Privacy Policy
Effective date: 9 September 2026
- Your photos and videos are yours. We store them so you can view them, and for nothing else.
- We do not sell your data, run ads, or build advertising profiles.
- The camera only captures when a schedule you set is running, or when you tap Capture. No audio, no live stream.
- You can export or delete everything, any time. Deleting your account removes your images within 24 hours.
- Questions or requests: jordan@snitchy.net.
Snitchy ("Snitchy", "we", "our", or "us") is a time lapse camera service operated from Australia. It lets you turn a spare Android phone into a long-term time lapse and monitoring camera, and watch it from the Snitchy app on your main phone. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over it.
This policy applies to the Snitchy Camera app (Android), the Snitchy dashboard app (iOS and Android), the websites snitchy.net and snitch.cam, public camera share links, the Snitchy hardware store, and the backend service at api.snitch.cam (together, the "Service").
We handle personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles. If you are in the European Economic Area, the United Kingdom, or California, additional rights described in section 9 also apply to you.
1. Information we collect
1.1 Account information
When you create an account we collect your name and email address. If you sign up with an email and password, the password is stored only as a salted bcrypt hash. We never store or log your plain-text password.
If you sign in with Google or Apple, we receive your name, email address, and a provider account identifier from Google or Apple. We do not receive your Google or Apple password. Apple may give us a private relay email address instead of your real one if you choose to hide it.
1.2 Images and time lapse videos
The camera app captures images on the schedule you configure, or when you tap Capture in the dashboard app, and uploads them to our cloud storage so you can view them. If you generate time lapse videos, the rendered videos are stored there too. Pro editing options such as title cards, logos, and music are stored with the video job so it can be rendered.
For each capture we store the full-size image, a small thumbnail, the capture time, the camera phone's battery level, and whether it was charging. We do not collect location data from your images, and we do not analyse who or what is in them.
1.3 Camera phone information
So the dashboard can show the camera's status and so we can keep it capturing reliably while unattended, the camera app reports:
- Device make and model, Android version, app version, and a pairing identifier for the device
- Battery level and charging state, connection status, and the time of its last activity
- Whether the app has the permissions and battery settings it needs to run in the background (used to show you a fix-it guide when the phone's manufacturer is throttling the app)
- A push notification token, so we can alert you when the camera goes offline or stops capturing
1.4 Subscription and promo information
If you upgrade to Snitchy Pro, the purchase is processed by Apple's App Store or Google Play. RevenueCat manages the subscription state for us (active, expired, renewal date, product). We receive that status so we can unlock Pro features. We never receive or store your payment card details, Apple ID password, or Google account password.
If you redeem a promo code, or we grant you complimentary Pro access, we record that against your account so it can't be redeemed twice.
1.5 Notifications
The dashboard app registers a device token with Firebase Cloud Messaging so we can send push notifications such as "camera offline", "low battery", or "your time lapse is ready". You can turn notifications off in your phone's settings at any time.
1.6 Public share links (Pro)
If you turn on "Share latest image" for a camera, we create a public link that shows that camera's newest photo, the camera's name, and the capture time to anyone who has the link, without an account. Requests to that link are logged like any other request (see 1.9). You can turn the link off at any time, which stops it working immediately.
1.7 Website analytics
Our website records first-party page views and clicks on app store links so we can understand which pages are useful. For each event we record the page path, the referring website's domain, a random visitor identifier stored in your browser's local storage, your device type and browser (from the user agent string), and an approximate location (country and city) derived by our hosting provider from your IP address. We do not store your IP address in analytics, we do not use third-party advertising or analytics trackers, and analytics events are deleted after 180 days.
The website loads the Nunito font from Google Fonts and embeds example videos from Vimeo in "do not track" mode. Those services receive your IP address when their content loads, under their own privacy policies.
