Missing User Warnings
Medium
- Confidence
- 85% confidence
- Finding
- The README explicitly states that the dashboard sends daily summaries to the homeowner via Slack or email, but it provides no warning about the privacy sensitivity of home telemetry such as occupancy, room status, energy usage, and device state. In a smart-home context, these summaries can reveal behavioral patterns, presence/absence, and security-relevant information, so transmitting them through third-party channels without data-minimization or privacy guidance creates a real data exposure risk.
