Last updated: August 5, 2026
Sentry Studio is a free, open-source project maintained by Jhoan Romero and Scott Vandereems ("we", "us", "our"). This Privacy Policy explains what data we collect, why we collect it, and how we handle it across our free apps and services:
Sentry Cloud (our paid cloud sync service at sentryusb.com) is operated separately and is not covered by this policy. It has its own Terms of Service and Privacy Policy at sentryusb.com/legal.
We are committed to transparency. Sentry Studio is designed with a privacy-first approach — your dashcam footage and personal information stay on your local machine or device unless you explicitly choose to share them, including through clip sharing, diagnostics, legacy human support chat, or AI Support where offered.
Our website is an informational site. We do not use analytics, tracking scripts, or advertising of any kind on sentry-six.com. With the exception of strictly necessary security cookies used by our infrastructure provider (Cloudflare) to prevent bot attacks, we do not deploy cookies on your device.
The website and the free apps described in this policy have no user accounts or login systems. (Sentry Cloud, our separate paid sync service, does use accounts — it is governed by its own policy at sentryusb.com/legal.) The clip sharing service (clip.sentry-six.com) is a separate service with its own data practices, described below.
The website uses the following third-party services:
__cf_bm cookie strictly for bot management and security purposes. This is controlled by Cloudflare, not by us. See Cloudflare's Privacy Policy.All of your video files, TeslaCam footage, and SEI telemetry data remain entirely on your local machine. The application processes everything locally. We never access, upload, or transmit your footage — unless you explicitly choose to share a clip using the Clip Sharing feature.
To maintain application security, prevent API abuse, and ensure technical compatibility, the app performs a mandatory check with our server during update checks. This includes:
This reporting is a functional requirement for the secure operation of the Service and cannot be disabled. This data helps us ensure you are running a secure version of the app and prevents unauthorized API usage.
Diagnostics are never collected automatically. They are only uploaded when you explicitly approve sending them through an in-app support feature. Diagnostic data includes:
Diagnostics are stored on our support server for 7 days and then automatically deleted. They are accessible only by the Sentry Studio developer via a secure passcode. If diagnostics are sent through the legacy human-support workflow, a forwarded copy may also remain in its private Discord thread as described below.
Some covered apps continue to provide the legacy in-app support chat for communicating directly with the developer. When you open a legacy support ticket:
Local copies of legacy support diagnostics and attachments are automatically deleted 7 days after the last activity, even if the ticket remains open. The open ticket record, associated IP metadata, and ordinary text messages remain until the ticket is resolved; after closure, those remaining local records are automatically deleted 7 days after the last activity. The corresponding private Discord thread is archived when the ticket closes but is not currently deleted on that seven-day schedule; its forwarded messages and attachments remain until we manually delete the thread or Discord removes them under its policies. This automatic private-thread forwarding is part of the legacy human-support workflow and is different from the optional Discord link in AI Support.
If AI Support is offered in the app or version you are using, it is clearly identified as the online AI Support Assistant described in Section 7. It is not a human or a model running solely on your device. Messages and files are handled according to the disclosures, consent controls, and retention periods in that section.
Your preferences (language, theme, layout, etc.) are stored locally on your machine in a local configuration file. These settings are never transmitted to any server.
This section covers two separate Raspberry Pi products: Sentry USB (for Tesla vehicles) and Dash USB (for supported GM vehicles with the built-in Surround Vision Recorder dashcam). They use separate product-specific software and share a local-first design—your footage stays on hardware you control. They are not interchangeable. Where the two devices differ, including in what each one reports during update checks, this section says so explicitly.
Sentry USB and Dash USB perform their core recording, storage, viewing, and management work on the Pi and your local network. By default, dashcam footage stays on storage you control and is not uploaded to our servers. The Pi serves a local web dashboard for viewing and managing recordings. The limited outbound flows described below—such as update checks, notification pairing, support you initiate, community submissions, and destinations or services you configure—are exceptions to this local-first operation.
Both devices can also archive your clips to a destination you configure — a CIFS/SMB share, an NFS share, an rsync target, or an rclone remote. Those destinations are yours, not ours: footage copied to them travels directly from your Pi to the storage you chose and does not pass through our servers. If you do not configure an archive destination or another optional sync service, footage remains local. Dash USB has no Sentry Cloud integration, but it may archive footage to a cloud-backed rclone remote you configure; that destination is operated by you or your chosen provider and is outside this policy. Sentry Cloud is available only to Sentry USB users who choose it. It syncs encrypted drive-history and telemetry data—not dashcam video—and is governed by its separate policy.
