Privacy
Privacy policy
Last updated:
This privacy policy covers two things, because they are two different things: the ViewTile app on your device, and this website, viewtile.com. It is written to meet the App Store, Google Play, GDPR and Turkish KVKK requirements in one place; where a law asks for a specific statement, it is given under its own heading below.
Every sentence here describes what the software actually does. If one stops being true, the sentence changes or the software does.
Who is responsible
The app and this website are provided by the operator named on the legal notice (“ViewTile”, “we”). That page carries the postal address; the address for any privacy request is:
For data protection law, the operator is the controller of the little data described below. No data protection officer is required for an operation of this size, and none is appointed.
The app
The app collects nothing about you
ViewTile has no account, no sign-up and no server of ours behind it. Nothing you do in the app is sent to us or to anyone else on our behalf: not your camera list, not what you watch, not how often you open the app, not the device you run it on. We do not know that you use ViewTile.
The app contains no analytics, no advertising identifier, no crash reporter and no third-party service that reports anything. The video libraries it ships with (listed under About › Third-party notices) run entirely on the device and do not send data anywhere.
What stays on your device
- Your cameras — addresses, names, layouts and settings — are stored on the device, in the app’s own storage.
- Camera passwords are stored in the device’s secure storage: the iOS Keychain, or Android’s encrypted storage. They are never written anywhere else, not shown again after entry, not put into an exported setup file, and removed from any report before it is written.
- Snapshots and clips you take are saved to your photo library and to the app’s storage. The app can add to your photo library; it cannot read it back.
Video and sound
Streams go straight from the camera to your device over your own network. ViewTile does not receive, relay, store or analyse them. What the camera itself does — whether it also talks to its maker’s cloud, whether its stream is encrypted on the wire — is the camera’s design. ViewTile does not change it and cannot vouch for it.
Sending a setup to another screen
When you hand your cameras to a television or another phone, the setup travels directly between the two devices over your local network, encrypted between those two devices with a key agreed for that one hand-over. Nothing is saved on the other screen until somebody there accepts it. Camera passwords are included only when you choose to include them. Nothing passes through the internet or through us.
Permissions the app asks for, and why
- Local network — to find cameras and to reach them. This is the app’s whole job.
- Camera — only to read a pairing code shown on another screen. No photo or video is taken or stored.
- Adding to your photo library — to save the snapshots and clips you take. The app asks for add-only access where the platform offers it and cannot read your library.
- Face ID, Touch ID or the device passcode — only if you turn on the app lock, and only to unlock the app on that device. The biometric check is done by the operating system; the app never sees your face or fingerprint.
You can withdraw any of these in the device’s Settings at any time; the corresponding feature then stops working and nothing else changes.
Diagnostic reports
The report you can copy from a camera’s page is text placed on your clipboard for you to send if you choose to. Passwords are removed from it before it is written. It contains the camera’s addresses and what the camera answered; send it only to people you trust with that.
Payment
There is no purchase in the app today. If a paid version is offered, it will be a one-time purchase through the App Store or Google Play. Those stores handle the payment under their own privacy policies; we never see your payment details, and there is no account on our side for a purchase to be attached to.
Children
ViewTile is a tool for viewing cameras you own or are responsible for. It is not directed at children, and it collects nothing from anyone, of any age.
Deleting your data
Because everything is on your device, deleting is in your hands:
- Removing a camera removes its saved password with it.
- Deleting the app removes the camera list and the settings. On iPhone and iPad, the system can keep secure-storage (Keychain) entries after an app is deleted; if you want the passwords gone for certain, remove your cameras before deleting the app. On Android, the app’s secure storage goes with the app.
- Snapshots and clips you saved to your photo library stay in your library until you delete them there.
- A setup file you exported, or a report you sent, stays wherever you put it.
There is nothing for us to delete, because we hold nothing of yours from the app.
This website
The website is static pages served by Cloudflare. It sets no cookies, runs no analytics, shows no advertising and loads nothing from third parties: the fonts, the images and the scripts come from this site itself.
Hosting and request logs
Cloudflare, Inc. (101 Townsend Street, San Francisco, CA 94107, USA) serves the pages from its network. To deliver a page and to protect the site from abuse, Cloudflare processes the technical data of each request: your IP address, the address of the page requested, the time, and the browser’s identification string. Cloudflare keeps these request logs for as long as its own security and operations need them, under its own retention rules, which we do not extend; we do not receive, keep or look at them, and we have turned on no Cloudflare analytics.
