Privacy

Privacy policy

Last updated: October 5, 2026

FiLMA.Ai is a camera monitoring and automation service operated by FIOS Serviços de Tecnologia Ltda. ("FiLMA.Ai", "we"). This policy explains what personal data we process, why, who we share it with and what your rights are, under Brazil's General Data Protection Law (Law 13.709/2018, LGPD) and other applicable laws.

It covers the filma.ai website, the app.filma.ai web app, the FiLMA.Ai apps for iOS and Android and the FiLMA.Ai appliance installed on the customer's local network.

1. Who is responsible for the data

For your account data (name, email, sign in, billing), FiLMA.Ai is the controller.

For images captured by cameras and for people enrolled in face recognition, the controller is the customer who installed the cameras and decides what to monitor. In those cases FiLMA.Ai acts as a processor: we handle that data only to provide the service, following the customer's settings.

2. Data we collect

  • Account: name, email, password (stored only as a hash), passkey public keys and, if you sign in with Google, the name and email Google provides.
  • Workspace: camera names, sites, zones, floor plans, automation workflows, alert recipients and device settings.
  • Images and events: live video, snapshots, recorded clips and the events derived from them, such as detected people, objects, vehicles and license plates.
  • Biometric data: when the customer turns on face recognition, we store numeric face vectors and face crops, linked to people the customer enrolled or marked as unknown.
  • Device and usage: push notification token, device model and operating system, IP address, access date and time and technical logs.
  • Billing: plan and payment status. Card details are processed directly by the payment providers; we do not store card numbers.
  • Appliance: local network addresses, camera and switch models and state. Camera and switch passwords stay only on the appliance, on the customer's premises, and are never stored in our cloud.

3. How we use data

  • To provide the service: show live video, record clips, run detections, automations and the assistant.
  • To send the alerts and notifications you configured.
  • To authenticate access, protect accounts and prevent fraud and abuse.
  • To provide support and fix problems.
  • To bill your plan and meet legal and tax obligations.

We do not sell personal data, we do not use your images for advertising and we do not use your images to train artificial intelligence models.

4. Legal bases

We process data to perform our contract with you, to comply with legal obligations, for legitimate interests (security and service improvement) and with consent where required, such as for notifications and access to your device photos.

Biometric data is sensitive data (LGPD art. 11). A customer who turns on face recognition must have an appropriate legal basis, such as the consent of enrolled people, and must inform people on site that cameras and face recognition are in use. FiLMA.Ai provides the tools to enroll, correct and delete this data.

5. Where data is stored

  • Live video leaves the appliance over an encrypted private network, passes through our gateway and reaches your browser or app. It is not recorded along the way.
  • Recordings are kept on the appliance at the customer's premises, or in cloud storage (Cloudflare R2) when the plan includes cloud recording.
  • Account, settings, events and face recognition data are kept on cloud servers contracted by FiLMA.Ai.

6. Who we share data with

We share data only with vendors that help us provide the service, and only as needed for each function:

  • Infrastructure: cloud server providers and Cloudflare (recording storage).
  • Private network: Tailscale, which connects the appliance to our cloud with end to end encryption.
  • Artificial intelligence: Anthropic and OpenAI, when you use the assistant or a workflow that asks questions about an image. We send the question and the frame needed to answer it.
  • GPU processing: RunPod, for face recognition when it runs in the cloud.
  • Notifications: Expo, Apple and Google for app push notifications, and Telegram when you connect a Telegram bot.
  • Payments: Stripe and Asaas.
  • Sign in: Google, when you choose to sign in with Google.

We may also disclose data when required by law, court order or a competent authority, or to protect the rights and safety of people.

7. International transfers

Some of these vendors process data outside Brazil, for example in the United States and Europe. In those cases we rely on the safeguards in LGPD art. 33, such as contractual data protection clauses.

8. How long we keep data

  • Account and settings: while the account is active.
  • Cloud recordings and events: for your plan's retention period, then deleted automatically.
  • Recordings on the appliance: until the customer deletes them or uninstalls the appliance.
  • Faces and enrolled people: until the customer deletes them or closes the account.
  • Access logs: 6 months, as required by Brazil's Internet Civil Framework (art. 15), and tax records for the legal period.

When an account is closed, we delete or anonymize its data within 30 days, except what the law requires us to keep.

9. Security

We use encrypted connections (TLS), an encrypted private network between the appliance and the cloud, hashed passwords, per customer data isolation and role based access control. Camera credentials stay only on the appliance. No system is completely immune to failure; if a relevant security incident occurs, we will notify affected people and the ANPD as the law requires.

10. Your rights

You may at any time:

  • confirm whether we process your data and access it;
  • correct incomplete, inaccurate or outdated data;
  • request anonymization, blocking or deletion of unnecessary or unlawfully processed data;
  • request data portability;
  • request deletion of data processed on the basis of consent and withdraw consent;
  • learn who we share your data with;
  • object to processing and complain to the Brazilian Data Protection Authority (ANPD) or your local authority.

To exercise your rights, write to privacidade@filma.ai. We reply within 15 days. If you were filmed by a FiLMA.Ai customer's cameras, please direct your request to that customer, who controls the images; we will help them respond.

11. How to delete your account

Email privacidade@filma.ai from the address on the account with the subject "Delete account". We confirm the request and, within 30 days, delete the account, the workspace, cloud recordings, events and face recognition data. Recordings kept on the appliance remain at the customer's premises and are erased when the appliance is uninstalled.

12. Mobile apps

The iOS and Android apps ask only for the permissions they need:

  • Notifications: to deliver the alerts you configured.
  • Photos: to save a clip or snapshot to your library when you ask.
  • Local network: to reach the FiLMA.Ai appliance and cameras on your network.

Your session is kept in the device's secure storage. The apps contain no ads or advertising SDKs and do not track you across third party apps or websites.

13. Cookies and local storage

The website and web app use browser local storage only to remember your language and keep you signed in. We do not use advertising cookies or third party tracking tools.

14. Children

FiLMA.Ai is not intended for anyone under 18, and accounts must be created by adults. Images of children captured by cameras are the responsibility of the customer, who must handle them in the children's best interest.

15. Changes to this policy

We may update this policy. The current version is always on this page, with its last updated date. We will announce material changes by email or in the app.

16. Contact

Controller: FIOS Serviços de Tecnologia Ltda. Data protection officer (DPO): privacidade@filma.ai.