top of page

DoorGuardian AI Privacy Policy

Version: 1.0 | Effective Date: January 2026

(Updated based on Data Protection Impact Assessment (DPIA) as of 22 January 2026)

DoorGuardian AI is a beta home security app that processes data in compliance with China's Personal Information Protection Law (PIPL), the EU General Data Protection Regulation (GDPR), Singapore's Personal Data Protection Act (PDPA), the California Consumer Privacy Act (CCPA), and the California Privacy Rights Act (CPRA).

This Policy follows the principles of necessity, proportionality, privacy by design, data minimization, user rights, transparency, and robust security measures in accordance with all applicable laws.

The app uses a local processing model: most data is processed solely on your device and is not uploaded to any servers. We do not sell or share personal data for commercial purposes (e.g., targeted advertising). For California residents, we comply with CCPA/CPRA requirements, including no sale or sharing of personal information and rights to know, delete, and limit use of sensitive personal information.

1. Data Collection

  • Noise Detection Real-time monitoring of environmental noise (e.g., loud sounds or anomalies). No noise data is stored. The app starts in a fully disabled state with no monitoring or processing. Monitoring begins only after you manually click “Start Monitoring”.

  • Facial Recognition

    • You may voluntarily upload upper-body photos of family members (one or more per person). Each upload requires separate authorization via a popup: “Requires family member authorization. [Agree]”.

    • The app locally extracts face embedding vectors (templates). Both photos and vectors are stored in the app's local sandbox on your device (protected by system-level encryption, e.g., iOS NSFileProtectionCompleteUntilFirstUserAuthentication). No data is uploaded to the cloud. This is sensitive biometric data.

    • You can delete photos and linked vectors at any time via the “Setting> Manage Family Faces” page.

    • If no photos are uploaded, all faces are treated as strangers by default.

    • Stranger faces are compared in real-time only; no original samples or vectors are stored.

  • Video Recording

    • If a stranger lingers for one minute, the app issues voice reminders every 20 seconds: “This area is under monitoring. Please leave promptly.”

    • Triggers (siren + 10-second video recording with image and audio) occur only if a stranger (non-family) causes loud noise (within 1–2 minutes), lingers over 2 minutes, or appears to carry a dangerous object.

    • Pushed video will include text reminder: “Test video – expires in 72 hours.”

2. Processing and Storage

  • All data is encrypted and stored in the app's designated local sandbox directory on your device.

    • iOS uses NSFileProtectionCompleteUntilFirstUserAuthentication (encrypted after device lock).

    • Android uses equivalent system-level encryption.

  • Videos are transmitted via HTTPS/TLS to Telegram servers (not end-to-end encrypted) for delivery. Telegram handles further distribution/storage under its own privacy policy. The local copy is deleted immediately after successful transmission.

  • The app recommends deleting videos within 72 hours (via reminders in Telegram).

3. Purposes of Processing

  • Solely for testing home security features (e.g., intrusion detection, siren triggering, reducing false alarms).

  • Facial vectors are used only to distinguish family from strangers for personalized responses.

  • No other purposes. No sale or sharing of personal data with third parties for commercial use. Processing is limited to small-scale private use (not public surveillance).

4. Data Deletion

  • Videos are deleted locally immediately after successful push to Telegram. Users must manually delete them from Telegram (the app sends a reminder: “Test video – please review and delete. Suggested expiration in 72 hours”).

  • Facial vectors and photos can be deleted at any time with no backups.

  • All consents can be withdrawn via the settings page (“One-Click Withdraw All Consents”). Processing and monitoring stop immediately.

  • Noise data and stranger face data are never stored.

5. Third-Party Data

  • Videos may incidentally include images/audio of strangers. Processing is based on your explicit consent (GDPR Art. 6(1)(a), PDPA consent, PIPL consent, CCPA/CPRA informed consent) — not legitimate interests.

  • Safeguards include voice reminders, encryption, 72-hour deletion recommendation, and sharing restrictions. Multi-round voice alerts promote transparency by informing strangers of monitoring.

