# Privacy Policy for Starship PTZ
**Last updated:** August 4, 2026
**App name:** Starship PTZ
**Developer / operator:** TYLOAL (or insert your legal name)
**Contact:** [your-email@example.com]
This Privacy Policy describes how **Starship PTZ** (“the App”) collects, uses, and shares information when you use the App on Apple devices. By using the App, you agree to this policy.
---
## 1. Overview
Starship PTZ is a free app that lets you:
- Watch a live camera stream associated with the service
- Join a fair queue to control a remote PTZ (pan / tilt / zoom) camera
- Optionally purchase a **private booked hour** of exclusive camera control via Apple In‑App Purchase
The App is free to download and use for queue-based control. The only paid feature is booking a private hour.
We designed the App to collect **only what is needed** to run the queue, bookings, live stream, and camera control. We do **not** require you to create an account with an email address or password, and we do **not** use third-party advertising SDKs.
---
## 2. Information We Collect
### 2.1 Information you provide
| Data | When | Purpose |
|------|------|---------|
| **Display name** | You enter a name in Settings (optional but recommended) | Shown to other users in the control queue and associated with your turn / bookings so others know who is controlling the camera |
| **Booking choices** | You select a date and hour to book | To reserve and confirm your private control slot |
We do not ask for your real legal name, email, phone number, or address to use the core features of the App. If you contact us for support, we will receive whatever contact details you choose to send (for example, your email address).
### 2.2 Information collected automatically
| Data | How | Purpose |
|------|-----|---------|
| **Device identifier (app-generated)** | A random UUID is created on first launch and stored on your device | Identifies your device for queue fairness, “whose turn” control, unique viewer counting, and linking bookings to you—**without** requiring an account |
| **Queue and control activity** | When you request control, stay in line, or send PTZ commands | To operate the queue, enforce turn limits, accept commands only from the current controller, and keep the camera safe (including stopping motion if your device stops responding) |
| **Stream / viewer activity** | When you open the live stream | To count active viewers and lifetime unique devices for basic service stats |
| **Purchase / transaction reference** | When you buy a booked hour through Apple | Apple processes payment. We receive a transaction identifier (and related purchase confirmation data) so we can mark your booking as paid and grant exclusive control for that hour |
| **Connection / technical data** | Network requests to the service | Server URL used, connection success/failure, and basic request handling needed to run the App. We do not use this for advertising profiling |
### 2.3 Information stored only on your device
The App may store locally (for example via on-device preferences):
- Your display name
- Your app-generated device identifier
- The server address the App last successfully connected to
This data stays on your device unless you clear app data or delete the App. Clearing data may generate a new device identifier and lose local preferences.
### 2.4 Information we do **not** collect
The App does **not**:
- Access your device camera, microphone, photos, contacts, calendar, or precise GPS location for its core features
- Require an email/password account with us
- Use third-party analytics or advertising trackers (such as Firebase Analytics, Facebook SDK, or ad networks) as part of the App’s design
- Sell your personal information
- Collect government IDs, payment card numbers, or bank details (payments are handled by Apple)
**Local network:** On some networks the App may connect to the operator’s equipment on a local network (for example a home Raspberry Pi). iOS may show a **Local Network** permission prompt for that purpose. That access is only to reach the camera control service—not to scan or collect data from other devices on your network.
---
## 3. How We Use Information
We use the information above to:
1. **Provide the service** — live viewing, queue-based PTZ control, presets / saved positions, and booked exclusive hours
2. **Process purchases** — confirm Apple In‑App Purchases for hour bookings and grant the corresponding control time
3. **Maintain fairness and safety** — one controller at a time, timed turns, deadman stop if the controller disconnects
4. **Operate and improve reliability** — connection health, viewer counts, and basic operational stats
5. **Respond to support requests** if you contact us
We do **not** use your data for third-party advertising or sell it to data brokers.
---
## 4. How Information Is Shared
### 4.1 Visible to other users of the service
- Your **display name** may be shown to other people using the same live camera / queue (for example, “who is controlling now” or position in line).
- **Saved camera positions** you create may include a creator label (such as your display name) visible to other users of that shared camera.
Do not enter sensitive personal information as your display name.
### 4.2 Service operator / backend
The App connects to a **backend service** operated for Starship PTZ (typically a server that relays PTZ commands and manages the queue and bookings). That server may receive:
- Your display name
- Your app-generated device identifier
- Queue, control, stream, and booking activity
- Purchase transaction identifiers needed to confirm paid bookings
Camera credentials (for example the physical camera’s password) are **not** stored in the App; they remain only on the operator’s private server configuration.
### 4.3 Apple
In‑App Purchases are processed by **Apple**. Apple’s handling of payment data is governed by [Apple’s Privacy Policy](https://www.apple.com/legal/privacy/). We do not receive your full payment card details.
