โ Back
Privacy Policy
Last updated: May 2026 ยท Effective: May 2026
Updated to add explicit AI policy (Section 7), human-access disclosure (Section 8), and security incident response procedure (Section 10).
DailyLens ("we", "us", "the app") is a Ring camera companion app that captures scheduled
snapshots from your Ring camera and builds a visual timeline. This policy explains exactly
what we collect, how we use it, who we share it with, how long we keep it, and how you
can delete it.
1. What We Collect
We collect only what's needed to run the service:
- Your email address โ collected once during account linking, used only to identify your account and contact you about service issues.
- Your Ring Account ID and device IDs โ provided by Ring during account linking so we know which camera to capture from.
- Ring OAuth access and refresh tokens โ stored securely so we can capture snapshots on your behalf.
- Snapshot images from the Ring camera you choose, captured on the schedule you set.
- Cloudinary credentials (Cloud Name, API Key, API Secret) that you provide so we can upload your snapshots to your own Cloudinary account.
- App preferences โ your chosen theme, timezone, accent color, timeline names, capture schedules, notes you add to photos, and favorite/cover selections.
- Capture log โ timestamps of capture attempts and their result (success, no new footage, error). No image content beyond filenames.
What we do NOT collect: live video streams, audio, biometric data,
facial recognition data, license plates, location data, names of people who appear in
snapshots, or any data from cameras you did not explicitly link.
2. How We Use Your Data
Your data is used only to:
- Capture snapshots from your Ring camera at the times you've scheduled.
- Display your timeline of past snapshots inside the app.
- Generate time-lapse videos from your photos when you request them.
- Send you in-app status messages (e.g., "Ring connection expired โ please re-link").
- Operate basic service maintenance (e.g., logging errors so we can fix bugs).
We do not use your data for advertising, marketing, profiling, or analytics beyond what's
needed to keep the service running. We do not sell or rent your data.
3. Who We Share Data With
DailyLens uses these third-party services to operate. Each gets only the minimum data they need:
- Ring (Amazon) โ we exchange OAuth tokens with Ring's API to authenticate you and request snapshots from your camera. Your existing Ring privacy notice (linked from the Ring app) applies to data Ring holds about you.
- Cloudinary โ your snapshot images are uploaded to your own Cloudinary account using credentials you provide. DailyLens does not own the Cloudinary account and cannot access your images outside the credentials you've shared with us. See Cloudinary's privacy policy.
- Render โ DailyLens runs on Render's hosting platform. Render processes data only to deliver the service. See Render's privacy policy.
- cron-job.org โ sends a periodic, authenticated "tick" to our server to trigger scheduled captures. No personal data is shared with cron-job.org.
We do not share your data with law enforcement, advertisers, data brokers, or any other
third party except as required by valid legal process.
Sub-processor changes: the list above is current as of the "Last
updated" date. If we add, remove, or change a sub-processor, we will update this
section and bump the date. Material changes will also be announced inside the app
before they take effect.
4. Where Your Data Is Stored
Your account data, timeline metadata, and capture logs are stored in a managed Postgres
database in the United States. Your snapshot images are stored in your own Cloudinary
account (default region: United States, configurable by you in Cloudinary).
5. How Long We Keep Your Data
- Account and timeline data: kept for as long as your account is active.
- Snapshots: kept until you delete them or until the per-timeline cap is reached (you can also delete individual photos at any time).
- Capture log: retained for the lifetime of the timeline; deleted when the timeline is deleted.
- Login session tokens: rotate every 30 days; expired tokens are deleted automatically.
- After account deletion: all data is removed from our database and from your Cloudinary account within 30 days. Backups are overwritten on a rolling basis and fully purged within 90 days.
6. Your Choices and Controls
You can, at any time:
- Pause a timeline to stop new captures (Settings on each timeline).
- Delete individual photos from a timeline (swipe-select or via the lightbox).
- Delete an entire timeline and all of its photos (Timeline Settings โ Delete).
- Delete your entire account and all stored data (Settings โ Delete My Account). This wipes your DailyLens database records AND removes the photos DailyLens has uploaded to your Cloudinary account.
- Disconnect DailyLens from Ring entirely by removing it from the Ring app's connected apps list. After disconnecting, please also delete your DailyLens account inside the app to remove your stored data.
- Request data export or deletion by emailing the address in Section 13.
