Privacy Policy

Local-first by design, transparent about the website.

NearLens processes Bluetooth detection locally in the app. This website uses one necessary preference cookie and, only with your affirmative permission, Umami Cloud analytics.

Who We Are and What This Policy Covers

NearLens is currently operated by Marcos Rezende. For privacy questions or requests, use hello@marcosrezende.com.

This policy covers the NearLens iOS app and the website at nearlens.app. The app and website have different processing boundaries: the app keeps detection activity on your device, while the website must process limited request information to deliver pages and protect the service.

The operator's formal legal name, postal address, establishment details, and whether a data protection officer or European representative is required have not been confirmed in this notice. Those details should be verified and added before relying on this page as a complete legal notice.

What Data the App Uses

NearLens scans for nearby Bluetooth Low Energy (BLE) devices and processes the following information locally on your device:

  • Device names broadcast via Bluetooth
  • Manufacturer IDs from BLE advertisement packets
  • Signal strength (RSSI) to estimate proximity
  • Detection timestamps for the activity log

This data is used solely to compare local observations with known smart-glasses signatures and alert you to possible compatible signals. A result does not prove that a person is recording, that a camera is active, or that every compatible device is present.

Data Storage

Detection logs and app settings are stored locally on your device using on-device storage. This data is:

  • Never uploaded to any server
  • Never shared with third parties
  • Never used for analytics or advertising
  • Fully under your control: clear all logs anytime from within the app

Detection history is opt-in. The exact automatic-clearing interval in the current release has not been verified, so this policy does not promise a fixed retention period. You can clear local history from within the app at any time.

No Data Collection

NearLens does not collect:

  • Personal information (name, email, phone number)
  • Your geographic location (the app never reads, stores, or transmits GPS coordinates)
  • Device identifiers or advertising IDs
  • Usage analytics or crash reports
  • Any data from other apps on your device
  • Camera, microphone, audio recording, or video capture
  • An account or profile required to use the app

App: No Third-Party Services

The NearLens app does not integrate with any third-party analytics, advertising, or tracking services. There are no SDKs inside the app that collect or transmit your data.

Website Analytics (nearlens.app)

This website uses Umami Cloud to understand aggregate website use. Its script loads only after you click Allow analytics or enable the Analytics category in cookie settings.

  • Data involved: page URL, referrer, browser, operating system, device type, approximate country derived from the request, and technical request data such as an IP address that the provider may receive when delivering or processing the analytics request. We do not configure heatmaps or session replay.
  • Purpose: understanding how the site is used so we can improve it.
  • Service: Umami Cloud. Its script is loaded from cloud.umami.is only after you allow Analytics. See Umami's privacy-first analytics overview and its data collection FAQ.
  • Legal basis: consent under GDPR Article 6(1)(a), where GDPR applies. Any local-law basis, including under LGPD, must be confirmed for the circumstances in which the site is offered.
  • Cookies and tracking: Umami does not use cookies in its tracking script or track visitors across websites. The consent cookie (nearlens_consent) is stored locally for 365 days.
  • Retention: Umami Cloud stores analytics records in its hosted service. The service account's configured retention period has not been verified for this notice and must be confirmed by the operator.
  • International transfers: the vendor's contracting entity, subprocessors, hosting location, transfer mechanism, and data processing agreement have not been verified for this notice. Analytics therefore remains optional and off until consent, but these vendor details still require owner review.
  • Withdrawal: decline or withdraw Analytics at any time through cookie settings. Withdrawal prevents future analytics loading and does not affect processing that occurred before withdrawal.

Website Delivery, Security, and Retention

When you request a website page, hosting and network infrastructure necessarily receive technical request information such as your IP address, requested URL, timestamp, browser headers, and response status. NearLens uses this processing to deliver the page, maintain security, prevent abuse, and diagnose failures.

  • Legal basis: legitimate interests in operating and protecting the website under GDPR Article 6(1)(f), where GDPR applies.
  • Application logs: NearLens application logs omit IP addresses and query-string values.
  • Rate limiting: the application uses an IP address temporarily in memory to limit abusive page traffic. Entries expire after the short rate-limit window and are pruned without being written by that mechanism to persistent application storage.
  • Infrastructure logs: the hosting platform may independently process or retain network and access information. Its exact retention and subprocessor details have not been verified for this notice and require operator confirmation.

Website fonts are self-hosted. Loading a NearLens page does not contact Google Fonts.

The demo video is hosted by YouTube and is not loaded on initial page view. If you choose to play it, NearLens loads an embedded player from youtube-nocookie.com. YouTube then receives request information such as your IP address and browser headers and may use browser storage according to its own practices. The provider's exact retention, subprocessor, and international-transfer details require operator review.

Your Rights

Depending on your location and the circumstances, applicable privacy law may give you rights concerning personal data processed through the website. Under GDPR these can include:

  • Access the personal data we hold about you.
  • Correct inaccurate or incomplete data.
  • Delete data collected with your consent (withdraw consent and request deletion).
  • Restrict processing while a dispute about accuracy, lawfulness, or an objection is considered.
  • Object to processing based on legitimate interests.
  • Portability of data in a structured format where technically feasible.
  • Information about data sharing and processors.
  • Withdraw consent at any time without affecting the lawfulness of prior processing.
  • Complain to the supervisory authority in the EU or EEA country where you live, work, or believe an infringement occurred.

To make a request, email hello@marcosrezende.com with the subject "NearLens privacy request", describe the right you want to exercise, and identify the relevant website interaction without sending unnecessary sensitive information. We may ask for proportionate information to verify that the request concerns you. We aim to respond within the time required by applicable law.

Because the app has no account and keeps its detection history on your device, NearLens normally cannot access, export, correct, or delete that local app data for you. Use the app's controls to clear it. You can withdraw website Analytics consent immediately through cookie settings.

Permissions

NearLens requests the following device permissions:

  • Bluetooth: Required to scan for nearby BLE devices. This is the core functionality of the app.
  • Notifications (optional): Used to alert you when smart glasses are detected nearby. You can enable or disable this in Settings.

iOS does not require location authorisation for Core Bluetooth scanning. NearLens does not need GPS coordinates for detection. The permissions above are used exclusively for the app's stated purpose and never for tracking or data collection.

Children's Privacy

The app is not designed to collect personal data from any user. The website is directed to a general audience and optional analytics is not intended to profile children.

Where consent for an online service is given by a child, the age at which a parent or guardian must authorize that consent varies by country under GDPR and other laws. A single age threshold does not apply everywhere. Children who cannot validly consent in their location should decline Analytics or use the site with authorization from a parent or guardian.

Acknowledgements

With thanks to the people and projects that helped shape NearLens:

  • Marcos Rezende: Product design, UX and visual identity (marcosrezende.com)
  • Emanuel Cardoso, Mariana Fernandes & Marcos Rezende: User discovery research and field testing

Open Source Software

NearLens is built on open-source software. Under the GNU Affero General Public License v3.0 (AGPL-3.0), you have the right to access, study, modify, and redistribute the source code. The app and website do not use open-source components to collect, process, or share your personal data.

A full list of third-party open-source libraries, their authors, and their licence texts is available on the Licences page.

Changes to This Policy

We may update this Privacy Policy from time to time. Any changes will be reflected on this page with an updated effective date. We encourage you to review this page periodically.

Contact

If you have questions about this Privacy Policy or want to make a privacy request, contact hello@marcosrezende.com. Do not send device scan history or other sensitive information unless it is necessary for your request.

Effective date: August 30, 2026