Privacy Policy
Effective: July 10, 2026
CAMMY LLC ("Cammy," "we," "us," or "our") provides a mobile app for recording, editing, organizing, and sharing photos, videos, shared event media, and Edits. This Privacy Policy explains what information we collect, how we use it, how collaborative and media-analysis features work, when we share information, and what choices and rights are available to people who use Cammy in the United States and the other countries where Cammy is offered, including Canada, Mexico and Latin America, Australia, and New Zealand.
1. Scope of This Policy
This Privacy Policy applies to information processed through the Cammy mobile app, the Cammy App Clip, related backend services, support flows, optional integrations, and collaborative media features. It covers information you provide directly, information created through your use of Cammy, information created by automated analysis tools used in the product, and information shared with us by service providers that help operate the app. It applies whether you use Cammy with an account or contribute to an event as a guest without one.
2. Information We Collect
Account, profile, and authentication information
We collect information needed to create and secure your account, including your email address, phone number, username, first and last name, date of birth, country or region, profile photo, account verification status, profile privacy settings, and records showing when you accepted our Terms of Service and Privacy Policy. If you use password, email-code, phone-code, or social sign-in features, we process the credentials, verification details, and account metadata needed to support those methods. If you enable biometric sign-in, your device operating system handles the biometric check and Cammy receives only the success or failure result.
Content and collaboration data
We collect the content and related records you create, upload, save, or share in Cammy, including photos, videos, thumbnails, captions, event names and descriptions, invite codes, event join settings, favorites, edit settings, editing choices, notifications, and Edits you create.
If you choose to use Cammy AI Edit, we also process the media you select for that edit, your written prompt and editing preferences, optional music selections or uploaded audio, render settings, progress records, provider usage records, cost telemetry, generated manifests, thumbnails, and final rendered Edits. Only the media selected for the requested AI Edit is sent through that server-rendered workflow.
Media metadata and derived analysis
We collect metadata associated with media and collaborative activity, including file names, timestamps, duration, file size, resolution, orientation, filter selections, capture-time metadata, uploader and event linkage, cloud storage keys, device model, app version, and sharing or export status. Cammy also generates derived analysis data through its media tools, including motion analysis, scene timing, person or face presence signals, quality scores, and highlight-worthiness indicators. These features are used to support editing, ranking, syncing, and highlight-reel functionality. Cammy is not designed to identify a specific person by biometric template or to perform facial recognition for identity verification. Cammy does not create, collect, store, or use a faceprint, scan of face geometry, voiceprint, or other biometric identifier or biometric information as those terms are defined under the Illinois Biometric Information Privacy Act (BIPA) or similar state laws. Where an event uses face-presence analysis, it is subject to the in-app consent controls for that event.
For Cammy AI Edit, our backend may sample frames from selected media, transcribe speech in selected media on Cammy-controlled servers, and generate semantic tags, captions, speech transcripts, prompt-match scores, scene or moment choices, audio timing data, and render plans. These outputs are used to create the requested Edit, support revisions, troubleshoot failures, estimate processing cost, and improve product reliability. The shipped configuration does not use server-side face recognition or identity matching.
Contacts and invites
If you choose to use contact-based features, we request access to your device contacts. Contact names and phone numbers are used in the app to help you choose who to invite. If you send invites, we may keep invite codes, invite outcome records, referral-credit records, and related invite metadata. We do not need to store your full raw contact list on our servers to provide these features.
Guest contributions and the Cammy App Clip
You can contribute media to an event without creating a Cammy account, by scanning a host's QR code or opening an invite link that launches the Cammy App Clip. When you do, we collect the display name you type so the host knows who contributed, a randomly generated guest identifier stored on your device so your own contributions stay associated with you across scans, the photos and videos you upload together with the media metadata described above, and your IP address, which we use to apply rate limits and prevent abuse. We also log basic events about the contribution flow — for example that an event card was viewed or an upload was started — to understand whether the feature is working. Guest contributions do not create an account or profile, and we do not use them to build an advertising or cross-app tracking profile.
If you later install the full Cammy app on the same device and create an account, the media you contributed as a guest may be associated with that account so it appears in your own library.
