Old Bird Privacy Policy

Last updated: 2026-07-12

Old Bird is an Android security camera app. It is local by default: camera, microphone, settings, recordings, and the viewer password live on the phone. Data leaves the phone only when you deliberately view or download it, enable a backup or webhook integration, sign in for remote access, or send diagnostics to the services described below. Old Bird's application database stores only its small camera registry; Firebase also provides the authentication and diagnostic services described below. You can wipe the registry from inside the app.

Camera and microphone

When streaming is enabled, Old Bird captures video and optional audio. By default it is reachable only on your Wi-Fi (LAN). If you subscribe to Pro and use off-LAN viewing, WebRTC media travels peer-to-peer when possible and may pass through Old Bird's TURN relay when required — see Remote viewing below. Old Bird does not record or store camera or microphone content on its servers.

Optional cloud features

Each feature below is opt-in. The app works fully without any of them.

Google sign-in

Credential Manager provides Old Bird with your Google account ID, email, and display name, used to link cameras to your account. Authentication runs through Firebase Authentication.

Camera registry (Firebase Firestore)

When you sign in and turn on off-LAN viewing (Pro), Old Bird writes a small record per camera to Firestore: the camera's name, its current relay URL (present only while the camera is online), and a last-seen timestamp. It does not store your viewer password, device model, or app version. The record is removed when you cancel Pro, sign out, or tap Delete cloud data.

Remote viewing

Off-LAN viewing (a Pro feature) reaches your camera through Old Bird's relay at relay.oldbird.app. The relay authenticates the account owner and camera, forwards WebRTC signaling and remote admin requests and responses, and provides TURN when a peer-to-peer media path is unavailable. It processes traffic in memory and does not record or store it. Because Old Bird infrastructure can process relayed traffic in transit, off-LAN viewing is not end-to-end encrypted. If you would rather your streams never traverse Old Bird's servers, leave off-LAN viewing off and use the app on your LAN or through your own VPN.

Cloud backup (WebDAV / Google Drive)

Recorded MP4 segments can be uploaded to a WebDAV server you supply, or to your own Google Drive (using the drive.file scope, which only accesses files Old Bird creates). The destination is yours; Old Bird's servers never see the segments.

Motion alerts

If you configure a motion-alert webhook (Generic, ntfy, Slack, Discord, Telegram, or a custom URL), Old Bird POSTs a small JSON event to the address you chose when motion is detected. The body contains the camera name, IP, and timestamp — no media. Old Bird's servers are not involved.

Subscription billing

Pro subscriptions are processed by Google Play Billing. Old Bird never sees your payment information; it only receives the subscription state (active / pending / cancelled) from Play.

Crash reports and analytics

If the app crashes, Firebase Crashlytics receives the stack trace and device/OS/app-version metadata, plus a short trail of internal lifecycle events ("camera started", "settings updated") — never the values of fields you typed, IP addresses, file names, or passwords. Firebase Analytics logs anonymous feature-usage events (which screens open, which lens is selected). Neither stream contains your Google account or camera content. Crashlytics retains up to 90 days; Analytics up to 14 months.

App integrity

Each request to Firebase carries an anonymous Play Integrity attestation token proving the request came from a genuine Old Bird install. The token contains no personal information.

Children

Old Bird is not directed at children under 13 and does not knowingly collect their data.

Data retention and deletion

To delete the cameras registry and profile tied to your Google account, open the app and tap Settings → Account → Delete cloud data. See the deletion guide for what's removed. For sooner deletion of crash/analytics data, email the address below.

Contact

[email protected]