### 4.4 YouTube / video providers
Live video may be provided via **YouTube** (or a similar embed / stream). When you watch that video, YouTube (Google) may collect data under its own policies. See [Google’s Privacy Policy](https://policies.google.com/privacy). The App may also receive a live image stream from the operator’s camera infrastructure for on-device viewing.
### 4.5 Legal and safety
We may disclose information if required by law, valid legal process, or to protect the rights, safety, or property of users, the operator, or the public.
We do **not** sell personal information.
---
## 5. Data Retention
| Data | Typical retention |
|------|-------------------|
| Display name / device ID on your phone | Until you change it, clear app data, or delete the App |
| Queue / active control state | Ephemeral; drops when you leave the queue or disconnect |
| Unique device viewer records | May be kept on the server for lifetime unique-viewer statistics |
| Booking records (date, hour, name, device ID, transaction reference) | Kept as long as needed to honor bookings, prevent fraud/double-spend of consumables, and maintain service history; may be retained longer if required for legal or accounting reasons |
| Support emails | As long as needed to resolve your request |
If you want booking or server-side records associated with your device identifier deleted, contact us (see **Contact** below). We will honor reasonable deletion requests where we control the data and are not required to keep it by law.
---
## 6. Security
We take reasonable measures appropriate to a consumer camera-control service, including:
- Authenticated API access between the App and the backend
- Accepting PTZ commands only from the current authorized controller
- Keeping physical camera credentials on the private server, not in the App
No method of transmission or storage is 100% secure. Use the App over trusted networks when possible. For public releases, HTTPS is recommended between the App and the server.
---
## 7. Children’s Privacy
The App is not directed at children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided information through the App, contact us and we will take appropriate steps to delete it.
---
## 8. International Users
The backend may be hosted in the country where the camera / operator is located (for example, on equipment at the operator’s premises). By using the App, you understand that your information may be processed in that location, which may differ from your own country.
---
## 9. Your Choices
- **Display name:** Change or clear it anytime in Settings.
- **Purchases:** Managed through your Apple ID and App Store purchase history / refunds per Apple’s policies.
- **Local Network permission:** You can deny or revoke it in iOS Settings; some connection paths may then be unavailable.
- **Delete local data:** Offload or delete the App to remove on-device preferences and the stored device ID.
- **Server-side deletion:** Email us to request deletion of booking or identifier records we control.
---
## 10. App Store “App Privacy” Summary (for App Store Connect)
Use this as a guide when filling Apple’s privacy nutrition labels. Adjust if your live deployment differs.
| Category | Linked to user? | Used for tracking? | Notes |
|----------|-----------------|--------------------|-------|
| **User ID** (app-generated device UUID) | Yes (to app identity / queue) | No | Queue, control, viewers, bookings |
| **Name** (display name) | Yes | No | Shown in queue / bookings |
| **Purchases** | Yes | No | Consumable hour booking via StoreKit; transaction ID for fulfillment |
| **Product Interaction** (queue, control, stream use) | Yes | No | Service operation |
| **Other Diagnostic / Performance Data** (if any basic connection errors) | No / limited | No | Operational only; not advertising |
**Data Not Collected** (typical for this App design): Health, Fitness, Financial Info (beyond IAP via Apple), Precise Location, Contacts, Photos, Audio, Customer Support (unless you email us), Sensitive Info, Advertising Data, etc.
**Tracking:** The App does not use data for cross-app tracking under Apple’s definition for advertising. Do not enable App Tracking Transparency unless you later add tracking SDKs.
---
## 11. Third-Party Services
| Service | Role | Privacy info |
|---------|------|----------------|
| **Apple / App Store / StoreKit** | Distribution and In‑App Purchase | [apple.com/legal/privacy](https://www.apple.com/legal/privacy/) |
| **YouTube / Google** (if live video uses YouTube) | Video playback | [policies.google.com/privacy](https://policies.google.com/privacy) |
| **Operator backend (e.g. Raspberry Pi service)** | Queue, bookings, PTZ relay, stream | Covered by this policy |
---
## 12. Changes to This Policy
We may update this Privacy Policy from time to time. The “Last updated” date at the top will change when we do. Continued use of the App after changes means you accept the updated policy. Material changes may also be noted in an App Store release note or in-app notice when practical.
---
## 13. Contact
Questions about this Privacy Policy or your data:
- **Email:** [your-email@example.com]
- **App:** Starship PTZ
- **Developer:** TYLOAL (or insert legal name / DBA)
---
## 14. Short version (plain language)
Starship PTZ lets you watch and take turns controlling a remote camera. We store a random ID on your phone and the name you choose so the queue and bookings work. If you buy a private hour, Apple handles payment and we keep the transaction reference so you get your hour. Other people on the same stream may see your display name. We don’t sell your data or use ad trackers. Contact us if you want server-side data deleted.
---
*This document is provided as a practical template based on the Starship PTZ app’s design. It is not formal legal advice. Have a lawyer review it before relying on it for App Store submission or commercial launch, and replace bracketed placeholders with your real contact and legal entity details.*