Privacy notice

How Camily handles data.

Camily is built around one idea: the room's video stays in the room. This notice says what leaves the phone, what we hold, and the choices every household controls. Effective 29 September 2026. Camily is made by NeoSpark Solutions, Sydney, Australia.

The short version

  • The room phone analyses what it sees on the phone itself. In the default strict mode, no photo or video is ever uploaded.
  • If your household turns on check-in stills, every image is blurred on the phone before it leaves, then blurred again on our servers before it is stored. Faces are destroyed, not softened.
  • We never sell data, run advertising, or track you across other apps.

What the room phone processes

The room phone runs pose and motion analysis in memory. Frames are used for the check and discarded. What it reports is a text event, for example that fall-like activity was seen, that the room is too dark to observe, or that someone pressed the HELP button. It also sends routine status such as battery level and whether the camera can see enough to be useful.

Camily does not record audio and does not request microphone access.

Accounts and sign-in

You sign in with Google or Apple. We receive your name, email address and a provider account identifier. We never see your password.

Household information you enter

Events, alerts and audit records

We keep the event timeline for your household: alerts, acknowledgements, pause requests and who did them. Providers can see an audit trail of which staff member viewed or actioned what.

Optional check-in stills

A household can opt in to occasional still images, for example to confirm a camera view during setup or when a responder requests a fresh look during an alert. When this mode is on:

Blurring is permanent. A stored image cannot be turned back into a clear photo.

Who provides the plumbing

These providers receive only what their job needs: a push token and alert text, or a contact's phone number or email address and the message. Alert text never names the room or the person beyond what is needed to act.

What we do not do

Consent and the person being watched

Watching someone requires their consent, recorded in the app during setup. They can pause monitoring, and any guardian or the household owner can withdraw consent, which stops image-related processing and clears pending media.

Retention

Event history is kept for the retention window the household selects, then deleted. Optional blurred images are deleted when the event they belong to expires. Deleting a household removes its residents, contacts, devices and history.

Your choices

Changes

If we change what data leaves the room in a way that affects consent, households are asked to confirm the new notice before the related feature is used again.

Camily is not a medical device and not an emergency service. It is a "worth checking" layer that sometimes cannot see, and it says so rather than pretending.