SmashCam

Privacy policy

This policy explains how we handle personal information in connection with the SmashCam app. It is written to meet the Australian Privacy Principles.

_Last updated: 3 October 2026_

This policy explains how Greg Kuhnert, an individual and Australian sole trader ("we", "us"), handles personal information in connection with the mobile app SmashCam (the "app").

We have written it to meet the Australian Privacy Principles (APPs) in the _Privacy Act 1988_ (Cth). It is deliberately short, because the app does very little with personal information. We have not padded it.

If anything here is unclear, contact us at privacy@smashcam.app.

About the app

SmashCam is a dashcam companion app. It runs entirely on your own iPhone. It has no server, no user account, and no login. There is nothing to sign up for, and nothing about you is sent to us.

That single design decision is the whole of this policy's substance, so it is worth stating plainly before going further.

Personal information we collect

In this version of the app, we do not collect personal information.

To be specific, the app does not collect, transmit to us, or store anywhere other than your own device:

We have no analytics software, no advertising, no third-party tracking, and no cloud storage in the app.

This statement is true of the app as it stands. It is scoped that way deliberately, because a sharing feature is planned that will send a video off your device — see "Sharing a clip to YouTube" below for exactly what it will do, and what has to change when it does.

Things the app does on your device — and why they are not collection

Three features use permissions that may look like data collection. On the evidence of how the app is built, none of them transmits anything off your device, and so none of them is "collection" in the sense the APPs and Apple both use.

Location. If you grant it, the app uses your location (When In Use) for one purpose: to record where a smash happened and to place it on a map. Your location is stored on your device, with that smash, and nowhere else. The app is fully usable if you decline location — a smash simply has no location attached.

Local network. The app talks to your own dashcam over the dashcam's own Wi-Fi network, so it can list and download your recordings. This is a device-to-device connection on your local network. It does not reach the internet, and no data passes through us.

Video. Recordings are downloaded from your own camera to your own device, and stay there. We never receive them. You can delete them at any time using your phone's normal means.

The free-tier configuration fetch. The app makes one outbound request: a plain GET for a static configuration file (JSON) that tells the app what the free tier allows. That request carries nothing about you — no identifier, no account, nothing that distinguishes you from any other device. It is the same file served to everyone.

Sharing a clip to YouTube — planned, and what it changes

This feature is not in the app yet. It is described here because it changes this policy's position, and a user is entitled to know what is coming rather than discover it in an update.

Nothing here describes processing that happens today.

The app will offer a user-triggered action: exporting a smashed clip and uploading it to YouTube.

Nothing is ever uploaded unless you initiate it for that clip (and even the opt-in automatic mode described below is a mode you switch on deliberately).

Where a clip can be sent

Two destinations, and they are materially different:

If you submit to the SmashCam channel — what you are giving us

Submission is private by default and published only after a human review. Submitting a clip to the SmashCam channel is a licence to publish that clip on the channel.

What we do not ask for and do not attach. No name, no email, no account, no Apple ID, no device identifier. We do not know who submitted a clip, and we cannot find out from what we hold. The submission is anonymous.

What we do hold, so that abuse is possible to stop. One random token, generated on our server when you first submit, and stored on your device. It is a plain random number. It is not derived from your Apple ID, your device, or anything about you, and it cannot be turned back into one. Its only job is to let us stop a submission source that is abusing the facility — spamming, or uploading things that must not be published. It identifies the submission, not you.

Two consequences you should know, because they follow from that design:

In plain terms, about the licence:

Why this section exists even though the feature is not built

Because the moment it ships, this policy stops being accurate unless it is rewritten. The statement that "we do not collect personal information" is true today; a video submitted to our channel is data we hold, which is collection by any definition — Apple's and the Privacy Act's. So the position is written here, in advance, rather than left to be discovered.

This section will be rewritten before the feature reaches you, and it will then state the specific data, the purpose, the retention period, and the overseas-disclosure position — none of which can honestly be stated while the feature does not exist.

A note on the footage itself

Dashcam footage is not neutral. It may show other people, licence plates, faces, and places — people who have not consented to anything. By submitting a clip to our channel you confirm you have the right to share it. For your own channel that responsibility is already yours; for ours, the human review step exists partly so that a clip we would not want to publish can be declined.

Why we are confident this is "Data Not Collected"

Apple defines "collect" for its App Privacy labels as transmitting data off the device in a way that lets you or your third-party partners access it for longer than is needed to serve the request in real time. By that definition, and by the description above, the app's App Privacy label is "Data Not Collected". This policy is written to be consistent with that label.

