Privacy Policy & Security Standards
Sentinel is engineered around a singular core commitment: complete, local data sovereignty with zero network transmission.
100% AIR-GAPPED
Runs entirely on Apple Silicon Neural Engine. Zero cloud servers, zero analytics, and zero network calls.
VOLATILE MEMORY
Camera video feeds are processed frame-by-frame in RAM and instantly overwritten. Zero video files recorded.
KEYCHAIN ENCRYPTED
Normalized facial landmark metrics are stored strictly inside your local macOS Keychain with AES-256 hardware encryption.
ZERO DATA SALES
CAMMIO Industries does not collect, track, license, sell, or transmit any user data under any circumstances.
Executive Summary & Architecture
This Privacy Policy details how CAMMIO Industries ("we", "our", or "us") engineers and maintains Sentinel — Presence Shield for macOS. We adhere to the strict philosophy that biometric utility must exist completely free of data collection.
Sentinel runs as an air-gapped system utility. It executes Apple's native Vision framework (VNFaceObservation) directly on your device's Apple Silicon Neural Engine to deliver real-time facial presence analysis and shoulder-surfing protection without sending bytes over the internet.
Sentinel contains zero background telemetry, user analytics, crash reporting SDKs, or biometric streaming. No data ever leaves your computer during normal operation.
Camera Access & Volatile RAM Lifecycle
Sentinel requests camera hardware access (NSCameraUsageDescription) to perform passive facial presence detection. Frame processing adheres to a strict volatile memory lifecycle:
- Real-Time RAM Buffering: Incoming video frames from your FaceTime HD camera or external USB webcam are held strictly in temporary RAM buffers.
- Immediate Buffer Overwriting: Once 2D landmark coordinates are calculated (~16-33ms per frame), the raw video buffer is immediately flushed and erased from memory.
- Zero Video Storage: Sentinel does not record, encode, stream, or write video feeds to disk during standard operation.
Biometric Signatures, Calibrated Profile Thumbnails & Local Storage
During face registration and multi-angle posture calibration, Sentinel computes a normalized 2D relative geometric signature (floating-point arrays representing distances between eye centers, nose contour, and mouth corners) and saves a local reference profile thumbnail.
- Non-Reconstructable Metrics: Biometric landmark signatures consist of abstract mathematical ratios. It is impossible to reconstruct a human face or image from these numbers.
- Calibrated Profile Thumbnails: Reference thumbnails of calibrated face profiles are stored locally in your Mac's sandboxed data container (
~/Library/Containers/com.camo.Sentinel/Data/Library/Application Support/Sentinel/) strictly to enable profile management in Sentinel Preferences and assist multi-pose posture matching. - macOS Keychain Protection: Mathematical signatures are stored locally inside your encrypted macOS Keychain (com.camo.Sentinel), protected by Apple's hardware Secure Enclave.
- One-Click Purge & Deletion: You retain complete ownership and can purge or recalibrate your signature and profile thumbnails at any time by clicking "Reset Calibration" in Sentinel Preferences.
Local Activity Logs, Event Snapshots & 24-Hour Retention Policy
Sentinel includes an Activity Log feature allowing users to review security events, unauthorized access attempts, and secondary observer ("shoulder surfing") alerts.
- Security Event Snapshots: When an unauthorized person or secondary observer is detected, a single-frame JPEG snapshot and cropped face thumbnail are stored locally in your sandboxed application support directory (
~/Library/Containers/com.camo.Sentinel/Data/Library/Application Support/Sentinel/Intruders/). - Automatic 24-Hour Purge: Security activity log snapshots are automatically purged and permanently deleted from local disk storage after 24 hours (or up to a maximum of 30 entries per profile sector).
- App Sandbox & POSIX File Security: All stored image files are protected by macOS App Sandbox isolation and restricted POSIX file permissions (0o600 / 0o644), restricting file access exclusively to your logged-in macOS user account and encrypted via FileVault / APFS hardware encryption at rest.
- Zero Network Entitlement & Non-Disclosure: Sentinel declares zero network access entitlements (com.apple.security.network.client / server). Stored images, landmarks, and face data physically cannot leave your Mac, and are never shared, sold, transferred, or disclosed to any third parties or cloud servers.
- User Control: Users can manually clear activity logs or delete individual snapshots at any time in Sentinel Preferences.
In-App Support & Voluntary Diagnostic Data Sharing
Support for Sentinel is requested directly within the app via the In-App Support & Feedback tab (located in Sentinel Preferences → Support).
- User-Initiated Submissions: Technical support and bug reports are initiated solely by the user from inside the app interface. Sentinel never sends automated crash reports or background diagnostics.
- Opt-In System Telemetry: When submitting an in-app support ticket, users can explicitly choose whether to include basic diagnostic details (such as macOS version, screen count, and hardware architecture) to assist engineers in diagnosing issues.
- Strict Usage Scoping: Diagnostic details voluntarily submitted through the in-app support form are used exclusively by our engineering team to investigate, reproduce, and resolve your specific ticket.
- Confidentiality & Zero Data Sales: Information provided through in-app support is strictly confidential and is never sold, licensed, or shared with third-party advertisers or data brokers.
- Data Retention & Erasure: In-app support tickets and attached diagnostic details are retained only until the technical inquiry is resolved, and are permanently purged upon ticket resolution or upon written request.
Automation Permissions & Application Integrations
Sentinel requests local automation permission (com.apple.security.temporary-exception.apple-events) solely to send play/pause commands to Apple Music and Spotify when user presence changes.
These commands execute locally via AppleScript events. Sentinel never reads, accesses, or logs your media library, listening history, or account credentials.
Global Regulatory Compliance
Because Sentinel operates as an on-device utility and collects zero personal tracking data, it satisfies and exceeds global privacy frameworks:
| Regulatory Standard | Compliance Posture & Implementation |
|---|---|
| GDPR (EU) | Fully compliant via data minimization (Art. 5), on-device processing, and instant local erasure (Art. 17). In-app support communications respect full Data Access & Erasure rights. |
| CCPA / CPRA (US) | Zero sale, rental, or sharing of personal data. Zero third-party tracking identifiers. |
| Privacy Act 1988 (AU) | Exceeds Australian Privacy Principles (APPs) by keeping biometric templates strictly within local user custody. |
| COPPA (Children) | 100% compliant. No data of any kind is collected from any user, regardless of age. |
Contact & Corporate Details
If you have technical questions regarding Sentinel's security design or privacy architecture, please contact CAMMIO Industries: