
Privacy
We would ratherbe checkedthan believed.
Every company in this category promises not to look at your video. We removed the possibility instead. Here is exactly how, in enough detail to argue with.

Frame read locallySealed · AES-256-GCM
Privacy
We built itso we couldn'tlook.
Every company in this category promises not to look at your video. We removed the possibility instead — which is a harder thing to build and a much easier thing to trust.
Video never leaves your home.
Streams are read on the Hub, in the house, and the frames are discarded as they are read. There is no upload path for footage, because we never built one.
Guardian Cloud cannot read photos.
What we route is a sealed envelope. We can see that it exists and where it is going. We cannot open it — not for a partner, not for a subpoena, not for ourselves.
Only your family holds the keys.
Keys are generated on your Hub and shared directly with your family's devices. If every server we own were taken tomorrow, not one photograph would be exposed.
Technical note
The long, boring, checkable version.
What is processed, and where
Camera streams are decoded on the Hub. Frames are held in memory only as long as inference takes, then dropped. Sensor events arrive as small messages over the local radio stack and are handled the same way. Nothing is written to disk in a form that could be replayed as video.
What leaves the house
A short sentence, a timestamp, a confidence value, and — only if your family enabled snapshots — up to three stills at reduced resolution. All of it is sealed with AES-256-GCM before it touches the network interface.
How the keys work
The Hub generates a household key pair at setup. Each family device generates its own on-device. Envelope keys are wrapped per recipient. Guardian Cloud stores ciphertext and routing metadata. It has never held a private key and there is no code path in which it could.
What we can see
That a household is online. That envelopes were posted, and to how many recipients. Approximate size. We cannot see contents, room names, event types, or which family member read what.
Retention
Envelopes expire on a schedule your family sets — 24 hours by default, up to 30 days. Expiry is a delete, on the mailbox and on every device that pulled it. There is no cold archive and no soft-delete flag.
Requests from third parties
We will comply with lawful orders by handing over what we hold: ciphertext and routing metadata. We cannot decrypt it. We publish a transparency count of such requests twice a year.
Training
No household's data is used to train models, ours or anyone else's. The on-device model that learns your parents' routine never leaves the Hub, and is destroyed if the Hub is factory reset.
If any of this turns out to be untrue, we would like to be the second people to know.