KerbCam

Privacy policy

Your work stays yours.

This policy explains what KerbCam handles, why we need it, who helps us provide the service and how you stay in control.

Effective 18 August 2026. Last updated 18 August 2026.

No advertising trackingWe do not sell personal data or use advertising identifiers.
Private cloud libraryYour media is private unless you choose to share or export it.
Real account deletionDelete your account in the app or on the web to remove active cloud data.

Who we are

Quilliam AI Ltd, a private limited company registered in England and Wales under company number 17151006, trading as KerbCam, is the controller of the personal data described in this policy. KerbCam provides an iPhone app and website for organising, storing and sharing work photos and videos.

ICO registration reference: ZC134964.

You can contact us at hello@kerbcam.com. This policy applies to the KerbCam app, the service at kerbcam.com and support conversations with us.

Information we handle

Account and sign-in
Your email address, a generated account ID, account creation date, subscription status and security records for one-time sign-in links and signed-in devices. Sign-in links work once and expire after 15 minutes. Server-side session and sign-in tokens are stored only as cryptographic hashes.
Work media
The photos, videos and thumbnails you create with KerbCam. Video files include any sound recorded with them. Media can show people, homes, gardens, addresses or anything else in the camera frame, so only capture and share content you are allowed to use.
Capture metadata
Capture date and time, time zone, file type and size, image dimensions, video duration, file integrity checks and, when you allow it, precise latitude and longitude, location accuracy, location time and optional altitude.
Job organisation
Names and approximate boundaries of work sites, before-and-after pairings, job groupings, manual photo categories and display rotation choices. A work-site name can be one you enter or a street address KerbCam derives from its coordinates using Apple's reverse-geocoding service. The resulting site name or address, centre point and radius are retained with your account.
Billing
A Stripe customer ID and your subscription state. Full card numbers and security codes are entered directly on Stripe's website and are not stored by KerbCam. Stripe processes billing contact, address, tax, payment-method and invoice information and can make limited billing records available to us for support, accounting, fraud prevention and legal obligations.
Website account and support
The Start free and Sign in forms send your email address to KerbCam so we can deliver a one-time link. After web sign-in, an essential, secure and HTTP-only cookie holds the session credential. Page scripts cannot read it. If you email support, we receive the information and attachments you choose to include.
Service operations
Random request identifiers, product interactions needed to perform an action, response status and limited error or invocation details. Our hosting provider also processes standard network information, such as IP address and browser or device request data, to deliver and protect the service.

Website analytics and the free before-and-after tool

Images selected in the free before-and-after tool are processed entirely in your browser and are not uploaded to KerbCam.

On public marketing and information pages, Google Analytics 4 is optional and stays off until you choose Accept all. If you accept, Google Analytics uses first-party identifiers and cookies such as _ga to measure page views and limited interactions: Start free selections, successful email-link requests, sign-up or login, checkout starts, confirmed trials, cancelled checkouts, use of the free before-and-after tool, downloads, App Store selections and 90% scroll depth. We also receive browser, device, referrer and approximate-location information. Automatic form-interaction, site-search and video tracking are disabled. Google Signals, advertising storage and ad personalisation are also disabled.

Sign-in and billing pages do not load analytics before a successful action. If this browser already stores your analytics consent, KerbCam may send a limited milestone after sign-in succeeds, checkout begins, a trial is confirmed or you return from a cancelled checkout. Those events do not include your email address, account identifier, authentication token or payment details. Analytics does not run on the account page.

Your analytics choice is stored in your browser's local storage. You can change it at any time from this policy; withdrawing consent stops future analytics collection and removes KerbCam's Google Analytics cookies from that browser. The web account's separate, strictly necessary HTTP-only session cookie remains available so you can stay signed in and manage billing. It expires after up to 90 days and is cleared when you sign out or delete the account.

How and why we use information

To provide the service

We use account details, media, metadata and job organisation to sign you in, upload and retrieve your library, organise visits by time and place, create comparisons, export media and sync your choices. This processing is necessary to provide the KerbCam service you request.

To operate and secure KerbCam

We use limited request and error information to keep uploads reliable, investigate problems, prevent unauthorised access and protect customer libraries. We do this for our legitimate interests in running a secure, dependable service, balanced against your rights.

To understand the public website, with your consent

If you accept optional analytics, we use aggregated Google Analytics reports to understand which public pages are useful and improve the marketing website. Our legal basis for this measurement is your consent. Declining analytics does not affect the site or KerbCam service.

For billing and legal obligations

We use account and subscription information to start or manage a subscription, handle payment events, answer billing questions and meet tax, accounting or legal requirements. This is necessary for our contract with you and, where applicable, to comply with law.

We do not sell your personal data, use it for targeted advertising or track you across other companies' apps and websites. We do not make decisions about you using automated profiling.

Camera, location, microphone and Photos

iOS asks for camera access so KerbCam can take work photos and videos. The microphone is used only when you record a video with sound.

Location is requested while you use KerbCam. When you capture media, the app attaches a recent precise location only if an accurate fix is available. This lets KerbCam organise visits and named job sites. If you deny location access or a suitable fix is unavailable, the media is stored with its location marked unavailable. KerbCam does not request background location access.

If you choose Save to Photos from the share sheet, iOS asks for add-only Photos access and KerbCam adds the selected export. KerbCam does not read or import your existing Apple Photos library, and it does not add captures there automatically.

