Account Data
Authentication
- What
- Email address, or an Apple account identifier if you use Sign in with Apple. A phone number if you sign in by SMS code.
- Why
- To create your StealthGuard account and let your devices recognise each other.
- Where
- Supabase Auth. Our Supabase project is hosted in the United States (East US, Ohio). Encrypted in transit and at rest.
- Control
- Sign out at any time, or permanently delete the account and its stored data from Settings → Account → Delete Account.
Your Name
- What
- The name you enter during setup, or the name Apple supplies when you choose Sign in with Apple.
- Why
- So your account reads correctly on every device you sign in to.
- Where
- Stored on your account record in Supabase Auth.
- Control
- Edit or clear it from Settings → Account → Name.
Face Photo (Setup)
- What
- See Section 2 — Face Data and Biometric Authentication for the complete collection, use, storage, sharing, retention, and deletion disclosure.
Face Data and Biometric Authentication
StealthGuard uses two separate technologies that must not be confused.
Apple Face ID, Touch ID and Device Authentication
- Purpose: Unlocking StealthGuard, authorising Anti-Theft cancellation, confirming account deletion, and protecting other sensitive actions.
- What StealthGuard receives: Only Apple's success, failure, or cancellation result from the LocalAuthentication framework.
- What StealthGuard never receives: The Face ID image, Face ID template, Touch ID fingerprint, passcode, or any Secure Enclave biometric data.
- Storage and sharing: StealthGuard cannot access, store, transmit, or share Apple's biometric data. Apple and the operating system control it.
StealthGuard Face Recognition
StealthGuard's security-camera recognition is separate from Apple Face ID. Apple does not permit apps to use the system Face ID database to identify a person in ordinary camera footage, so users optionally enrol faces directly in StealthGuard. The purpose is to protect the user, their private space, devices, property, and security evidence by distinguishing people the user has enrolled from unknown people detected by the security camera.
Data processed
- Optional setup face photo: One image the account owner captures or selects during onboarding. The face step can be skipped.
- Enrolled-face thumbnails: Images the user deliberately adds in the Faces screen for people they want StealthGuard to recognise.
- Feature prints: Mathematical Apple Vision representations generated from enrolled images for on-device comparison.
- Security-event images: A camera snapshot may contain a face when motion or an unknown person triggers an alert. This is security evidence, not a Face ID template.
Use
- Recognise people deliberately enrolled by the user in the protected space.
- Avoid unnecessary alerts when a recognised person is present.
- Detect an unknown person in the protected space and notify the account owner.
- Capture a security-event preview for the account owner's paired device.
- Help protect the user's room, device, property, and security evidence from unauthorized access or activity.
Face data is never used for advertising, analytics, behavioural profiling, sale, or model training. The private Supabase setup-photo copy is not used for face matching.
Storage
- Feature prints and enrolled-face thumbnails: Stored only inside the app's private sandbox on the device where the user enrolled them.
- Optional setup photo: Stored in a private, account-scoped Supabase Storage bucket in the United States and linked to the authenticated account.
- Security-event snapshots: Stored in private, account-scoped Supabase Storage so the user's paired device can display the alert. Access uses expiring signed links rather than public object URLs.
Disclosure and service providers
StealthGuard does not sell, rent, or disclose face data to advertisers, data brokers, analytics companies, model-training providers, or unrelated users.
- Supabase acts only as StealthGuard's contracted authentication, database, and private cloud-storage processor. It hosts the optional setup photo and security-event images on StealthGuard's behalf and is not permitted to use them for its own purposes.
- OneSignal processes notification routing information and may carry an expiring signed image URL so the account owner's paired device can fetch an alert preview. It does not receive Apple Face ID data or local Vision feature prints.
- Metered may relay end-to-end encrypted live video packets when direct device-to-device connectivity is unavailable. It does not store enrolled images or feature prints and cannot decrypt the video.
Retention and deletion
- Local enrolled-face thumbnails and feature prints remain until the user deletes that face in the Faces screen, permanently deletes the account, or removes the app.
- The optional Supabase setup photo remains until the user permanently deletes the StealthGuard account.
- Security-event images follow the user's configured cloud-evidence retention period or are removed when the related evidence/account is deleted.
- Permanent account deletion removes the account-scoped setup photo, security-event images, and other cloud data before deleting the authentication user.
Other On-Device Processing
Camera & Microphone — Every camera frame is analysed on your device for motion and faces. Nothing is streamed anywhere for analysis. Recordings are written to the app's private storage on your device. If Cloud Evidence is enabled, selected security evidence is also uploaded as described in Section 5.
Room Sweep — Bluetooth, Wi-Fi and Magnetometer — Scanning for nearby Bluetooth devices, devices on the local network, and magnetic-field anomalies happens entirely on your device. This is a defensive feature. It exists to help you find cameras, microphones and trackers that someone else may have hidden near you. Results stay on your device and are not transmitted.
NFC — Reading an AirTag or similar tag happens on-device only.
