Straight to the solution
Search by keyword or filter the questions by subject area.
Schnell beantwortet
From the first URL to the managed device fleet, you'll find clear answers about features, licenses, platform boundaries, data protection and operations.
Search by keyword or filter the questions by subject area.
For setup and all features, the help page guides you step by step through the product.
If an answer is missing, you can reach us directly at apps@cesinger.de.
Installation, homepage and the way to kiosk mode.
Nein. Free and the local Pro functions can be used without a customer account. An account is only necessary if you voluntarily pair devices with Fleet Cloud, manage licenses in the portal or work with a team.
An HTTPS site is the norm. Unencrypted HTTP is only accepted for explicitly permitted private LAN destinations.
Public HTTPS pages and private LAN pages are possible. Navigation, pop-ups, scanner and NFC targets must match the domain allowlist. Public HTTP pages, invalid certificates and safe browsing warnings are not bypassed.
The PIN protects local settings and leaving the administered area. The allowlist limits which hosts the main navigation, pop-ups and imported links are allowed to switch to. Both complement kiosk mode, but do not replace operating system management.
On Android, this is possible depending on the device configuration and is most reliable in device owner operation. iOS does not allow normal apps to auto-start on their own; Supported devices can be returned to kiosk operation via MDM and single app mode.
Browser, autopilot, display, home assistant and integrations.
Autopilot monitors charge status, network and renderer. If there are problems, it escalates locally: reload, open the homepage, rebuild the WebView and finally display Offline Rescue. For paired devices, only a technical diagnostic status is reported - no page content or screenshots.
Offline Rescue shows a clear replacement local view instead of a black or frozen screen. As soon as the homepage is accessible again, KioskPilot tries to return in a controlled manner. Local LAN dashboards can continue to run independently of the Internet.
Yes. Quick Setup finds Home Assistant instances via mDNS in the local network, adopts the address and adds the host to the allow list. Pro also offers local API as well as TLS-MQTT and Home Assistant Discovery.
After the specified period of inactivity, it deletes the Kiosk WebView's cookies, web storage, and form and browser history and loads the homepage as a fresh session. The function must be activated consciously; the reset cannot be undone.
The local check highlights small touch targets, missing labels, horizontal overflow, problematic scaling, and basic contrast and font size issues. A value like 30/100 is a clear test indication, but not a complete WCAG certificate.
Depending on the platform, screen keeper, orientation, day and night brightness, schedule, pixel shift and a black, clock or message screensaver are available. Operating system and hardware limitations remain.
Yes, each separate and restrictive by default. Web permissions are only granted to shared hosts. File uploads use the system dialog. Scanners and NFC targets go through the same URL and allowlist check.
The Universal Launcher bundles tested web and app targets. Configurations can be exported and imported as validated JSON without PIN, passwords or tokens. Browser profiles control user agent, zoom, cookies, pop-ups and other compatibility options.
Free, Pro and a clear separation from the Fleet Cloud.
Always per device or tied installation. A user account can manage multiple devices, but does not automatically give those devices Pro. Four device licenses are required for four Pro devices.
The fully-fledged local web kiosk with allowlist, autopilot, offline rescue, home assistant quick setup, basic browser and display functions, accessibility check and without advertising and time limits. A visible free watermark remains in the kiosk.
Pro removes the watermark and enables, among other things, advanced local management features, device owner/lock task support on Android, local token-protected API, TLS-MQTT, enterprise policies as well as advanced autopilot, privacy and display features.
An assigned license space can be released and reassigned in the customer portal. Store licenses and cryptographically bound installations also follow the rules of the respective store; a portal association does not automatically transfer a store purchase.
Pro activates local functions on exactly one device. Fleet Cloud is a separate B2B offering for central administration, teams, heartbeats, groups, rollouts, health, incidents and support sessions. Fleet does not replace a Device Pro license.
Store receipts come from the respective store. KioskPilot direct invoices and fleet documents are protected under Abrechnung & Belege. The invoice address valid at the time of issue will be stored unchangeably.
Pair devices, assign licenses and operate them together.
Generate a short-lived pairing code under Devices in the portal and enter it in the app. After successful pairing, the device will appear in your organization. Access can be revoked in the portal; After that, a new pairing is necessary.
