LAST UPDATED: 6 july 2026

Privacy Policy

Privacy Policy

This Privacy Policy explains how Esplora (“Esplora”, “we”, “us”, or “our”) collects, uses, and shares information when you use the Esplora mobile application (the “App”) and the related cloud services available atapi.esplora.ai (together, the “Service”). The App lets you set up, configure, view, and manage Esplora AI cameras, including live video, recordings, notifications, and optional face- and object-recognition features.

Data Controller.  Esplora is a product brand owned and operated by Noam Cantoni, Milan, Italy. Privacy contact: privacy@esplora.ai.

Data Controller.  Esplora is a product brand owned and operated by Noam Cantoni, Milan, Italy. Privacy contact: privacy@esplora.ai.

1. Information We Collect

Account information
Examples: Email address and password you provide to create and sign in to your account; a session token stored on your device to keep you signed in. Why we collect it: To create your account, authenticate you, and secure the Service.

Camera & setup data
Examples: Camera device identifiers (device ID, MAC address, local IP), the server URL you configure, and the Wi-Fi network name (SSID) and password you enter to connect a camera to your network. Wi-Fi credentials are sent to the camera to provision it. Why we collect it: To pair, configure, and connect your camera(s) to your network and to the Service.

QR / pairing scans
Examples: Data read from QR codes you scan with the camera during setup.
Why we collect it: To identify and pair a camera with your account.

Photos you upload
Examples: Images you choose to upload — including photographs of faces — so the Service can recognize specific people. Why we collect it: To provide the optional face-recognition feature you enable.

Video & images from your camera
Examples: Live video streams, still images, and recordings produced by your camera and routed through the Service. Why we collect it: To deliver live view, recordings, alerts, and recognition features.

Push notification token
Examples: A Firebase Cloud Messaging (FCM) registration token associated with your device. Why we collect it: To send you alerts and notifications.

Device & technical data
Examples: App version, operating system, and network connection state.
Why we collect it: To operate the App, diagnose problems, and maintain security.

Location permission
On Android, the App requests location permission because the operating system requires it to scan for and configure nearby Wi-Fi networks during camera setup. We do not collect, store, or transmit your geographic location. The permission is used solely to enable Wi-Fi provisioning.

What we do not do
We do not use third-party advertising networks, and the App contains no advertising or third-party analytics/tracking SDKs. We do not sell your personal data.

2. How We Use Your Information

  • To provide, operate, and maintain the Service (camera setup, live view, recordings, notifications).

  • To authenticate you and keep your account secure.

  • To deliver the optional face- and object-recognition features you choose to enable.

  • To send service-related and alert notifications.

  • To respond to your support requests.

  • To detect, prevent, and address fraud, abuse, and security incidents.

  • To comply with legal obligations.

Our legal bases under the GDPR are: performance of a contract (providing the Service you sign up for), legitimate interests (security, fraud prevention, and improving the Service in a manner that does not override your rights), legal obligation, and consent (for the optional uses described in Section 3, and for any processing of biometric data).

3. Use of Images and Video to Improve and Train Our Models

We are continually improving the accuracy of the object- and face-recognition technology that powers the Service. With your explicit, opt-in consent, we may use images and video captured or uploaded through the App — which can include footage and photographs of people — to develop, test, train, and improve our machine-learning models.

  • This is strictly optional and off by default. You are asked to opt in, and you can turn it on or off at any time in the App’s privacy settings.

  • If you do not opt in, your images and video are used only to provide the App’s features to you and are not used to train our models.

  • If you opt in, you grant Esplora a non-exclusive right to store and process the selected images and video for the purpose of developing and improving our recognition models. Where feasible, we minimize, pseudonymize, or aggregate this data, and we restrict access to authorized personnel.

Withdrawal. You may withdraw this consent at any time. Withdrawal stops future use of your content for training; it does not affect processing already carried out, though you may also request deletion as described in Section 6.

Your responsibility regarding other people. Footage from a camera may capture people other than you. You should only enable this feature for content you are lawfully entitled to share, and you are responsible for obtaining any consent required from individuals who appear in that content before enabling it.

Biometric / special-category data. Facial images used for recognition are treated as biometric data (a special category of personal data under GDPR Article 9). We process such data only on the basis of your explicit consent, which you provide when you enable face recognition and, separately, when you opt in to model training. You can withdraw either consent at any time. To provide recognition, we derive a numerical representation of each face (a face “embedding” or template) from the photographs you upload and from faces detected in footage from your own camera. Face photographs and embeddings are used solely to recognize the specific people you have chosen to identify, are stored on our own servers in the European Union, are never shared with or sold to third parties, and are permanently deleted when you remove the person or photo in the App or delete your account.

4. How We Share Information

We share information only with service providers (processors) acting on our behalf, and only as needed to run the Service:

Google LLC — Firebase Cloud Messaging Data: Push notification token; notification payloads. Purpose: To deliver push notifications to your device.

Cloud hosting / infrastructure providers Data: Account data, camera data, and media routed through our servers. Purpose: To host and operate the Service on our behalf, under contract.

We may also disclose information where required by law, to enforce our terms, or to protect the rights, safety, and security of our users or the public. We do not sell personal data and do not share it for third-party advertising.

5. Data Retention

We keep personal data only as long as necessary for the purposes described in this Policy:

  • Account data — for as long as your account is active, then deleted or anonymized after closure (subject to legal retention requirements).

  • Recordings and media — for the retention period applicable to your camera/storage configuration, or until you delete them.

  • Face photographs and face embeddings — until you delete the photo or the person’s profile in the App, or until you delete your account, whichever comes first. Deletion permanently removes them from our servers.

  • Images/video you opted in for model training — retained for as long as needed to develop and validate our models, unless you withdraw consent or request deletion.

  • Push tokens — until they expire, you sign out, or you uninstall the App.

6. Your Rights & How to Delete Your Data

If you are in the European Economic Area or the United Kingdom, you have the right to access, rectify, erase, restrict, and port your personal data, to object to certain processing, and to withdraw consent at any time. You also have the right to lodge a complaint with a supervisory authority — in Italy, the Garante per la protezione dei dati personali.

Account and data deletion: You can permanently delete your account and all associated personal data — including camera registration, alerts, face photographs, and face embeddings — directly in the App via Settings → Delete Account. You can also request deletion by emailing privacy@esplora.ai; we will respond within the timeframe required by applicable law.

7. Security

We use technical and organizational measures to protect your information, including encryption in transit (HTTPS/TLS) for communication with our cloud Service. Note that communication between the App and a camera on your local network may use the camera’s own local interface. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. International Transfers

Your information may be processed in countries outside your own, including outside the EEA. Where we transfer personal data internationally, we rely on appropriate safeguards such as the European Commission’s Standard Contractual Clauses.

9. Children

The App is not directed to children and is not intended for use by anyone under 16. We do not knowingly collect personal data from children. If you believe a child has provided us personal data, please contact us so we can delete it.

10. Changes to This Policy

We may update this Policy from time to time. We will post the updated version here and revise the “Last updated” date above. Material changes will be communicated through the App or by other appropriate means.

11. Contact Us

Esplora — Milan, Italy
Privacy enquiries: privacy@esplora.ai

© 2026 Esplora.

Create a free website with Framer, the website builder loved by startups, designers and agencies.