Services We Use
| Service | Data it receives | Purpose |
|---|---|---|
| Supabase Auth | Email, phone, or Apple identifier; your name | Signing in, identifying your account across devices |
| Supabase Postgres | Your device list, pairing records, alert history, remote-arm commands | Multi-device pairing, alerts, remote arm, live view setup |
| Supabase Storage | Optional setup face photo, alert snapshots, and clips if Cloud Evidence is on | Account setup, alert previews, tamper-proof evidence |
| OneSignal | A push notification token for each device | Delivering alerts to your other devices |
| Metered (TURN relay) | Your device's IP address during a live view session | Relaying encrypted video when a direct connection isn't possible |
| Apple StoreKit | Purchase receipts | Subscriptions and billing |
We do not use advertising SDKs, analytics SDKs, or any tracking framework.
Video Recordings and Cloud Evidence
This deserves to be stated plainly.
- Clips are always recorded to your device.
- Cloud Evidence is switched ON by default. While it is on, each motion or alarm clip is also uploaded to Supabase Storage.
- Why the default is on: if the device acting as your camera is stolen or destroyed, evidence stored only on that device is lost with it. Uploading is the point of the feature.
- Control: Turn Cloud Evidence off in Settings. With it off, clips stay on your device only. Alert thumbnails are still uploaded so notifications on your other devices can show a preview.
Location
Location is used for three specific things, and only when you enable them:
- Auto-Arm: an optional geofence around a room you designate, so a paired device can arm itself after you leave. You set the room; you can turn Auto-Arm off at any time.
- Emergency SOS: if you use SOS, your live location is shared for a period you choose so a contact can see where you are.
- Tamper alerts: if a device is moved while armed, an alert may include its location so you can find it.
Room Sweep also reads your Wi-Fi network name to label a scan. It does not need or use your GPS position to do that.
Secure Contacts and Live Location Sharing
- If you add secure contacts, they can receive an in-app alert when you trigger SOS or miss a check-in.
- Sharing live location creates a short-lived code. Anyone you give that code to can see your location until the session expires or you stop it.
- Control: Stop sharing at any time from the Safety screen.
What We Never Do
- We do not sell, rent, or monetise your data.
- We do not use advertising or tracking SDKs.
- We do not upload Apple Vision feature prints or use face data for advertising, analytics, profiling, sale, or model training. The optional setup photo and security-event images are stored as described in Section 2.
- We do not access your contacts, calendar, photo library, or browsing history.
- We do not watch your camera. Live video travels between your own paired devices, end-to-end encrypted.
Data Retention
- Account data: kept until you delete your account or ask us to.
- Local recordings: on your device until you delete them, or until the storage limit and retention period you set in Settings removes the oldest.
- Uploaded clips and thumbnails: kept until deleted. Alerts older than 24 hours are cleaned up automatically.
- Pairing tokens: short-lived and single-use.
- Face data: retained and deleted according to the specific rules in Section 2.
Your Rights
- Delete recordings: Clips screen, or Settings → Delete All Recordings.
- Delete enrolled faces: Faces screen.
- Remove a device: Devices screen.
- Turn off cloud uploads: Settings → Cloud Evidence.
- Revoke any permission: iOS or macOS system settings, at any time.
- Delete your account and its stored data: Settings → Account → Delete Account.
- Cancel a subscription: Settings → Apple Account → Subscriptions.
Security
- On-device data sits in the app's sandbox with file-level encryption.
- Data in Supabase is encrypted in transit (TLS) and at rest, and every row is scoped to your account by database-level security policies.
- Live video is end-to-end encrypted (DTLS-SRTP). The TURN relay forwards encrypted packets and cannot read them.
- Optional Face ID, Touch ID or passcode lock for arming and disarming.
Children's Privacy
StealthGuard is not directed at children under 13, and we do not knowingly collect data from children.
Contact
App Store Privacy Label
Data Used to Track You
- None
Data Linked to You
- Email address
- Phone number (only if you sign in by SMS)
- Name
- User ID (your Supabase account identifier)
- Photos (the setup face photo)
- Coarse and precise location (only for the features in Section 6, when enabled)
- Video and audio (only when Cloud Evidence is on)
Data Not Linked to You
- Device identifier, used to route push notifications
- Purchase history, handled by Apple
Data Types Declaration
| Data Type | Collected | Linked to Identity | Used for Tracking | Purpose |
|---|---|---|---|---|
| Yes | Yes | No | Account | |
| Phone | Optional | Yes | No | Account sign-in |
| Name | Yes | Yes | No | Account |
| Photos (face) | Yes | Yes | No | Security-camera face enrollment and alert protection |
| Video / audio clips | Only if Cloud Evidence is on | Yes | No | Tamper-proof evidence |
| Camera / microphone frames | Analysed on device, not collected | No | No | Motion and face detection |
| Location | Only when Auto-Arm, SOS, or tamper alerts are used | Yes | No | Arming, safety, device recovery |
| Identifiers | Push token, device ID | No | No | Push notifications |
| Purchases | Via Apple | No | No | Subscription management |
