1. Scope and controller
XXCam is provided by developer Peng Chujin (“we,” “us,” or “our”). This policy applies to the XXCam app with bundle identifier cc.camm.xxcam, its ReplayKit broadcast extension, and the website at xxcam.qust.me. Contact us at 2093959501@qq.com.
2. Data XXCam does not collect
- No registration or login, and no collection of names, phone numbers, contacts, or precise location.
- No advertising, cross-app tracking, user profiling, or behavioral analytics SDK.
- No upload of camera frames, screen broadcasts, or photos to a server controlled by us.
- No sale, rental, or trade of personal data.
Under Apple’s definition of app data “collection,” we do not obtain or retain user data transmitted from XXCam. A local-network viewing device selected by the user is the direct recipient of the stream, not our server.
3. Information processed on your devices
Camera
With your permission, XXCam uses the iPhone camera to show a viewfinder, take photos, and send compressed live frames to paired viewers on the local network. Camera data is processed in real time on the device and is not uploaded to us.
Photo Library
With your permission, XXCam can save captured photos to the system Photos library and read the most recent photo for an in-app thumbnail. If an asset exists only in iCloud, Apple’s Photos service may download it according to your device settings; we cannot access that transfer. You control photo retention and deletion in the Photos app.
Local Network and Bonjour
XXCam runs a local HTTP service on the iPhone and uses Bonjour so devices on the same Wi‑Fi or personal hotspot can connect. A viewer browser requests live frames, current quality, connection status, and viewer count from the iPhone’s local address. These requests do not pass through an internet server controlled by us.
ReplayKit screen broadcast
When you explicitly start the ReplayKit broadcast extension through Apple’s system interface, XXCam captures screen frames so the viewer can see framing from the system Camera app or a third-party camera app. Frames are sent in real time only during the broadcast, are not written to a file by XXCam, and are not uploaded to us. Screen broadcasts may include status bars, notifications, or other on-screen content; protect sensitive information before starting.
Camera app availability
XXCam uses iOS canOpenURL checks for a limited list of known camera apps so it can show only available shortcuts. Results remain on the iPhone and are not sent to us.
4. Pairing links, cookies, and session data
Each time XXCam launches, it generates a random 128-bit pairing token and includes it in the QR code and local-network URL. Devices without the current token cannot view the feed. After the viewer first opens the link, the iPhone’s local service stores a first-party cookie named camm in that browser for up to one year so the same browser can continue accessing the session.
- XXCam does not persist the token across app launches. Restarting the app creates a new token and invalidates the old one.
- The cookie stays only in the viewer browser and can be deleted by clearing that browser’s site data.
- Quality choices, stall reports, and viewer counts serve the current local session and are primarily kept in device memory.
5. Sharing, third-party code, and platform services
XXCam does not share data with advertisers, data brokers, or analytics providers. The app uses the open-source NextLevel camera library to access Apple camera frameworks. It is not used for networking, advertising, or analytics and does not receive user data from us.
Apple may separately process App Store downloads, purchases, crash diagnostics, or analytics that a user chooses to share, under Apple’s own policies and system privacy settings. This is separate from XXCam’s local-network streaming service.
6. This website
This website has no analytics script, advertising, fingerprinting, contact form, or site cookie. It is hosted by Vercel, with DNS provided by Cloudflare. To deliver pages, prevent abuse, and maintain security, these infrastructure providers may process standard network logs such as IP address, User-Agent, access time, and requested path under the Vercel Privacy Policy and Cloudflare Privacy Policy.
7. Retention, deletion, and withdrawal
- We have no XXCam account or user database, so we hold no app user profile for us to retrieve, export, or delete.
- You can revoke Camera, Photos, or Local Network permission in iOS Settings under Privacy & Security.
- You can stop the ReplayKit broadcast to end screen transmission immediately.
- You can delete photos in the Photos app, clear site data in the viewer browser, and remove XXCam’s local app data by deleting the app.
If you email us, we use the message only to address your request and retain the correspondence only as reasonably necessary.
8. Security notice
A random pairing token reduces casual access by unknown devices on the same network, but the local viewer URL uses HTTP and the stream is not end-to-end encrypted. Use XXCam only on Wi‑Fi or hotspots you trust, do not publish pairing links, and make sure every viewer is authorized. A viewer can still save visible content using system screenshots or screen recording.
9. Children
XXCam is not directed to children and we do not knowingly collect children’s personal information. A parent or guardian should obtain any required consent before recording or sharing images of a minor.
10. Changes and contact
If the app’s features or data practices change, we will update this page and its effective date. Where appropriate, we will provide notice in the app or on this website. For privacy questions, email 2093959501@qq.com.