📹
Privacy Policy
MongleCam · Effective September 29, 2026
MongleCam (the "App") is a home camera service that connects two spare
phones — one as the camera (sender) and one as the monitor (viewer) — to
keep an eye on your space. The App's video and audio are transmitted
directly between the two devices (P2P) and are never stored on or viewed
by the operator's servers. The App is used without any account
registration.
1. Information We Collect and Process
The App processes the following information in order to provide the video
connection and notifications.
- Video and audio data: the camera video and microphone audio of the
sender device. It is streamed in real time to the viewer device; the
operator does not store or view it. Recordings and snapshots (paid)
are stored only on your devices (see "Recorded video" below).
- Device identification and authentication data: an anonymous device key
generated by the App, authentication tokens, and a push notification
token (FCM). These are not linked to personally identifying
information such as your name or phone number.
- Device status data: the device name you set, battery level, online
status, and last response time.
- Connection signaling data: session information and network candidate
addresses (such as IP addresses) used to connect the two devices. It
is consumed or expires once the connection is established.
- Detection events: the time and type (sound or motion) of a detection
made by the sender device on its own, and a sound level value. The
sound (audio) itself is not transmitted or stored.
- Detection preview image: some devices (Android cameras) create one
small still image (about 160 pixels wide) at the moment of a detection
and store it on the server together with the event, so the alert can
show it. Only devices paired with that camera can see it, and it is
deleted automatically after 7 days. Video and audio streams are not
included.
- Recorded video (paid): detection recordings are stored on the camera
device. When you play or download one on the viewer, it is sent
directly between the two devices (P2P) and stored on the viewer
device. The server stores only a list of recorded segments (such as
start time and length), not the video.
- Purchase information: subscription receipts and status (issued by the
store).
- Advertising identifier (free users): to display ads, the device's
Advertising ID is collected and sent to the ad provider (Google). It
is not linked to personally identifying information such as your name
or phone number, and no ads are shown to Premium subscribers.
- Usage records: to improve service quality, the App keeps records of
how it is used — viewing start and end times and duration, time taken
to connect, time spent on the relay server, connection failure causes
and end reasons, how often each feature is used (light, recording,
snapshots, etc.), visits to the subscription screen and purchase
steps, app and OS version, device model, language setting, install
time, last active time, role (camera or viewer), and free or Premium
status. These records are linked to the anonymous device key created
by the App and are shown to the operator under a further pseudonym.
They do not include personally identifying information such as your
name or phone number, video or audio, device names, or IP addresses.
- Security records: to block attempts to guess pairing codes, the App
records failed code entries per device, together with a one-way hash
of the connecting IP address, for a short time. The original IP
address is not stored.
The App does not collect information beyond the items above, such as
contacts, photo library, call logs, or location.
2. Purpose of Use
Video and audio data
Real-time video and audio between the sender and viewer devices, and two-way talk
Device identification and authentication data
Pairing and connection authorization between the two devices, and delivery of sound alerts
Device status data
Showing camera online status and battery, and determining connection availability
Connection signaling data
Establishing the video connection (WebRTC) between the two devices
Detection events and preview images
Sending an alert to the viewer device when sound or motion is detected, showing the alert image, and showing the history
Recording list
Letting the viewer find and play recorded segments
Purchase information
Verifying the paid subscription ("Premium") status and providing features
Advertising identifier
Displaying and measuring ads for free users and preventing fraudulent clicks
Usage records
Understanding connection quality and failure causes, improving features, managing app version compatibility, and service statistics
Security records
Preventing pairing code guessing (temporarily limiting code entry on a device after repeated failures)
3. How Video and Audio Are Handled (Important)
Video and audio are transmitted directly between the sender device and the
viewer device (WebRTC P2P). When the two devices are on the same network
(for example, the same Wi-Fi at home), no server is involved at all.
When the two devices are on different networks (remote viewing) and a
direct connection is difficult, the video may be relayed through a relay
server (TURN). In this case the video is transmitted with end-to-end
encryption (DTLS-SRTP), so even the relay server cannot know its
contents, and the operator does not store or view the video or audio.