Dash USB exists because GM's Surround Vision Recorder keeps only a rolling window of footage (approximately 2 hours) before overwriting it. Dash USB snapshots that footage before the vehicle deletes it and retains it according to the storage and archive destination you provide.
When mobile push notifications are enabled, the Pi registers a unique device_id and device_secret with our notification backend (notifications.sentry-six.com). These credentials are used solely to authenticate push notification delivery and are not used for tracking or any other purpose.
Temporary 6-character alphanumeric codes are generated on the Pi and registered with our notification backend to pair with the iOS app. Pairing codes expire after 5 minutes and are automatically deleted once consumed or expired.
The Pi advertises itself on your local network via mDNS so it can be reached by name and discovered by companion software. Each device advertises a product-specific service record (_sentryusb._tcp or _dashusb._tcp) alongside a standard _http._tcp record, reachable at sentryusb.local or dashusb.local. This data never leaves your local network.
During initial setup, the Pi may advertise a BLE service for WiFi configuration. WiFi credentials are transmitted over BLE directly between your phone and the Pi and are never sent to any external server. This applies to both Sentry USB and Dash USB.
Sentry USB contacts api.sentry-six.com during its update check so it can report whether a compatible update is available and help us identify vulnerable builds. By default, this request has no device identifier. It includes:
A one-way salted SHA-256 hash derived from the board serial is included as a device fingerprint only if you explicitly opt in to analytics in setup or under Settings → System. The opt-in is off by default and can be changed at any time. When opted out, Sentry USB stops sending the fingerprint and its future update checks create no new per-device record. Opting out does not automatically erase an analytics row sent earlier; you may request its deletion using the contact details below.
Sentry USB also sends a single aggregate install ping the first time it runs. The request has an empty body—no device identifier, version, or configuration—and the server persists only an aggregate daily install counter. As with any internet request, the server necessarily sees the connection's source IP; the application uses it only in a short-lived in-memory rate-limit bucket. The ping fires once per installation and is not linked to the optional analytics fingerprint.
Dash USB performs a daily update check with our server (api.sentry-six.com) so it can tell you when a new release is available and so we can detect devices running a vulnerable build. By default this check carries no device identifier. It sends:
A device fingerprint — a one-way salted SHA-256 hash derived from the board's serial number — is included in this check only if you explicitly opt in to analytics, either in the setup wizard or afterwards under Settings → System → Analytics opt-in. This setting is off by default, takes effect immediately when you change it, and is the only setting that causes a device-derived identifier to leave your Pi. When you are opted out, the fingerprint is not sent on future checks and those checks create no new per-device record. Opting out does not automatically erase an analytics row sent earlier; you may request its deletion using the contact details below.
Dash USB also sends a single aggregate install ping the first time it runs. The request has an empty body — no device identifier, version, or configuration — and our server persists only a daily aggregate count. The connection's source IP is necessarily seen and is used by the application only in a short-lived in-memory rate-limit bucket. It fires once per installation and never again.
Some Sentry USB and Dash USB versions continue to include the legacy human support chat described in Section 2. Messages are proxied through api.sentry-six.com and forwarded to a private Discord thread, and the legacy retention periods apply. If AI Support is offered in a particular product or version, the interface will clearly identify it as AI and the disclosures, consent controls, and retention periods in Section 7 will apply. This does not mean AI Support is currently available in every product.
If you submit a wrap or lock-chime file to the Sentry USB community library, we receive the submitted file (and any optional wrap-preview file), display name, applicable vehicle model for wraps, original filename for wraps, file size, lock-chime duration where applicable, and the connection's source IP. Our server also generates a submission code and records review status and timestamps. Current Rusty versions send no device or hardware fingerprint. The IP is used for rate limiting and abuse investigation and is retained with the submission record. Pending and approved asset files remain until declined or manually removed. Declining a submission deletes its asset file, but the submission record—including its source IP and review metadata—has no fixed automatic deletion period and remains until manually removed or deletion is requested. Submission metadata and a private review link or file may be forwarded to our private Discord moderation workflow; an item is not placed in the public library until approved. We process the submitted content and publishing metadata as necessary to provide the community-publishing service you requested, and we rely on legitimate interests for proportionate rate limiting, abuse investigation, and moderation.
