Privacy Policy

Last updated: August 5, 2026

Sentry Studio is a free, open-source project maintained by Jhoan Romero and Scott Vandereems ("we", "us", "our"). This Privacy Policy explains what data we collect, why we collect it, and how we handle it across our free apps and services:

  • Website — sentry-six.com
  • Desktop Application — Sentry Studio for Windows, macOS, and Linux
  • Sentry USB Device — Raspberry Pi-based smart USB drive for Tesla dashcam recording
  • Dash USB Device — Raspberry Pi-based smart USB drive for GM vehicles with the built-in Surround Vision Recorder dashcam
  • Sentry Connect iOS App — Companion mobile app for iOS (available on the App Store)
  • Sentry Drive — Desktop drive-history analytics app for Windows, macOS, and Linux
  • Clip Sharing Service — clip.sentry-six.com
  • Support API — api.sentry-six.com (update checks, diagnostics, legacy human support chat, and AI Support where offered)
  • Notification Service — notifications.sentry-six.com (push notification pairing and delivery)

Sentry Cloud (our paid cloud sync service at sentryusb.com) is operated separately and is not covered by this policy. It has its own Terms of Service and Privacy Policy at sentryusb.com/legal.

We are committed to transparency. Sentry Studio is designed with a privacy-first approach — your dashcam footage and personal information stay on your local machine or device unless you explicitly choose to share them, including through clip sharing, diagnostics, legacy human support chat, or AI Support where offered.

1. Website (sentry-six.com)

Our website is an informational site. We do not use analytics, tracking scripts, or advertising of any kind on sentry-six.com. With the exception of strictly necessary security cookies used by our infrastructure provider (Cloudflare) to prevent bot attacks, we do not deploy cookies on your device.

The website and the free apps described in this policy have no user accounts or login systems. (Sentry Cloud, our separate paid sync service, does use accounts — it is governed by its own policy at sentryusb.com/legal.) The clip sharing service (clip.sentry-six.com) is a separate service with its own data practices, described below.

Third-Party Services

The website uses the following third-party services:

  • Cloudflare Pages — Our website is hosted on Cloudflare's content delivery network. Cloudflare processes your IP address and request headers to serve the site, and may set a __cf_bm cookie strictly for bot management and security purposes. This is controlled by Cloudflare, not by us. See Cloudflare's Privacy Policy.
  • Google Fonts — We load the Inter typeface from Google's font servers (fonts.googleapis.com). This means your browser makes a connection to Google when loading the site. See Google's Privacy Policy.

2. Desktop Application

Your Dashcam Footage

All of your video files, TeslaCam footage, and SEI telemetry data remain entirely on your local machine. The application processes everything locally. We never access, upload, or transmit your footage — unless you explicitly choose to share a clip using the Clip Sharing feature.

Security & Compatibility Reporting (Mandatory)

To maintain application security, prevent API abuse, and ensure technical compatibility, the app performs a mandatory check with our server during update checks. This includes:

  • User ID (UID) — a SHA-256 hash derived from your machine ID and a salt. This is a pseudonymous, one-way hash: it lets us recognize an installation across update checks but does not, on its own, reveal your name, machine, or identity.
  • Platform and architecture — e.g., "windows", "x64", "macos", "arm64"
  • App version — e.g., "v2026.7.20"

This reporting is a functional requirement for the secure operation of the Service and cannot be disabled. This data helps us ensure you are running a secure version of the app and prevents unauthorized API usage.

Diagnostics (User-Initiated Only)

Diagnostics are never collected automatically. They are only uploaded when you explicitly approve sending them through an in-app support feature. Diagnostic data includes:

  • Operating system and version
  • App version
  • Hardware information (CPU, memory)
  • Redacted terminal/console logs (file paths and personal info are stripped)

Diagnostics are stored on our support server for 7 days and then automatically deleted. They are accessible only by the Sentry Studio developer via a secure passcode. If diagnostics are sent through the legacy human-support workflow, a forwarded copy may also remain in its private Discord thread as described below.

