localeye.cam
Privacy notice

What localeye.cam keeps about you

In short: your email address and what you set up here. No advertising, no analytics, no tracking, no third-party scripts or fonts, and nothing is sold. Your recordings and camera passwords never come here.

Version 2026-10-09

Who is responsible

localeye.cam is run by the operator of localeye.cam. For anything about your data use the contact details below. Under the GDPR and UK GDPR they are the "controller" of the information on this site.

The operator hasn't finished adding their contact details to this page yet.

Your own LocalEye server is yours: for the recordings and faces it keeps, you are responsible, not this site.

What we keep

Your account

  • Your email address (your sign-in name), and when you confirmed it.
  • Your password, only as a one-way scrypt hash: nobody here can read it.
  • If you turn on two-step sign-in: its secret and one-way hashes of your recovery codes.
  • When you created the account and last signed in, and which version of these terms you agreed to (with "18 or older").

Your names and servers

  • The names you claim (localeye.cam/<name>) and the display names you give them.
  • For each linked server: its name and address here, its public key, the web addresses it reports (public and local network), its software version, the internet address it reports in from, and when it was last online.
  • With the tunnel on: how much data went through it each month (totals only).

Sharing

  • The email addresses you invite to see a name, and whether they accepted. If you invite someone, make sure they would expect it.

Security records

  • An activity log of important actions (signing up, password and email changes, linking or unlinking a server, invitations, admin actions), with the email address of who did it.
  • Failed sign-ins and similar attempts, with the internet address and email used, to stop password guessing. These are deleted after 24 hours.
  • The web server in front of this site may keep its own access logs (internet address, page, time) for running and protecting it.

The tunnel

If you switch on remote access through this site, everything you do with your server from outside - signing in to it, live video, recordings you watch - travels through this site's relay. It is encrypted between your browser and this site, and between this site and your server, but it is unencrypted for a moment inside the relay, so the operator's server could technically read it. It is not stored or looked at; only the byte and request counts above are kept. If that is not acceptable for you, leave the tunnel off and use your own VPN.

What we don't do

  • We never receive your recordings, faces, camera passwords or the password of your server's own accounts (except passing through the tunnel, as above).
  • No advertising, analytics, session recording, keystroke logging, tracking pixels, social-media buttons or third-party scripts. Every page, style and font comes from this site itself.
  • We don't sell or share personal information (as "sell" and "share" are meant in the California Consumer Privacy Act), and we don't send newsletters or marketing.

Cookies

One cookie: session, which keeps you signed in (and protects forms against forgery). It is set when you open a page with a form (such as Sign in), is sent only to this site, can't be read by scripts, and lasts up to 14 days. It is strictly necessary for the service you asked for, so no consent banner is needed. The setup guide remembers which operating system you picked in your browser's own storage; it never leaves your browser. Nothing else.

Why (legal basis)

  • To provide the service you signed up for (contract): your account, names, servers, tunnel and the emails that go with them (confirming your address, resetting a password, invitations).
  • To keep it secure and stop abuse (legitimate interests): the activity log, the attempt records and access logs.
  • When the law requires it (legal obligation), for example answering a valid request from the authorities.

How long

  • Your account, names and servers: until you delete them. Deleting your account (Account page) removes it, releases your names and unlinks your servers at once.
  • The activity log: until the operator deletes it (no automatic limit is set at the moment). Entries naming you stay that long after you delete your account, as a security record.
  • Failed-attempt records: 24 hours. Password-reset links: 60 minutes. Email-confirmation links: 24 hours.
  • A sign-up that never confirms its email (and claimed no name): deleted after 7 days.
  • Tunnel usage totals: about 13 months.
  • An address that asked not to get invitations: kept, so we can keep that promise.

Who else sees it

The operator and the administrators they appoint. Emails go out through the operator's email provider. The site runs on the operator's own server. Nobody else, unless the law requires it.

Your rights

Depending on where you live (for example under the GDPR, UK GDPR or US state privacy laws) you can:

  • See and take your data: Account → Download my data gives you all of it as a file.
  • Correct it: change your email or names yourself on the Account page and the dashboard.
  • Delete it: Account → Delete account.
  • Object to or restrict how it is used, or ask anything else: contact the operator.
  • Complain to your data-protection authority (in the EU/UK, the one where you live or work).

Got an invitation and don't want more? Every invitation email has a link that stops them.

Children

This site is for adults: you must be 18 or older to create an account. It is not meant for children and we don't knowingly collect information about anyone under 13. If you think a child has made an account, tell us and we will delete it.

Changes

If this notice changes, the version above changes too; important changes are announced on this site before they apply. See also the terms.