Camera Shy

Privacy Policy

Last updated: July 26, 2026

Who we are

Camera Shy is operated by Monument Labs LLC, a Virginia limited liability company. This page describes what the product actually collects and where it goes, as of the date above. It is written to match the code, not to cover every hypothetical.

What we collect

Account information. Your email address, a password that our authentication provider stores hashed (we never see or hold it in plain text), an optional display name, and the timestamp your account was created.

  • Session content. The video and audio recording of your session, its transcript, the brief and beat plan, the per-beat clips you cut, and a raw event log of the session. These are files in a private storage bucket. Session records — title, slug, date, duration, brief, and beats — live in our database.
  • Context files. Any notes or reference text you paste into your context corpus, stored as text in our database.
  • Usage analytics. First-party events describing how the product is used: an event name, your user ID when you are signed in, a durable browser ID, a visit ID, the page path, the names of any URL query parameters (never their values), the first hop of your referrer, your browser's user-agent string, a server timestamp, and the IP address the request came from.
  • Error reports. When a server request fails, we record a sanitized fingerprint of the failure — route, message, and a few stack frames — after stripping email addresses, IDs, quoted strings, and long numbers.

Analytics event payloads are limited by rule to counts, durations, booleans, and fixed labels. They never contain transcript text, brief text, session titles, or the contents of your context files.

About the IP address

We record the IP address alongside each analytics event. We use it for coarse geography, for spotting abuse, and for debugging — we do not build advertising profiles, and we do not share it with advertisers or data brokers.

Being straight about the retention position: that IP address is stored on the event row, and event rows are an append-only log with no expiry today. So an IP is kept indefinitely unless you ask us to remove your events. See "How long we keep things" below.

How we use it

To run the interview and produce your clips, to keep you signed in, to understand which parts of the product work and which lose people, and to find and fix errors. That is the whole list.

We do not run advertising, we do not sell or rent personal information, and we do not use your recordings, transcripts, or context files to train AI models.

AI processing

Camera Shy sends data to AI model providers through the Vercel AI Gateway to do four jobs: hold the live voice interview, transcribe what you say, plan and direct the interview against your beats, and segment the finished transcript into clips. Today those providers are OpenAI and Anthropic.

What gets sent to them: your live microphone audio during the session, the transcript text, your brief, and any context files you have added.

What does not get sent: your camera video. The video is captured in your browser and uploaded directly to our private storage bucket. It is never passed to an AI provider.

Cookies and local storage

Camera Shy sets first-party cookies only. There are no third-party trackers, no advertising pixels, and no third-party analytics scripts on the site.

  • A session cookie from our authentication provider, which is what keeps you signed in.
  • cs_anon — a random ID, set by our server, HTTP-only (page scripts cannot read it), lasting one year. It ties events from the same browser together so we can tell one returning visitor from two new ones. It is not linked to your identity until you sign in.
  • cs_internal — marks our own and our test accounts' traffic so it can be excluded from product metrics.

In your browser's own storage we also keep your light/dark preference, a flag recording that you have seen the cookie notice, and a visit ID that resets after 30 minutes of inactivity. None of that is sent anywhere except the visit ID, which rides along on analytics events.

Security

Traffic is served over HTTPS. Recordings, transcripts, and clips live in a private storage bucket with per-object policies that allow only the owning account to read or write them, and database rows for sessions and context files are protected by row-level security scoped to the owner. Download links are signed and short-lived. Analytics and error data are readable only by accounts we have flagged as employees.

No system is perfectly secure, and we will not pretend otherwise. If you find a problem, email us.

How long we keep things

Plainly: there is no automatic retention or deletion today. Recordings, transcripts, clips, context files, session records, analytics events, and error fingerprints are kept until they are deleted on request. There is no scheduled cleanup job and no expiry.

There is also no delete button in the app yet — you cannot currently delete a session, a recording, or your account from the interface. Email us and we will do it by hand.

When we delete your account, your profile, session records, and context files are removed from the database, and your files are removed from the storage bucket. Analytics events are handled differently: they are an append-only log, so deleting your account unlinks your user ID from past events rather than removing the rows. If you want those rows deleted too — including the IP addresses and browser ID on them — say so in the same email and we will purge them.

Your rights

You can ask us for a copy of the personal data we hold about you, ask us to correct it, or ask us to delete it. There is no automated portal — email us and a person handles it. We honor these requests regardless of where you live, and we do not sell personal information to anyone.

Who else touches your data

We use a small number of service providers, each processing only what their job requires:

  • Supabase — database, authentication, file storage, and the transactional emails that confirm your address.
  • Vercel — application hosting, and the AI Gateway that routes our model calls.
  • OpenAI and Anthropic — the AI models behind the voice interview, transcription, direction, and segmentation, reached through that gateway.

That is the complete list. There are no advertising networks, no third-party analytics vendors, and no data brokers.

Children

Camera Shy is not directed at children and is not for anyone under 13. We do not knowingly collect personal information from children. If we learn we have, we delete it.

Changes to this policy

We may update this policy as the product changes. The date at the top always reflects the current version, and we will give notice in the app or by email if a change materially affects you.

Contact

Privacy questions, data requests, and deletion requests go to kyle@monumentlabs.io.