Current Rusty downloads send no custom or device identifier, although the source IP is necessarily seen and briefly held in an in-memory rate-limit bucket. Older clients may still send a legacy fingerprint that created a per-item unique-download record; those legacy records may remain until manually deleted. Contact us to request deletion. Do not submit a file or download from the library if you do not want the described processing.
The Sentry Connect app connects to Sentry USB devices for camera viewing, file browsing, device setup, and push notifications. It also delivers push notifications from Dash USB devices via the notification pairing described below. The app's local device discovery, Bluetooth setup, and camera streaming features do not currently support Dash USB devices — where a subsection below refers only to Sentry USB, that is why.
The app streams and displays dashcam footage from your Sentry USB device over your local network. Video data never leaves your local network and is never uploaded to our servers.
When you enable push notifications, Apple assigns your device a unique push notification token (APNS token). This token is:
When you pair with a Sentry USB or Dash USB device for push notifications, the following data is sent to our notification backend:
You can remove pairings at any time from the iOS app settings or the Pi's web interface, which deletes your APNS token from our servers.
Device connection info (hostname, IP address, display name, BLE identifier) is stored locally on your device using iOS UserDefaults. This data is never transmitted to any external server.
The app uses CoreBluetooth for initial device setup, including WiFi configuration. BLE communication occurs directly between your iPhone and the Sentry USB Pi. No BLE data is sent to external servers.
The app uses Bonjour/mDNS to discover Sentry USB devices on your local network. Discovery data (IP addresses, hostnames) stays on your device and is never transmitted externally.
The iOS app continues to include the legacy human support chat described in Section 2. When using that chat, your APNS token may also be registered with the support backend to receive reply notifications. The legacy data practices and retention periods apply. If AI Support is offered in a future iOS version, the app will clearly identify it as AI and the disclosures, consent controls, and retention periods in Section 7 will apply.
The Sentry Connect iOS app does not include any analytics SDKs, crash reporters, or advertising frameworks. We do not track your usage patterns within the app.
Sentry Drive is a desktop application for Windows, macOS, and Linux that visualizes and analyzes your drive history from the SEI telemetry embedded in TeslaCam files. All drive processing happens locally on your computer — your footage and telemetry are never uploaded to us.
Sentry Drive reads the SEI data in your TeslaCam files (GPS coordinates, self-driving state, speed, pedal inputs, and similar) and the optional drives-data.json produced by Sentry USB. This data is processed and stored only on your local machine.
To display your drives on a map, the app loads map tiles from third-party tile providers (OpenStreetMap/CARTO and Google Maps, depending on the selected map style). Because the tiles requested are determined by where your drives took place, your approximate drive locations are necessarily shared with the chosen tile provider as part of normal map rendering.
The following features transmit data only when you explicitly choose to use them:
api.tessie.com using an API token you provide to retrieve your drive history. That data is governed by your relationship with Tessie. See Tessie's Privacy Policy.Sentry Drive checks for new versions through GitHub Releases. Unlike Sentry Studio and Sentry USB, it does not send a hashed device identifier on update checks.
Sentry Drive is open-source software (originally derived from Sentry USB). Source code: github.com/Sentry-Six/Sentry-Drive.
When you use the clip sharing feature to generate a shareable link, the following data is collected:
When someone views a shared clip, we record their IP address to count unique views (one view per IP per clip). This data is deleted when the clip expires.
Shared clips are publicly accessible to anyone with the link. There is no password protection. Do not share clips containing sensitive or private information.
Shared clips are automatically deleted from our servers after a user-selected duration (up to 7 days, default 72 hours). You can also delete your clip at any time using the delete token provided at upload. Once deleted, the video file, thumbnail, and associated view records are permanently removed.
Where offered, the AI Support Assistant is an online, automated service. It is not a human, and the AI model does not run solely on your Sentry USB or other local device. When you use it, your messages and the assistant's responses are transmitted over the internet through api.sentry-six.com. We provide the assistant with product-specific instructions and knowledge, along with relevant product and software-version context, to tailor support to the product you are using.
Every AI Support conversation is logged on our server as it occurs, whether or not it is escalated. Records may include your messages, AI responses, timestamps, a pseudonymous conversation identifier, and product and software-version context. Before retaining a transcript, we apply automated redaction intended to remove common secrets and personal identifiers. Automated redaction may not catch everything, so do not include passwords, access tokens, precise location data, or other information you do not want to share. The public IP seen from the Pi's connection is processed separately for rate limiting and security: raw values remain only in short-lived in-memory rate buckets (up to about two hours), while a gateway-keyed one-way hash and daily diagnostic-upload counters may remain for up to about 49 hours and are not linked to the transcript or diagnostic text.
Authorized Sentry Studio maintainers may review redacted transcripts to provide support, investigate abuse and service failures, identify inaccurate or hallucinated answers, and improve the assistant's prompts, product knowledge, routing, safeguards, and support quality. We do not use retained transcripts or uploaded files to train a public or third-party general-purpose AI model.
To generate a response, relevant conversation content and all or relevant portions of files you approve may be processed by Ollama Cloud, our third-party AI inference provider. According to Ollama's current Privacy Policy, cloud-hosted prompts and responses are processed transiently to provide the service, are not stored beyond the time required to fulfill the request, and are not used to train AI models. Ollama's practices are governed by its own policy and may change. This processing may occur outside Canada, including in the United States.
The assistant may ask for a specific diagnostic report or file, but it cannot browse your device or read files automatically. Nothing is generated, collected, or uploaded until you affirmatively approve that specific request. In the current Sentry USB diagnostics flow, selecting Approve once generates the named report on your device and immediately uploads it to our backend; there is no arbitrary-file access or standing permission. The report can include software and service state, hardware and storage status, network configuration and local addresses, recent logs and errors, and identifiers or location-related data that appear incidentally in those logs. All or relevant portions may then be processed by Ollama Cloud and reviewed by authorized maintainers for the purposes described above. Declining a request does not prevent you from continuing the conversation.
Approved reports or files are retained on our server for 7 days and then automatically deleted. Do not approve an upload if the disclosed categories may contain credentials, private keys, access tokens, location data, or third-party information you are not authorized to share.
Redacted conversation transcripts are retained for 90 days after the last activity and then automatically deleted or irreversibly de-identified. Limited records may be retained longer where required by law or necessary to investigate abuse or a security incident.
To resume an anonymous conversation, the app stores its random conversation identifier and access token in that browser's local storage. Anyone with access to that browser profile may be able to open the conversation until it is deleted or expires. Using the in-app New chat/delete control removes the server copy and local token; clearing the site's browser data removes the local copy only.
After a conversation is deleted, its messages and uploaded files are removed immediately. A non-content deletion receipt containing the conversation identifier, one-way hashes of the access token and deletion idempotency key, and the deletion time remains available solely for safe retries and replay prevention until it expires 24 hours after deletion. The expired receipt is removed during the next scheduled cleanup sweep, normally within about one additional hour.
On Sentry USB Rusty, the browser normally reaches the Pi over local HTTP. Chat content, conversation access tokens, and approved diagnostic uploads are therefore not encrypted on that browser-to-Pi hop; use AI Support only from a trusted local network. The Pi's onward connection to api.sentry-six.com uses HTTPS.
The assistant may suggest joining our Discord server for further community or human help. Joining Discord is optional. Opening the link does not automatically transfer your AI conversation or files to Discord. Anything you choose to post on Discord is governed by Discord's Privacy Policy.
| Data Type | Retention Period | Deletion Method |
|---|---|---|
| Shared video clips | Up to 7 days (user-selected) | Automatic + manual via delete token |
| Legacy human-support ticket records, associated IP metadata, and ordinary text messages | Open until resolved; closed: 7 days after last activity | Automatic after closure retention period |
| Local copies of legacy human-support diagnostics and attachments | 7 days after last activity, whether the ticket is open or closed | Automatic |
| Legacy support content forwarded to a private Discord thread | No fixed automatic deletion period | Thread archived on closure; retained until manual deletion or removal under Discord's policies |
| Redacted AI Support conversation transcripts | 90 days after last activity | Automatic deletion or irreversible de-identification; deletion on verified request |
| AI Support files you approve for upload | 7 days | Automatic |
| AI Support diagnostic-upload quota records (gateway-keyed IP hash plus daily count and byte totals) | About 49 hours | Automatic after 48-hour expiry plus the scheduled hourly cleanup sweep |
| AI Support non-content deletion receipts | Expires 24 hours after deletion | Automatic on the next scheduled hourly cleanup sweep |
| Diagnostic uploads | 7 days | Automatic |
| Community wrap or lock-chime files, submission metadata, and associated source IP | Asset file until declined or manually deleted; submission metadata and IP have no fixed automatic period | File removed on decline or manual deletion; metadata and IP on manual removal or verified request |
| Legacy per-item community-download fingerprint records | Until manually deleted | On verified request; current Rusty versions do not create them |
| Installation records — Desktop (secure device hash) | Indefinite | On request |
| Installation records — Sentry USB (secure hardware hash, analytics opt-in only) | Until manually deleted | Opting out stops future identified checks; deletion on verified request |
| Installation records — Dash USB (secure hardware hash, analytics opt-in only) | Until manually deleted | Opting out stops future identified checks; deletion on verified request |
| Aggregate install counts — Sentry USB and Dash USB (daily totals, no linked identifiers) | Indefinite | Not applicable — no per-user data is stored |
| Other rolling rate-limit counters (IP-based or secure-device-hash based) | In-memory only; normally no more than about two hours | Cleared on server restart or window expiry |
| Security lockout & ban records (IP-based) | Indefinite | At our sole discretion |
| Local app settings | Until you uninstall | Deleted with app data on uninstall |
| APNS device tokens | Until unpairing or token invalidation | Manual unpair or automatic cleanup |
| Notification pairings | Until manually removed | User-initiated via app or Pi web UI |
| Pairing codes | 5 minutes | Automatic (expiry + consumed cleanup) |
| Device registrations (device_id, hostname) | Indefinite (while Pi is active) | On request |
| Saved devices (iOS local) | Until app deletion or manual removal | User-initiated or app uninstall |
Our backend server (api.sentry-six.com) and notification service (notifications.sentry-six.com) are hosted on a dedicated server in Montreal, Canada provided by OVHcloud. Data you send to our API — including shared clips, diagnostics, legacy human support messages and attachments, AI Support transcripts and approved files, and notification pairing data — is stored in Canada for the retention periods described above. Legacy human support messages and attachments are also forwarded to a private Discord thread for the developer to respond.
Our website (sentry-six.com) is served globally via Cloudflare's CDN, which may route your request through servers in various countries.
AI Support content may also be processed transiently by Ollama Cloud outside Canada, including in the United States, as described in Section 7. By using our services, you acknowledge that your data may be processed in Canada and by these providers in jurisdictions different from your own.
We use IP addresses for rate limiting, abuse prevention, and security purposes. IP addresses are used to:
We reserve the right to restrict or deny access to any of our services, at any time, for any reason, without notice or explanation. This includes but is not limited to temporary lockouts, permanent IP bans, and content removal.
For the free apps and services covered by this policy (this section does not describe Sentry Cloud — see sentryusb.com/legal):
These apps are available worldwide, so residents of the EEA and UK may use them. For the limited personal data we receive—including opt-in update-check identifiers and data you actively send via clip sharing, diagnostics, legacy human support chat, or AI Support:
Our services are intended for users who are at least 18 years of age. We do not knowingly collect data from anyone under 18. If you believe someone under 18 has provided us with data, please contact us and we will take steps to remove it.
We take reasonable measures to protect your data, including:
The Sentry USB web interface is normally opened over plain HTTP on your local network (for example, http://sentryusb.local). Traffic between your browser and the Pi—including a message before the Pi forwards it to our external API over TLS—is therefore not encrypted by HTTPS. Use Sentry USB only on a trusted local network, enable its web authentication, and do not expose the Pi's web port directly to the internet.
No system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
Our services may link to external sites such as GitHub (for downloads and source code) and Discord (for community and support). These third-party services have their own privacy policies, and we are not responsible for their practices.
Ollama Cloud acts as an AI inference provider for AI Support and processes relevant conversation or approved file content as described in Section 7. Legacy human support messages and attachments are automatically forwarded to a private Discord thread so the developer can respond. By contrast, opening the optional Discord link suggested by AI Support does not automatically send Discord your AI conversation or files.
Sentry Studio is not affiliated with Tesla, Inc. in any way. Dash USB is likewise not affiliated with General Motors in any way.
The Sentry Studio desktop viewer and Sentry Drive are open-source software licensed under the MIT License. The Sentry USB and Dash USB Pi device software is source-available under the PolyForm Noncommercial License 1.0.0 (some bundled components remain MIT-licensed). In every case, you can review exactly what data these applications collect by inspecting the source code on GitHub:
The Sentry Connect iOS app is distributed via the Apple App Store and is not open source.
We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of our services after changes constitutes acceptance of the revised policy.
If you have questions about this Privacy Policy or wish to exercise your data rights, you can reach us through: