Camwarden
FeaturesHow It WorksPricingFAQ
Get Started
Get Started

Privacy Policy

Last updated: 30 July 2026 Effective date: 30 July 2026

This Privacy Policy describes how CMP IT ApS ("we", "us", or "our") collects, uses, and protects your personal data when you use the Camwarden platform ("Service"). We are committed to compliance with the EU General Data Protection Regulation (GDPR) and other applicable privacy laws.

Our role. For account, authentication, billing, support, and service-usage data, CMP IT ApS is the data controller.

For camera media — photos you upload or that your cameras send to the Service, together with associated metadata and detection results — you (or your organisation) are the data controller and CMP IT ApS acts as your data processor. That processing is governed by our Data Processing Agreement, which forms part of the Terms of Service. If a person captured by your cameras contacts us about their data, we will refer the request to you.

This Privacy Policy therefore describes our processing of the data for which we are the controller, and explains how camera media is handled at your direction.


1. Who We Are

CMP IT ApS CVR: 41254041

General enquiries: [email protected] Privacy enquiries: [email protected]

For all questions relating to this Privacy Policy or the exercise of your data protection rights, please contact us at [email protected].


2. Data We Collect

2.1 Account Data

When you register, we collect your name and email address, together with your account settings. We authenticate you using one-time codes sent to your email address, or via Google sign-in if you choose that option. We do not store passwords. If you sign in with Google, we receive your email address and basic profile information (such as your name and profile picture) from Google in order to create and access your account; your use of Google sign-in is also subject to Google's privacy policy. We do not receive access to your Google account contents.

You may also choose to set a display name and upload a profile avatar for your personal account, and a name and avatar for any team you create or manage. These are optional and provided voluntarily. If you subscribe to a paid plan, payment is handled by our payment processor — we do not store your full card details.

2.2 Camera and Media Content

We store images you upload manually (for example from a camera's SD card) or that are delivered to the Service via email ingestion from your connected cameras. Where this content contains embedded metadata (such as EXIF data including GPS coordinates or timestamps), that metadata is stored alongside the content.

2.3 Location Data

If you manually associate cameras or media with a geographic location, we store those coordinates. This data is used solely to provide the Service features you have requested.

2.4 Usage Data

We collect standard technical data necessary to operate the Service, such as IP addresses, device type, browser type, and interaction logs. This data is used for security, debugging, and service improvement. Where we use automated bot detection or CAPTCHA tools, those systems may also analyse browser and device signals (such as interaction patterns and browser characteristics) to distinguish human users from automated traffic. No additional personal data is collected beyond what is described in this section.

2.5 Communications

If you contact us by email or through the platform, we retain that correspondence for as long as is reasonably necessary to resolve your enquiry and for legitimate record-keeping purposes.

2.6 Feedback and Diagnostics

When you send us feedback through the app, we store the message you write, the page you were on, and the date you sent it, so that we can respond and track the issue to resolution.

You may optionally attach a screenshot. Screenshots are stored privately, are accessible only to our support staff, and are deleted after 90 days. Please be aware that a screenshot captures whatever was on screen at the time, which may include other people's names or email addresses and your camera locations — attach one only if you are comfortable sharing what it shows.

Feedback submissions also include, unless you switch the option off before sending, a set of non-identifying technical details about the session: your browser and its major version, operating system, device type, window and screen size, interface language, timezone, light/dark display setting, the application build you were running, and your subscription plan. These help us reproduce a problem on the same setup you saw it on. We do not record your full browser user-agent string, your IP address, or your on-screen activity as part of this. The exact values are shown to you in the feedback form before you send it, and unticking the option sends none of them.

2.7 Error Monitoring

We use automated error monitoring tools to identify and diagnose technical issues in the Service. When errors occur, we may collect the following categories of technical data: JavaScript error messages and stack traces, browser type and version, operating system, the URL and page context at the time of the error, and a timeline of user interactions preceding the error (such as clicks and navigation events).

This processing is carried out on the basis of our legitimate interests (Art. 6(1)(f) GDPR) in operating a functional and reliable service. Error monitoring data is processed by a third-party processor whose infrastructure is located within the European Union.

2.8 Public Share Links

You may choose to create a public share link for individual photos or media items. When you do so, you voluntarily make that content — including any embedded metadata such as GPS coordinates or timestamps — accessible to anyone who holds the link, without requiring authentication. The decision to share content publicly, including the decision to include location data, is made entirely by you.

Share links may be configured with an expiry duration at the time of creation. You may also revoke a share link at any time through your account settings. Once revoked, the link will cease to function, though copies of the content may persist temporarily in content delivery caches for a short period before being cleared. We cannot guarantee immediate removal from all caching layers following revocation.


3. How We Use Your Data

We process your personal data only for the purposes and on the legal bases set out in the table below.

Purpose of ProcessingLawful Basis (GDPR)
Providing and operating the ServicePerformance of contract (Art. 6(1)(b))
Processing paymentsPerformance of contract (Art. 6(1)(b))
Storing and processing your camera mediaPerformance of contract (Art. 6(1)(b))
AI-powered species and object detectionPerformance of contract (Art. 6(1)(b))
Improving and training AI detection modelsLegitimate interests (Art. 6(1)(f))
Security, abuse prevention, and fraud detectionLegitimate interests (Art. 6(1)(f))
Sending transactional and account-related emailsPerformance of contract (Art. 6(1)(b))
Responding to support requestsLegitimate interests (Art. 6(1)(f))
Generating and serving public share linksPerformance of contract (Art. 6(1)(b))
Error monitoring for service reliabilityLegitimate interests (Art. 6(1)(f))
Complying with applicable legal obligationsLegal obligation (Art. 6(1)(c))

4. AI Processing and Model Training

Your media content is processed by automated AI systems for species and object detection as part of delivering the Service to you. This is carried out on the legal basis of performance of contract (Art. 6(1)(b) GDPR).

Future model improvement. We may in the future use camera media to improve our detection models. Before any such use begins, we will: (a) notify account owners at least 30 days in advance; (b) provide a per-account opt-out that can be exercised at any time, including after training has begun (applying to future training runs); and (c) exclude all images in which a person has been detected from any training set. Objection under Art. 21 GDPR is always available regardless of these mechanisms.

We will never use your content for any purpose unrelated to providing or improving the Service.


5. Location and GPS Data

Location data — whether derived from EXIF metadata in uploaded files or manually associated by you — is treated with particular care. It is used only to provide the features you have requested and is never sold or shared with third parties for commercial purposes. Where location data is embedded in media uploaded to the Service, it will be retained only for as long as the media itself is retained.

If you create a public share link that includes media with embedded location data, that location information becomes accessible to anyone with the link. We strongly recommend reviewing the metadata included in any content before generating a public share link, particularly where location data could reveal sensitive information such as a property address or private land.


6. Data Sharing

We do not sell your personal data.

A current list of our sub-processors, including their purpose, data location, and transfer safeguards, is published at camwarden.com/sub-processors. We provide at least 30 days' notice of additions or replacements via that page and by email to account owners.

We may also disclose personal data where required by law, court order, or to protect our legal rights and the safety of others.


7. International Transfers

Some of our processors may be located or store data in countries outside the European Economic Area (EEA). This includes processors that transiently process data in third countries as part of delivering their service, even where that data is not permanently stored outside the EEA. Not all processors involve international transfers — some, including our error monitoring provider, operate exclusively within the EU. Where transfers outside the EEA do occur, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission, or other appropriate safeguards as recognised under GDPR Chapter V. You may request a copy of the relevant safeguards by contacting us at [email protected].


8. Data Retention

We retain your personal data for as long as your account is active and as necessary to provide the Service to you. If you delete your account, we will delete your personal data within 30 days of that request, except where we are required to retain it for legal or financial compliance purposes (for example, billing records may be retained for up to five years under Danish bookkeeping law).

Audit records of security-relevant account and team activity (such as sign-ins, membership changes, and changes to team settings) are retained for as long as the associated team exists, as this is necessary to protect the security and integrity of the Service. These records do not contain IP addresses; if you delete your account, they are stripped of the reference to you as described below. Operational logs that involve IP addresses or similar identifiers — such as abuse-prevention and rate-limiting records — store those identifiers only in hashed (pseudonymised) form and are automatically pruned within days. Diagnostic records of failed camera-email ingestion, which may contain personal data from the inbound email, are deleted after 30 days. Screenshots you attach to feedback are deleted after 90 days; the text of your feedback is retained as support correspondence as described above.

When you delete content, it is removed from live systems immediately and from backup copies through ordinary backup rotation within 35 days. When you delete your account, we delete your personal data within 30 days: records we must retain for legal reasons or database integrity are stripped of identifying information (a "tombstone" record), and all other personal data is erased. Residual backup copies are overwritten within a further 35 days.

Inactive Accounts

We may delete accounts that have remained inactive for an extended period. If we intend to delete your account for inactivity, we will send a notice to your registered email address at least 30 days before deletion takes place; if you log in or respond within that period, your account will not be deleted. We will never delete your account for inactivity without this prior notification. You may request reactivation at any time before deletion occurs.

Media Retention

Camera media is retained in accordance with your subscription plan. Media associated with a deleted account is removed within 30 days of account deletion, subject to any applicable legal retention obligations.


9. Business Transactions

If CMP IT ApS is involved in a merger, acquisition, asset sale, restructuring, or insolvency proceedings, your personal data may be transferred as part of that transaction. In such circumstances, we will take reasonable steps to ensure that the receiving party is bound by obligations consistent with this Privacy Policy. To the extent required by applicable law, we will notify you before your data is transferred and becomes subject to a different privacy policy.


10. Automated Decision-Making

The Service uses automated processing of your media content to perform species and object detection. This processing does not produce legal effects or similarly significantly affect you within the meaning of Article 22 GDPR. AI detection results are provided as an assistive feature only and are not used to make binding decisions about you.