Owners manage the entire organization. Admins manage users, licenses, billing and devices. Operators work with devices and rollouts. Read-only is allowed to view organizational, device and billing data, but cannot change anything.
Devices are grouped together. New configurations can be initially rolled out to test devices or a percentage, monitored based on revision and health, then expanded or reverted to the previous configuration.
Health evaluates technical conditions and warnings. Related warnings are bundled into incidents. Secure actions such as reload, home page and configuration synchronization can be scheduled manually, once or weekly; Maintenance windows suppress expected warnings.
It is one-time, short-lived and only becomes active after visible consent on the device. Permissions are limited, access ends automatically and can be revoked locally. This means that the camera or microphone are never released unnoticed.
Local-first, secure accounts and traceable boundaries.
No website content, form entries or browser histories in local operation. With voluntary fleet coupling, technical states such as device ID, version, heartbeat, configuration revision and diagnostic counter are transmitted. Content stays local.
The backend token remains server-side; the browser only receives a Secure, HttpOnly and SameSite Strict session cookie. Strong passwords, timed password reset, TOTP MFA, one-time recovery codes and revocation of active sessions are supported.
It is off by default, limited to private networks and requires a random bearer token. TLS-MQTT or the HTTPS control plane should be used for untrusted networks, as a local HTTP transport does not ward off LAN attackers who are already reading.
Android can be heavily locked as a correctly provisioned dedicated device with device owner and lock task. A normal installation remains restricted by Android system limits. Guided Access or MDM Single App Mode for supervised devices are required on iPhone and iPad.
Quickly narrow down the most common causes.
Check internet access, pairing status, system time and whether the app is active or paused by the operating system. A locally running kiosk can continue to function despite the lack of a cloud heartbeat. If necessary, revoke and re-pair the device.
First run “Restore Purchases”. If the status remains inconsistent, full license synchronization can remove local entitlement caches and requery the store and control plane. It does not delete a store purchase.
The target host must be allowed, pop-ups require a user gesture and the corresponding browser option. Scanner, NFC and launcher links are also checked. SSL errors or safe browsing hits cannot be unlocked.
Nutze Passwort vergessen, check the email address and do not delete any necessary session cookies. After changing the password, old sessions are intentionally terminated. In the event of repeated failed attempts, protection against misuse temporarily takes effect.
No suitable answer found. Try a different search term or open the detailed help.
The complete instructions explain each feature step by step. If you have a specific problem, you can also write to us with the platform, app version and a short description of the error - please without passwords or secret tokens.
Quick answers
From the first URL to a managed device fleet: find clear answers about features, licenses, platform limits, privacy, and operations.
Search by keyword or filter questions by topic.
The help page walks you through setup and every major feature.
If an answer is missing, contact us directly at apps@cesinger.de.
Installation, home page, and entering kiosk mode.
No. Free and local Pro features work without an account. You only need one when voluntarily connecting devices to Fleet Cloud, managing licenses in the portal, or working with a team.
HTTPS is the default. Unencrypted HTTP is accepted only for explicitly allowed private LAN targets.
Public HTTPS sites and private LAN pages are supported. Navigation, pop-ups, scanner, and NFC targets must match the domain allowlist. Public HTTP, invalid certificates, and Safe Browsing warnings are never bypassed.
The PIN protects local settings and administrative exit. The allowlist limits which hosts navigation, pop-ups, and scanned links can open. Both complement kiosk mode but do not replace operating-system management.
On Android this depends on device configuration and is most reliable with Device Owner. iOS does not allow regular apps to auto-start; supervised devices can return to kiosk operation through MDM and Single App Mode.
Browser, Autopilot, display, Home Assistant, and integrations.
Autopilot monitors loading, network, and renderer state. It escalates locally: reload, open the home page, rebuild the web view, and finally show Offline Rescue. Connected devices report only technical diagnostics—never page content or screenshots.
Offline Rescue shows a clear local fallback instead of a black or frozen screen. KioskPilot returns to the home page when it becomes available. Local LAN dashboards can continue independently of the internet.
Yes. Quick Setup discovers Home Assistant via mDNS, adopts the address, and adds the host to the allowlist. Pro also offers a local API, TLS MQTT, and Home Assistant Discovery.
After configured inactivity it clears cookies, web storage, form data, and browsing history from the kiosk web view, then opens a fresh home-page session. It must be enabled deliberately and cannot be undone.