Purchases
If you make purchases in Cammy, we may process transaction-related identifiers, product identifiers, entitlement or fulfillment status, platform information, event linkage, and limited billing or purchase metadata provided through Apple, Google, RevenueCat, or other authorized billing partners.
Device, notification, security, and app data
We collect information about your device and app session, such as device model, operating system, app version, network status, session state, local-storage and secure-storage records needed to keep you signed in, device push tokens, notification preferences or opt-outs, diagnostics, crash or performance data when available, and activity logs needed for security, fraud prevention, account protection, and service reliability.
Permissions we request
Depending on the features you choose to use, Cammy may request access to your camera, microphone, photo library, contacts, notifications, and biometric sign-in. You can decline or later revoke many of these permissions through your device settings, but some features will not function without the required access.
3. How We Use Information
We use personal information to:
• create and secure accounts;
• record, edit, upload, store, sync, stream, export, and share content;
• run collaborative events, public-profile features, invitations, and moderation tools;
• provide Edits, captions, and media analysis features;
• operate on-device and cloud-assisted analysis workflows, including syncing certain analysis results to our backend;
• process Cammy AI Edit requests, including prompt matching, selected-media analysis, server rendering, revision support, progress updates, and cost/reliability monitoring;
• process purchases, restore entitlements, credit paid features, and prevent payment abuse;
• personalize settings and remember user preferences;
• send in-app and push notifications;
• provide customer support and respond to legal, privacy, copyright, and rights requests;
• detect bugs, enforce our Terms and community rules, prevent fraud, and protect users, rights, and the service;
• comply with legal obligations.
4. How Media Analysis Features Work
Cammy currently uses automated tools to help analyze media and support editing features. Depending on the feature, that may include on-device processing and backend syncing of analysis results. Analysis outputs may include signals such as motion, scene changes, person or face presence, quality scoring, and highlight-worthiness. We use these systems to support the product experience, not to make legal decisions about you, not to infer your identity from biometric templates, and not to sell your data for advertising.
Standard Cammy Edit can use on-device analysis through Apple's Vision Framework and Cammy's local media-analysis tools. Cammy AI Edit is a cloud-assisted feature: when you start that workflow, Cammy sends the selected event media, prompt, edit settings, and related job metadata to Cammy-controlled backend services. Those services may use AWS Batch/SQS/ECR for queued processing and rendering, Cloudflare R2 for media storage, Supabase for authentication, database, and job state, and OpenAI Vision-capable API models for prompt and image understanding on sampled frames and on text derived from the selected media, such as speech transcripts and caption text. Audio itself is not sent to OpenAI; speech transcription runs on Cammy-controlled servers. OpenAI API data is not used to train OpenAI models by default unless Cammy separately opts in with OpenAI.
5. How Sharing and Visibility Work in Cammy
Cammy includes collaborative and public-facing features, so the visibility of content depends on how you use the app:
• if you upload or add media to a collaborative event, other permitted participants in that event may be able to view, use, or interact with that shared event media inside Cammy;
• if you create an Edit, that Edit may be visible in the places where you choose to share, pin, or publish it in the app;
• if your profile is public, completed Edits that you pin to your profile may be visible to other users or viewers of that profile;
• if you use device-level export or sharing tools, copies may be saved to your photo library or shared through your device's share sheet, messaging tools, or other apps outside Cammy;
• hosts and co-hosts may have moderation tools that allow them to remove or manage shared event media inside collaborative event spaces.
Once content has been viewed, exported, downloaded, copied, re-shared, or incorporated into another user's content or creation, Cammy may not be able to retrieve, control, or delete every copy. Deleting content from Cammy does not guarantee deletion of copies already stored on another person's device, in another app, or in content another user independently created.
People who appear in content. Cammy is used to capture and edit media that may include other people, including people who do not use Cammy. If you appear in content on Cammy and believe it was uploaded, shared, or published without the rights or consent required, you may request its removal or object to its processing by contacting us at [email protected] — you do not need a Cammy account to make this request. We will review the request and may remove or restrict the content or take other appropriate action. Account holders remain responsible under our Terms of Service for obtaining all consents and releases required for anyone who appears in their content.
