Privacy Policy
Sentinel (“Sentinel”, “the Service”, “we”, “us”, or “our”) is an anti-theft solution for macOS, iOS, and watchOS, operated by Aloïs Canot, an independent sole developer established in France (“the Developer”). This Privacy Policy explains what personal data we collect when you use Sentinel, how we use that data, with whom we share it, how long we keep it, and the rights you have under applicable privacy laws, including the European Union General Data Protection Regulation (GDPR).
We have written this policy in plain language wherever possible. If you have questions about anything below, please contact us at alois@canot.dev.
1. Who We Are and How to Contact Us
Sentinel is designed, developed, and distributed by:
For the purposes of the GDPR, the Developer is the data controller for all personal data processed through Sentinel. You may exercise any of your rights under this policy, or ask any question about how your data is handled, by emailing the address above.
2. Scope of This Policy
This Privacy Policy applies to:
- The Sentinel macOS menu bar application (distributed as a DMG from our website);
- The Sentinel iOS companion application (distributed via the Apple App Store);
- The Sentinel watchOS extension that accompanies the iOS app;
- The Sentinel backend, hosted on Cloudflare Workers with a Cloudflare D1 (SQLite) database located in the European Union.
It does not apply to third-party services you may separately use (for example, Apple’s iCloud, your email provider, or your mobile network), which are governed by their own privacy policies.
3. Data We Collect
We collect only the data we need to operate Sentinel and to provide the anti-theft features you enable. Specifically:
3.1 Account data
- Email address, used to create and identify your account.
- Apple ID identifier (a stable, opaque user ID), if you choose to Sign in with Apple. We do not receive your Apple password.
3.2 Device and technical data
- Mac device metadata: computer name and model identifier, used to distinguish devices in your account and to display them in the companion app.
- iOS push notification token (APNs token), used to deliver alerts to your iPhone and Apple Watch.
3.3 Event data
- Event records generated by the Mac app: trigger type (for example motion detection, charger unplug, USB connect or disconnect, lid movement, failed login), timestamp, and a severity level.
- Location data, collected in two circumstances: (a) when you configure trusted or restricted geographic zones, we process the Mac’s approximate location to evaluate the zone; (b) when an event is triggered, we may include the Mac’s GPS position so you can locate the device.
3.4 Capture data
- Webcam photos captured from the Mac’s built-in camera at the moment an event is triggered, when you have enabled photo capture.
- Screenshots of the Mac’s display captured at the moment an event is triggered, when you have enabled screenshot capture.
Photos and screenshots are transmitted in base64 form through our backend and delivered to your iPhone, where they are cached locally. They are not retained long-term in our cloud storage (see Section 6 on retention).
3.5 Purchase data
- Apple transaction receipts and identifiers for any Pro subscription or lifetime purchase you make. Payment itself is handled entirely by Apple; we never see your payment card or Apple ID password.
3.6 What we do not collect
We do not collect browsing history, contacts, calendar, messages, microphone audio, health data, or content from files unrelated to a triggered event. Sentinel has no advertising identifiers or web tracking cookies.
4. How We Use Your Data
We use the data described above only for the following purposes:
- To provide the core service: creating your account, associating your Mac(s) and iPhone, evaluating triggers, and delivering alerts.
- To send you notifications through Apple Push Notification service (APNs), including photo and screenshot payloads when applicable.
- To operate the companion experience: showing your event feed, displaying captured media, and indicating device status.
- To process subscriptions and purchases through Apple StoreKit, and to grant you the appropriate entitlements.
- To secure the Service: detecting abuse, preventing unauthorized access, and investigating incidents.
- To comply with legal obligations to which the Developer is subject.
We do not sell your personal data, and we do not use it for advertising or profiling.
5. Legal Bases for Processing (GDPR)
Where GDPR applies, we process personal data on the following legal bases:
- Performance of a contract (Art. 6(1)(b)) for account creation, event delivery, subscriptions, and core functionality.
- Consent (Art. 6(1)(a)) for optional features you enable explicitly, including camera capture, screenshot capture, and location-based zones. You may withdraw consent at any time by disabling the feature in Sentinel’s settings.
- Legitimate interests (Art. 6(1)(f)) for security, fraud prevention, and ensuring the integrity of the Service.
- Legal obligation (Art. 6(1)(c)) where we must retain or disclose data to comply with applicable law.
6. Data Retention
We keep data only as long as necessary:
- Account data: retained for as long as your account exists. When you delete your account, it is removed within 30 days, except where law requires longer retention.
