Privacy

Privacy policy

Last updated August 7, 2026

This product watches doorways, so it is reasonable to want to know exactly what it keeps. The short version: video never leaves the building, no face is ever recognised, there are no trackers on this site, and the things we do keep are listed below without euphemism.

If you only read two sections, read the inventory, which names every record that holds something about a person, and who we share it with, which is a complete list rather than an example of one.

Contents and other documents

1.Who this covers

This policy covers five groups of people, who are in very different positions:

Visitors to this website
People reading these pages. We hold almost nothing about you, and this site sets no cookie until you sign in.
Account holders
People who sign in to the console: administrators, responders, reviewers, viewers.
Alert recipients
People on a customer's roster who receive alerts. You may have no account and may never have visited this site.
People captured in a detection frame
Anyone who passes a customer's camera. You have no relationship with us, and the camera belongs to the customer, not to us.
Home customers
Individuals rather than organizations, whose household is the site.

For business, school, and other organizational customers, the customer decides what cameras exist and who is on the roster. They are the controller of that data and we process it for them; see the data processing agreement. For a home customer there is no such split, and this policy is the whole answer.

2.What we collect

Account data. Name, email address, an optional phone number, a password hash, and, if you enable it, a two-factor secret and backup codes. Sessions record IP address and browser user agent.

Roster data. For each person a customer designates to receive alerts: name, email address, phone number, role, and which channels they should be reached on. Many roster entries belong to people who have no account.

Detection data. A cropped still frame from the moment of a detection, plus the camera name and location label, the timestamp, the confidence band, the detected class, and the bounding geometry. The frame may contain an image of a person.

Site data. Site name, street address, coordinates, timezone, an uploaded floorplan where you provide one, camera inventory, arming state, and your response configuration.

Operational records. Delivery records for each notification, acknowledgment records, drill reports naming the staff who acknowledged, and an append-only audit log recording who did what.

Billing identifiers. A payment-processor customer and subscription identifier, and invoice records. Payment card details go directly to the processor and never reach our servers.

The next section lists each of these against the record that holds it.

3.The inventory, record by record

Everything this system stores about a person, and where. This list is written from the database schema rather than from a description of it.

Users
Name, email address, optional phone number, password hash, and a two-factor secret and backup codes where enabled. The phone number exists so an alert can fall back to SMS.
Sessions
IP address, browser user agent, a session token, and an expiry. Kept so you can be signed out everywhere and so an unexpected session can be spotted.
Roster recipients
Name, phone number, email address, role, notification tier, and channels. Most of these people never sign in, and their entry exists only so an alert can reach them.
Notification deliveries
The recipient's name, the destination phone number or email address, the full text of the message that was sent, the provider's message id, and whether it succeeded. This is how an incident timeline can show what was actually sent and to whom.
Sites
Street address, coordinates, timezone, arming state, response configuration, and any floorplan uploaded. The address and coordinates are what an emergency dispatch request carries.
Cameras and discovered devices
Camera name, location label, make, position on a floorplan, connection details, and, where you ran a network scan, the host, port, MAC address, manufacturer, and model of devices found on your network.
Camera credentials
A camera or recorder username in the clear, and its password sealed with AES-256-GCM. The sealed value is deleted once your appliance confirms it has received it, leaving only a sha256 fingerprint. After that point we cannot produce the password again.
Detections and media
The cropped frame and the wider snapshot, held in our database, with the detection's time, geometry, weapon class, confidence band, model version, and whether it was a drill. A frame may be a photograph of a person.
Alerts and their timelines
The band, the status, who reviewed it, what they decided, any free-text dismissal note, who cancelled it, and every event in between with the name of the person or system that caused it.
Acknowledgments
The typed name of the person acknowledging, their IP address, the version of the document they were shown, and the time. This is what makes an acknowledgment evidence rather than a checkbox.
Audit log
Who acted, what they did, what they did it to, and when, hash-chained so the sequence can be shown to be intact.
Invitations and share links
The invited email address, the inviter, an expiry, and a sha256 of the token rather than the token itself. A share link also records the watermark shown on it and every view.
Contact form submissions
Your name, email address, the topic you chose, an optional organization and phone number, the message, and which page you sent it from. No IP address is recorded with it, and rate limiting is done in memory rather than by storing one.

4.What we never collect

No biometrics. No face recognition, no gait analysis, no voiceprints, no enrolment of individuals, no matching a person in one incident against a person in another. Within a single incident the system associates a person across frames so a trail can be reconstructed; it computes no identity while doing so, and there is no column anywhere in which an identity could be stored.

No continuous video. Streams are analysed on the appliance inside the customer's building. We receive cropped frames attached to detections and nothing else from the stream. There is no cloud recording and no inbound connection from us to a customer's cameras or network.

No advertising or behavioural tracking. This site and the console contain no analytics service, no tag manager, no advertising pixel, and no third-party script of any kind. We do not sell personal data, and we do not share it for cross-context behavioural advertising. There is nothing here to opt out of.