Legacy Human Support Chat

Some covered apps continue to provide the legacy in-app support chat for communicating directly with the developer. When you open a legacy support ticket:

  • Your messages and any attached media are sent to our support server
  • Your IP address is processed for rate limiting and abuse prevention
  • Messages and attached media are forwarded to a private Discord thread for the developer to respond

Local copies of legacy support diagnostics and attachments are automatically deleted 7 days after the last activity, even if the ticket remains open. The open ticket record, associated IP metadata, and ordinary text messages remain until the ticket is resolved; after closure, those remaining local records are automatically deleted 7 days after the last activity. The corresponding private Discord thread is archived when the ticket closes but is not currently deleted on that seven-day schedule; its forwarded messages and attachments remain until we manually delete the thread or Discord removes them under its policies. This automatic private-thread forwarding is part of the legacy human-support workflow and is different from the optional Discord link in AI Support.

AI Support (Where Offered)

If AI Support is offered in the app or version you are using, it is clearly identified as the online AI Support Assistant described in Section 7. It is not a human or a model running solely on your device. Messages and files are handled according to the disclosures, consent controls, and retention periods in that section.

Local Settings

Your preferences (language, theme, layout, etc.) are stored locally on your machine in a local configuration file. These settings are never transmitted to any server.

3. Sentry USB & Dash USB Devices

This section covers two separate Raspberry Pi products: Sentry USB (for Tesla vehicles) and Dash USB (for supported GM vehicles with the built-in Surround Vision Recorder dashcam). They use separate product-specific software and share a local-first design—your footage stays on hardware you control. They are not interchangeable. Where the two devices differ, including in what each one reports during update checks, this section says so explicitly.

Local Operation

Sentry USB and Dash USB perform their core recording, storage, viewing, and management work on the Pi and your local network. By default, dashcam footage stays on storage you control and is not uploaded to our servers. The Pi serves a local web dashboard for viewing and managing recordings. The limited outbound flows described below—such as update checks, notification pairing, support you initiate, community submissions, and destinations or services you configure—are exceptions to this local-first operation.

Both devices can also archive your clips to a destination you configure — a CIFS/SMB share, an NFS share, an rsync target, or an rclone remote. Those destinations are yours, not ours: footage copied to them travels directly from your Pi to the storage you chose and does not pass through our servers. If you do not configure an archive destination or another optional sync service, footage remains local. Dash USB has no Sentry Cloud integration, but it may archive footage to a cloud-backed rclone remote you configure; that destination is operated by you or your chosen provider and is outside this policy. Sentry Cloud is available only to Sentry USB users who choose it. It syncs encrypted drive-history and telemetry data—not dashcam video—and is governed by its separate policy.

Dash USB exists because GM's Surround Vision Recorder keeps only a rolling window of footage (approximately 2 hours) before overwriting it. Dash USB snapshots that footage before the vehicle deletes it and retains it according to the storage and archive destination you provide.

Notification Credentials

When mobile push notifications are enabled, the Pi registers a unique device_id and device_secret with our notification backend (notifications.sentry-six.com). These credentials are used solely to authenticate push notification delivery and are not used for tracking or any other purpose.

Pairing Codes

Temporary 6-character alphanumeric codes are generated on the Pi and registered with our notification backend to pair with the iOS app. Pairing codes expire after 5 minutes and are automatically deleted once consumed or expired.

mDNS / Bonjour

The Pi advertises itself on your local network via mDNS so it can be reached by name and discovered by companion software. Each device advertises a product-specific service record (_sentryusb._tcp or _dashusb._tcp) alongside a standard _http._tcp record, reachable at sentryusb.local or dashusb.local. This data never leaves your local network.

Bluetooth Low Energy (BLE)

During initial setup, the Pi may advertise a BLE service for WiFi configuration. WiFi credentials are transmitted over BLE directly between your phone and the Pi and are never sent to any external server. This applies to both Sentry USB and Dash USB.

Update Checks & Analytics Opt-In—Sentry USB

Sentry USB contacts api.sentry-six.com during its update check so it can report whether a compatible update is available and help us identify vulnerable builds. By default, this request has no device identifier. It includes:

  • Software version—the version currently installed
  • CPU architecture and board model—for compatible release selection
  • Update status—whether an update is available and the offered version, when relevant

A one-way salted SHA-256 hash derived from the board serial is included as a device fingerprint only if you explicitly opt in to analytics in setup or under Settings → System. The opt-in is off by default and can be changed at any time. When opted out, Sentry USB stops sending the fingerprint and its future update checks create no new per-device record. Opting out does not automatically erase an analytics row sent earlier; you may request its deletion using the contact details below.