- Event records (trigger type, timestamp, severity, location): automatically purged after 90 days.
- Captured photos and screenshots: held in backend transit storage only long enough to deliver them to your iPhone (typically seconds to minutes). They are not written to long-term cloud storage. Cached copies on your iPhone remain there until you remove them.
- Purchase receipts: retained as long as your entitlement is active and for any additional period required by Apple or by tax law.
- Backups and logs: minimal operational logs (timestamps, error codes, request sizes) are retained up to 30 days for security and debugging, and contain no capture media.
7. How We Share Your Data
We share personal data only with the following categories of recipients, and only when necessary:
- Cloudflare, Inc., our backend infrastructure provider. Data is processed on Cloudflare Workers and stored in Cloudflare D1 (SQLite) within the European Union.
- Apple Inc., for push notifications (APNs), Sign in with Apple, and in-app purchases and subscriptions (StoreKit). Apple acts as an independent data controller for these services under its own privacy policy.
- Legal authorities, where we are legally required to disclose information (for example, valid court orders).
We do not share your data with advertisers, data brokers, analytics companies, or any third party for marketing purposes.
8. International Transfers
Our primary data storage is located in the European Union. Certain of our service providers (notably Apple and, in limited cases, Cloudflare) may process data in the United States or other jurisdictions. Where that is the case, we rely on appropriate safeguards such as the EU-U.S. Data Privacy Framework and the European Commission’s Standard Contractual Clauses.
9. Security
We take reasonable administrative, technical, and physical measures to protect your data, including:
- Transport encryption (HTTPS/TLS) for all connections between the Mac app, iPhone app, and backend;
- Access controls and authentication for our backend;
- Minimal retention of capture media;
- Segregation of account data from transient media;
- Regular review of dependencies and infrastructure configuration.
No system is perfectly secure. If we become aware of a data breach that is likely to affect your rights, we will notify you and the competent supervisory authority in accordance with Article 33 and Article 34 of the GDPR.
10. Your Rights
Subject to applicable law, you have the following rights:
- Right of access: obtain a copy of the personal data we hold about you.
- Right to rectification: correct inaccurate or incomplete data.
- Right to erasure (“right to be forgotten”): ask us to delete your data.
- Right to restriction: ask us to limit processing in certain cases.
- Right to data portability: receive your data in a structured, commonly used, machine-readable format.
- Right to object: object to processing based on legitimate interests.
- Right to withdraw consent at any time, without affecting the lawfulness of prior processing.
- Right to lodge a complaint with a supervisory authority. In France, the competent authority is the CNIL (www.cnil.fr).
To exercise any right, email alois@canot.dev. We will respond within one month, and may extend the period by two further months for complex requests, in which case we will inform you.
You can also delete your account directly from the iOS app, which will permanently erase associated personal data within 30 days.
11. Cookies and Similar Technologies
Sentinel does not operate a public web application and does not use cookies, web beacons, or tracking pixels. The only website we publish is an informational landing page that may include a minimal set of strictly necessary technical resources and no analytics.
12. Children
Sentinel is not directed to children under the age of 13 and we do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has created an account, please contact us at alois@canot.dev and we will delete the account and associated data.
For users in the European Union, you must be at least 16 years old to use Sentinel, or the minimum age of digital consent in your country, whichever is lower.
13. Automated Decision-Making
Sentinel may automatically classify events (for example, flagging a motion event as a potential theft trigger), but no decision that produces a legal or similarly significant effect on you is made solely by automated means. You remain in control of how you respond to alerts.
14. Third-Party Services
The operation of Sentinel relies on the following third parties, whose privacy policies apply in parallel:
- Apple Inc.: App Store, StoreKit, Sign in with Apple, Apple Push Notification service. See Apple’s Privacy Policy at apple.com/legal/privacy.
- Cloudflare, Inc.: Workers and D1 hosting. See Cloudflare’s Privacy Policy at cloudflare.com/privacypolicy.
We are not responsible for the privacy practices of these providers beyond the scope of our own processing.
15. Changes to This Policy
We may update this Privacy Policy from time to time, for example to reflect new features, legal requirements, or operational changes. When we do, we will:
- update the “Last updated” date at the top of this policy;
- post the new version at the same URL; and
- if changes are material, notify you by email or through the app.
Continued use of Sentinel after an update means you accept the revised policy.
16. Contact
For any question about this Privacy Policy, or to exercise your rights, contact:
Email: alois@canot.dev
We will do our best to respond promptly and, in any case, within the time limits set by applicable law.