What we collect
Account email, optional display name, accepted terms version, camera-source and workflow settings, security events, usage totals, and the photo, RAW, video, filename, media type, size, checksum, and capture metadata you transmit.
This notice describes the founding beta as it operates today. It is not a promise of features that have not shipped, and it must be reviewed by counsel before a paid public launch.
Account email, optional display name, accepted terms version, camera-source and workflow settings, security events, usage totals, and the photo, RAW, video, filename, media type, size, checksum, and capture metadata you transmit.
To authenticate your account and devices, receive media, execute the routes you save, verify delivery, show receipts, enforce allowances, prevent abuse, troubleshoot failures, and meet legal obligations. We do not sell personal data or use it for advertising.
Original media is staged privately while deliveries are active. Once every copy is terminal, an hourly job deletes staging after 24 hours and verifies the object is gone. A seven-day storage lifecycle is a failure backstop. Removing an asset requests verified deletion immediately.
You choose each destination. Camera to Anywhere sends only the media and path needed for that route. Completed copies remain in your destination until you remove them there. Disconnect revokes or deletes our credential and cancels unfinished copies.
We request drive.file to create a Camera to Anywhere folder and upload files you explicitly route. We do not list or read unrelated Drive files. Refresh tokens are encrypted and access is revoked on disconnect. Use of Google Workspace API information follows the Google API Services User Data Policy, including Limited Use requirements.
Netlify hosts the web control plane, Supabase provides authentication and tenant data, Cloudflare R2 provides temporary private staging, and AWS Lightsail receives SFTP uploads. Connected destinations process media under their own terms at your direction.
Camera passwords and device tokens are stored as verifiers, not readable secrets. OAuth refresh tokens and resumable sessions use authenticated encryption. API rate-limit subjects are one-way digests. Infrastructure providers may process IP addresses and operational logs to deliver and secure the service.
Remove a staged asset from Delivery Activity, disconnect a cloud destination or NAS agent in the routing workspace, and revoke access in the provider account. To export or delete the remaining account record, email hello@cameratoanywhere.com from the account address.
The beta is for adult creatives and organizations, not children. Do not create public youth galleries or collect direct child submissions through this beta. The account owner remains responsible for permissions, releases, safeguarding, and lawful handling of media involving minors.
Contact hello@cameratoanywhere.com. We will publish material changes here and request renewed consent before using Google user data for a newly disclosed purpose.