HelmVision Privacy Policy
HelmVision is an independent Android client for a user-selected, self-hosted Frigate NVR server. It is not affiliated with or endorsed by Frigate, Inc.
Overview
HelmVision is designed to connect directly from the Android device to the Frigate server address configured by the user. The app does not require or operate a developer-hosted user account, cloud relay, or subscription service. HelmVision includes banner advertising provided through Google AdMob.
The developer does not operate a service that receives copies of the user's Frigate credentials, camera video, recordings, events, or diagnostic logs as part of normal app operation.
Information the app handles
Frigate server address
The user enters the URL or network address of the Frigate server they want the app to access. The server address is stored locally on the Android device so the app can reconnect later.
Frigate login credentials
The user may enter a Frigate username and password. These credentials are stored locally on the Android device using the app's Android credential-protection implementation. Optional biometric or device-credential protection can be enabled by the user.
HelmVision does not send Frigate credentials to the developer. Credentials are used to authenticate directly with the Frigate server configured by the user.
Camera and Frigate content
When connected to a Frigate server, the app may display or process content provided by that server, including camera images and video, recordings, review and event information, camera names, system information, and export or download content.
This content is exchanged between the Android device and the user-configured Frigate server as required for app functionality. The developer does not operate a cloud service that receives copies of this content.
Microphone and two-way audio
When the user activates Frigate's two-way-talk feature, HelmVision may request Android microphone permission and allow the configured Frigate WebView origin to capture microphone audio. Microphone access is requested on demand for two-way talk.
Microphone audio is sent to the user-configured Frigate server and camera infrastructure as required for the requested two-way communication. HelmVision does not send microphone audio to the developer.
Diagnostic information
HelmVision can create diagnostic logs for troubleshooting. Diagnostic logging can be controlled from the app's native settings. Logs are stored on the Android device and are not automatically uploaded to the developer.
A user may explicitly choose to export or share a diagnostic log through Android's share interface. In that case, the user chooses the destination. The app attempts to redact credentials and other secrets from diagnostic output, but users should still review diagnostic files before sharing them.
Downloads and exports
Frigate exports or other supported downloads may be saved to the Android device at the user's request. These files originate from the user-configured Frigate server. If the user later shares those files with another application or service, that sharing occurs at the user's direction.
Advertising, consent, and Google Mobile Ads
HelmVision uses the Google Mobile Ads SDK (AdMob) to display banner advertisements. The app also uses Google's User Messaging Platform (UMP) to obtain or manage advertising/privacy choices where required.
According to Google's documentation for the Mobile Ads SDK used by HelmVision, the SDK may automatically collect and share data such as the device IP address, user product interactions, diagnostic information, and device or account identifiers for advertising, analytics, and fraud-prevention purposes. This data is handled by Google under Google's terms and privacy practices and is transmitted using TLS.
HelmVision does not intentionally provide Frigate usernames, passwords, camera video, recordings, server configuration, or diagnostic-log contents to Google Mobile Ads as advertising request parameters.
Advertising identifiers and ad personalization are subject to the device's settings, applicable consent choices, Google Mobile Ads behavior, and applicable law. Users may also have controls provided by Android, Google, or UMP.
Network access and security
HelmVision uses network access to communicate with the Frigate server selected by the user. Depending on the user's configuration, this may be a local-network address, VPN address, private DNS name, or remote HTTPS address.
The app supports HTTPS and relies on Android's trusted system or user-installed certificate authorities as configured for the app. HelmVision does not bypass TLS certificate errors.
The app can also support a user-configured HTTP Frigate address. HTTP traffic is not protected by TLS. The app warns users about this risk, and HTTPS is recommended whenever available.
The app uses Android platform security facilities for local credential protection and optional biometric or device-credential authentication. App content is hidden from Android Recents/Overview snapshots to reduce accidental disclosure of camera imagery.
No security mechanism can guarantee absolute protection. Users are responsible for securing their Frigate server, network access, Android device, credentials, certificates, and exported files.
Android permissions
HelmVision may request or use Android permissions needed for its functionality, including:
- Internet and network access to communicate with the configured Frigate server.
- Local-network access on Android versions that require explicit permission for connections to local or private network devices.
- Microphone access, requested on demand when the user activates Frigate two-way talk.
- Biometric or device-credential APIs when the user enables app lock.
HelmVision does not request permission to install unknown applications in the current Play-distribution architecture.
Android WebView
The Frigate user interface is displayed inside Android System WebView. The WebView loads the interface from the Frigate server configured by the user. Frigate server functionality and content served by the user's Frigate installation are outside the developer-operated infrastructure for HelmVision. HelmVision grants WebView microphone capture only to the configured Frigate origin and only after Android microphone permission is available.
The app may store Frigate session cookies and WebView site data locally on the device to maintain the user's authenticated session. Native settings provide controls to clear the WebView cache, clear the Frigate session, or reset Frigate WebView data.
Data collection and sharing by the developer
HelmVision includes Google AdMob banner advertising. Google Mobile Ads may collect and share data as described in the advertising section above. HelmVision does not sell user data.
The developer does not intentionally collect or receive Frigate login credentials, camera content, recordings, events, server configuration, or diagnostic logs during normal app operation.
Information can leave the device when required to communicate with the user-selected Frigate server or when the user explicitly directs Android to export, share, download, or open content with another application or service. Those destinations are selected or configured by the user and are not operated by the developer unless explicitly stated otherwise.
Data retention and deletion
Server configuration, credentials, session information, app preferences, and diagnostic logs remain on the Android device until they are cleared by the user, removed by an app reset or uninstall, or otherwise deleted by Android according to platform behavior.
The app's native settings include controls to clear saved credentials, clear Frigate WebView cache, session, and data, and clear diagnostic logs.
Frigate server-side retention of recordings, events, snapshots, user accounts, and other server data is controlled by the user's Frigate deployment and is not managed by HelmVision or by the developer.
HelmVision does not create or operate a developer-hosted user account. Any Frigate account used with the app belongs to the user's own Frigate server and must be managed or deleted through that server by the user or its administrator.
Children
HelmVision is a technical client for a self-hosted video-security system and is not designed or marketed specifically for children.
Third-party and user-selected services
HelmVision relies on Android platform components, including Android System WebView, and on Google services used for advertising and consent management, including Google AdMob and UMP. HelmVision also communicates with the Frigate server selected by the user. A user's Frigate server, network provider, VPN provider, certificate authority, external links, or apps selected through Android's sharing interface may have their own privacy practices. The developer does not control those third-party or user-selected services.
Changes to this policy
This policy may be updated when HelmVision functionality, data practices, dependencies, or legal or Google Play requirements change. The effective date at the top of this policy will be updated when material changes are published.
Contact
For privacy questions, support requests, or questions about this policy, contact:
HelmVision
Email: jgasca30@gmail.com