RemoCam turns devices you already own into private cameras. This policy explains what the service collects, why, how long it keeps it, and how you remove it. It is written to describe how the product actually works rather than to describe every possibility.
The short version. Live video and audio travel directly between your own devices and are never recorded by RemoCam. Cloud clips exist only if you buy a paid plan, and only for that plan's retention window. There is no advertising, no advertising or analytics SDK, and no sale or sharing of your monitoring data with anyone.
The data controller is RemoCam, a sole proprietorship based in North Carolina, United States. Contact us at support@remo.cam; a mailing address for formal requests is available on request by email.
When you sign in with Google, Firebase Authentication provides RemoCam with your account identifier and email address. RemoCam uses them to associate your cameras, preferences, and subscription with you. RemoCam never receives your Google password.
For each camera you set up, RemoCam stores the camera's name, the uses you selected, any optional labels you typed (for example a pet's name or an area name), which controls are enabled, whether camera-side viewing is allowed, device capability flags such as whether a torch exists, and the time the camera was last seen online. Choose labels you are comfortable storing.
Establishing a live view requires short-lived signaling records: session offers, answers, and network candidates, which include your devices' IP addresses. These records let two devices find each other and are removed once the session ends or goes stale. If a direct connection is impossible, media may be relayed through a TURN server, which forwards encrypted media without storing it.
If you allow a camera device to also act as a viewer, you set a PIN. RemoCam stores only a salted, peppered scrypt hash of that PIN on the server, plus failed-attempt counters used for lockout. The PIN itself is never stored and never leaves the verification function.
Sound and motion detection run on the camera device. The resulting events (kind, time, and a short description) are sent to your viewer and kept in that device's local activity list. On the free plan they are not stored on RemoCam's servers.
On a paid plan, a camera may record a short clip when it detects sound or motion. The clip is uploaded directly to Google Cloud Storage through a short-lived signed link, and RemoCam stores metadata about it: an identifier, which camera recorded it, the event kind and description, the time, the file size, the duration, and its expiry. Only you can request playback, which issues another short-lived signed link.
Payments are processed by Stripe. RemoCam stores your Stripe customer and subscription identifiers, plan, status, and renewal date so it can grant the right features. RemoCam never sees or stores your card number; Stripe handles payment details under its own privacy policy.
RemoCam uses Firebase App Check with reCAPTCHA Enterprise to verify that requests come from the genuine app. This sends device and request signals to Google for risk scoring. It is used only to block abuse, not to profile you.
The app keeps a diagnostics log on the device to help you troubleshoot connections. It stays on that device unless you copy and send it to support.
Where the GDPR or a similar law applies, processing rests on performing the contract you enter when you use the service (running cameras, viewers, and subscriptions), on legitimate interests (keeping the service secure and preventing abuse), and on legal obligations (retaining billing records).
These providers act as processors under contract and may not use your data for their own purposes. If you use the service from outside the United States, your data is transferred to and stored in the United States. For transfers from the EU, EEA, UK, and Switzerland, these providers rely on recognised safeguards — the EU–US Data Privacy Framework and standard contractual clauses.
The RemoCam website — this page, the landing page, and the compare page — runs no scripts and sets no cookies. The app itself stores your sign-in state on your device (Firebase Authentication uses localStorage and IndexedDB) so you stay signed in, and Firebase App Check with reCAPTCHA Enterprise may set cookies or local state to tell genuine apps from bots. All of this is strictly necessary to run the service. There are no advertising or analytics cookies anywhere, so there is nothing to opt out of and no consent banner to click.
| Data | Retention |
|---|---|
| Account and camera configuration | Until you delete the camera or the account |
| Signaling records | Removed when the session ends or goes stale |
| Viewer grants | Expire automatically; revoked immediately on request |
| Cloud clip media | 30 days on Plus, 90 days on Family, then deleted automatically |
| Cloud clip metadata and activity history | 30 days on Plus, 90 days on Family |
| Billing records | As required by tax and accounting law |
If a paid plan ends, uploads stop immediately and you keep a short export window of 72 hours before existing cloud clips are purged. Free live monitoring and real-time alerts continue working.
You can access, correct, export, or delete your data. Most of it is directly editable in the app; deleting a camera removes its configuration, and deleting your account removes the rest. See the account deletion instructions. For an export, or to exercise any right that the app does not cover, email support@remo.cam. Requests are answered within 30 days. Depending on where you live you may also have the right to object to processing, to withdraw consent, or to complain to your data protection authority.
RemoCam does not sell or share personal information as those terms are defined by the California Consumer Privacy Act, and does not use it for cross-context behavioural advertising, so there is no opt-out to exercise. California residents may request access, correction, deletion, or a copy of their data by emailing support@remo.cam, directly or through an authorised agent. We never treat you differently for exercising a privacy right.
RemoCam is not directed to children, and holding an account requires being at least 18, as the Terms of Service set out. We do not knowingly collect personal data from children. A parent or guardian may of course point a camera at their own child's room; that footage is treated like any other live video and is not recorded by RemoCam unless cloud clips are on.
Live media uses the encryption built into WebRTC. Server access is scoped per device so that one camera cannot read another camera's data or grant itself viewing rights. PINs are hashed with scrypt using a per-account salt and a server-held pepper, with progressive lockout on repeated failures. Cloud clip media is reachable only through short-lived signed links. No system is perfectly secure, so please use a strong Google account password and two-factor authentication.
If this policy changes materially, the effective date above changes and the app shows a notice before the change takes effect. Continued use after that point means the updated policy applies.