Privacy Policy

Last updated: July 31, 2026

The short version: BirdWatch does not collect, transmit, or store any of your personal data. The app communicates with the Frigate™ NVR server(s) you configure. No analytics, no tracking, no ads. The one optional cloud-touching feature — Battery-Saver Push — routes only end-to-end encrypted ciphertext through your own Firebase project; we still see nothing, ever.

1. Information We Collect

We collect nothing. BirdWatch does not collect any personal information, usage data, analytics, crash reports, or telemetry of any kind.

2. Data Stored on Your Device

The app stores the following data locally on your device only:

All credentials and keys are stored using Android EncryptedSharedPreferences with AES-256 encryption. This data never leaves your device except as described in Section 3.

3. Network Communication

By default, BirdWatch communicates only with the Frigate™ NVR server URLs you provide. The app makes the following requests to your server(s):

Optional Battery-Saver Push: if you enable this feature, event notifications travel from your self-hosted relay through Google Firebase Cloud Messaging (FCM) to your phone. Every payload is end-to-end encrypted on your relay with your phone's public key (NaCl sealed-box) before it leaves your network — Google transports ciphertext it cannot read, and the decryption key never leaves your device. The Firebase project involved is yours, created under your own Google account; we operate no server in this path and receive nothing. With this feature disabled (the default), no third-party communication occurs at all.

Beyond that, the app does not communicate with any third-party servers, APIs, analytics services, or ad networks.

4. Third-Party Services

BirdWatch embeds no analytics SDKs, crash reporting tools, or advertising frameworks. The only third-party service the app can touch is Google Firebase Cloud Messaging, used solely by the optional Battery-Saver Push feature described in Section 3 — disabled by default, carrying only end-to-end encrypted ciphertext when enabled, through a Firebase project you own.

5. Data Sharing

We do not share any data with anyone. There is no data to share, because we do not collect any.

6. Children's Privacy

BirdWatch does not collect personal information from anyone, including children under 13.

7. Google Play Purchase

Your purchase through Google Play is handled entirely by Google. We do not receive or have access to your payment information. Google's privacy policy applies to that transaction: policies.google.com/privacy

8. Security

Credentials are encrypted on-device using Android's security libraries. The app supports HTTPS connections to your Frigate™ server. We recommend configuring your Frigate™ instance with TLS/HTTPS, especially when accessing it over the internet.

9. Changes to This Policy

If we ever change this privacy policy, we will update it on this page with a new "Last updated" date. Significant changes will be reflected in app update notes.

10. Contact

If you have questions about this privacy policy, contact us at:
support@cyrilina.it