The local check flags small touch targets, missing labels, horizontal overflow, scaling issues, and basic contrast or font-size concerns. A score such as 30/100 is a strong review signal, not a complete WCAG certification.
Depending on platform: keep-awake, orientation, day/night brightness, schedules, pixel shift, and black, clock, or message screen savers. OS and hardware limits still apply.
Yes, separately and restrictively by default. Web permissions are granted only to allowed hosts. File uploads use the system picker. Scanner and NFC targets go through the same URL and allowlist checks.
Universal Launcher combines approved web and app targets. Validated JSON can be imported or exported without PINs, passwords, or tokens. Browser profiles control user agent, zoom, cookies, pop-ups, and compatibility settings.
Free, Pro, and the clear separation from Fleet Cloud.
Always per device or bound installation. One user account can manage multiple devices, but does not automatically give them Pro. Four Pro devices require four device licenses.
The local web kiosk with allowlist, Autopilot, Offline Rescue, Home Assistant Quick Setup, core browser and display features, Accessibility Check, no ads, and no time limit. A visible Free watermark remains.
Pro removes the watermark and enables advanced local management, Android Device Owner/Lock Task support, token-protected local API, TLS MQTT, enterprise policies, and enhanced Autopilot, privacy, and display features.
A portal license seat can be released and reassigned. Store licenses and cryptographically bound installations also follow store rules; changing a portal assignment does not automatically transfer a store purchase.
Pro unlocks local features on one device. Fleet Cloud is a separate B2B offering for centralized management, teams, heartbeats, groups, rollouts, health, incidents, and support sessions. Fleet does not replace a device Pro license.
Store receipts come from the respective store. KioskPilot direct invoices and Fleet documents are protected under Billing & receipts. The billing address valid at issue time is stored immutably.
Pair devices, assign licenses, and operate together.
Create a short-lived pairing code under Devices and enter it in the app. The device then appears in your organization. Access can be revoked in the portal; pairing is required again afterward.
Owners manage the organization. Admins manage users, licenses, billing, and devices. Operators handle devices and rollouts. Read-only can view organization, device, and billing data without changing it.
Devices are grouped. New configurations can start on test devices or a percentage, be observed by revision and health, then promoted or rolled back to the previous configuration.
Health evaluates technical state and alerts. Related alerts form incidents. Safe actions such as reload, home, and config sync can run manually, once, or weekly; maintenance windows suppress expected alerts.
It is single-use, short-lived, and starts only after visible consent on the device. Permissions are limited, access ends automatically, and it can be revoked locally. Camera and microphone are never enabled silently.
Local-first operation, secure accounts, and clear limits.
In local mode, no website content, form entries, or browsing history. Voluntary Fleet pairing sends technical state such as device ID, version, heartbeat, configuration revision, and diagnostic counters. Content remains local.
The backend token stays server-side; the browser receives only a Secure, HttpOnly, SameSite-Strict session cookie. Strong passwords, expiring password reset, TOTP MFA, one-time recovery codes, and session revocation are supported.
It is off by default, limited to private networks, and requires a random bearer token. Use TLS MQTT or the HTTPS control plane on untrusted networks, because local HTTP cannot defeat an attacker already reading LAN traffic.
Properly provisioned Android Dedicated Devices can use Device Owner and Lock Task. Regular installations remain subject to Android limits. iPhone and iPad require Guided Access or MDM Single App Mode on supervised devices.
Quickly narrow down the most common causes.
Check internet access, pairing, system time, and whether the OS suspended the app. A local kiosk may keep working without a cloud heartbeat. Revoke and pair again if needed.
Run Restore purchases first. If state remains inconsistent, full license sync clears local entitlement caches and queries store and control plane again. It does not delete a store purchase.
The host must be allowed, pop-ups require a user gesture and the relevant option, and scanner, NFC, and launcher links are checked too. TLS errors and Safe Browsing warnings cannot be bypassed.
Use Forgot password, verify the email address, and keep required session cookies enabled. Password changes deliberately revoke old sessions. Repeated failures temporarily trigger abuse protection.
No matching answer found. Try another term or open the detailed guide.
The complete guide explains every feature step by step. For a specific issue, send us the platform, app version, and a short description—never passwords or secret tokens.