If you believe you have found a contradiction between this policy and how the app actually behaves, please tell us — that is a bug, and we would want to know.

How we hold personal information

We do not hold personal information, and so there is nothing for us to store securely or to destroy.

Information the app creates — smashed moments, downloaded clips, and any location attached to them — is held on your own device under your control, and is protected by your device's own security (passcode, Face ID, encryption). It is not backed up to us. Whether it is included in your own iCloud or iTunes backup is a matter for your device settings, not for us.

Disclosure to anyone, including overseas

We do not disclose personal information to anyone, because we do not have any. This includes overseas recipients: nothing is disclosed to any overseas person or body, because nothing is disclosed at all.

Notifiable Data Breaches

The Notifiable Data Breaches scheme requires an organisation to notify affected individuals and the OAIC when a data breach involving personal information is likely to result in serious harm. Because nothing is transmitted off your device to us and we hold no personal information, a breach on our side of personal information you have given us is not something that can occur: there is no store of your information for anyone to breach.

This does not reduce the security of your own device to a matter of no consequence — it is simply a risk you carry, and manage, yourself. If you lose your phone, the information on it is your data on your hardware.

If the app is ever changed so that we hold personal information, this section must be rewritten before that version ships.

Accessing and correcting your information

Under APPs 12 and 13 you may ask to access, or to correct, personal information we hold about you.

We do not hold personal information about you, so in the ordinary case there is nothing for us to give you or correct. You already have full access to everything the app creates, on your device, and you can change or delete it there directly.

You are still welcome to make a request, and we will respond. Requests should go to:

Complaints

If you think we have mishandled your personal information, please tell us first:

We will acknowledge your complaint and respond, normally within 30 days.

If you are not satisfied with our response, or we do not respond within 30 days, you may complain to the Office of the Australian Information Commissioner (OAIC), which is the regulator for the Privacy Act. The OAIC accepts complaints in writing via its online form, by email to oaicintake@oaic.gov.au, or by post to GPO Box 5288, Sydney NSW 2001. The OAIC's enquiries line is 1300 363 992.

Automated decision-making

The APPs require a privacy policy to say so if an entity uses a computer program to make, or substantially assist in making, decisions that could significantly affect an individual's rights or interests.

We do not do this. There is no automated decision-making about you anywhere in the app or in our business.

If you are in the European Union or the United Kingdom

Owner's answer, 2026-10-03: leave EU/UK distribution open — apps are distributed worldwide — and handle it as follows.

Apple distributes worldwide by default, so some users will be in the EU or UK. The GDPR and UK GDPR require a lawful basis for processing their personal data.

The app's position, stated plainly rather than hedged. The app runs on the user's own device, with no server, no account and no transmission to us. To the extent any personal data is processed at all, it is processed by the user, on the user's own device, under the user's own control, for the user's own purposes — recording where a smash happened, and copying the user's own recordings from the user's own camera. We are not a controller of that processing, because nothing reaches us. There is nothing for us to give a lawful basis for.

What this section therefore says, and does not say:

This is a reasoned position, not legal advice. It rests on the app's architecture (no server), which is a verifiable fact about the build rather than a claim about the law. If a data-protection authority were ever to take a different view, the correct response would be to add a lawful-basis section then — not to pre-assert one now.

Is the Privacy Act even the right frame for us?

Owner's answer, 2026-10-03: the owner is an individual sole trader with an ABN, and is not registered for GST (income below the threshold).

That matters because the OAIC states the Privacy Act applies to organisations with an annual turnover above $3 million, "and some other organisations". A sole trader below that threshold is generally outside the APPs unless an exception applies (trading in personal information, providing a health service, or being related to a larger organisation). On the facts given, none of those exceptions is apparent.

So this policy is written to a higher standard than the law may require — deliberately. The APPs frame is kept because it is honest, it is short, and it is consistent with what Apple expects of an app's privacy policy regardless of whether the Act technically binds a small operator. Undertaking to meet the APPs when the law does not compel it is a promise the app can comfortably keep: it collects nothing.

One practical consequence to note. Being outside the APPs means the OAIC's complaint route is not strictly available to a user. The policy still names the OAIC rather than inventing a private dispute process, but it should not overstate that route. This is recorded as a judgement, not as verified law — if the position is ever tested, a specialist should confirm it.

Changes to this policy

We will update this policy when the app changes in a way that affects it, and we will show the new "last updated" date at the top. The current version will always be available at https://smashcam.app/privacy.

Contact

Greg Kuhnert, an individual, an Australian sole trader. Email: privacy@smashcam.app Post: PO Box 241, Sylvania Southgate NSW 2224, Australia