participants to enter their name, postal address, email address, phone number, payment details, or any other direct contact details.
- The app does not contain advertising, does not use app data for advertising, does not sell app data, and does not use advertising identifiers.
- The app is not a medical or diagnostic app. Readings, alerts, advice, and in-app indicators are informational only.
- The app is not intended for children or general public use.
What Data the App Collects
Smart Green Indoor Air may collect, use, store, or transmit the following app data:
- Sensor access information: assigned sensor ID entered in the app, hashed sensor identifier, local sign-in state, and passcode verification information. The passcode is hashed locally for access checking.
- Indoor air quality readings: sensor readings linked to the assigned sensor, namely CO₂, PM2.5, VOC, temperature, humidity, and reading timestamps.
- Derived air quality information: indoor air quality score, indoor air quality statuses, time-in-good-air measures and related timestamps.
- Optional in-app survey answers: room type, room size, occupancy, time spent in the room, ventilation options, outdoor surroundings, main concern, available devices, cooking sources, indoor pollution sources, moisture sources, and temperature control options.
- Optional report answers: selected mood options, selected action options, and any optional free-text action entered under "Other".
- App progress information: badges, points, streaks, and related timestamps.
- Notification information: Firebase Cloud Messaging token, device platform type, and notification preferences.
- Local app settings: sign-in state, assigned sensor state, survey completion state, and push token state stored on the participant's device.
- Technical information: request times, status or error information, network metadata needed to operate, troubleshoot, and secure the app, and backend logs.
The app does not collect names, postal addresses, email addresses, phone numbers, payment details, precise location, contacts, calendar information, camera data, microphone recordings, screen recordings, government identification numbers, clinical medical records, or advertising identifiers. The main identifier used in the app is the assigned sensor ID, and app records are linked to the assigned sensor rather than to a direct personal profile.
Recruitment, research consent, contact lists, and wider study administration records are not collected or stored in the app. They are managed separately outside the app under the relevant study materials and University records processes.
Where the Data Comes From
Some data is provided directly by participants, such as the assigned sensor ID, optional survey answers, optional report answers, notification preferences, and optional free-text report content.
The assigned sensor ID is entered by the participant to connect the app to the correct sensor. The app uses a hashed version of this sensor ID for app requests and sensor-linked app records where possible.
Indoor air quality readings come from the participant's assigned sensor and are retrieved through Airthings, the approved sensor data provider.
Notification tokens are generated by Firebase Cloud Messaging so notifications can be delivered to the participant's device where notifications are enabled.
Technical information is generated when the app, sensor systems, and backend services communicate with each other.
How the Data Is Used
App data is used to:
- verify access to the assigned sensor
- show current and historic indoor air quality readings
- calculate and display scores, statuses, charts, and progress
- generate indoor air quality alerts and advice
- personalise alert wording based on optional survey answers
- send notifications where notifications are enabled or supported
- support optional reports about actions taken and how the room felt
- support progress features such as badges, points, and streaks
- support analysis and evaluation for the PhD research project
- maintain, troubleshoot, secure, and improve the app and backend services
- respond to support, operational, research governance, and data protection requests
App data is not used for advertising, advertising profiling, sale to third parties, or unrelated marketing.
Research Participation
The app is used in the context of an academic PhD research project. The app dataset is sensor-linked and does not include direct contact details collected through the app. Where sensor-linked app data is treated as personal data under applicable UK data protection law, it is handled in line with the relevant approved research study materials, University research governance processes, and applicable data protection requirements.
Participation in the research project is voluntary and is managed through the relevant participant consent process outside the app.
Some app features are optional. For example, participants can disable notifications, choose whether to answer survey questions, and choose whether to submit optional reports.
Who May Receive Data
App data may be accessed by the PhD researcher, supervisors, authorised project team members, technical support staff, or other authorised University staff where access is necessary for the research project, app operation, support, security, maintenance, service delivery, or data protection requests.
External service providers may process information where necessary to operate the app:
- Firebase Cloud Messaging, to generate and manage push notification tokens and deliver app notifications
- Airthings, to provide readings from assigned sensors
- Google Play, Apple App Store, and device notification services, for app distribution, device-level app functions, and notification delivery where notifications are enabled
- Liverpool John Moores University server infrastructure, to host the app backend, database, API, and related technical services
These service providers may process app data only where needed for their service role. App data is not sold, shared with advertising networks, or used for advertising.
If a participant uses the app's share feature, the app may create shareable app-generated content, such as badge or progress content, and pass it to the device share sheet. Sharing is user-initiated, and the participant chooses the receiving app or person.
Information may also be shared where required by law, research governance, University audit or records requirements, or valid legal process.
Permissions and Device Features
The app uses internet access to communicate with backend services, retrieve assigned sensor readings, send survey or report answers where submitted, register or unregister notification tokens, and show linked information.
The app may ask for notification permission so it can send indoor air quality alerts and optional reminders. Notifications can be disabled in the app or device settings.
The app does not request access to precise location, contacts, calendar, camera, microphone, SMS, call logs, installed app inventory, or advertising identifiers.
The app does not read the photo library. If a participant chooses to save or share an app-generated badge or progress image, the device may ask for permission to save that generated image or pass it to another app selected by the participant.
Security
The app uses technical and organisational measures intended to protect information, including:
- HTTPS for communication between the app and backend services
- hashed sensor identifiers where possible rather than raw sensor IDs
- local hashing of the passcode for app access validation
- not storing participant names, postal addresses, email addresses, or phone numbers in the database
- access controls for backend systems and databases
- limiting access to staff or service providers who need the information for their role
- deleting or replacing push notification tokens when tokens change, notifications are unregistered, or a device is disconnected where possible
No system can be guaranteed to be completely secure, but reasonable steps are taken to protect the information used by the app.
Retention and Deletion
App data may be kept for the duration of the PhD research project and for any further period required for examination, audit, research governance, publication, archiving, legal, or University records management purposes.
Push notification tokens may be deleted or replaced when notifications are disabled, the device token changes, a device is unregistered, or the participant logs out.
Survey answers, optional reports, app progress records, and sensor-linked history may be retained while needed for the research project, unless deletion is requested and deletion is compatible with applicable legal, research governance, audit, archiving, or University records requirements.
The app does not let members of the public create their own accounts. Access is based on assigned sensor details provided to agreed research participants. Disconnecting the sensor or logging out removes local app access information from the device and attempts to unregister the push notification token where possible. It does not automatically delete sensor-linked research data already held by the project.
Participants can request deletion of sensor-linked app data by contacting Kheybar Mammadnaghiyev at K.Mammadnaghiyev@2025.ljmu.ac.uk.
Your Choices
Participants can choose not to enable notifications. The app can still show readings when opened, but it will not send push notifications to the device.
Participants can choose not to provide survey answers. Core app features can still be used, but alerts and advice may be less personalised.
Participants can choose not to submit optional reports about mood and actions taken. The app can still be used, but some optional in-app features may be limited.
Participants should avoid entering direct identifiers, contact details, or unnecessary sensitive information in optional free-text report fields.
If a participant does not provide the assigned sensor ID and passcode needed for access, the app will not be able to show readings for the assigned sensor.
If a participant chooses not to use the app or assigned sensor, they may not be able to take part in this element of the research project. The research team should explain any effect on participation in the participant information sheet.
Automated Processing
The app does not use automated decision-making to make decisions about participants that have legal or similarly significant effects.
The app may automatically generate alerts, advice, in-app indicators, badge progress, and report prompts based on sensor readings, survey answers, notification preferences, and app activity. These outputs are informational only and are intended to help participants understand indoor air quality and possible actions.
Changes to This Policy
This privacy policy may be reviewed and updated where necessary. If there is a genuine change in how app data is used, updated privacy information will be brought to participants' attention before starting any new processing where required.