6. How We Share Information
We do not sell personal information. We may disclose information:
• to other users, viewers, event participants, hosts and co-hosts when you use collaborative, profile, public, or sharing features;
• to service providers that help operate Cammy, including providers for authentication, verification, database and realtime services, cloud storage and delivery, push notifications, machine-learning processing, media processing, payments, purchase management, diagnostics, and customer support;
• to device-level services such as your SMS app, email app, share sheet, notification center, or photo library when you choose to use those tools;
• to law enforcement, regulators, copyright claimants, or other third parties when required by law, legal process, or to protect rights, safety, security, and the service;
• in connection with financing, acquisition, merger, or sale of assets, subject to applicable law.
Current service providers may include, without limitation, Supabase for authentication, database, storage, and realtime backend services; Cloudflare R2 for object storage; Amazon Web Services for Cammy AI Edit queueing, container hosting, and batch rendering; OpenAI for Cammy AI Edit prompt, frame, and transcript-text understanding; RevenueCat and Apple for in-app purchase receipt validation and entitlement management; Apple Push Notification Service and Expo for push delivery; Twilio through Supabase for phone-code delivery; and Sentry (Functional Software, Inc.) for crash and performance diagnostics, which may include device information and account identifiers. If you choose to share an Edit to an outside platform such as TikTok or Instagram/Meta, that sharing is handled by those platforms under their own terms and privacy policies. We use these providers to operate Cammy and do not share personal information with advertising networks, data brokers, or third-party analytics providers for cross-app tracking.
We may also preserve logs, records, or content when reasonably necessary to investigate abuse, enforce our rules, respond to takedown or legal requests, resolve disputes, or protect people, rights, and the platform.
7. Your Choices, Access, and Deletion Controls
Depending on your location and the nature of our processing, you may have the right to access, correct, delete, or obtain a portable copy of certain personal information, and to withdraw consent for optional processing where applicable. In the app today, you can manage many permissions through your device settings, delete your own account, and delete certain content that you own or control through the product features made available to you.
Cammy's product controls are content-specific. Users generally may delete their own account and content they personally created or uploaded where the feature allows that action, including their own Edits. Users generally cannot delete content another user created or uploaded. In collaborative event spaces, hosts and co-hosts may be able to remove or moderate shared event media as part of event administration. If you request deletion, we may retain information that must be preserved for legal, security, fraud-prevention, backup, dispute-resolution, or rights-enforcement purposes.
If you contributed as a guest. Because guest contributions do not create an account, there are no in-app account controls for them. To access or delete media you contributed as a guest, email us at [email protected] with the name you used and enough detail to identify the event — for example the host's name, the event name, or the invite link you opened — and we will locate and act on your request. You can also ask the event host to remove your contribution, since hosts can moderate media shared in their own events.
When you delete your account or content, we also delete the analysis our editing and AI features derived from that content — including numerical embeddings, scene, motion, and quality signals, captions, speech transcripts, prompts, and rendering data — from our active systems, except for (i) limited de-identified or aggregated information that is no longer linked to you and cannot reasonably be used to identify you, and (ii) records we are required or permitted to retain for the legal, security, billing, or similar purposes described in this policy. Backups are overwritten on our normal backup cycle. Information you already exported, downloaded, copied, re-shared, or that was incorporated into another user's content may persist outside our control, as described in Section 5.
8. Legal Bases and Regional Notices
Depending on where you are, we rely on one or more of the following: consent, performance of our contract with you, legitimate interests such as product operation, security, moderation, and service reliability, and legal obligations.
United States: We provide an in-app privacy policy, point-of-collection notice through this policy and just-in-time permission prompts, and a process for access, correction, deletion, and portability requests where required. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use or disclose sensitive personal information for purposes that would require a right to limit under applicable law.
If you live in California, Colorado, Connecticut, Texas, Virginia, Utah, or another U.S. state with a comprehensive consumer privacy law, you may have the right to: confirm whether we process your personal information and access it; correct inaccuracies; delete personal information; obtain a portable copy; and opt out of sales, targeted advertising, and certain profiling (activities we do not currently engage in). To exercise a right, contact us at [email protected]. We will verify your request using information associated with your account and respond within the time required by law. Where permitted, an authorized agent may submit a request on your behalf with proof of authorization. We will not discriminate against you for exercising a privacy right. If we decline your request, you may appeal by replying to our decision with the word "Appeal," and we will respond as required by your state's law; if your appeal is denied, you may contact your state attorney general.