No audio. The system analyses images. It does not receive, record, or process sound.

5.How we use it

To detect and deliver alerts; to run the response ladder the customer configured; to request emergency dispatch when the customer has enabled it and the incident warrants it; to produce drill reports and incident exports; to bill; to secure accounts; and to answer support requests.

We compute aggregate measured false-alert rates by segment. Those figures are averages across deployments. They contain no personal data and do not identify a customer or a site.

We do not use detection frames, rosters, or incident data to train models for other customers without a separate written agreement. That consent is off by default, is recorded against a typed name, and is enforced in the query that assembles a training set rather than by a filter applied afterwards.

We do not make automated decisions about a person that have a legal or similarly significant effect on them. An alert is a statement that a shape in a frame looked like a firearm. What happens next is decided by the people the customer designated.

6.Who we share it with

We use a small number of service providers. This list is complete, and each entry names what that provider actually receives.

Noonlight: emergency dispatch
When a customer escalates to dispatch, Noonlight receives the site address, the incident details, the name and phone number of the designated callback contact, and a link to the detection frame that is valid for six hours. Drills are never sent.
Twilio SendGrid: email delivery
Recipient name and email address, the subject and body of the alert, and a link to the detection frame that is valid for twenty-four hours. Because the frame is linked rather than attached, it is fetched by the recipient's mail client and may be fetched by their mail provider's scanning systems.
Twilio: text messages
The recipient's phone number and the text of the message, which names the site, the camera and its location, and the band. Used where a roster entry is reached by SMS, including as the fallback when a push notification is unavailable.
Anthropic: second look at a frame
Where the second look is enabled, the cropped image behind a detection is sent for a second opinion on whether it shows a firearm. The image is the whole payload: no name, no roster, no address, and no site identity travels with it. The verdict can raise a band and never lowers one.
OpenWeather: conditions at a site
A site's coordinates, or its postal code when coordinates are being established, so that an incident can record what the weather was. No personal data and no incident detail is sent.
Stripe: payments
Billing contact and payment details, which the customer provides to Stripe directly. We receive identifiers and subscription state, never card numbers.
Hosting and managed database
The application and database run on managed infrastructure in the United States. Providers hold data at rest on our behalf and do not access it.

Beyond these, we share personal data only where a customer directs us to, such as establishing access for a law-enforcement agency or a share link the customer generates, and where we are legally required to. We will tell the affected customer about a legal demand unless we are prohibited from doing so. If we are ever acquired, personal data may transfer with the business, subject to this policy.

7.The second look at a frame

When a detection is raised, the cropped image can be sent to a model provider for a second opinion on whether it shows a firearm. It is worth being precise about this, because it is the one path on which a photograph that may contain a person leaves our systems for a third party.

What is sent is the crop and the name of the weapon class the first stage claimed. What is not sent: the site, its address, the camera name, the roster, the customer's identity, or any previous frame. The request carries nothing that ties the image to your organization, and the provider returns one verdict and a sentence describing what it saw.

The verdict can only raise. A verdict of firearm can lift a band or promote a detection that sat below the alerting threshold. A verdict of not a firearm, or an uncertain one, is written to the incident timeline and changes nothing else. A second model's doubt is not grounds for standing an alert down.

8.If you appear in a detection frame

The camera that captured you belongs to the customer, not to us. They decided where it points and what notice to give; questions about that are properly directed to them. What we can tell you is what happens to the frame.

It is shown to the recipients the customer designated. It may be shown to a monitoring agent if the customer uses reviewed dispatch, to an emergency dispatch provider, to a law-enforcement agency the customer has linked, to anyone holding a share link the customer generated, and to the second-look provider described above. Links to a frame are individually signed and expire: one hour by default, six hours where the link travels with a dispatch request, twenty-four hours where it travels in an email. A link grants access to that one image and to nothing else.

You are not identified. No face is matched, no name is attached, and no record is built that connects you to any other incident.

9.Schools and students

Where a school uses this service, we act as a school official with a legitimate educational interest under FERPA, performing a function the school would otherwise perform itself, and under the school's direct control. We do not receive student records, grades, schedules, or rosters of students. The roster we hold is of staff who receive alerts.

A detection frame from a school camera may contain an image of a student. It is not associated with a name, is not matched against anyone, and is not used for discipline analytics or any purpose other than the incident it belongs to.

The full commitments a district asks for, including the FERPA criteria we operate under, the redisclosure limits, and what we do not do with student information, are on the student privacy page. School customers also accept the data processing agreement as part of setup.

10.Home customers

For a household, the site is your home and the roster is the people you choose to notify. Whether you are out, in, or disarmed is recorded with each detection, because arming state determines whether a detection is an event at all. Home dispatch always goes through a monitoring agent who looks at the camera first; that agent sees the frame and the site address. Household members are not enrolled or recognised, and no member of your household is distinguished from anyone else by this system.