1.8 Hardware store and waitlist
Purchases in the Snitchy store are processed by Stripe. Stripe collects your name, email address, shipping address, and payment details on its own checkout page. We receive the order details we need to ship your item (name, address, email, what you bought) but never your full card number. If you join the hardware waitlist, we store your email address, the time you signed up, and your IP address (used only to limit abuse), and send you one confirmation email.
1.9 Logs and technical data
Our servers automatically log request metadata such as timestamps, endpoints, response codes, IP addresses, and error traces. We use these logs to operate and troubleshoot the Service. They are retained for a short period and then rotated. We do not use them for advertising or profiling.
1.10 Support
If you email us, we keep the correspondence so we can help you and refer back to it if you contact us again.
2. How we use your information
- To provide, operate, and maintain the Service
- To store and deliver your images and time lapse videos
- To authenticate you and keep your account secure
- To tell you when your camera goes offline, stops capturing, or runs low on battery
- To unlock Pro features based on your subscription status
- To ship hardware you order and let you know when new hardware is available, if you asked us to
- To diagnose problems and improve reliability, including keeping the camera app running on phones that aggressively limit background apps
- To respond to support requests and meet our legal obligations
We do not use your information or images to build advertising profiles, to train machine learning models, or to sell to anyone.
3. Where your data is stored
- Amazon Web Services (S3 and CloudFront) stores and serves your images, thumbnails, and rendered videos. The storage bucket is in the us-east-1 region (Northern Virginia, USA). Objects are encrypted at rest (AES-256) and in transit (TLS).
- MongoDB Atlas stores your account, camera pairings, image metadata, schedules, notification records, and subscription state. Encrypted at rest and in transit.
- Railway hosts the backend application and the video rendering worker. Rendering uses temporary working files that are removed when the job finishes.
- Upstash (Redis) queues video rendering jobs. Queue entries hold job settings and image references, not the images themselves, and are removed once processed.
- Vercel hosts the website and the small functions behind the waitlist and analytics.
- Neon (Postgres) stores the hardware waitlist.
All traffic between the apps, the website, and our servers is encrypted with TLS 1.2 or higher.
4. How long we keep it
- Free plan images: automatically deleted 30 days after they were captured.
- Pro plan images: kept for as long as your Pro subscription is active. If Pro ends and your storage exceeds the Free limit, your account enters a 30-day read-only grace period. Your images stay visible, but new uploads pause. After the grace period the oldest images are removed until your storage fits within the Free limit.
- Time lapse videos: kept until you delete them or delete your account.
- Account deletion: when you delete your account, your images, videos, camera pairings, schedules, and profile are permanently removed on the next run of our cleanup job, within 24 hours.
- Website analytics: 180 days.
- Hardware waitlist: until we have told you the hardware is available, or until you ask to be removed, whichever is sooner.
- Store orders: order records are kept for as long as Australian tax and consumer law requires.
- Server logs: a short rolling window for troubleshooting.
5. Who we share it with
We do not sell, rent, or trade your personal information or your images. We share limited data with the following providers, strictly to run the Service:
- Amazon Web Services: image and video storage and delivery
- MongoDB Atlas: database hosting
- Railway and Vercel: application and website hosting
- Upstash: job queue for video rendering
- Neon: waitlist database
- RevenueCat: subscription management and receipt validation. Receives a pseudonymous account identifier, the product purchased, and transaction metadata from the app stores
- Apple App Store and Google Play: process Pro subscription payments. They receive your payment information directly; we do not
- Google and Apple: sign-in, if you choose to sign in with them
- Firebase Cloud Messaging (Google): push notification delivery
- Resend: sends transactional emails such as password resets, email verification, and waitlist confirmations. Receives your name, email address, and the content of that email
- Stripe: hardware store checkout and payment processing
- Google Fonts and Vimeo: font and example video delivery on the website
- Postal carriers: receive your name and address to deliver hardware orders
We may also disclose information if required by law, to respond to a valid legal request, or to protect the rights, property, or safety of Snitchy, our users, or others. If Snitchy is ever sold or merged, your data may transfer as part of that transaction and we will notify you by email first.
6. What the camera does and does not do
The camera app captures a still image only when a schedule you configured is running, at the interval you set, or when you tap Capture in the dashboard app. It does not record audio, does not stream live video, does not use motion detection, and does not capture outside those triggers. You can pause or delete a schedule at any time from the dashboard app, and you can unpair the camera to stop it completely.
7. Your responsibility for people in the frame
Snitchy points a camera wherever you put it, so you are responsible for complying with the surveillance, privacy, and workplace laws that apply where the camera is. In Australia these vary by state and territory and generally include:
- Not filming places where people have a reasonable expectation of privacy
- Giving the notices required by workplace surveillance laws if employees or contractors will be in view
- Only placing the camera where you have permission to do so
- Not using the Service to harass, stalk, or intimidate anyone
You agree to capture and upload only images you have the legal right to capture and store. Snitchy is a tool; responsibility for how it is used belongs to you.
8. Your choices and controls
8.1 Access and export
You can view all of your images and videos in the dashboard app at any time. For a complete export of your data, email jordan@snitchy.net and we will provide one within 30 days.
8.2 Correction
You can update your name in the dashboard app. Email address changes can be requested by contacting us.
8.3 Deletion
Delete your account any time from inside the dashboard app: open Settings, then Danger Zone, then Delete Account. After you confirm, your account and all associated images, videos, camera pairings, and schedules are permanently removed. You can also delete individual images or videos without deleting your account.
Deleting your Snitchy account does not cancel an active Pro subscription billed through the App Store or Google Play. Cancel that separately in the store you bought it from.
8.4 Notifications, share links, and waitlist
Turn push notifications off in your phone's settings. Turn share links off per camera in Settings, then Cameras. To leave the hardware waitlist, reply to the confirmation email or contact us.
8.5 Complaints
If you have a concern about how we have handled your information, contact us first at jordan@snitchy.net and we will respond within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
9. Additional rights in some regions
9.1 EU, UK, and Switzerland (GDPR)
You have the rights of access, rectification, erasure, restriction, data portability, and objection, and the right to lodge a complaint with your local supervisory authority. Our lawful bases for processing are performance of our contract with you (to deliver the Service), our legitimate interests in operating, securing, and improving the Service, and your consent where we ask for it (for example, the hardware waitlist). Exercise any of these rights by emailing jordan@snitchy.net.
9.2 California (CCPA/CPRA)
You have the right to know what personal information we collect, to request its deletion, to correct it, and not to be discriminated against for exercising those rights. We do not sell or share personal information for cross-context behavioural advertising. Contact jordan@snitchy.net to make a request.
10. International transfers
We operate from Australia and our infrastructure providers are primarily in the United States. Your data will be transferred to, stored in, and processed in the United States and other countries where our providers operate. We take reasonable steps to make sure those providers protect your data to a standard consistent with the Australian Privacy Principles. For EU and UK users, our providers rely on recognised transfer mechanisms such as the EU-US Data Privacy Framework or Standard Contractual Clauses.
11. Security
- TLS 1.2 or higher for all traffic between the apps, the website, and our servers
- AES-256 encryption at rest for stored images, videos, and database records
- Salted bcrypt password hashing
- Short-lived access tokens and rotating refresh tokens for the dashboard app
- Per-camera credentials that are invalidated when you unpair a camera or delete your account
- Share links use long random tokens and can be revoked instantly
No system is completely secure. If we become aware of a data breach that is likely to cause you serious harm, we will notify you at the email address on your account and the relevant regulator as required by law.
12. Children
Snitchy is not intended for anyone under 13, or the equivalent minimum age where you live. We do not knowingly collect information from children. If you believe a child has created an account, contact jordan@snitchy.net and we will delete it promptly.
13. Changes to this policy
We may update this policy as the Service, our providers, or the law change. When we make material changes we will update the effective date above and, where appropriate, notify you by email or in the app. Continued use of the Service after an update means you accept the revised policy.
14. Contact
Questions, requests, or concerns: jordan@snitchy.net.