PRIVACY POLICY - REKAMI (FORMERLY RECAM VIEWER) FOR WINDOWS Last updated: July 28, 2026 Version: 2.0 1. WHO WE ARE AND SCOPE This Privacy Policy applies to Rekami (formerly ReCam Viewer) for Windows distributed through the Microsoft Store (the “App”). The data controller is R. Retamal, Chile. Privacy questions and requests may be sent to hello@rretamal.dev. The App lets users discover, connect to, view, and manage compatible RTSP and ONVIF cameras. Camera streams are processed locally. Rekami does not provide cloud video storage or a remote camera-streaming relay. 2. INFORMATION PROCESSED LOCALLY The App may process and store on the Windows device: • Camera names, descriptions, tags, IP addresses, ports, RTSP and ONVIF addresses. • Camera usernames, passwords, connection settings, ONVIF profiles, and PTZ settings. • Display layouts, preferences, license state, and other App settings. • Screenshots and video recordings created at the user’s request. • Local diagnostic records about preview failures, such as App version, setup method, failed stage, timing, selected profile characteristics, general failure reason, exception type, and a sanitized exception message. Camera configuration is kept in encrypted local application storage, with encryption secrets protected by Windows. Locally stored information remains on the device unless the user exports, copies, backs up, synchronizes, or shares it. Local diagnostic records remain until the App data is reset or removed. Screenshots and recordings are stored in the Pictures or Videos folder, or another location selected by the user. Uninstalling the App may not delete files stored outside the App data folder. 3. CAMERA AND LOCAL NETWORK ACCESS The App connects only to cameras configured, selected, or discovered by the user. It may communicate over a local network, private network, VPN, or a remote connection configured by the user. When the user starts ONVIF discovery, the App sends discovery requests on the local network and may temporarily read local IP addresses, device names, manufacturer, model, firmware, ONVIF services, capabilities, and connection addresses. Discovery results are used locally to help configure a camera. The App does not use the computer’s built-in camera or microphone for normal RTSP or ONVIF viewing. Audio contained in a configured network-camera stream may be played locally when supported. Depending on the camera configuration, RTSP or ONVIF communication may use protocols that are not encrypted. Users are responsible for securing their cameras, Windows account, device, network, router, VPN, firewall, and remote-access configuration. 4. OPTIONAL PRODUCT ANALYTICS — POSTHOG On Windows, optional analytics are disabled until the user expressly permits optional data sharing. The choice can be changed at any time under Settings > Privacy and data. Denying or withdrawing permission does not affect the App’s core camera functionality. If permission is granted, the App uses PostHog to receive a randomly generated installation identifier, event name and timestamp, App version and build, platform and device category, license or trial status, feature interactions, general result categories, counts, and performance timings. The App only accepts a fixed list of event names and properties, disables person-profile creation, and requests that IP-based geographic enrichment not be performed. Like any Internet connection, the connection necessarily makes the public IP address technically visible to the receiving service and its network providers. PostHog data is used to understand feature adoption, diagnose setup problems, improve reliability, and prioritize development. It is not used for targeted advertising, cross-application tracking, facial recognition, or decisions concerning credit, insurance, employment, or people shown by cameras. The App’s analytics code is designed not to send camera video or audio, screenshots, recordings, camera names, labels, IP addresses, RTSP or ONVIF addresses, usernames, passwords, or camera content. PostHog privacy information: https://posthog.com/privacy PostHog data processing addendum: https://posthog.com/dpa 5. OPTIONAL ERROR DIAGNOSTICS — SENTRY The same Windows privacy control governs automatic Sentry diagnostics. If permission is granted, Sentry may receive the error type, sanitized error message and stack trace, App version and build, timestamp, and a small number of breadcrumbs limited to the App's permitted product events. On Windows, the App disables automatic Sentry sessions, failed-web-request capture, performance tracing, SDK debug logging, client reports, local event caching, and default collection of personally identifiable information; it does not add attachments. Before an error is sent, the App removes request and user objects, device and operating-system contexts, tags, extra fields, source-file paths, source-code context, and captured variable values. It also sanitizes camera URLs, IP addresses, usernames, passwords, user-directory paths, and similar sensitive values. Events without an exception and expected local-camera probe failures are discarded. No sanitization method can guarantee detection of every unexpected value, so users should not place personal information in camera names or other diagnostic text. Like any Internet connection, transmission makes the public IP address technically visible to Sentry and its network providers, but the App does not add it to the diagnostic event and disables default PII collection. Sentry privacy information: https://sentry.io/privacy/ Sentry data processing addendum: https://sentry.io/legal/dpa/ 6. USER-SUBMITTED FEEDBACK Feedback is separate from optional automatic analytics and diagnostics. A comment is sent to Sentry only when the user writes it and presses “Send comment.” The submission may include the sanitized comment, App version, platform, timestamp, and network information necessary to transmit it. Users should not include camera addresses, credentials, or personal information belonging to another person. 