Huntcam Logo

Moose, deer or bear?

Pick out the interesting photos from all your trail cameras, automatically.

Privacy Policy

Last updated 21 September 2026

This policy explains what personal data Huntcam.ai collects, why, who it is shared with, and what you can require of us. It covers the website at huntcam.ai and the service reachable through it.

Who is responsible

The controller of your personal data is Sammut Software Oy (business ID 2688524-9), registered in Finland. Contact us about anything in this policy at huntcam@sammutsw.com.

We have not appointed a data protection officer, because the scale and nature of the processing does not require one.

What we collect

Account data

Your email address, and the name you supply. If you sign in with Google, we receive your email address, name and Google account identifier from Google. We never receive your Google password. Accounts are held by our authentication provider on our behalf.

Content you create

The names you give your locations, the analysis instructions you write, and the email addresses the service allocates to your cameras.

Photographs sent by your cameras

Your trail cameras email photographs to an address the service allocates to them. We store the photographs, the time each was taken, the time it arrived, and the message it arrived in.

A trail camera photographs whatever passes in front of it, which can include people. Those people are rarely aware of the camera and have not agreed to anything. Read “Photographs of other people” below: where you place a camera, and whether you may lawfully photograph what it sees, is your responsibility, not ours.

Analysis results

Each photograph is analysed by an artificial intelligence provider, which returns a description and counts of the humans, mammals and birds it believes are in the image. We store that result, the provider, the model and the request identifier alongside the photograph. The analysis is a description, not a decision: nothing is decided about anyone on the basis of it, and no legal or similarly significant effect follows from it.

Technical data

Our infrastructure providers process your IP address, the country it resolves to, the pages you request and the time of each request, in order to deliver the service and to protect it from abuse.

Why we process it, and on what basis

  • To provide the service — receiving, storing, analysing and displaying your photographs, and running your account. Basis: performance of our contract with you (GDPR Article 6(1)(b)).
  • To keep the service secure and working — diagnosing faults, preventing abuse, and protecting the service and its users. Basis: our legitimate interests (Article 6(1)(f)).
  • To meet legal obligations — where accounting, tax or another law requires it. Basis: legal obligation (Article 6(1)(c)).

Who we share it with

We do not sell your personal data, and we do not share it for advertising. We use the following providers, each of which processes data only on our instructions:

  • Neon — database and account storage, in the European Union.
  • Amazon Web Services — inbound email, photograph storage and processing, in the European Union (Frankfurt).
  • Cloudflare — serving the site and delivering images, from locations worldwide.
  • An analysis provider — OpenAI, Anthropic, Google or Amazon Web Services. A photograph goes to one of them to be analysed, and which one we use may change. The record we keep of each analysis names the provider that produced it, so we can always say where a particular photograph went. We do not consent to your photographs being used to train any provider’s models, and we use each provider on terms that exclude it.
  • Google — only if you choose to sign in with a Google account.

We also disclose data where the law requires it, and to professional advisers where necessary.

Transfers outside the EU

Your account data, your photographs and our database are held in the European Union. Two things leave it: a photograph sent to an analysis provider, which may process it in the United States, and the delivery of the site itself, which Cloudflare serves from wherever you are. Those transfers rely on the European Commission’s Standard Contractual Clauses, or on the EU–US Data Privacy Framework where the provider is certified under it. Ask us at the address above for a copy of the safeguards.

How long we keep it

  • The raw email a camera sends is deleted seven days after it arrives.
  • Deleting a photograph removes it from the service at once. The stored copy and its analysis are erased permanently within 30 days.
  • A photograph you do not delete is kept for as long as you keep your account.
  • Account data is kept while your account exists. Ask us to close your account and we delete it and the content that belongs to it.
  • Backups holding deleted data are overwritten within thirty days.
  • We keep what accounting or other law requires us to keep, for as long as it requires.

Cookies

We use only cookies the service cannot work without: one that keeps you signed in, and one that remembers your choice of language if you make one. We use no analytics, no advertising and no tracking cookies, so we ask for no cookie consent. Your browser can block them, and signing in will then stop working.

Your rights

Under the GDPR you may ask us to give you a copy of your personal data, correct it, delete it, restrict or object to how we use it, or hand it to you or another provider in a portable form. Where we rely on your consent, you may withdraw it at any time without affecting what we did before you did so.

Write to the contact address above. We answer within one month. If you are not satisfied, you may complain to your national data protection authority; in Finland that is the Office of the Data Protection Ombudsman (tietosuoja.fi).

If you are in the United States

Residents of California and of other states with comparable laws have the right to know what personal information we collect and disclose, to obtain a copy of it, to correct it, to have it deleted, and not to be discriminated against for exercising those rights. We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not process it for targeted advertising, so there is nothing to opt out of. Use the same contact address.

Photographs of other people

If a photograph you upload identifies someone, you are the one who decided to photograph them, and you are responsible for having a lawful basis to do so and for meeting the obligations that follow. We process those images for you, as your processor, in order to run the service.

If you believe a photograph in this service identifies you and should not be here, write to the contact address above and tell us what you can about where and when it was taken. We will find it, act on your request, and tell the account holder.

Children

The service is not intended for children. Do not create an account if you are under 16, or under the age your country sets for consenting to online services on your own. If we learn that we hold a child’s data without a parent’s authorisation, we delete it.

Security

Data is encrypted in transit. Access to production systems is limited to the people who operate the service. Image links are signed and expire. If a breach puts your rights at risk we will tell you and the supervisory authority as the GDPR requires.

Changes

We update this policy as the service changes. The date at the top is when it last changed. If a change is material, we notify every registered user by email before it takes effect.