4. Third-Party Services and Processing
The App does not sell your personal information to third parties. It uses
the following external services to operate.
- Google Firebase — connection signaling and device status storage
(Realtime Database), anonymous device authentication (Authentication),
issuance of pairing and connection tokens (Cloud Functions), storage
of detection events, preview images and the recording list (Realtime
Database), detection push notifications (Cloud Messaging), and app
error diagnostics (Crashlytics), and storage of usage and security
records (Realtime Database).
- Cloudflare Realtime (TURN) — relays encrypted video during remote
viewing. Short-lived credentials are issued per session, and the
relayed content is not stored. To measure relay usage, a pseudonymous
identifier derived one-way from the device key is also sent.
- Google Play / App Store billing — payment and receipt verification for
paid subscriptions. The App does not collect payment method
information such as card numbers.
- Google AdMob (advertising) — used to serve ads to free users. In this
process the device's Advertising ID is collected and sent to Google,
and is processed and shared for ad delivery, measurement, and fraud
prevention. For details, see the
Google Advertising Policy.
You can reset or opt out of ad personalization in your device's
[Settings → Google → Ads], and ads and Advertising ID collection stop
when you subscribe to Premium.
5. Retention and Deletion
- Connection signaling data is cleaned up once the connection ends, and
old data is deleted automatically.
- Device key, pairing, and device status data are deleted when you unpair
or delete the App.
- Detection events and preview images are deleted from the server
automatically after 7 days.
- The recording list is deleted from the server automatically after the
retention period set on the camera (30 days by default).
- Recorded video and snapshots are stored only on the camera and viewer
devices, and are removed when the retention period ends, when you
delete them in the App, or when you delete the App.
- Usage records (viewing, connection, feature use, purchase steps) are
deleted from the server automatically after 90 days. App and device
information is kept as a single record per device, updated to the
latest values; you can ask for its deletion using the contact
below.
- Security records are deleted automatically within one day after the
restriction period (10 minutes) ends.
6. Permissions
- Camera (required when sending): used to capture and transmit video.
- Microphone (required when sending / for audio): used to transmit audio
and to detect sound. Sound detection is processed only within the
device.
- Notifications (optional): used to display sound and motion detection alerts.
- Display over other apps (optional): used to reliably start the capture
service when waking the camera remotely. The App works even if
denied.
- Battery optimization exemption (optional): used to keep long-running
capture from stopping midway.
You can change each permission at any time in your device's settings, and
you can still use the core features even if you deny an optional
permission.
7. Children's Privacy
The App may be used for purposes such as monitoring infants at home, but
it runs on the guardian's device and does not collect personal
information directly from children. Responsibility for those being filmed
lies with the user who installs and operates the device.
8. Your Rights
You can unpair within the App, delete stored recordings, or change
permissions, and you can stop all processing of your information by
deleting the App.
9. Privacy Officer and Contact
For inquiries regarding the processing of personal information, please
contact us below.
10. Users in the European Economic Area and the United Kingdom
If you are in the EEA or the UK, the following also applies.
- Controller: Jongbeom Lee (RimiTech), who can be contacted at the email
address in section 9.
- Legal bases: we process the data in section 1 to provide the service
you request (performance of a contract); crash diagnostics and abuse
prevention are based on our legitimate interest in keeping the App
working and secure; personalized advertising is based on your consent,
which you can give or withdraw in the consent dialog shown in the App.
- International transfers: our service providers (Google and Cloudflare)
may process data outside your country, including in the Republic of
Korea and Singapore. These providers use safeguards such as the
European Commission's Standard Contractual Clauses.
- Your rights: you can request access to, correction of, deletion of, or
a copy of your data, object to or restrict its processing, and
withdraw consent at any time. Because the App has no accounts, most
data can be deleted directly by unpairing or deleting the App; for
anything else, contact us. You also have the right to lodge a
complaint with your local data protection authority.
11. Changes to This Policy
This Privacy Policy may be amended in line with laws or changes to the
service, and any changes will be announced on this page.