6. Telegram Sharing

  • Only users who accept this Policy and the Terms of Service can bind their Telegram account to the DoorGuardian Bot (API bot) for video alerts. Otherwise, no video recording occurs.

  • Uses regular private Telegram chats (cloud chats); transmission is encrypted in transit but not end-to-end encrypted (E2EE).

  • Upon receiving alerts, please delete videos within 72 hours. The app sends a text message below the video advising deletion to protect privacy.

  • Sharing to non-private chats or other platforms may create privacy risks; you bear responsibility.

  • If encrypted push fails, the app automatically pauses recording and notifies you.

7. User Rights

  • Telegram binding for alert videos is optional.

  • View or delete data via the app’s “Settings—> Manage Family Faces” page.

  • Rights under GDPR, PDPA, PIPL, CCPA/CPRA include access, correction, deletion, objection, and withdrawal of consent.

California Residents (CCPA/CPRA) Specific Rights:

  • Right to Know: Categories collected include biometric information (locally stored facial vectors) and temporary audiovisual clips (pushed to Telegram).

  • Right to Delete: Request deletion via the app or by contacting support.

  • No Sale/No Share: We do not sell or share personal information for commercial purposes; no opt-out is needed.

  • Limit Sensitive Personal Information Use: Biometric data is used only for home security; no other uses.

  • Non-Discrimination: Exercising rights will not result in service degradation.

  • How to Exercise: Contact info@primesoft.com.sg. We respond within 45 days (extendable by 45 days). Identity verification is required. Processing is free (limited to 2 requests per year).​

For other jurisdictions (GDPR/PDPA/PIPL), third parties may contact info@primesoft.com.sg; we respond within 1 month (or as required by law), free of charge.

8. Remote Control

Users can remotely toggle the siren or restart monitoring via buttons under the alert video in Telegram.

9. Security Measures

  • Technical: All processing is on-device. Biometric vectors are stored in the local app sandbox with system protection (e.g., iOS NSFileProtectionCompleteUntilFirstUserAuthentication against loss/theft). No stranger data is stored. Temporary data is deleted locally once pushed to Telegram. Regular app updates address vulnerabilities; annual penetration testing is conducted.

  • Notifications: Voice reminders ensure transparency. A mandatory privacy popup appears on first launch, requiring explicit consent and commitment to “private residence use only; do not point at public spaces”.

  • Restrictions: The Terms of Service prohibit public-area use. In-app prompts help prevent misuse. No permanent local video storage occurs; videos are used only for real-time matching and Telegram push.

10. Contact Information

Data Controller: PRIMESOFT PTE. LTD.

Email: info@primesoft.com.sg

Website: www.primesoft.com.sg

11. Reminders

  • For private residence use only. Do not point cameras at public areas. A popup reminder appears on install/first launch: “Do not point at public spaces; private residence use only.”

  • By participating in the beta test, you agree to this Policy.

Through privacy by design (local processing, data minimization, strong encryption, and prominent notices) and best practices aligned with PDPC biometric guidelines (and similar standards), privacy risks are effectively controlled to an acceptably low level in compliance with GDPR, PDPA, PIPL, CCPA, and CPRA.

 

EFFECT OF NOTICE AND CHANGES TO NOTICE

  1. This Notice applies in conjunction with any other notices, contractual clauses and consent clauses that apply in relation to the collection, use and disclosure of your personal data by us.

  2. We may revise this Notice from time to time without any prior notice. You may determine if any such revision has taken place by referring to the date on which this Notice was last updated. Your continued use of our services constitutes your acknowledgement and acceptance of such changes. 

Effective date : 22/01/2026
Last updated : 22/01/2026

Your Trustworthy AI Partner

PRIMESOFT PTE. LTD., ANCHORVALE CRESCENT, SINGAPORE 544631,

UEN: 202537341C

  • Facebook
  • Instagram
  • X
  • TikTok

 

© 2026 Primesoft Pte. Ltd.

 

bottom of page