Skip to content
ViewPane
FeaturesPricingDocsNewsBlogReport a bugDownload
FeaturesPricingDocsNewsBlogPressReport a bug
Privacy Policy

Privacy Policy

ViewPane Companion App

Last updated: 2026-09-08 · Effective: 2026-05-02

The short version

ViewPane does not collect, store, transmit, or sell any personal data — with one narrow, opt-in exception: a device push token, only if you enable push notifications. The app connects directly to your own self-hosted Frigate NVR server on your own network. We never see your camera footage, your server address, your account, or anything else. There are no accounts to make. There is no telemetry. There is no tracking.

Data we collect

ViewPane collects zero analytics, zero telemetry, zero usage statistics, zero crash reports, and zero diagnostic information. No third-party analytics SDKs, no advertising SDKs, no tracking pixels. The single exception: if you opt in to push notifications, a device push token (an anonymous delivery address for notifications, not linked to your identity) is registered with Expo's push service and stored on your own self-hosted relay — see the Push notifications section below. Never enable notifications and even that never happens.

Data Safety / App Privacy declaration

For purposes of the Google Play Data Safety form and Apple App Privacy nutrition label:

  • Data collected by ViewPane: a device push token (Play category "Device or other IDs"), optional, collected only when you enable push notifications, used solely for app functionality (delivering your alerts)
  • Data linked to user identity: none
  • Data used for tracking: none
  • Data shared with third parties: none beyond the push-delivery transit described in the Push notifications section (Expo, then Google/Apple, deliver the notification — they are processors of the delivery, and no other party receives anything)
  • Data encrypted in transit: traffic between your device and your server is encrypted when you use HTTPS or a VPN/Tailscale tunnel; the app permits plain HTTP only on private LAN addresses and refuses to send credentials over plain HTTP to public addresses
  • User can request data deletion: Yes — disable Motion Alerts (which unregisters the push token from your relay) or uninstall the app.

Data stored on your device

ViewPane stores your Frigate server connection details (server URL, server name, and authentication credentials if you provide them) locally on your device using the operating system's secure storage (iOS Keychain / Android Keystore / Expo SecureStore). The app also caches camera snapshots, event thumbnails, downloaded clips, and basic UI preferences in the app's private sandbox. None of this data leaves your device. None of it is accessible to CampbellSoft Studios or any third party.

Network communication

The app communicates exclusively with the Frigate NVR server(s) you configure and, if you opt in to push notifications, with the optional self-hosted push relay you configure and Expo's push token service (token registration and refresh, which recurs while notifications are enabled — see the next section) and, once ViewPane Desktop ships (planned Q1 2027), the optional Link-a-PC feature will also talk to that app on a computer on your own network (pairing data never leaves your LAN). On iOS the app makes one throwaway request to a private LAN address on first launch so iOS can show its Local Network permission prompt; nothing is sent or stored. All camera and event traffic flows directly between your device and your server — over your local network, your Tailscale tailnet, your WireGuard tunnel, or your VPN of choice. CampbellSoft Studios does not operate any servers, proxies, intermediaries, or cloud infrastructure. No data is routed through us.

Push notifications

Push notifications are an opt-in Pro feature. If enabled, the app registers a push token with Expo's push token service (and re-registers automatically when your device's platform rotates the token), and your self-hosted relay delivers each alert through the Expo Push API to your device's platform push service (Firebase Cloud Messaging on Android, Apple Push Notification service on iOS). This means alert metadata — camera name, detection label, detection confidence score, event timestamp, an alert-priority flag, and an event identifier — transits Expo's and Google's/Apple's delivery infrastructure. If you enable face recognition on your Frigate server and create a face alert rule in the relay, the name you gave that face in Frigate (for example "Ken") is included in the notification title and payload and transits the same path; enrolling faces, choosing the names, and obtaining any consent that biometric or privacy laws require from the people involved are your responsibility, and CampbellSoft Studios never receives face images, face data, or those names. If you enable snapshot images in notifications (by giving your relay a public base URL), the payload additionally carries a short-lived, signed link pointing at your own relay; the snapshot image itself is fetched by your phone directly from your relay and never passes through Expo, Google, or Apple. When your server determines an alert was a false positive, a silent retraction signal (the same event identifier and camera name, no new content) travels the same path so the stale notification can be dismissed. Your relay also stores, on your own server, the push token, your device's name as set in your OS settings (used only as a label so you can tell devices apart), and your notification rules and timezone — that data stays on your hardware. No video, snapshots, or credentials are ever included in a notification payload, and CampbellSoft Studios does not see, store, or process any of it. On Android, ViewPane explicitly disables Firebase's automatic initialization, so no push plumbing runs and no device push token exists until you enable notifications in the app. You can disable notifications at any time in your device's system settings or in the app.

This section describes what data a push notification carries. It is not a delivery guarantee: push notifications are best-effort and can be delayed or dropped, as described in our Terms of Use.

Pro subscription handling

Pro subscriptions are billed and managed by Apple's App Store and Google Play. Payment information, billing addresses, and tax information go directly to Apple and Google — ViewPane never sees any of it. The app receives a single boolean entitlement from the platform store ("is this user Pro?") and uses that to unlock Pro features. Refunds, cancellations, and subscription changes are handled in your Apple ID / Google Play account, not by us.

Camera footage

All camera footage is stored on your own hardware (your Frigate NVR server and storage). ViewPane is a viewer, not a storage service. We never have access to your footage, recordings, snapshots, or event clips. The app simply displays what your server provides over your own network.

Account deletion

ViewPane does not require an account and does not create one. There is nothing for you to "delete" with us because we never had it. To remove all locally-stored data: uninstall the app from your device. To cancel a Pro subscription: do so in your Apple ID or Google Play account. If you would like written confirmation of the above for a store reviewer or auditor, email ken@campbellsoftstudios.com.

GDPR / CCPA / CPRA

Because ViewPane collects no personal data beyond the optional push token, the rights granted under the EU General Data Protection Regulation, the California Consumer Privacy Act, and the California Privacy Rights Act — access, rectification, deletion, portability, opt-out of sale, opt-out of sharing — are satisfied directly: there is nothing to sell or share, and the one collected item is deleted by disabling notifications (which unregisters the token from your relay) or uninstalling the app. Uninstalling removes everything held on your device.

Children's privacy

ViewPane is not directed at children. Our Terms of Use require users to be at least 18 years old (or the age of majority where they live). The app does not collect personal data from anyone, including children, beyond the optional push token described above. There is no account creation and no profile.

Marketing site (viewpane.app)

The viewpane.app website is statically hosted, uses no cookies, no analytics, and no third-party scripts beyond what's strictly required to render the page. We do not log visitors. Hosting may produce standard server access logs which are not used for tracking.

Changes to this policy

If we ever change this policy, the updated version will be posted at this URL with a new "Last updated" date. Given that we collect no data, material changes are unlikely.

Contact

Questions about this privacy policy:
ken@campbellsoftstudios.com

"CampbellSoft Studios" is the trade name of Kenneth Campbell, an individual doing business in Alabama, United States.

CampbellSoft Studios
Alabama, USA
viewpane.app · campbellsoftstudios.com
DocsNewsBlogFeaturesPricingPressPrivacyTermsReport a bug

ViewPane is a viewer for your own Frigate server — not an alarm system or a monitored security service. Push notifications are best-effort and can be delayed or dropped. Terms

© 2026 CampbellSoft Studios · Made for the Frigate community.