HomeGlance Privacy Policy
The short version: your video, audio, recordings, snapshots and timeline are never uploaded to our servers — they stay on your own devices. Our servers hold only the minimum needed for two devices to find each other: an Apple user identifier, device identifiers, the names you give your cameras, status heartbeats, push tokens, and presence events (with a small thumbnail) used to generate notifications, which are deleted after 7 days. There is no analytics, no advertising and no tracking.
1. What we collect and why
| Data | Purpose | Retention |
|---|---|---|
| Apple user identifier (the user ID returned by Sign in with Apple) | Identify your account and attach cameras to it | For the life of the account |
| Email address (only if you choose to share it at sign-in; may be Apple's private relay address) | Contact you about your account when necessary | For the life of the account |
| Device identifiers (an app-generated device ID, the hostname and private-network IP of the device) | Attach the device to your account and establish encrypted connections between your devices | Until the device is removed |
| Device model, system version, app version | Compatibility and troubleshooting | Until the device is removed |
| Camera name (the name you chose) | Shown in the viewer interface and in notification titles | Until the camera is removed |
| Status heartbeat: battery level and charging state, thermal state, whether a person is currently detected, last report time (roughly every 60 seconds) | Show online/offline state and send "camera offline" alerts | Only the latest value is kept |
| Push token (APNs token), push environment, app version | Deliver notifications to your viewer devices | Until the device is removed or the token becomes invalid |
| Presence events: type (person appeared / person left), timestamp, and an optional small thumbnail (JPEG, at most 64 KB) | Generate push notifications and let a notification show its thumbnail | Deleted automatically after 7 days |
| Session, camera and pairing tokens | Verify that a request comes from your devices | Stored only as SHA-256 hashes, never in the clear |
The servers also produce ordinary access logs (request time, endpoint, IP address) used for troubleshooting and abuse prevention. They are deleted automatically after at most 90 days.
2. What we do not collect
- Video and audio. The live stream and two-way talk go directly between your two devices. We have no way to view or record them.
- Recorded clips. Clips recorded when a person is detected stay on the camera phone; only your own viewer can fetch them over the encrypted connection.
- The timeline. The database of presence intervals lives on the camera phone.
- Snapshots. Snapshots you save go to your phone's photo library only.
- We do not collect location, contacts, calendars, photo library contents or health data, and we do not use the advertising identifier (IDFA).
Presence detection answers only "is a person in frame". It performs no face recognition, does not identify anyone, and runs entirely on the camera phone.
3. How your devices connect
HomeGlance embeds WireGuard so your devices form a private network that belongs to your account alone. The private keys used for encryption are generated on and never leave the devices; our control server only distributes public keys and node information so the devices can find each other.
- Direct. The two devices establish an encrypted connection between themselves and no third party sees the traffic.
- Relayed. When the network does not allow a direct path, encrypted packets are forwarded by a relay server we operate. The relay sees only ciphertext — the operator cannot decrypt your video or audio.
The control server, the backend API and the relay are all self-hosted and located in Shanghai, China. None of them store video or audio content.
4. Permissions the app requests
| Permission | Why |
|---|---|
| Camera | Camera mode: capture the scene and run on-device human detection. Viewer mode: scan the pairing QR code. |
| Microphone | Two-way talk and live audio |
| Local network | Discover and connect directly to the other device on the same Wi-Fi network |
| Photos (add only) | Save snapshots from the viewer to your photo library |
| Notifications | Event and offline alerts; in camera mode, a reminder if the app gets sent to the background |
5. Third parties
- Apple. Sign in with Apple is used for login, and the Apple Push Notification service (APNs) delivers notifications. A notification contains the camera name, the event type, a timestamp and a one-time link used to fetch the thumbnail.
- No analytics SDK, no third-party crash reporting, no advertising, no cross-app or cross-site tracking.
- We do not sell, rent or share your data with third parties. We would disclose data only where the law clearly requires it.
6. App Store privacy label
| Category | Contents |
|---|---|
| Data Linked to You |
Identifiers: Apple user ID, device ID User Content: camera names, presence-event thumbnails (kept 7 days) Contact Info: email address, only if you share it at Apple sign-in Diagnostics: performance data (battery, thermal state) and other diagnostic data (device model, OS version, app version, online and presence flags) |
| Data Not Linked to You | None |
| Data Used to Track You | None |
7. Retention and deletion
- Deleting a camera. Unpair it from the camera's settings screen in the viewer. The server deletes that camera's record and its node in the private network, and invalidates the related tokens. The camera phone returns to the unpaired state.
- Deleting your account. Choose "Delete account" on the account screen in the app. The server deletes your account, every device record under it, push tokens, any events and thumbnails that have not yet expired, and all network nodes. This cannot be undone.
- Data on the devices. Clips and the timeline live on the camera phone; clear them from the camera's settings screen, or delete the app.
- Presence-event thumbnails are deleted from the server after 7 days in every case.
8. Security
- All communication with our servers uses TLS.
- Device-to-device communication uses WireGuard encryption; keys do not leave the devices.
- Tokens are stored only as hashes. Pairing secrets are valid for 10 minutes and network enrolment keys are single-use and valid for 15 minutes.
- Access control guarantees that a viewer can reach only cameras on the same account; other accounts are invisible, and viewers cannot reach each other.
No system can be guaranteed absolutely secure, but we keep the amount of data held on our servers as small as possible.
9. Children
HomeGlance is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe we have received such information, contact us and we will delete it.
10. Your responsibilities
A camera records whatever it is pointed at. Please follow the laws in your area about video and audio recording, obtain any consent required where other people may appear, and do not point a camera into someone's private space.
11. Your rights
You can review the devices on your account, rename a camera, delete a single camera or delete the whole account from inside the app at any time. If you want a copy of the data our servers hold about your account, or have another data request, email us.
12. Changes to this policy
If this policy changes we will update this page and the effective date at the top. Material changes will also be surfaced in the app.
13. Contact
Yang Cao · homeglance [at] defg.uk