Sentry USB also sends a single aggregate install ping the first time it runs. The request has an empty body—no device identifier, version, or configuration—and the server persists only an aggregate daily install counter. As with any internet request, the server necessarily sees the connection's source IP; the application uses it only in a short-lived in-memory rate-limit bucket. The ping fires once per installation and is not linked to the optional analytics fingerprint.

Update Checks & Analytics Opt-In — Dash USB

Dash USB performs a daily update check with our server (api.sentry-six.com) so it can tell you when a new release is available and so we can detect devices running a vulnerable build. By default this check carries no device identifier. It sends:

  • Software version — the version currently installed on the device
  • CPU architecture — e.g., "aarch64"
  • Board model — e.g., "Raspberry Pi 4 Model B"
  • Update status — whether an update is available, and the new version number when one is

A device fingerprint — a one-way salted SHA-256 hash derived from the board's serial number — is included in this check only if you explicitly opt in to analytics, either in the setup wizard or afterwards under Settings → System → Analytics opt-in. This setting is off by default, takes effect immediately when you change it, and is the only setting that causes a device-derived identifier to leave your Pi. When you are opted out, the fingerprint is not sent on future checks and those checks create no new per-device record. Opting out does not automatically erase an analytics row sent earlier; you may request its deletion using the contact details below.

Dash USB also sends a single aggregate install ping the first time it runs. The request has an empty body — no device identifier, version, or configuration — and our server persists only a daily aggregate count. The connection's source IP is necessarily seen and is used by the application only in a short-lived in-memory rate-limit bucket. It fires once per installation and never again.

Support

Some Sentry USB and Dash USB versions continue to include the legacy human support chat described in Section 2. Messages are proxied through api.sentry-six.com and forwarded to a private Discord thread, and the legacy retention periods apply. If AI Support is offered in a particular product or version, the interface will clearly identify it as AI and the disclosures, consent controls, and retention periods in Section 7 will apply. This does not mean AI Support is currently available in every product.

Sentry USB Community Wraps & Lock Chimes

If you submit a wrap or lock-chime file to the Sentry USB community library, we receive the submitted file (and any optional wrap-preview file), display name, applicable vehicle model for wraps, original filename for wraps, file size, lock-chime duration where applicable, and the connection's source IP. Our server also generates a submission code and records review status and timestamps. Current Rusty versions send no device or hardware fingerprint. The IP is used for rate limiting and abuse investigation and is retained with the submission record. Pending and approved asset files remain until declined or manually removed. Declining a submission deletes its asset file, but the submission record—including its source IP and review metadata—has no fixed automatic deletion period and remains until manually removed or deletion is requested. Submission metadata and a private review link or file may be forwarded to our private Discord moderation workflow; an item is not placed in the public library until approved. We process the submitted content and publishing metadata as necessary to provide the community-publishing service you requested, and we rely on legitimate interests for proportionate rate limiting, abuse investigation, and moderation.

Current Rusty downloads send no custom or device identifier, although the source IP is necessarily seen and briefly held in an in-memory rate-limit bucket. Older clients may still send a legacy fingerprint that created a per-item unique-download record; those legacy records may remain until manually deleted. Contact us to request deletion. Do not submit a file or download from the library if you do not want the described processing.

4. Sentry Connect iOS App

The Sentry Connect app connects to Sentry USB devices for camera viewing, file browsing, device setup, and push notifications. It also delivers push notifications from Dash USB devices via the notification pairing described below. The app's local device discovery, Bluetooth setup, and camera streaming features do not currently support Dash USB devices — where a subsection below refers only to Sentry USB, that is why.

Dashcam Footage

The app streams and displays dashcam footage from your Sentry USB device over your local network. Video data never leaves your local network and is never uploaded to our servers.

