Privacy and your data
Fregata Mobile has no account, no analytics, no advertising and no crash-reporting service. Video goes from your NVR to your devices and nowhere else. This page explains where everything else lives. The privacy policy is the formal version.
Who the app talks to
Section titled “Who the app talks to”- Your NVR, at the addresses you gave it.
- Our notification relay,
push.fregata.app, once you turn on alerts. - Apple, for push notifications and iCloud sync.
Links to Frigate’s documentation open in Safari. The app contacts nothing else.
On your iPhone
Section titled “On your iPhone”- Passwords, custom header values and sign-in cookies are kept in the iOS Keychain.
- Server names, addresses, usernames, header names and camera order are kept in the app’s own storage.
- Cached thumbnails and descriptions sit in the app’s cache, which iOS can clear.
- The last 100 alerts this device received are listed in Notification Activity.
- Spotlight gets reviews and events, so you can search for them, for 60 days.
- Exports are deleted after an hour. Clips and snapshots you save go through the share sheet, and Photos access is add-only: the app can’t see your library.
- Diagnostics logs stay on the device unless you copy them. A copy masks your servers’ addresses and usernames.
- Picture descriptions written by Apple Intelligence are made on the device, and nothing is sent anywhere to make them. Explore keeps an event’s description for 30 days.
iOS keeps Keychain items after an app is deleted, so reinstalling can pick up your sign-in.
iCloud
Section titled “iCloud”With Sync with iCloud on, the default:
- Server names, addresses, usernames and header names go in iCloud’s key-value storage. Apple encrypts it in transit and on its servers, with keys Apple manages. Because that isn’t end-to-end encrypted, no password or secret goes there.
- Passwords and header values go in iCloud Keychain, which is end-to-end encrypted.
- Your notification filters, such as Home and Away, go in iCloud’s key-value storage. Which one is active, and any snoozes, stay on each device.
Certificate trust, alert registrations, notification wording and sounds, and appearance aren’t synced. Turn sync off in Settings › iCloud Sync. See iCloud Sync.
Apple Watch
Section titled “Apple Watch”Your iPhone hands the watch your servers’ addresses, sign-in, custom headers and certificate trust, through Apple’s own connection between the two. The watch keeps the secrets in its own Keychain and signs in to your server itself.
The watch keeps a log of its connection to your server, which names your server’s address. It sends it to your iPhone, over the same connection, only when you tap Get watch log under Diagnostics › Apple Watch Log. Like the iPhone’s own logs, it goes nowhere else unless you copy it, and a copy masks your server’s address.
Our notification relay
Section titled “Our notification relay”Apple accepts push notifications for an app only from its developer’s server. Ours is a small relay, which passes alerts from your NVR to Apple, encrypted so that Apple’s servers can’t read them.
When a device turns on alerts, it registers with the relay: its Apple push token and your NVR’s public push key. The relay never receives your NVR’s address, your sign-in, camera footage or snapshots, and it doesn’t keep what your alerts say, or a history of them. Your notification filters reach it as rules, so it can hold back what you’ve asked it to. Remove a server from the app, and the relay stops delivering its alerts to this device.
The privacy policy lists everything the relay keeps, and how it handles an alert.
Questions
Section titled “Questions”Ask on GitHub Discussions, or see the contact details in the privacy policy.