Canada: We limit collection to what is needed for identified purposes, obtain consent where required, make our practices available to users, and provide reasonable access and correction rights consistent with PIPEDA and similar provincial laws.
Mexico: We make this privacy notice available when personal data is collected, describe the purposes of processing, explain how to limit use and disclosure, and provide a mechanism to exercise ARCO rights (access, rectification, cancellation, and opposition), consistent with the Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares.
Brazil: We process personal data consistent with the Lei Geral de Protecao de Dados (LGPD), including processing on a lawful basis, limiting use to disclosed purposes, and applying security safeguards. If you are in Brazil, you may request confirmation that we process your personal data, access, correction of incomplete or outdated data, anonymization or deletion of unnecessary data, a portable copy, and information about the third parties with whom we share data, by contacting [email protected]. We respond to these requests as required by law.
Australia and New Zealand: We handle personal information consistent with the Australian Privacy Principles and the New Zealand Privacy Act 2020, including collecting only what we need, using it for the purposes described in this policy, protecting it with reasonable security safeguards, and providing rights to access and correct your information. You may raise concerns with us first at [email protected], and you may also complain to the Office of the Australian Information Commissioner (OAIC) or the New Zealand Office of the Privacy Commissioner.
Other countries: Where the law of your country provides additional privacy rights, such as habeas data or similar data-protection rights recognized in parts of Latin America, we honor valid requests to access, correct, or delete your personal information consistent with applicable law. Contact us at [email protected].
9. Retention
We retain personal information for as long as reasonably necessary to provide the service, maintain accounts and collaborative records, support reels and media features, complete transactions, maintain the analysis records that power product functionality while the related account and content exist, resolve disputes, enforce our agreements, and satisfy legal, tax, accounting, security, or backup obligations. When you delete content or your account, we delete the related media and the analysis derived from it as described in Section 7, and some data may remain for a limited period in backups, logs, fraud-prevention systems, notification records, or legal-hold archives.
10. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including encrypted transmission (HTTPS/TLS), access controls, and row-level database permissions that limit each account to the data and events it is authorized to see. Your sign-in credentials are stored in your device's secure hardware keystore (the iOS Keychain or Android Keystore), and we do not embed administrative keys or secrets in the app.
Your photos and videos are delivered through unique, non-guessable private links rather than public directories or browsable listings. Because a link can be opened by anyone you share it with, and because content can be viewed, exported, downloaded, or re-shared, those links and copies may remain accessible outside our systems, as described in Section 5. No method of storage or transmission is perfectly secure, so we cannot guarantee absolute security.
11. Children and Age Restrictions
Cammy is not intended for children under 13. In some regions, higher digital-consent ages apply. Cammy currently blocks sign-up below the applicable threshold until compliant parental-consent tooling is available. If we learn that we collected personal information in violation of these age rules, we will take steps to delete it.
12. International Transfers
We and our service providers may process information in the United States and other countries where we or they operate. By using Cammy, you understand that your information may be transferred to and processed in jurisdictions with different privacy laws, subject to applicable safeguards.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we may provide notice in the app, by email, or by other appropriate means. The "Effective Date" above shows when this version took effect.
14. Contact Us
For privacy requests, questions, or complaints, contact us at [email protected].
CAMMY LLC
1738 SW 57th Ave
Unit # A505
Miami, FL 33155
Cookies and Consent (Website)
The Cammy website uses a small number of strictly necessary local-storage entries to keep the site working (for example, remembering your cookie choice). The website does not currently load advertising or behavioral-tracking cookies. When we add analytics or marketing tools that use non-essential cookies, those tools will only run after you click “Accept” in the cookie banner shown at the bottom of the page on your first visit.
Your choice is remembered for approximately twelve months. You can change it at any time by clearing your browser’s site storage for this site, which resets your choice so the banner reappears on your next visit.