Push Notifications (APNS)

When you enable push notifications, Apple assigns your device a unique push notification token (APNS token). This token is:

  • Stored locally on your device
  • Sent to notifications.sentry-six.com during the pairing process
  • Used solely to deliver push notifications from your Sentry USB or Dash USB device
  • Not used for tracking, advertising, or any other purpose

Notification Pairing

When you pair with a Sentry USB or Dash USB device for push notifications, the following data is sent to our notification backend:

  • APNS device token — your Apple push notification token
  • Device name — e.g., "Scott's iPhone"
  • Platform — "ios"
  • Pairing ID — a server-generated unique identifier for the pairing

You can remove pairings at any time from the iOS app settings or the Pi's web interface, which deletes your APNS token from our servers.

Saved Devices

Device connection info (hostname, IP address, display name, BLE identifier) is stored locally on your device using iOS UserDefaults. This data is never transmitted to any external server.

Bluetooth (BLE)

The app uses CoreBluetooth for initial device setup, including WiFi configuration. BLE communication occurs directly between your iPhone and the Sentry USB Pi. No BLE data is sent to external servers.

Local Network Discovery

The app uses Bonjour/mDNS to discover Sentry USB devices on your local network. Discovery data (IP addresses, hostnames) stays on your device and is never transmitted externally.

Support

The iOS app continues to include the legacy human support chat described in Section 2. When using that chat, your APNS token may also be registered with the support backend to receive reply notifications. The legacy data practices and retention periods apply. If AI Support is offered in a future iOS version, the app will clearly identify it as AI and the disclosures, consent controls, and retention periods in Section 7 will apply.

No Analytics or Tracking

The Sentry Connect iOS app does not include any analytics SDKs, crash reporters, or advertising frameworks. We do not track your usage patterns within the app.

5. Sentry Drive

Sentry Drive is a desktop application for Windows, macOS, and Linux that visualizes and analyzes your drive history from the SEI telemetry embedded in TeslaCam files. All drive processing happens locally on your computer — your footage and telemetry are never uploaded to us.

Local Processing

Sentry Drive reads the SEI data in your TeslaCam files (GPS coordinates, self-driving state, speed, pedal inputs, and similar) and the optional drives-data.json produced by Sentry USB. This data is processed and stored only on your local machine.

Map Tiles

To display your drives on a map, the app loads map tiles from third-party tile providers (OpenStreetMap/CARTO and Google Maps, depending on the selected map style). Because the tiles requested are determined by where your drives took place, your approximate drive locations are necessarily shared with the chosen tile provider as part of normal map rendering.

Optional Third-Party Features

The following features transmit data only when you explicitly choose to use them:

  • Route reconstruction (OSRM) — The "Fix Broken Drives" feature sends drive coordinates to the public OSRM (Open Source Routing Machine) routing service to reconstruct missing route segments.
  • Tessie import — If you use Tessie import, the app connects to api.tessie.com using an API token you provide to retrieve your drive history. That data is governed by your relationship with Tessie. See Tessie's Privacy Policy.

Updates

Sentry Drive checks for new versions through GitHub Releases. Unlike Sentry Studio and Sentry USB, it does not send a hashed device identifier on update checks.

Sentry Drive is open-source software (originally derived from Sentry USB). Source code: github.com/Sentry-Six/Sentry-Drive.

6. Clip Sharing Service

When you use the clip sharing feature to generate a shareable link, the following data is collected:

  • Video file — your exported MP4 clip is uploaded to our server
  • Original filename — stored alongside the clip for display purposes
  • IP address — logged for rate limiting and abuse prevention
  • Delete token — a unique token generated so you can delete your clip

Clip Viewer Data

When someone views a shared clip, we record their IP address to count unique views (one view per IP per clip). This data is deleted when the clip expires.

Public Accessibility

Shared clips are publicly accessible to anyone with the link. There is no password protection. Do not share clips containing sensitive or private information.

Automatic Deletion

Shared clips are automatically deleted from our servers after a user-selected duration (up to 7 days, default 72 hours). You can also delete your clip at any time using the delete token provided at upload. Once deleted, the video file, thumbnail, and associated view records are permanently removed.

7. AI Support Assistant

Where offered, the AI Support Assistant is an online, automated service. It is not a human, and the AI model does not run solely on your Sentry USB or other local device. When you use it, your messages and the assistant's responses are transmitted over the internet through api.sentry-six.com. We provide the assistant with product-specific instructions and knowledge, along with relevant product and software-version context, to tailor support to the product you are using.

