Emoncms.org privacy policy
Emoncms.org is run by Megni and is part of the OpenEnergyMonitor project.
This privacy policy applies to the emoncms.org service, Emoncms Android app and Emoncms iOS app.
What data do we hold, how is it collected and used?
- Account credentials: When you create an account an email address, username and password are required, enabling you to sign in to use the emoncms service. Your email address is used to verify your account, password recovery and to contact you with relevant service notifications.
- Account profile: The 'My Profile' section provides the option to enter a gravatar, name, location and bio to personalise your account. These are optional fields and are not used by emoncms other than shown in the profile section. The Timezone is used to format visualisations/graphs correctly.
- Inputs and Feeds: Emoncms stores inputs and feeds submitted to the input and feed API's and UI interface, including input & feed names, descriptions and tag/groupings. Emoncms stores timeseries data as PHPTimeSeries or PHPFina feeds, these are used to provide you with the service of data logging and data visualisation in graphs, visualisations, dashboards and apps. If you choose to make a feed public it will be accessible to read by anyone, feeds are private by default.
- Dashboard, Apps, Graph Modules: The Emoncms dashboard, apps and graph modules store configuration data required to render a dashboard, app or graph. Dashboard data contains any text and headings that you enter for use in rendering a dashboard. Dashboards are private by default but can be made public for use as public dashboards. A public dashboard will be accessible to view by anyone.
- Email reports: If you enable email reports, we store the report configuration including recipient email addresses that you enter, which may belong to people other than the account holder. Report emails contain a summary of your own feed data.
- Billing: Emoncms.org uses a notional credit balance to provide usage-based billing. We store your account balance and billing status. If you choose to link your OpenEnergyMonitor shop account, we store the email address associated with that shop account and a summary of its orders (order ID, date, order total and the emoncms credit issued), retrieved from our shop platform (BigCommerce), so that shop credit can be applied to your balance and shown on your account page. Payment is handled entirely by the shop checkout - emoncms.org does not store or have access to payment card details.
- IP addresses: Your IP address is used for rate limiting and is recorded in our security logs on events such as failed login attempts. These records are kept temporarily for security and abuse prevention.
- Cookies: Emoncms.org uses session cookies to track active session e.g to keep you signed in. The site also sets, if selected during the login process, a persistent 90-day "remember me" cookie with hashed tokens stored server-side. Neither of these are used for tracking.
- Analytics: We only record basic analytics on emoncms.org account use such as number of inputs and feeds used and the rate at which different emoncms.org API's are accessed. We use these analytics to help manage server resource use.
How do we use your data?
We use your personal information to provide the emoncms.org service to you. We store your content so that you can access it via the website, android or ios app, and so you can choose to share it.
Apart from the service providers listed below, we will not share your data with any third parties without your explicit permission (e.g unless you provide consent for use of data for research purposes for a particular defined project). We will not use your data for advertisement purposes. We will only access your data for service maintenance such as data migration and backup integrity verification and in response to specific support requests we receive from you. Service administrators are able to view an account's data (including viewing the account as you would see it) for these maintenance and support purposes.
We may also use personal information as required by applicable law, legal process or regulation; or to investigate and help prevent security issues and abuse.
Our lawful bases for processing
Under UK GDPR, we rely on the following lawful bases:
- Performance of a contract: providing the emoncms.org service itself: your account, storing and displaying your input and feed data, dashboards, apps, and billing.
- Legitimate interests: keeping the service secure and reliable: security and abuse-prevention logs, rate limiting, and basic usage analytics used for capacity management.
- Consent: optional features you choose to use: profile fields (gravatar, name, location, bio) and email reports. You can withdraw consent at any time by removing the information or disabling the feature.
- Legal obligation: where we must retain or disclose information to comply with applicable law (for example billing records, or responding to lawful requests from authorities).
Third-party service providers
We use a small number of service providers to run emoncms.org. They only receive the minimum data needed for their function:
- MailerSend: delivers our service emails (verification, password recovery, notifications, email reports). Receives your email address and the content of those emails.
- Gravatar (Automattic): if you choose to set a gravatar in your profile, our server fetches the avatar image from gravatar.com and caches it. Gravatar receives a hash of the email address you entered, but never your IP address or any other information about your visit.
We do not sell your data or share it with anyone for advertising.
Publicly Available Information
All emoncms.org account data is private by default. You can choose to make feeds and dashboards public if you wish to share your data and dashboards publicly. Please be aware that energy monitoring data can reveal information about daily routines and occupancy, so before making feeds or dashboards public please make sure that everyone in your household is happy for this data to be shared.
How is your data stored?
All non-timeseries account data is stored in a MySql database. Passwords are stored within this database as a salted one-way cryptographic hash. Timeseries data is stored as PHPTimeSeries or PHPFina feeds. Emoncms.org is built on a multi-server architecture with multiple storage servers. Your timeseries data may be stored on any of these storage servers and moved between them in order to manage disk and processor resource use. We keep regular backups on separate servers to protect against data loss.
Emoncms.org servers are located in the UK. Service emails are delivered via MailerSend, whose services are hosted in a data centre in Belgium, a transfer covered by the UK's adequacy regulations for the EEA.
How do we protect your data?
Emoncms.org has industry-standard security measures in place to protect the data under our control against loss, misuse, destruction and alteration, including:
- Access control: account data is private by default. Access requires your username and password, or your account's read or write API key, which grant different levels of access.
- Encryption in transit: access to the emoncms.org web interface is encrypted with TLS: plain HTTP requests to the home and login pages are redirected to HTTPS, so signing in through your browser always happens over an encrypted connection. API endpoints accept both HTTPS and plain HTTP, as some low-power embedded devices cannot support TLS. For these devices emoncms.org provides an AES-128 encryption option, which encrypts posted data using your API key as a pre-shared key. We recommend using HTTPS, or the AES-128 option, wherever your device supports it.
- Password storage: passwords are stored as a salted one-way cryptographic hash, never in plain text.
- Rate limiting and monitoring: requests are rate limited and security events such as failed login attempts are logged, helping us detect and respond to abuse.
- Backups: regular backups are kept on separate servers to protect against data loss.
How long do we store your information?
We keep your information for as long as your account remains active and as needed to provide you with the emoncms.org service.
Your rights
Under UK GDPR you have the right to access, correct, delete, export, restrict or object to the processing of your personal data. Most of these can be exercised directly from your account:
- Access & portability: feed data can be exported in CSV format from the emoncms.org feeds page. Alternatively to migrate inputs and feeds to another Emoncms server it's possible to use either the backup / replication script or the emoncms sync module. Dashboards can be downloaded using the sync module or using the html editor within the dashboard module configuration page.
- Rectification: your username, email and profile details can be changed from the emoncms.org account and profile sections.
- Erasure: feed data can be permanently removed from the emoncms.org server at any time by logging into your account and deleting the feeds you wish to delete. To delete your whole emoncms.org account, use the delete account feature on the 'My Account' page.
- Restriction & objection: contact us at the address below.
All of this is free of charge. If you contact us about your data, we may need to ask for futher information to confirm your identity.
Identifying the Data Controller
Megni Partnership, trading as OpenEnergyMonitor, based in the UK, is the data controller for emoncms.org.
Complaints
If you have a concern about how we handle your data, please contact us first and we will do our best to resolve it. You also have the right to lodge a complaint with the UK data protection authority, the Information Commissioner's Office (ICO), at any time: https://ico.org.uk/make-a-complaint/.
Data breaches
In the event of a personal data breach we will notify the ICO and, where required, affected users, in accordance with UK GDPR requirements.
Children and young people
Accounts must be held by someone aged 18 or over. Young people are welcome to use emoncms.org for school projects or to monitor their own home, but the account should be registered to a parent, guardian or teacher, who remains responsible for it.
Changes to the Privacy Policy
We may modify this Privacy Policy at any time, and such modifications shall be effective upon posting of the modified Privacy Policy. Notification of material changes to this Privacy Policy will be provided by noting a new "updated" date at the bottom of this page.
Contact Us
If you have any questions about this Privacy Policy, please contact us at:
support@openenergymonitor.zendesk.com.
Megni (T/A OpenEnergyMonitor)
Glyn Hudson & Trystan Lea
Caban Cyf, Brynrefail
Caernarfon, Gwynedd
LL55 3NR
United Kingdom
+44(0)1286800870
Updated August, 2026.