11.Cookies

Two cookies, both strictly functional, both first-party:

Session cookie
Set when you sign in, so you stay signed in. Cleared when you sign out.
Site selection
Remembers which of your sites you were last looking at, so the console opens where you left it.

There are no analytics, advertising, or third-party cookies, so there is no consent banner and nothing to decline. If you are reading this page without signing in, we have set nothing. Because we do no cross-site tracking, there is nothing for a browser do-not-track or global privacy control signal to switch off, and we honour it by having nothing to honour.

12.How long we keep it

We apply no automatic retention schedule by default. Detections, frames, alerts, and delivery records are kept for the life of the account unless a customer sets a period. If you want data deleted, ask and we will delete it.

A customer's administrator may set a retention period for detection frames. It is expressed in days, between seven and 3650, and covers snapshots and crops only. Frames older than the period are removed on a recurring sweep that runs hourly, and the detection records are retained so an incident stays reconstructible. Nothing in the service sets or changes that period on its own.

Four categories of frame are kept regardless of the period, and each is enforced in the deletion query itself rather than by a filter applied afterwards: frames from an incident that escalated or reached an emergency provider, frames under an alert that is still open, frames from an incident whose evidence package has been exported, and frames in a consented training set. Floorplans and generated exports are never part of the sweep. Each purge writes an audit entry recording the period, the cutoff, and how many frames were removed.

Account records are kept while the account is open. Billing records are kept as long as tax and accounting rules require.

The audit log is different. It is append-only and hash-chained by design, so that an incident timeline exported into a police report can be shown to be intact. Entries record who acted and are retained for the life of the account. We cannot selectively erase an entry without destroying the property that makes the log worth having, and we will not. Deleting an account removes its log in whole.

13.Security

The appliance connects outbound only; there is no inbound path from us into a customer's network. Connections are encrypted in transit. Passwords are hashed, and appliance device tokens, invitation tokens, and share tokens are stored as hashes rather than as the value that was issued.

A camera or recorder password is sealed with AES-256-GCM on entry, delivered to your appliance once, and then erased, leaving a fingerprint we can compare but cannot reverse. Links to a detection frame are signed with a secret, bound to a single object, and expire in hours. Access within an organization is role-based and enforced on the server for every request rather than in the browser. Two-factor authentication is available and is required before configuration that permits automatic action without human confirmation.

No system is perfectly secure. If you believe you have found a vulnerability, write to security@optiarms.com. We will not pursue good-faith security research.

14.Your rights

Depending on where you live you may have the right to access, correct, delete, or receive a copy of your personal data, and to object to certain processing. Write to privacy@optiarms.com and we will respond within the time the applicable law allows. We do not charge for this and will not treat you differently for asking. We may need to verify who you are before acting, and we will ask for no more information than that requires.

Two honest limits. If your data sits inside an organization's account, a roster entry or a frame from their camera, we will refer you to that organization, because it is their data and their decision. And the audit-log carve-out described in how long we keep it applies: entries recording who acted cannot be selectively removed.

15.State privacy rights

Residents of several states have specific rights over personal information. Where a state law gives you one of these, we will honour it, whichever state you are in:

Know and access
What categories of personal information we hold about you, where it came from, why we hold it, and who it has been disclosed to. The inventory above is written to answer most of this before you ask.
Correct
Have inaccurate personal information corrected.
Delete
Have personal information deleted, subject to the audit-log carve-out and to any legal hold or retention rule we are bound by.
Portability
Receive a copy in a portable form.
Opt out of sale, sharing, and targeted advertising
There is nothing to opt out of. We do not sell personal information, do not share it for cross-context behavioural advertising, and run no advertising or profiling of any kind.
No retaliation
We will not deny service, change a price, or reduce quality because you exercised a right.

An authorized agent may make a request on your behalf with proof that you authorized them. If we refuse a request we will say why, and you may appeal by replying to our response; where your state gives you a route to its attorney general, that route stays open to you. Where the data belongs to an organization's account, we act on that organization's instruction and will pass your request to them.

16.Children

The service is not directed to children, and no child creates an account. Accounts are for adults acting for an organization or a household, and holding one requires you to be at least 18.

A camera at a school will see students, including students under 13. Where that happens we are processing on the school's behalf and under its direction, as its service provider, and the school gives any notice or consent its own obligations require. We do not knowingly collect personal information directly from a child, we build no profile of any student, and we use nothing from a school camera for advertising or for any purpose beyond the incident it belongs to. The detail is on the student privacy page.

A parent or guardian who wants to know what is held about their child should contact the school, which controls the data and can direct us. If you believe a child has given us information directly, write to privacy@optiarms.com and we will delete it.

17.Changes to this policy

We will change the "last updated" date above when this policy changes and will notify account administrators of material changes before they take effect. A change that would put personal data to a new purpose is not applied to data already collected without asking first.

18.Contact

Privacy questions, requests, and appeals go to privacy@optiarms.com. Security reports go to security@optiarms.com. If you need a postal address for a formal request, ask and we will give you the one that matches your requirement.