[[double brackets]] is a placeholder that must be completed before this policy becomes binding.
Privacy Policy
The short version: Supervision is self hosted. Your cameras, recordings, and footage live on hardware you control and never reach us. The only personal data we handle is the small amount you give us to create an early access account — your name, email, and optional company — plus the minimal technical data any website generates. This policy explains it in full.
1. Who we are
The data controller for the personal data described here is [[LEGAL_ENTITY]] ("Supervision", "we", "us"), [[REGISTERED_ADDRESS]]. For privacy questions, contact hello@bipolarfactory.com[[PRIVACY_CONTACT]].
2. What this policy covers
This policy covers personal data processed by the supervisionvms.com website and the early access account system. It does not cover the footage or data inside your self hosted Supervision installation, because that data stays on your infrastructure and we have no access to it. When you run Supervision, you are the controller of the personal data your cameras capture, and you are responsible for it (see our Acceptable Use Policy).
3. What we collect
| Data | Why |
|---|---|
| Name | To address you and personalize your account and emails. |
| Email address | To verify it is really you, send your access code, deliver downloads access, and send product updates. |
| Company (optional) | To understand where Supervision is being run. You may leave it blank. |
| Email verification code | A one time 6 digit code is generated at sign in. We store only a keyed HMAC-SHA256 hash of it, never the code itself, and it expires after 10 minutes. |
Session cookie (sv_session) | A signed, HttpOnly cookie set after you verify your email, so the downloads page recognizes you. See our Cookie Notice. |
| Download records | When you download a build we record your email, the platform, version, file name, and a timestamp, so we understand which builds are in use. IP address and browser user-agent are not logged unless we explicitly enable it for abuse prevention. |
| Server and edge logs | Our host, Cloudflare, processes standard technical information (such as IP address and request metadata) to serve and protect the site. |
4. What we do not collect
Because Supervision is self hosted, we do not collect, receive, host, or have any access to:
- Your video streams, recordings, clips, screenshots, incidents, or exports.
- Your camera credentials, camera IP addresses, or network configuration.
- The user accounts, roles, or audit logs inside your Supervision server.
- Any footage of, or data about, the people your cameras capture.
All of that stays on the hardware you control.
5. How we use it
- To create and secure your early access account and verify your email.
- To give you access to downloads and to understand which builds are used.
- To send you service and product messages about Supervision (updates, availability, and important notices).
- To operate, protect, and improve the website.
- To comply with legal obligations and enforce our Terms.
We do not sell your personal data, and we do not use it for third party advertising.
6. Legal bases (GDPR)
Where the GDPR applies, we rely on: contract (to provide the account and downloads you request); legitimate interests (to secure the site, understand build usage, and send closely related product updates); consent where required (for example, any non-essential analytics); and legal obligation where applicable. You can object to processing based on legitimate interests as described in "Your rights".
7. Who we share it with
We share personal data only with service providers ("processors") that help us run the website, under agreements that require them to protect it:
- Cloudflare — website hosting, content delivery, edge functions, and the database that stores your account record.
- Resend — delivery of the verification and product emails we send to your address.
- [[ANALYTICS_PROVIDER]] — if and when we enable privacy-respecting analytics, described here and in the Cookie Notice.
We may also disclose data if required by law, to protect our rights, or in connection with a corporate transaction, subject to this policy.
8. How long we keep it
We keep your account data for as long as your account is active and for [[EMAIL_RETENTION_PERIOD]] after your last activity, after which we delete or anonymize it, unless we must keep it longer for legal reasons. Verification code hashes are cleared as soon as the code is used or expires. Download records are retained for [[EMAIL_RETENTION_PERIOD]] for product analytics. You can request deletion at any time (see below).
9. Your rights
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal data, to object to certain processing, and to withdraw consent. If you are in the EEA/UK (GDPR) or California (CCPA/CPRA), these rights apply to you; we do not "sell" or "share" personal data as those laws define it. To exercise any right, email hello@bipolarfactory.com and we will respond within the time required by law. You also have the right to lodge a complaint with your local data protection authority.
10. Cookies
We use one strictly necessary cookie (sv_session) so the downloads page can recognize a verified account. We do not use advertising or cross-site tracking cookies. Full detail is in our Cookie Notice.
11. International transfers
Our providers (Cloudflare and Resend) may process data in countries other than yours. Where required, such transfers are covered by appropriate safeguards, such as the European Commission's Standard Contractual Clauses.
12. Security
We use reasonable technical and organizational measures to protect account data, including HTTPS, HttpOnly and Secure cookies, signed sessions, and hashing of verification codes. No system is perfectly secure, but the amount of personal data we hold is deliberately small.
13. Children
Supervision is intended for businesses and adults. It is not directed to children, and we do not knowingly collect personal data from anyone under 16.
14. Changes
We may update this policy. We will revise the effective date above and, for material changes, take reasonable steps to notify you.
15. Contact
[[LEGAL_ENTITY]]
[[REGISTERED_ADDRESS]]
Email: hello@bipolarfactory.com