Conversation Logging & Review

Every AI Support conversation is logged on our server as it occurs, whether or not it is escalated. Records may include your messages, AI responses, timestamps, a pseudonymous conversation identifier, and product and software-version context. Before retaining a transcript, we apply automated redaction intended to remove common secrets and personal identifiers. Automated redaction may not catch everything, so do not include passwords, access tokens, precise location data, or other information you do not want to share. The public IP seen from the Pi's connection is processed separately for rate limiting and security: raw values remain only in short-lived in-memory rate buckets (up to about two hours), while a gateway-keyed one-way hash and daily diagnostic-upload counters may remain for up to about 49 hours and are not linked to the transcript or diagnostic text.

Authorized Sentry Studio maintainers may review redacted transcripts to provide support, investigate abuse and service failures, identify inaccurate or hallucinated answers, and improve the assistant's prompts, product knowledge, routing, safeguards, and support quality. We do not use retained transcripts or uploaded files to train a public or third-party general-purpose AI model.

Third-Party AI Processing

To generate a response, relevant conversation content and all or relevant portions of files you approve may be processed by Ollama Cloud, our third-party AI inference provider. According to Ollama's current Privacy Policy, cloud-hosted prompts and responses are processed transiently to provide the service, are not stored beyond the time required to fulfill the request, and are not used to train AI models. Ollama's practices are governed by its own policy and may change. This processing may occur outside Canada, including in the United States.

File Upload Consent

The assistant may ask for a specific diagnostic report or file, but it cannot browse your device or read files automatically. Nothing is generated, collected, or uploaded until you affirmatively approve that specific request. In the current Sentry USB diagnostics flow, selecting Approve once generates the named report on your device and immediately uploads it to our backend; there is no arbitrary-file access or standing permission. The report can include software and service state, hardware and storage status, network configuration and local addresses, recent logs and errors, and identifiers or location-related data that appear incidentally in those logs. All or relevant portions may then be processed by Ollama Cloud and reviewed by authorized maintainers for the purposes described above. Declining a request does not prevent you from continuing the conversation.

Approved reports or files are retained on our server for 7 days and then automatically deleted. Do not approve an upload if the disclosed categories may contain credentials, private keys, access tokens, location data, or third-party information you are not authorized to share.

Retention & Discord

Redacted conversation transcripts are retained for 90 days after the last activity and then automatically deleted or irreversibly de-identified. Limited records may be retained longer where required by law or necessary to investigate abuse or a security incident.

To resume an anonymous conversation, the app stores its random conversation identifier and access token in that browser's local storage. Anyone with access to that browser profile may be able to open the conversation until it is deleted or expires. Using the in-app New chat/delete control removes the server copy and local token; clearing the site's browser data removes the local copy only.

After a conversation is deleted, its messages and uploaded files are removed immediately. A non-content deletion receipt containing the conversation identifier, one-way hashes of the access token and deletion idempotency key, and the deletion time remains available solely for safe retries and replay prevention until it expires 24 hours after deletion. The expired receipt is removed during the next scheduled cleanup sweep, normally within about one additional hour.

On Sentry USB Rusty, the browser normally reaches the Pi over local HTTP. Chat content, conversation access tokens, and approved diagnostic uploads are therefore not encrypted on that browser-to-Pi hop; use AI Support only from a trusted local network. The Pi's onward connection to api.sentry-six.com uses HTTPS.

The assistant may suggest joining our Discord server for further community or human help. Joining Discord is optional. Opening the link does not automatically transfer your AI conversation or files to Discord. Anything you choose to post on Discord is governed by Discord's Privacy Policy.