You can change camera, precise location, microphone and Photos permissions in iOS Settings. Turning a permission off affects future captures or exports and does not remove metadata already stored. You can delete individual media or delete your account if you want existing cloud data removed.

Service providers and sharing

We use a small number of providers to run KerbCam:

  • Cloudflare hosts the website and API and provides the private live object storage and database used for media and metadata.
  • Backblaze provides private EU object storage for the restricted disaster-recovery copy of the database and media.
  • GitHub runs the scheduled backup on an ephemeral hosted runner. The runner temporarily processes the encrypted-in-transit backup while verifying and publishing it; KerbCam does not retain a GitHub Actions artifact containing customer media.
  • Resend receives your email address and one-time link so it can deliver a sign-in email.
  • Apple provides iOS camera and location services, including reverse-geocoding a work-site coordinate into a suggested street-address label.
  • Stripe handles web checkout, payment methods, invoices and subscription management.
  • Google provides Google Analytics 4 on public website pages only after you consent. Google Signals, advertising features and automatic form-interaction tracking are disabled. See Google's Privacy Policy for information about its processing.
  • Our email provider processes messages you send to support.

These providers process data only for the services they supply and under their own security and data protection commitments. Core KerbCam media and metadata storage is configured for Cloudflare's EU jurisdiction, and the independent backup bucket is configured in Backblaze's EU region. Some providers, including the scheduled runner, operate internationally. Where personal data is transferred outside the UK, appropriate legal safeguards are used.

Sharing you choose

When you use the iOS share sheet, export a file or send media to a customer, you choose the recipient and destination. Once another person or app receives that copy, their handling of it is outside KerbCam's control.

Other disclosures

We may disclose information if required by law, to protect someone's rights or safety, or as part of a business reorganisation. We would limit any disclosure to what is reasonably necessary.

Retention and deletion

  • Work media and its metadata remain in your private library until you delete them or delete your account. Ending a subscription does not delete your library.
  • An individual photo or video you delete stays in Recently Deleted for 30 days so you can restore it. It is then permanently removed by a scheduled purge.
  • Deleting your account from the app permanently removes its media, thumbnails, job organisation records, sessions and active account record without the 30-day Recently Deleted period. You can also delete the account at kerbcam.com/account.
  • One-time sign-in links expire after 15 minutes. Signed-in sessions expire after 90 days of inactivity and can extend while used. Expired authentication records are cleared by a scheduled task.
  • A one-way hash of the request's source IP is used for a 15-minute sign-in-link rate-limit window. A cleanup runs every 15 minutes and removes expired limiter rows, so a hash remains for no more than about 30 minutes; raw IP addresses are not stored in that table.
  • Cloudflare operational logs are kept for short-term operational needs according to the provider and account settings. Cloudflare's current service limits cap that retention at 7 days. Support correspondence is kept only as long as needed to answer the request, resolve related issues and meet legal obligations.
  • The app keeps pending uploads and cached copies on your iPhone. Local original retention follows the Storage choice in the app. Account deletion clears KerbCam's local queue and cache on that device.
  • Stripe may retain transaction and billing records under its own legal obligations. KerbCam may retain records that law requires even after an account is closed.
  • The Google Analytics property is configured to retain event-level and user-level analytics data for 14 months. Your browser keeps the analytics choice until you change it or clear site storage.
  • Restricted operational backups are isolated from the live service and are not available to customers. Database exports currently retain 14 daily copies and then one copy per week for 12 weeks. When media is no longer present in the current database catalogue, a fully verified backup run removes it from the current mirror. Local quarantine and the independent provider's hidden prior version retain that recovery copy for 30 days before deletion. Rotated database versions may likewise remain hidden for up to 30 days. Every publication first rechecks the catalogue, file count, size and cryptographic digest; unexpected count drops stop rather than propagate. Deletion pauses rather than risking data loss if a backup or integrity check fails, so an operational incident can extend the period until verification is restored. If a recovery restores data already deleted, it will be deleted again.

Delete your account

In KerbCam, open Library, tap Library options, choose Account, then tap Delete Account. Type DELETE to confirm. This cannot be undone.

You can use the same confirmation flow on the web account page.

If you cannot access the app, email hello@kerbcam.com from the address on your account. We will need to verify the request before acting.

How we protect your data

KerbCam uses encrypted HTTPS connections, private cloud storage, account-scoped database access and short-lived one-time links. Session credentials are kept in the iPhone Keychain, and only cryptographic hashes of session and sign-in tokens are stored on the server.

The app confirms that an uploaded original matches its integrity check before removing the staged local upload. No service can guarantee absolute security, so please contact us promptly if you think your account or a sign-in link has been compromised.

Your data protection rights

Depending on the circumstances, UK data protection law may give you the right to ask for access to your personal data, correction, deletion, restriction, an objection to some uses and a portable copy. Where we rely on consent, you may withdraw it without affecting earlier lawful processing. Some rights have legal limits or exceptions.

Email hello@kerbcam.com to make a request. We may ask for information needed to confirm your identity. You can also complain to the Information Commissioner's Office if you remain concerned.

Contact and policy changes

Questions, requests and security concerns can be sent to hello@kerbcam.com.

Subscription cancellation and refund information is available in the Cancellation & Refund Policy.

We may update this policy as KerbCam changes or legal requirements develop. Material changes will be explained in the app or on this page, and the updated date above will change.