7. AI, Profiling, and Automated Decisions
DailyLens does not use artificial intelligence, machine learning, facial
recognition, object detection, or any other automated analysis on your snapshots. Your
images are stored and displayed exactly as Ring delivers them โ nothing is inferred,
classified, scored, or labeled.
No training: we do not use your data to train any AI or machine
learning model โ neither our own, nor any third party's. We do not share your data
with any AI provider for training purposes.
Opt-out: because we do not use your data for AI training or automated
profiling, no opt-out is required โ you are automatically opted out by default. There is
no separate setting to toggle, and your service experience is unaffected.
Future AI features: if we ever add AI-powered features (for example,
auto-tagging photos or motion summarization), we will (1) update this policy with the
"Last updated" date at the top, (2) post an in-app notice describing the new feature
and exactly what data it processes, and (3) require you to opt in before any AI-related
processing begins on your account. AI features will never be turned on for existing
accounts without explicit consent.
8. When Humans May View Your Data
Your snapshots are private to you. Day-to-day, no human at DailyLens looks at your
images โ captures, storage, and display are fully automated.
The narrow exceptions are:
- Debugging at your request โ if you email support about a problem and explicitly grant permission, the developer may view a small number of your captures or log entries needed to diagnose the issue. We will only view what's necessary and only for as long as needed to resolve your ticket.
- Suspected abuse or terms-of-service violations โ if we receive a credible report that DailyLens is being used to harm someone (for example, surveillance without consent), the developer may review the relevant account's metadata (timeline names, capture log) to investigate. Image content is reviewed only when strictly necessary and permitted by law.
- Legal process โ if compelled by valid legal process (subpoena, court order), we may need to provide data to law enforcement. We will notify the affected user unless legally prohibited.
Routine operations โ backups, hosting, scheduled captures โ are handled by automated
systems, not by humans reading your data.
9. Security
All communication uses HTTPS. Ring OAuth tokens and Cloudinary credentials are stored
server-side and never exposed to the browser. Account-linking nonces are verified using
HMAC-SHA256. Webhook payloads from Ring are verified with HMAC-SHA256 signatures before
being processed. Session cookies are HttpOnly, Secure, and SameSite=Lax.
10. Security Incident Response
If we detect or are notified of a security incident affecting your data, we will:
- Assess the scope โ what data was affected, how many users, and the
attack vector โ within 24 hours of detection.
- Contain the incident โ rotate credentials, revoke tokens, and take
affected systems offline if necessary.
- Preserve evidence โ capture relevant logs before remediation so the
root cause can be determined.
- Remediate โ patch the vulnerability and audit related systems for
similar issues.
- Notify affected users within 72 hours of confirmed scope, via an
in-app banner on the dashboard and an email to the address on file. The notice will
explain what data was affected, what we are doing in response, and what (if anything)
you should do.
- Notify Ring within 24 hours of any incident affecting Ring user data,
per Ring's Program Requirements.
- Notify regulators when applicable law requires it (e.g., 72-hour GDPR
breach notification, where it applies). The shorter of any applicable legal deadline
and our 72-hour user-notification window will govern.
After remediation, a brief written postmortem is created and this policy and our
security practices are updated as needed. During an active incident, the contact address
in Section 13 is monitored for prioritized response, and incident-related tickets are
triaged ahead of routine support.
11. Use in Workplace or Business Settings
If you use DailyLens to monitor a workplace or commercial property, you are responsible
for complying with all applicable employment, labor, and notification laws โ including
informing employees and visitors that recording is taking place and obtaining any
consents required in your jurisdiction. DailyLens is a tool, not a legal compliance
service.
12. Children
DailyLens is not directed to children under 13 and is not designed to be used by children.
We do not knowingly collect personal information from children under 13. If you believe
a child has provided us information, contact us using Section 13 and we will delete it.
13. Contact & Abuse Reports
For privacy questions, data deletion requests, abuse reports, or any other inquiries:
๐ง xenastore@outlook.com
We respond to all valid requests within 30 days. To report abuse of DailyLens (e.g.,
someone using it without your consent on a shared camera), include "ABUSE REPORT" in
the subject line and we will prioritize the response.
14. Changes to This Policy
We may update this policy as the service evolves. The "Last updated" date at the top
will reflect any change. Material changes will be announced inside the app before they
take effect.