---
title: "Tenon Cam — App Privacy Policy"
description: "What Tenon Cam sends and what it does not. Photos, projects and notes never leave your device. No accounts, no cloud, no ads, no tracking."
canonical_url: "https://tenon.tools/cam/privacy/"
language: "en"
last_updated: "2026-08-22"
source: "Tenon Tools"
---

# Tenon Cam — Privacy Policy

_Last updated: 2026-08-22_

> Your photos never leave your phone. Tenon Cam has no cloud, no account and no upload path — the pictures, the projects they sit in, your notes and the PDF binders you export are written to the device, and the only way one leaves is when you send it yourself through the share sheet. There is no advertising and no tracking of any kind. Four narrow things do use the network, and they are listed in full below: the app checks whether an update exists, it cross-checks the clock so a timestamp can be trusted, it asks the phone's own geocoder to turn a GPS fix into a street address for the stamp, and it confirms your purchase with the store. None of them carries a photograph.

This policy covers the mobile app Tenon Cam on iOS and Android. The tenon.tools website is covered separately by the site privacy notice, which describes different processing — a web server log, analytics under Consent Mode, and the waitlist. Tenon Calc has its own policy too: it ships a crash reporter and this app does not, so one shared page would be wrong for both.

It is written to be checked rather than agreed to. Each destination below is named, with what is sent to it and what is not. The list is derived from the app's own source tree by a check that runs on every build, so a new destination cannot appear in the app without appearing here.

## Who is responsible

Tenon Cam is made by Erkam Demirci, an independent software developer established in Türkiye, trading as Tenon Tools. There is no company data department; the person who answers a privacy question is the person who wrote the code.

For privacy questions, corrections, or any request under the rights listed further down, use the contact route on the Tenon Tools support page at tenon.tools/support.

## What stays on your device, always

Everything you capture is stored locally and is never transmitted. That is not a promise layered on top of a server — there is no server. Tenon Cam has no backend, no cloud sync and no account system.

- Every photograph you take, including the stamp burned into it
- The GPS position and street address drawn onto the stamp
- Projects, and any project name or note you type
- Your company logo
- PDF binders and ZIP exports you generate
- Your settings, including stamp defaults and date format

## The four things that do use the network

Each row names a destination, when it is contacted, and what is sent. No row carries a photograph, a project, a note or a binder.

| Destination | When | What is sent |
| --- | --- | --- |
| Expo Updates (u.expo.dev), operated by Expo, United States | On each cold launch of a release build | The project identifier, the build''s runtime fingerprint, the release channel, the platform and the app version. If a JavaScript update is available, it is downloaded. No identifier of you is sent. |
| The phone's own geocoder — Apple on iOS, Google on Android | On a capture that has a GPS fix, with location permission granted | The coordinates of the shot, and nothing else, with a 1.5 second timeout. It returns a street address, which is drawn into the stamp. The photograph itself is never sent. This is the platform''s own service, not ours, and we receive no copy. |
| www.cloudflare.com, and www.google.com only as a fallback | At most once every ten minutes, to cross-check the clock | Nothing. It is a bare request with no body, no header of ours and no identifier; only the server''s Date response is read. It exists so a timestamp can say whether the phone''s clock agreed with the network. |
| RevenueCat, operated by RevenueCat Inc., United States | On cold launch, and when you open the purchase screen, buy, or restore | An anonymous installation identifier generated by the purchase SDK, the store''s own receipt or purchase token, product identifiers, and device, OS and app-version metadata. The app has no accounts and hands it no identifier of yours. It answers one question: has this device bought the paid features. |

_Every outbound connection Tenon Cam makes_

## What Tenon Cam does not do

These absences are worth stating, because much of this category does the opposite.

- No advertising, no ad network and no ad SDK of any kind
- No crash reporter and no analytics SDK — not one, anywhere in the app
- No tracking as Apple defines it: nothing is linked with third-party data for advertising, and nothing is shared with a data broker
- No account, no sign-in, no email address collected
- No photo-library upload, and no background location
- No sale or sharing of personal information, under any definition

## Why the app declares Location

The App Store privacy label lists Precise Location, and that is deliberate. The only thing the app does with your position is send the coordinates of a shot to the phone''s own geocoder to get the street address for the stamp — the platform handles it, we never receive it, and it is not retained anywhere by us.

A reasonable reading of the store rules would let that go undeclared, as data processed to service your immediate request. It is declared anyway. On an app whose entire purpose is that its photographs can be trusted, a privacy label that undersells what leaves the phone would be the wrong place to be clever.

## Children

Tenon Cam is a professional tool for construction trades and is not directed at children. It has no account system and collects no information intended to identify anyone. Its age rating declares no objectionable content of any kind.

## Legal basis, retention and international transfer

Where the GDPR or the UK GDPR applies, the update check, the clock cross-check and the geocode rest on legitimate interest (Article 6(1)(f)) — delivering fixes, and producing a timestamp and an address that are worth relying on. Purchase validation rests on performance of a contract (Article 6(1)(b)). There is no consent-based processing, because there is no advertising or analytics to consent to.

The processors named above are established in the United States and each publishes its own retention schedule and transfer mechanism; the geocoder is the platform''s and is governed by Apple''s or Google''s own terms. Tenon Tools holds no copy of any of it and operates no database of app users.

## Your rights

Depending on where you live, you may have the right to access, correct, delete, restrict, or object to processing, and to lodge a complaint with your supervisory authority. Use the support page to make a request.

In practice the fastest remedy needs no request at all: deleting the app removes every photograph, project and binder it holds, because all of them live only on your device. Purchase records are held by Apple or Google and by RevenueCat, not by Tenon Tools.

## Changes to this policy

The date at the top is the date it last changed. Because the table above is generated against the app''s source on every build, a change to what the app sends cannot ship without this page changing with it.

## FAQ

### Do my photos ever get uploaded?

No. Photos are written to the device and never transmitted. A photo or a PDF binder leaves only when you send it yourself through the share sheet.

### What is sent when the app finds my location?

The coordinates of the shot, to the phone''s own geocoder (Apple''s on iOS, Google''s on Android), to get a street address for the stamp. The photograph is never sent, and we never receive the coordinates.

### Does Tenon Cam work without a network connection?

Yes. Capture, stamping, projects and PDF binders all work with no signal. Without a connection the clock cross-check and the address lookup simply do not happen, and the stamp says so.

### Does it show ads or track me?

No. There is no ad network, no analytics SDK and no crash reporter in the app, and nothing it sends is linked with third-party data for advertising.

---

_Tenon Cam produces tamper-evident photographs, not legal proof. The stamp is burned in at capture and a hash is written into the file, which makes later alteration detectable — it is not a certification, and this page describes data handling rather than giving legal advice._

Page: https://tenon.tools/cam/privacy/ — this file is its markdown mirror. All mirrors: https://tenon.tools/llms.txt
