Skip to content
Camcorder
Download About Support
About
The documents
Overview
Privacy
Terms
Accessibility
Release notes

Privacy

Camcorder is published by Manolab, LLC Β· in effect from 2 October 2026

Camcorder keeps your footage on your phone. It sends something only to do a thing you asked for β€” hand clips to a phone nearby, put a film up at a link, write to us β€” plus, on TestFlight builds, a few small requests to our own server, described below. There is no account, no analytics and no tracking. Everything below was checked against the app's own source rather than written from memory.

The short version

No account, no analytics, no crash reporter, no advertising, no third-party code in the app. The only servers it talks to are ours (camcorder.media and our contact form, both run on Cloudflare) and Apple's.

Your clips are files on your phone. Nothing is uploaded unless you publish a film, and nothing is deleted except by you. That last one is a rule the app is built around, not a promise invented for this page.

A film you publish is public to anyone who has its link, until you take it down.

This website sets no cookies, keeps nothing in your browser, runs no analytics, and loads nothing from anybody else's server.

Who this covers

Camcorder is an iPhone and iPad app published by Manolab, LLC, a US company. It is a prototype distributed through Apple's TestFlight; it is not on the App Store.

This policy covers the app, the films it publishes at camcorder.media, and this website.

The data controller is Manolab, LLC, 3463 State St #275, Santa Barbara, CA 93105, USA.

What the app keeps, and what it never asks for

It never asks where you are: there is no location access in the app at all. It never reads your Photos library, your contacts or your name. It contains no analytics library, no crash reporter and no telemetry.

It makes one random identifier for itself the first time it runs, stored on the phone, so that clips from one phone can be told from another's when you share. Deleting the app deletes it.

Moments you save are JPEGs carrying the date and time they were filmed, including the time-zone offset, so Photos files them on the right day. Films you export carry no metadata at all.

The permissions it asks for

Five, each for one job. These are the app's own words, the ones iOS shows you when it asks:

  • Camera β€” β€œCamcorder is a camera. It needs the camera to record your clips.”
  • Microphone β€” β€œCamcorder records sound with your clips.”
  • Local network β€” β€œCamcorder finds the other phones near you, so their clips can join your film.” Asked the first time you open the sharing screen, not at launch, so a feature you never use never interrupts you.
  • Photos, add only β€” β€œCamcorder saves your finished films to your Photos library.” The app can add a film to your library. It cannot read what is already in it.
  • Notifications, badge only β€” no sound, no banner. Asked only once you follow a channel, so the app's icon can show that something new is up. It is never used to send you anything.

Refusing any of them costs you that one feature and nothing else.

Sharing clips between phones

When more than one phone was at the same event, you can pull other people's clips into your film. It happens directly between the phones over the local network, through Apple's MultipeerConnectivity. No server of ours is involved and nothing crosses the internet.

The app is not on the network at all until somebody opens the sharing screen. Opening it is what starts this phone advertising, and it then stays findable until the app is closed β€” leaving the sharing screen stops it looking for other phones, but not other phones finding it. While it is advertising, what a nearby Camcorder can see is the random per-install identifier, whether that phone has any clips at all, the phone's name β€” and only if iOS hands the app a real one, which for most phones it does not β€” the colour this phone has chosen for its own dot, and the colours it remembers for other people it has already met: a short list of colour names, each paired with the first eight characters of that person's identifier.

The link between two phones is encrypted; the session is created with encryption required, and a pull is one-directional: clips travel to the phone that asked for them.

There is no per-transfer approval, and it is worth being exact about that. A findable phone accepts the connection, answers a request for its clip list and hands over the files asked for, without asking its owner anything at the time. Opening the sharing screen is the agreement; there is not a second one per clip or per person. If you would rather not be findable, close the app β€” that is what ends it. Apple's framework caps one session at eight phones including yours.

A clip that arrives keeps the identifier of the phone it came from. That is what the small coloured dot on a tile means: whose clip it is. Each phone picks one of eight colours for its own dot, and remembers the colour it first saw a person wearing β€” for good, so their clips stay that colour even if their own phone later picks a different one. Where two phones would otherwise show the same colour for different people, they negotiate so no colour on your screen ever belongs to two people at once.

Publishing a film to a link

On TestFlight builds you can put a film up at a link on camcorder.media. Anyone who has the link can watch it; the page asks search engines not to index it.

What goes up is the film itself β€” each clip's video and sound, its pictures, and the soundtrack β€” plus, for each clip, when it was filmed, its length, the look it was filmed in, and a short code derived from the app's random identifier, so clips from different phones can be told apart. No location, no project name, nothing about you.

