Privacy notice
camily.app is built around one idea: the room's video stays in the room. This notice says what leaves the phone, what we hold, and the choices every household controls. Updated 5 October 2026 to describe the optional Android voice reply. camily.app is made by NeoSpark Solutions, Sydney, Australia.
The room phone runs pose and motion analysis in memory. Frames are used for the check and discarded. What it reports is a text event, for example that fall-like activity was seen, that the room is too dark to observe, or that someone pressed the HELP button. It also sends routine status such as battery level and whether the camera can see enough to be useful.
On Android, an optional spoken verification check can ask “Are you okay?” and listen briefly for an answer if you grant microphone permission. It uses Android's on-device recogniser only when that capability is available; it does not fall back to cloud speech recognition. Camily does not retain or upload audio from this check. Denying microphone access leaves the on-screen response buttons available. The iPhone guardian app does not use this voice check.
You sign in with Google or Apple. We receive your name, email address and a provider account identifier. We never see your password.
If you join the updates list, we store the first name and email address you submit, the consent version, and the time you agreed to receive updates. New entries receive Camily product and Android room-phone beta updates. Earlier entries retain the consent recorded when they joined, including the earlier launch-offer statement; historical consent is not rewritten. Joining does not create an app account or a paid subscription, and no payment details are collected. The list is stored in Cloudflare D1. Ask [email protected] to remove your entry; entries are also deleted when the updates list closes.
On camily.app only, we store daily aggregate counts of page and section views, page-to-page transitions, referring website hostnames, and active-time ranges in Cloudflare D1. The analytics table has no visitor IDs, cookies, session IDs, IP addresses, full referrer URLs, query strings, or exact visit timestamps. It cannot identify unique visitors or reconstruct an individual journey. The signed-in family web app and room-phone app are not included in this site measurement.
We keep the event timeline for your household: alerts, acknowledgements, pause requests and who did them. Providers can see an audit trail of which staff member viewed or actioned what.
A household can opt in to occasional still images, for example to confirm a camera view during setup or when a responder requests a fresh look during an alert. When this mode is on:
This is not a guarantee of anonymity. Do not enable shared stills if room details or other context would disclose information you do not want shared. Strict privacy mode avoids this optional image-sharing path.
These providers receive only what their job needs: a push token and alert text, or a contact's phone number or email address and the message. Alert text never names the room or the person beyond what is needed to act.
Watching someone requires their consent, recorded in the app during setup. They can pause monitoring, and any guardian or the household owner can withdraw consent, which stops image-related processing and clears pending media.
Event history is kept for the retention window the household selects, then deleted. Optional blurred images are deleted when the event they belong to expires. Deleting a household removes its residents, contacts, devices and history.
If we change what data leaves the room in a way that affects consent, households are asked to confirm the new notice before the related feature is used again.
camily.app is not a medical device and not an emergency service. It is a "worth checking" layer that sometimes cannot see, and it says so rather than pretending.