SecureEyes does not collect your data.
There is no account to create, no analytics, no crash reporting, no advertising and no tracking of any kind. Your cameras, their passwords, your video, your snapshots and your motion history live on your own devices and your own network. We do not receive them, and we could not hand them over if we were asked, because we never have them.
The short version
SecureEyes does not collect your data. There is no account to create, no analytics, no crash reporting, no advertising and no tracking of any kind. Your cameras, their passwords, your video, your snapshots and your motion history live on your own devices and your own network. We do not receive them, and we could not hand them over if we were asked, because we never have them.
Two SecureEyes-operated servers exist, both optional and both used only by the Pro tier: a relay that carries encrypted traffic it cannot read, and a licence server that turns an App Store purchase into a signed licence. Neither stores anything about you. The rest of this document is the detail behind those paragraphs.
What SecureEyes stores, and where
All of it is on your device, in the app's own container.
- Camera list: names, addresses, ports, stream paths, and the brand and model found by discovery, in app storage.
- Camera usernames and passwords, in the system Keychain rather than app storage.
- Motion events, snapshots and recorded clips, in app storage on disk.
- App settings and preferences, in UserDefaults.
- A device name and key pair, so your devices can recognise each other for sync.
- Which plan you bought, read from Apple's StoreKit. The receipt is Apple's, not ours.
Motion history is deliberately excluded from device backups. It is short-term local evidence rather than an archive, so it does not restore onto a new device and does not consume your iCloud storage.
What leaves your device, and what does not
Your local network. The app talks to your cameras directly over your own network, using RTSP, ONVIF and HTTP. Video, snapshots and camera credentials travel between your camera and your device and go nowhere else. On iOS this is why the app asks for Local Network permission.
iCloud, only if you turn sync on. Sync is off by default. When it is on, your camera list travels through your own iCloud account, and camera passwords travel through iCloud Keychain, which Apple encrypts end to end. Apple is the processor and Apple's privacy policy governs it. SecureEyes has no access to your iCloud account and never receives any of it.
Device to device, if you use a transfer code. Moving a setup from one of your devices to another packs it into a PIN-protected transfer code that the receiving device scans. The data goes directly between your two devices.
Apple, when you buy something. Purchases run through the App Store. Apple processes the payment and tells the app what was bought. We never see your payment details, and we receive no name, email address or Apple Account identifier from the purchase.
Your own SecureEyes Hub, if you have one. The Hub is a computer in your house that you own and run. The app talks to it over your network. Cameras, recordings and events on the Hub stay on the Hub.
- The relay, only when you view your cameras away from home. Reaching your Hub from outside your network uses a relay at relay.secureeyes.app. Every frame is sealed end to end with a key belonging to your Hub, which the app learned on your own network during pairing. The relay forwards ciphertext it has no key for, refuses to carry anything unsealed, and stores nothing. It can see that a connection exists, from which network address, for how long, and how many bytes crossed it. It cannot see your video, your camera names or your credentials.
- The licence server, only when you license a Hub for Pro. Activation sends license.secureeyes.app four things: a random installation identifier the Hub generated for itself, a fingerprint of the Hub's public key, the tier being claimed, and Apple's signed proof of purchase. The server verifies the purchase with Apple's public keys, returns a signed licence bound to that Hub, and keeps no database. The installation identifier is not a device identifier, is not linked to you, and identifies nothing outside your own Hub.
Links that open your browser. The support address, this policy and the media engine source offer open in your browser when you tap them. From that point your browser's own behaviour applies.
What SecureEyes never does
These are absences in the code, not promises about intent.
- No analytics or usage measurement. No SDK of that kind is linked.
- No crash or diagnostics reporting. Nothing is sent automatically when the app fails. A bug report is an email you compose, read and send yourself, and the playback counters it pre-fills are visible to you in the message body before you send it.
- No advertising, no advertising identifier, no tracking. Nothing is shared with a data broker or an ad network, and nothing about you is combined with data from anywhere else.
- No user accounts. There is nothing to sign up for and no password of ours to lose.
- No runtime downloads. The bundled typefaces ship inside the app, so no font is fetched at runtime.
- No selling or sharing of personal information, under the CCPA meaning of either word. There is nothing to sell.
Permissions the app asks for, and why
- Local Network, on iOS and iPadOS, to find and reach cameras on your network. Nothing leaves your network because of it.
- Camera, to scan a setup code shown on another of your devices. It records no photo or video.
- Photos, add only, to save a snapshot or clip you chose to save. It does not read your library.
- Face ID or Touch ID, to unlock the app. Biometrics stay on your device with Apple; the app is told yes or no.
- Notifications, to alert you about motion your own cameras or Hub detected. Local notifications only; there is no push server.
Each of these is asked for at the moment it is needed, and the app works without the optional ones.
Keeping and deleting
Everything the app keeps is on your device, so you control all of it. Deleting a camera removes it and its stored password. Clearing events and clips removes them from disk. Deleting the app removes the app's container, and with it every event, snapshot, clip and setting. Camera passwords held in iCloud Keychain are managed by Apple in Settings, because they are your Keychain items rather than ours.
We hold no copy of any of it, so there is nothing for us to delete on request and nothing for us to retain after you stop using the app.
Children
SecureEyes is not directed at children and collects no data from anyone, including children under 13, under 16, or of any age.
Your rights
Under the GDPR, the UK GDPR, the CCPA and comparable laws you have rights to access, correct, delete and port your personal data, and to object to its processing. For SecureEyes those rights are satisfied structurally: we are not a controller or a processor of your personal data, because none of it reaches us. Your data is already in your hands, on your devices, and you can read, change, export and destroy all of it without asking us.
If you believe we hold something about you, write to the address below and we will tell you exactly what we find, which we expect to be nothing.
Security
Camera passwords are stored in the system Keychain rather than in app storage. Remote viewing is sealed end to end to your own Hub, and a relay connection that is not sealed is refused rather than downgraded. Pairing happens on your own network, which is what lets a later remote session verify it is talking to the same Hub. App Lock, if you turn it on, holds the app behind Face ID, Touch ID or your device passcode.
No system is perfect, and we would rather say so than imply otherwise. What we can say precisely is that a breach of our infrastructure would expose no customer video, no camera credentials and no camera list, because our infrastructure never holds any.
Changes
If this policy changes in a way that affects what happens to your data, the change will appear here with a new effective date, and the app's release notes will say so. Changes that only clarify wording will be noted by date alone.
Contact
Questions about this policy go to [email protected].