7. CAMERA COMPATIBILITY CATALOG When camera-brand profiles are needed, the App may download a compatibility catalog from a service operated for Rekami. The request does not intentionally include camera details, addresses, credentials, or camera content. The service or its hosting provider necessarily processes the public IP address, request time, requested resource, and ordinary HTTP metadata for delivery, security, and abuse prevention. 8. MICROSOFT STORE AND WINDOWS Microsoft independently processes information for downloads, installation, updates, licensing, trials, purchases, payment processing, Store analytics, fraud prevention, Windows diagnostics, and Microsoft account or device services under Microsoft’s own terms and privacy statements. Rekami does not receive complete payment-card details. 9. PURPOSES AND LEGAL BASES Local camera processing and Microsoft Store licensing are necessary to provide the App and perform the user’s requested functions. Optional PostHog analytics and automatic Sentry diagnostics rely on the user’s consent, which may be withdrawn at any time. User-submitted feedback is processed at the user’s request and with the consent expressed by pressing Send. Compatibility-catalog delivery and limited security logs are necessary to provide that feature and protect the service. Information may also be processed when required to comply with law or establish, exercise, or defend legal claims. The App stores the consent state, notice version, and decision, grant, or revocation time locally on the Windows device so that the user’s choice can be applied and demonstrated. This local consent record is not sent as analytics. When a materially changed notice requires renewed consent, optional telemetry remains disabled until a new choice is made. 10. RECIPIENTS, INTERNATIONAL PROCESSING, AND DISCLOSURE Remote information may be processed by PostHog, Sentry, Microsoft, the hosting providers supporting the compatibility service, and professional advisers or authorities when legally required. PostHog and Sentry endpoints used by the App process information in the United States. Where applicable, data processing agreements, Standard Contractual Clauses, and supplementary technical and organizational safeguards are used for international transfers. Copies or information about applicable safeguards may be requested at hello@rretamal.dev. Personal information is not sold or rented. Rekami for Windows does not display advertising and does not share information with advertising networks. Information may be disclosed when reasonably necessary to comply with law, a valid court order, or a lawful government request; investigate fraud, abuse, or security incidents; protect users or others; obtain legal, accounting, security, or technical assistance; or complete a business transfer. Because camera content and configurations are normally local, the controller generally does not possess them. 11. RETENTION • Local camera configurations and settings remain until deleted, reset, or removed with App data. • Screenshots and recordings remain until deleted from their storage location by the user or another authorized application. • PostHog product-analytics events are retained for no more than 12 months. • Automatic Sentry errors and diagnostic events are retained for no more than 90 days. • Feedback submitted through the App is retained for no more than 12 months. • Ordinary compatibility-service access logs are retained for no more than 30 days. Information may remain for a limited additional period in encrypted backups or security logs before scheduled deletion. A longer period may apply only when required by law, necessary for a specific security investigation, or needed to establish, exercise, or defend legal claims. 12. SECURITY Rekami uses reasonable technical and organizational safeguards appropriate to the data processed. These include encryption at rest and in transit where applicable, operating-system protections, data minimization, and telemetry sanitization. Access to remote service accounts is limited to legitimate development, support, security, and operational purposes. No device, network, application, or transmission method can be guaranteed completely secure. 13. USER CONTROLS AND RIGHTS Users may add or remove cameras, start discovery only when desired, create or delete screenshots and recordings, reset local App data, and enable or disable optional analytics and diagnostics at any time. Withdrawing consent stops future optional transmissions but does not automatically delete information previously received by a provider. The Settings page displays the pseudonymous installation identifier, when one has been created, and allows it to be copied for a privacy request. Depending on applicable law, users may request access, correction, deletion, restriction, objection, portability, or blocking of personal information and may withdraw consent without affecting prior lawful processing. Users may also complain to the competent data-protection authority. Requests should be sent to hello@rretamal.dev and should include the installation identifier when the request concerns analytics. Identity verification may be required. A request may not be technically possible when information cannot reasonably be associated with the requester. 14. CHILDREN The App is not directed to children under 14 or below the minimum age required to consent independently in their jurisdiction. The controller does not knowingly collect camera content, credentials, or contact information from children. A parent or guardian who believes a child submitted personal information should contact hello@rretamal.dev. 15. CHANGES This Policy may be updated when the App, providers, data practices, or legal requirements change. Material changes will be communicated through the App, the Microsoft Store listing, or another appropriate method. If a change requires new consent, optional transmissions will remain disabled until that consent is obtained. The current version is available in the Microsoft Store listing and in the App. 16. CONTACT Data controller: R. Retamal Country: Chile Email: hello@rekami.app This Policy describes the App’s current technical behavior and is not a guarantee that every third-party camera, network, operating-system service, or user-selected backup tool follows the same practices.