If you have concerns about an automated detection result, or wish to request a correction to classifications associated with your account, please contact us at [email protected]. We will review your request and respond within 30 days.


11. Your Rights

Under GDPR, you have the following rights in relation to your personal data:

  • Access — request a copy of the personal data we hold about you
  • Rectification — request correction of inaccurate or incomplete data
  • Erasure — request deletion of your data (the "right to be forgotten"), subject to applicable legal retention obligations
  • Portability — request a copy of your personal data in a structured, machine-readable format (JSON). You can trigger a data export directly from your account settings. Exports are processed within 48 hours and delivered by email as a download link. Download links expire after 48 hours. Requests are limited to one per 24-hour period.
  • Restriction — request that we limit our processing of your data in certain circumstances
  • Objection — object to processing based on legitimate interests
  • Withdrawal of consent — where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
  • Not to be subject to solely automated decisions — where automated processing produces significant legal or similar effects, request human review

To exercise any of these rights, please contact us at [email protected]. We will respond within 30 days. There is no charge for making a request, and we will not discriminate against you for exercising your rights.

Right to Lodge a Complaint

You have the right to lodge a complaint with the data protection supervisory authority in your EU member state of habitual residence, place of work, or the place of the alleged infringement.

In Denmark, the relevant authority is the Danish Data Protection Authority (Datatilsynet): www.datatilsynet.dk

If you are located in another EU member state, you may instead contact your local supervisory authority. A full list of EU supervisory authorities is available from the European Data Protection Board: https://edpb.europa.eu/about-edpb/about-edpb/members_en


12. Children's Privacy

The Service is intended for users aged 16 or over. If you are under 16, you may only use the Service with the consent of a parent or guardian. If we become aware that personal data has been collected from a child in breach of this section, we will delete it.


13. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, disclosure, alteration, or destruction. These measures include encrypted storage, access controls enforced on a least-privilege basis, secure data transmission (TLS), and automated bot detection and CAPTCHA systems to prevent abuse and spam. We regularly review our security practices and update them as necessary.

No system is completely secure. In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and, where required, inform you directly without undue delay.


14. Cookies and Local Storage

We use only cookies and similar browser-storage entries that are necessary to operate the Service or that store a preference you have chosen. We do not use tracking, advertising, or analytics cookies. If this changes, we will update this Policy and obtain appropriate consent before placing any non-essential cookies on your device.

NameSet byTypePurposeDuration
__cf_turnstileCamwardenCookieRemembers that you passed our automated bot check so you are not asked again7 days
sb-*-auth-token (may be split into numbered parts)Camwarden (Supabase authentication)CookieKeeps you signed in to your accountUp to 400 days, or until you sign out
sb-*-auth-token-code-verifierCamwarden (Supabase authentication)CookieSecures the sign-in hand-off when you log in with GoogleA few minutes, during sign-in only
sessionCamwardenCookieAuthorises secure delivery of your photos from our media CDN (cdn.camwarden.com)1 hour, renewed while you are signed in
cw_policiesCamwardenCookieRecords which version of the Terms and Privacy Policy you acceptedUp to 400 days
cw_localeCamwardenCookieRemembers your language (English/Dansk/Magyar) — set when you choose a language, or from your saved account preference when you sign in1 year
themeCamwardenLocal storageRemembers your light/dark mode preferenceUntil deleted
cw.photos.*, cw_lb_swipe_hint, cw-ownership-billing-prompt-*CamwardenLocal storageRemember interface preferences (photo grid layout, dismissed hints and notices)Until deleted
oauth_link_intentCamwardenSession storageCompletes linking a sign-in provider to your accountUntil the browser tab is closed
(bot-check widget state)CloudflareStorage inside the Turnstile widgetDistinguishes humans from automated traffic (security)Managed by Cloudflare

When you start a paid subscription you are redirected to our payment partner Polar (Merchant of Record), which sets its own cookies on its checkout pages under its own privacy policy. Map views load base-map imagery from OpenStreetMap, Esri, and CARTO, and if you use the location search your query is sent to OpenStreetMap's Nominatim geocoding service; these requests transmit your IP address — including, for location searches, the text of the search you type — but set no cookies (see our sub-processors page for details).


15. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice within the Service at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision. We encourage you to review this Policy periodically.


16. Contact

For any privacy-related questions, to exercise your rights, or to raise a concern about how we handle your personal data, please contact:

CMP IT ApS CVR: 41254041 [email protected]

We aim to respond to all legitimate enquiries within 30 days.

Camwarden

Your trail camera photos, your control. No vendor lock-in.

Product

FeaturesPricingHow It WorksFAQ

Company

AboutContact

Legal

Terms of ServicePrivacy PolicyCookiesWithdraw from contractData Processing AgreementSub-processorsSecurityLegal NoticeAttribution
© 2023 - 2026 Camwarden. All rights reserved.EU-hosted · GDPR-native