The legal basis is our legitimate interest in serving the site reliably and securely (GDPR Article 6(1)(f)). Cloudflare processes this data as our processor under its Data Processing Addendum, and transfers outside the EEA and the UK are covered by the EU–US Data Privacy Framework and Standard Contractual Clauses. Cloudflare’s own privacy policy is at cloudflare.com/privacypolicy.
Who receives anything at all
Three recipients, and no others: Cloudflare (hosting), the mail provider that carries our email, and Apple or Google when you ask for a test build. Each is outside the EEA at least in part and each covers the transfer under its own EU–US Data Privacy Framework certification or Standard Contractual Clauses.
If you write to us, we receive what you send — your address, your name if you give it, and the message — and we use it only to answer you. We keep the correspondence for as long as it takes to deal with it and for up to twelve months afterwards, so that a follow-up can refer to it; then it is deleted. It is not used for anything else and not shared with anyone. The legal basis is our legitimate interest in answering the people who write to us (GDPR Article 6(1)(f)), or the steps you ask us to take before a contract (Article 6(1)(b)) where that applies. Email travels through the mail provider of each side; ours is chosen for the confidentiality of the mailbox.
Test builds
If you ask for a test build, the platform that delivers it (Apple’s TestFlight or Google Play’s testing tracks) will need the email address of your store account and will show us that you installed the build. Those platforms process this under their own policies. We use your address only to send the build and to write to you about it — the legal basis is the steps you asked us to take (GDPR Article 6(1)(b)) — and we keep you on the testing list until the test period ends or you ask to be removed, whichever is sooner, and for no more than twelve months after the last build you received.
Your rights
Where data protection law applies to you — the GDPR in the European Economic Area, the UK GDPR in the United Kingdom, the KVKK in Türkiye, and similar laws elsewhere — you have the right to:
- ask whether we hold data about you, and to receive a copy of it;
- have it corrected or completed;
- have it erased;
- have its use restricted, or object to it;
- receive it in a portable form where it was given under a contract or consent;
- withdraw any consent you gave, without affecting what was done before;
- complain to a supervisory authority. In the EEA that is the authority of the country you live in; in the UK, the Information Commissioner’s Office; in Türkiye, the Kişisel Verileri Koruma Kurumu.
In practice, the only data we could hold about you is email correspondence, so most requests come down to “please delete our exchange”. Write to the address above; we answer within a month, and in Türkiye within thirty days as the KVKK requires. You are never asked to pay for a request.
KVKK (Türkiye) — aydınlatma
For people in Türkiye, this section is the notice required by Article 10 of Law No. 6698. Veri sorumlusu: the operator named on the legal notice. İşlenen veri ve amaç: only the email you send us, to answer it; and the request logs Cloudflare keeps to serve and protect the website. Hukuki sebep: Article 5(2)(f) of the Law — processing necessary for the legitimate interests of the controller, not overriding your fundamental rights — and Article 5(2)(c) where you ask us to take a step before a contract. Aktarım: the website is served from Cloudflare’s network, which includes servers outside Türkiye; email passes through the mail providers of each side; a test build is delivered through Apple or Google, which see your store address. Nothing else is transferred to anyone. Toplama yöntemi: electronically, through the email you send and the web request your browser makes. Haklarınız: those listed in Article 11 of the Law, including access, correction, erasure and objection. You can use them by writing to the address above, in the manner set out in the Veri Sorumlusuna Başvuru Usul ve Esasları Hakkında Tebliğ; requests are answered free of charge within thirty days.
Security
There is little to secure on our side, because there is little we hold. On your side, the app keeps camera passwords in the operating system’s secure storage, offers an app lock, and removes passwords from anything it exports or copies. The website is served over HTTPS only, with security headers that forbid embedding it in other sites and loading anything from elsewhere.
Changes
If this policy changes, the date at the top changes with it, and what changed is said in the release notes of the version it applies to. A copy of any earlier version can be had by writing to the address below.
Contact
ViewTile · info at viewtile.com · the postal address is on the legal notice.