There is no account. The app makes a signing key the first time it needs one and keeps it in your iCloud Keychain, so your other devices count as the same publisher; every change to a film is signed with it, and nothing secret is ever sent. Our server knows a publisher only as a code derived from that key, and never shows it to anyone watching.

On TestFlight builds the app checks camcorder.media each time it comes to the front, to see what you and the channels you follow have up. The first time, that creates your key and an empty channel record on our server, even if you never publish anything.

A film goes on your channel unless you untick it, and a channel has a public page listing its films. You can take a film down at any time from the app: that deletes its pieces, its listing and its link from our server. Your channels and any name you gave yourself stay until you delete them. If you lose the key β€” every device signed out of iCloud β€” the app can no longer take your films down, and you need to write to us.

Films are stored with Cloudflare (R2), in western North America. Watching one in Safari uses the browser's own player; other browsers load an open-source player (hls.js) from jsDelivr, which sees that request like any server does.

Following channels, and a television

Following a channel is kept on your phone only. To see what is new, the app asks camcorder.media for that channel's list of films β€” an ordinary request carrying nothing about you β€” when it comes to the front, every couple of minutes while it is open, and now and then in the background. Our server is never told who follows whom.

The one exception is a television you link by scanning its code. Then the list of channels you follow is uploaded so the television can show them, sealed with a key our server is never given: we store bytes we cannot read, at an address we cannot tie to you. It is updated when you follow or unfollow.

Writing to us

The support page on this site, and the app's Write to us page, send your message to us. From the app it carries the app's version and build, your iOS version, the phone's model and its language setting; from this site, the page it was sent from and your browser's language. A name and an email go only if you type them. No footage and no identifier. Before it sends, Cloudflare Turnstile checks that a person is writing, inside the form.

Messages arrive as private issues in our tracker on GitHub, readable only by the team that builds Camcorder.

Reporting a film

Anyone can report a published film from its page or from the app. A report keeps the reason given, the time, and the country the request came from β€” not your address or anything else about you. Reports are kept after a film is taken down, as a record of why.

What else leaves your phone, and only because you said so

Apart from everything above, two things leave, and each is a decision you make at the moment it happens:

  • A film you export. It goes through the iOS share sheet to wherever you send it β€” Photos, Messages, another app β€” and what happens after that is between you and whatever you sent it to.
  • A diagnostics report, if you choose to send one. It is a plain text file the app writes when you tap share on its diagnostics page, and it carries the build number, the phone's model and iOS version, the first eight characters of the app's own random identifier, how many projects and clips are on the phone, the names of files it could not read, and the rare events of that session. No footage, no names, no contact details.

Both go out through the system share sheet, which means you pick the destination and can change your mind.

What our servers log

Our servers keep no logs of their own: no addresses, no browser details, no visit records. Your network address is used for a moment to limit how often one place can make requests, and is not stored.

Cloudflare, which runs our servers and serves this website, handles every request under its own privacy policy and keeps its own records of traffic for security and operation.

Cloudflare's privacy policy

Buying

The app contains Apple's in-app purchase for a later version; it is not offered on TestFlight today. Any purchase would be handled by Apple, and nothing about it reaches us beyond what Apple tells every developer.

TestFlight

The app is handed out through Apple's TestFlight. Apple shows us crash reports, which build a tester is on, and how many people installed it. That collection is Apple's, under Apple's terms, and it is the only thing anyone sees about your use of the app β€” we add nothing to it and have nothing of our own.

Apple's privacy policy

This website

No cookies, no local storage, no analytics, no tracking pixels, no advertising. The type is set in fonts already on your device. The one thing fetched from elsewhere is the person-check on the support form, which loads only on that page.

This website is served by Cloudflare; see What our servers log above.

Your rights

If you are in the EU or the UK, the GDPR gives you the right to see what is held about you, to correct it, to have it deleted, to object to its use, and to complain to a supervisory authority.

What we can hold is small: films you published and their channels, a name you gave yourself, a message you sent, a report you filed. You can take films down yourself; for anything else, ask and it goes.

Children

The app records nothing about who is filming or who is in the picture. What a phone records stays on the phone that recorded it unless somebody publishes it, and a published film should only show people who agreed to be in it β€” children above all.

Changes to this policy

If it changes in a way that matters, the date at the top changes with it.

Contact

Write to us from the support page on this site, or from Write to us in the app. Both reach a person at Manolab.

By post: Manolab, LLC, 3463 State St #275, Santa Barbara, CA 93105, USA.

Write to us

Β© 2026 Manolab, LLC
build 66e79cb Β· 2026-10-02