8. Data Retention

Data TypeRetention PeriodDeletion Method
Shared video clipsUp to 7 days (user-selected)Automatic + manual via delete token
Legacy human-support ticket records, associated IP metadata, and ordinary text messagesOpen until resolved; closed: 7 days after last activityAutomatic after closure retention period
Local copies of legacy human-support diagnostics and attachments7 days after last activity, whether the ticket is open or closedAutomatic
Legacy support content forwarded to a private Discord threadNo fixed automatic deletion periodThread archived on closure; retained until manual deletion or removal under Discord's policies
Redacted AI Support conversation transcripts90 days after last activityAutomatic deletion or irreversible de-identification; deletion on verified request
AI Support files you approve for upload7 daysAutomatic
AI Support diagnostic-upload quota records (gateway-keyed IP hash plus daily count and byte totals)About 49 hoursAutomatic after 48-hour expiry plus the scheduled hourly cleanup sweep
AI Support non-content deletion receiptsExpires 24 hours after deletionAutomatic on the next scheduled hourly cleanup sweep
Diagnostic uploads7 daysAutomatic
Community wrap or lock-chime files, submission metadata, and associated source IPAsset file until declined or manually deleted; submission metadata and IP have no fixed automatic periodFile removed on decline or manual deletion; metadata and IP on manual removal or verified request
Legacy per-item community-download fingerprint recordsUntil manually deletedOn verified request; current Rusty versions do not create them
Installation records — Desktop (secure device hash)IndefiniteOn request
Installation records — Sentry USB (secure hardware hash, analytics opt-in only)Until manually deletedOpting out stops future identified checks; deletion on verified request
Installation records — Dash USB (secure hardware hash, analytics opt-in only)Until manually deletedOpting out stops future identified checks; deletion on verified request
Aggregate install counts — Sentry USB and Dash USB (daily totals, no linked identifiers)IndefiniteNot applicable — no per-user data is stored
Other rolling rate-limit counters (IP-based or secure-device-hash based)In-memory only; normally no more than about two hoursCleared on server restart or window expiry
Security lockout & ban records (IP-based)IndefiniteAt our sole discretion
Local app settingsUntil you uninstallDeleted with app data on uninstall
APNS device tokensUntil unpairing or token invalidationManual unpair or automatic cleanup
Notification pairingsUntil manually removedUser-initiated via app or Pi web UI
Pairing codes5 minutesAutomatic (expiry + consumed cleanup)
Device registrations (device_id, hostname)Indefinite (while Pi is active)On request
Saved devices (iOS local)Until app deletion or manual removalUser-initiated or app uninstall

9. Data Location & International Transfers

Our backend server (api.sentry-six.com) and notification service (notifications.sentry-six.com) are hosted on a dedicated server in Montreal, Canada provided by OVHcloud. Data you send to our API — including shared clips, diagnostics, legacy human support messages and attachments, AI Support transcripts and approved files, and notification pairing data — is stored in Canada for the retention periods described above. Legacy human support messages and attachments are also forwarded to a private Discord thread for the developer to respond.

Our website (sentry-six.com) is served globally via Cloudflare's CDN, which may route your request through servers in various countries.

AI Support content may also be processed transiently by Ollama Cloud outside Canada, including in the United States, as described in Section 7. By using our services, you acknowledge that your data may be processed in Canada and by these providers in jurisdictions different from your own.

10. IP Addresses & Access Restrictions

We use IP addresses for rate limiting, abuse prevention, and security purposes. IP addresses are used to:

  • Enforce upload and request rate limits
  • Count unique clip views
  • Detect and prevent brute-force attacks or abuse involving legacy human support chat or AI Support
  • Temporarily lock out or permanently ban abusive IP addresses

We reserve the right to restrict or deny access to any of our services, at any time, for any reason, without notice or explanation. This includes but is not limited to temporary lockouts, permanent IP bans, and content removal.

11. What We Do NOT Collect

For the free apps and services covered by this policy (this section does not describe Sentry Cloud — see sentryusb.com/legal):

  • We do not require an account, name, email address, or contact information to use these apps
  • We do not use marketing analytics, advertising, or commercial trackers
  • We do not sell or rent your data or share it with third parties for advertising; service providers process limited data only as described in this policy
  • We do not access your dashcam footage unless you explicitly choose to share it through a covered upload feature; otherwise it stays on your local machine, Sentry USB or Dash USB device, or an archive destination you configure (see Sections 3, 6, and 7)
  • We do not track your usage patterns within the desktop applications or iOS app
  • We do not upload your drive telemetry or location data — Sentry Drive processes it locally (see Section 5 for the optional features that contact third parties at your request)
  • We do not use any analytics, crash reporting, or advertising SDKs in the iOS app

12. Your Rights & Choices

  • Delete shared clips — Use the delete token provided at upload, or use the "My Shared Clips" panel in the app.
  • Request data deletion — Contact us to request deletion of your UID installation record or any other data associated with you.
  • Delete an AI Support conversation — Use the in-app New chat/delete control while you still hold the conversation token to delete the server copy immediately. You may also email [email protected]; because AI Support does not require an account, we may be unable to locate or verify an anonymous conversation without its identifier. Limited legal and security exceptions may apply.
  • Delete local data — Uninstalling the app removes all locally stored settings, diagnostics, and cached data.
  • Unpair notifications — Remove push notification pairings from the iOS app settings or the Pi's web interface. This deletes your APNS token from our servers.
  • Delete saved devices — Remove saved Sentry USB devices from the iOS app at any time. This only affects local storage on your phone.
  • Control analytics (Sentry USB and Dash USB) — Each product's analytics opt-in is off by default. You can turn it on or off at any time under Settings → System → Analytics opt-in; while it is off, that product sends no device-derived identifier on future update checks. Turning it off does not automatically erase a row sent earlier; contact us to request deletion.

European & UK Users

These apps are available worldwide, so residents of the EEA and UK may use them. For the limited personal data we receive—including opt-in update-check identifiers and data you actively send via clip sharing, diagnostics, legacy human support chat, or AI Support:

  • Legal basis—For AI Support, we rely on contractual necessity (GDPR Art. 6(1)(b)) to process the messages needed to provide the support service you request; consent (Art. 6(1)(a)) for each diagnostic or file upload you separately approve; and legitimate interests (Art. 6(1)(f)) for proportionate security, abuse prevention, reliability, redacted transcript retention, authorized quality review, hallucination detection, and prompt or knowledge-safety improvements. You may object to legitimate-interest processing or request deletion using the controls and contact details above, subject to applicable law. We separately rely on consent for an opted-in Sentry USB or Dash USB update-check fingerprint; turning analytics off withdraws consent for future identified checks, and you may contact us to request deletion of a row sent earlier.
  • Your rights — You have the right to access, rectify, erase, restrict, or object to our processing of your personal data, and to data portability, subject to applicable law.
  • How to exercise them — Contact us using the details in the Contact section below. We act as the data controller for these services.

13. Age Requirement

Our services are intended for users who are at least 18 years of age. We do not knowingly collect data from anyone under 18. If you believe someone under 18 has provided us with data, please contact us and we will take steps to remove it.

14. Security

We take reasonable measures to protect your data, including:

  • HTTPS/TLS encryption for our public websites and for connections from a Sentry USB device to our external APIs
  • Rate limiting and lockout mechanisms to prevent abuse
  • Timing-safe comparisons for authentication tokens
  • Automatic expiration and deletion of temporary data
  • Security headers (HSTS, X-Content-Type-Options, X-Frame-Options, etc.)

The Sentry USB web interface is normally opened over plain HTTP on your local network (for example, http://sentryusb.local). Traffic between your browser and the Pi—including a message before the Pi forwards it to our external API over TLS—is therefore not encrypted by HTTPS. Use Sentry USB only on a trusted local network, enable its web authentication, and do not expose the Pi's web port directly to the internet.

No system is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

15. Third-Party Links & Services

Our services may link to external sites such as GitHub (for downloads and source code) and Discord (for community and support). These third-party services have their own privacy policies, and we are not responsible for their practices.

Ollama Cloud acts as an AI inference provider for AI Support and processes relevant conversation or approved file content as described in Section 7. Legacy human support messages and attachments are automatically forwarded to a private Discord thread so the developer can respond. By contrast, opening the optional Discord link suggested by AI Support does not automatically send Discord your AI conversation or files.

Sentry Studio is not affiliated with Tesla, Inc. in any way. Dash USB is likewise not affiliated with General Motors in any way.

16. Source Code Transparency

The Sentry Studio desktop viewer and Sentry Drive are open-source software licensed under the MIT License. The Sentry USB and Dash USB Pi device software is source-available under the PolyForm Noncommercial License 1.0.0 (some bundled components remain MIT-licensed). In every case, you can review exactly what data these applications collect by inspecting the source code on GitHub:

The Sentry Connect iOS app is distributed via the Apple App Store and is not open source.

17. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be posted on this page with an updated "Last updated" date. Continued use of our services after changes constitutes acceptance of the revised policy.

18. Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, you can reach us through: