Privacy Policy
1. Scope and purpose
Virtual CAM is a browser extension that transforms camera video using a reference image and prompt during supported browser-based meetings. Processing requires a publisher-issued personal access key, not an in-extension signup. This notice covers the extension and its authorization service hosted on Railway. Other websites and meeting providers have their own privacy practices.
2. Information handled and why
- Authentication: your personal access key is sent over HTTPS to our Railway-hosted service to authorize processing. The server compares a hash of that key with configured user access records and obtains a temporary Decart token. The publisher's master Decart key remains on the server.
- Images, prompts and video: your reference image, prompt and camera video are sent to Decart for AI processing when you enable transformation. Faces and surroundings may identify people or reveal private information. Transformed output is delivered to the meeting page.
- Audio: the current integration sends video-only input to Decart. For combined camera/microphone requests, the original microphone track is passed to the meeting rather than to the AI transformation. The meeting provider handles that audio under its own practices.
- Meeting-tab information: the extension reads the selected tab's URL and uses tab identifiers and enabled/blocked state to route controls. It does not request unrestricted browser-history access or send a general browsing-history list to our backend.
- Connection information: Railway, Decart and other infrastructure involved in connections may process IP addresses, timestamps and request metadata. Our backend uses temporary per-user request counters to limit abuse.
- Support: contacting our Gmail address provides your email address and message contents to the publisher and Google's email service. Do not send access keys, API keys or private meeting recordings in support messages.
3. Browser storage and retention
The reference image, prompt and selected model are stored in extension local storage until replaced, cleared or removed with the extension. The personal key and session control state are stored in extension session storage, which Chrome clears on browser restart or extension reload, update or disable.
The website's optional photo library stores an original reference image (which may contain embedded metadata), its name, a thumbnail and upload time on the publisher's Railway persistent storage. Saving requires a separate storage-permission checkbox and the Save to extension button. Choosing a file alone does not upload it. Each library belongs to a configured user identifier authorized by a personal access key. Anyone sharing that key can view and delete its photos. Saved photos remain until deleted through the website or removed by the publisher. Removing or rotating an access key does not automatically delete the associated library. Keep stable user identifiers when rotating keys; never assign an old identifier to a different person without removing its old library.
The extension loads the library when a personal key is entered or the popup opens with a session key, then refreshes every 20 seconds while open. Thumbnails appear for selection; starting transformation downloads the selected original. Library refresh does not change an active meeting. Deleting a photo removes it from the live library and prevents new library downloads, but does not erase copies already downloaded into browser storage, active sessions or provider-held data. Backups may retain earlier copies according to the publisher's backup arrangements; no backup-expiry period is promised here.
The application does not implement server-side storage of camera recordings. This is not a promise that processing providers or meeting services do not retain them. Access-key hashes remain in server configuration until changed or removed. Local clearing does not remove cloud library photos, backend access records, infrastructure logs, support correspondence or provider-held data.
Exact retention periods for Railway logs, publisher support records and Decart processing data have not been verified for this deployment. Contact the publisher for retention information before sending sensitive material. No zero-retention or automatic deletion deadline is promised by this review copy.
4. Who receives information
Railway hosts the publisher's authorization backend. Decart processes transformation inputs and produces output. Your meeting service and participants receive the video you transmit and normal meeting audio. Google/Gmail handles email you send to our support address. These providers may use infrastructure in countries different from yours.
Part of the extension runs inside the meeting page. On Meet and Zoom Web that page receives the selected reference image, prompt and a temporary processing token; other scripts sharing its execution context could access them. On Teams Web the provider SDK and token run in an isolated extension context, with output handed to the page. The personal access key and full photo library are not intentionally sent to meeting-page scripts. Use the integration only on trusted meeting sites.
5. Decart processing and training
Decart's published API Terms, section 2.3, permit use of inputs and outputs to operate and improve services, develop products, and train AI models. This notice does not promise that your content is excluded from training. Any account-specific agreement changing those terms must be confirmed before a different promise can be made.
See Decart's Privacy Policy and Data Processing Agreement for further provider information. Their applicability and the deployment's retention arrangements require publisher confirmation. Do not send confidential or sensitive meeting content when these terms are unsuitable for you.
The extension's application code does not implement advertising, payment collection or behavioral analytics. This statement does not describe or override all provider practices.
6. Your choices and deletion requests
- Do not enable transformation if you do not agree to sending the disclosed inputs for cloud processing.
- Use the popup's Stop control to end transformation. To intentionally return to real video, use the explicit real-camera control and check the meeting preview.
- Use Clear saved settings in the extension to clear its saved working image, prompt, model and personal key. Some session control state can remain until the session ends. Use the website's Delete saved photo controls to remove cloud-library photos separately.
- Remove camera permission or uninstall the extension to prevent further extension use. Uninstalling does not delete data already shared with others.
- Email devblu.work@gmail.com to request access-key revocation, information about your data, or help with deletion. Describe the request without including credentials. Provider-held records and meeting recordings may require requests to the relevant provider; immediate or complete removal cannot be guaranteed.
Revoking a key prevents new authorizations after the server configuration is updated; it does not necessarily terminate an already established processing session. Privacy rights and exceptions depend on the applicable law.
7. Security and responsible use
The token service uses HTTPS, server-side key hashing and authorization checks. Browser storage and any online service are not risk-free; do not share your personal key. Only use portraits you own or have permission to use. Keep the AI-generated video label visible and tell participants about the transformation. Do not use Virtual CAM for deceptive impersonation or identity-verification bypass.
8. Updates and contact
The document date identifies this version. Check this page for revisions. Questions about the extension, access records, or this notice can be sent to devblu.work@gmail.com.