Last updated: 7 August 2026.
This Privacy Policy explains how Dangerous Animal Alert ("we", "us", "our") collects, uses, and shares information when you use the Dangerous Animal Alert application and related services (the "Service"). Dangerous Animal Alert is operated by Erbacci LTD ("Erbacci"), the controller of personal data described below. Contact: info@erbacciltd.com.
Dangerous Animal Alert is an awareness tool for wildlife activity near your home. It watches the outdoor Ring cameras you already own (backyard, driveway, or a doorbell facing the yard) and classifies motion events to notify you when a wild animal that could be dangerous to pets — such as a coyote, bear, mountain lion, bobcat, alligator, snake, or bird of prey — is detected, so you can decide whether to bring cats or small dogs inside.
Dangerous Animal Alert detects and informs; it does not protect. It is not a safety device, not a protection system, and not a security or alarm system. It is designed for external, outdoor monitoring only, is never intended for indoor use, and it does not identify people — it performs no facial recognition, reads no license plates, and does no biometric analysis of any kind.
The Service, its interface, and all of its notifications and emails are provided in English only.
All analysis is performed on infrastructure operated by Erbacci — our cloud environment on Amazon Web Services, and one inference server of our own.
The frame is saved before it is analyzed. When a motion event arrives, we fetch one still frame from Ring and write it to our encrypted storage first, together with a SHA-256 hash of the exact bytes. Only then do the checks below run. This means a frame that turns out to contain no animal at all has still been stored: it is recorded as a suppressed sighting so your timeline shows that motion happened, and it expires on the ordinary timer in §6. We state this plainly because the order matters — nothing here is "checked first and discarded before we keep it".
Then, in order:
What is sent, and what is not. The request sent to our inference server contains the single still frame and nothing else — no name, email address, account identifier, camera name, or any other detail about you — and it is sent only for the binary "is there an animal, yes or no" pre-filter. The species classification never happens there: naming the animal is done exclusively by Amazon Bedrock inside our AWS environment in the United States. It is our own equipment, not an outside company's service: the image is not sent to any third-party AI provider, and the check produces no copy in any product we do not run ourselves.
Your snapshots are never used to train, fine-tune, or improve any AI model — not the model on our own server, and not the models on Amazon Bedrock. All processing is inference-only: the image is analyzed to answer your alert, and that is all.
Your stored snapshot stays in the United States. The saved copy of every sighting
lives in encrypted Amazon S3 storage in AWS's US region (us-east-1) and is never moved
elsewhere. The brief animal-presence check in step 1 is the one point at which the image is
transmitted outside AWS and outside the United States — see §10.
Retention during that check — what we can state, and what we do not claim. Our
backend sends the frame for that single call, requests no storage of any kind,
accepts only a short yes/no answer in reply, and never logs the image or keeps a second copy
of it outside AWS. The server is Erbacci's own equipment, so the frame is never handed to
another company at any point on the path. We have not completed an independent
verification of what the server's own software writes to disk while it runs the check, and
we therefore do not claim that the image is never written there; we will state the
verified answer here once that check is done. The only copy we deliberately keep is the stored
sighting snapshot, which lives in AWS us-east-1 and is covered by the retention table in
§6.
The app does not collect analytics or diagnostics from your device, and does not transmit your OS version, app version, or locale for analytics purposes.
We do not collect: faces, faceprints, or other biometric identifiers; license plates; audio; location data outside the camera's fixed outdoor view; contact list, calendar, or other unrelated device data.
Dangerous Animal Alert analyzes motion at outdoor cameras you own or control. You are responsible for lawfully operating your Ring cameras and for giving any notice or obtaining any consent that applicable law requires for outdoor recording. Many jurisdictions require that recording devices be disclosed. Dangerous Animal Alert classifies wild animals and does not identify people, but you remain the party responsible for operating the underlying cameras lawfully.
People who are not our users. An outdoor camera can capture people who never signed up for anything — neighbours, delivery drivers, visitors, passers-by, and children. Where a frame contains such a person, we process their image incidentally, as part of answering the camera owner's alert. We want to be clear about what that does and does not involve:
If you believe you were captured by a camera using Dangerous Animal Alert and you want to exercise your rights, write to info@erbacciltd.com. Please note that we cannot search our systems by a person's appearance — we have no way to do so, by design — so we will generally need the camera owner's cooperation, and we will tell you honestly if we cannot locate any data about you.
We do not sell your personal information. We do not "share" personal information for cross-context behavioural advertising as defined under CCPA/CPRA.
If you are in the EEA or the UK, the GDPR / UK GDPR requires us to tell you the legal basis for each purpose:
| What we do | Legal basis |
|---|---|
| Create and maintain your account, link your Ring account, discover your cameras, classify events, send push notifications, and show your sighting history | Contract — Article 6(1)(b): this is the Service you asked for |
| Send the per-sighting alert email (on by default, one per notified sighting) | Contract — Article 6(1)(b), as a service message about your own cameras; our legitimate interest in reaching you reliably (Article 6(1)(f)) as a secondary basis |
| Send the weekly wildlife digest | Consent — Article 6(1)(a). It is off unless you switch it on, and one click in any digest turns it off |
| Send sign-in one-time codes | Contract — Article 6(1)(b) |
| Verify webhook signatures, deduplicate events, throttle sign-in attempts, prevent abuse, and keep security access logs | Legitimate interests — Article 6(1)(f): keeping the Service secure, available, and not abusable |
| Keep diagnostic logs and operational metrics | Legitimate interests — Article 6(1)(f): diagnosing and fixing faults in a service people rely on |
| Process the image of a person incidentally captured by a user's camera (see §3) | Legitimate interests — Article 6(1)(f): alerting the camera owner to a dangerous animal, with no identification of any person |
| Retain records we are required to keep, and respond to lawful requests | Legal obligation — Article 6(1)(c) |
Where we rely on legitimate interests, you have the right to object — see §7.
We do not share your snapshots with any third party for analysis. The animal-presence check described in §2.2.1 runs on Erbacci's own inference server — that is us, not an outside company, and it is not a disclosure of your images to anyone else. Beyond the parties listed below, no one receives your camera images.
| Data | Retention |
|---|---|
| Account record | Until account deletion |
| Camera & species settings | Until account deletion |
| Sighting timeline | Fixed when the sighting is recorded, from the plan you are on at that moment: 90 days on the trial or a paid plan, 30 days on the free plan. A record already written keeps the period it was given — so if your plan lapses, the sightings from your paid period still expire on their original 90-day clock rather than being shortened. |
| Snapshot images | 90 days from capture, for every tier — purged immediately when you delete your account |
| Push notification device tokens | Until you remove the device or delete your account |
| Sign-in one-time codes | 10 minutes |
| Webhook replay-protection records | About 24 hours |
| Diagnostic / error logs | 30 days (some components, 7 days) |
| API access logs (including IP address and user-agent) | 90 days |
| Backups (point-in-time recovery) | Up to 35 days |
One consequence worth stating plainly. Snapshot images are kept for 90 days regardless of your tier, but the sighting record on the free/lapsed tier is kept for 30 days. So if you are not on the premium tier, a sighting can disappear from your timeline after 30 days while the underlying image remains in our storage for up to another 60 days before it expires. Deleting your account purges both immediately, at any time. We are reviewing this mismatch and intend to align the two.
Depending on where you live, you may have the right to access, correct, delete, port, or restrict processing of your personal information. Exercise these rights in the web console at dangerousanimalalert.erbacciltd.com/app, or in the Android app (Account → Delete my data), or by emailing info@erbacciltd.com. We do not discriminate against you for exercising these rights.
You have the following rights under the GDPR / UK GDPR:
We respond to requests within one month, as Article 12(3) requires. If a request is complex or you have made several, we may extend that by up to two further months and will tell you why within the first month.
If you are a California resident, you have rights under the CCPA/CPRA including the right to know, delete, correct, and opt out of "sale" or "sharing" (we do neither). Residents of other US states with comprehensive privacy laws — including Virginia, Colorado, Connecticut and Utah — have comparable rights. Email info@erbacciltd.com and tell us which state you are in.
Deleting your account is a synchronous purge, not a scheduled expiry. In one operation we delete your push-notification device tokens and their push endpoints, every sighting record and every stored snapshot image, and finally your account record itself, including the Ring access and refresh tokens held on it. If any snapshot cannot be removed on the first attempt, we tell you so in the response rather than reporting a clean success.
Three honest limits:
Separately, we have not verified what the inference server described in §2.2.1 writes to disk during a check, so we cannot state that a deletion reaches it. We would rather say that than imply a completeness we have not confirmed.
Your Ring access and refresh tokens are held on your account record in our database, protected by the encryption-at-rest and least-privilege access controls above, and are deleted when you delete your account.
No system is perfectly secure. If we ever discover a breach affecting your data, we will notify you and the relevant authorities as required by law — including, where the GDPR / UK GDPR applies, the Cyprus Commissioner for Personal Data Protection or the ICO within 72 hours of becoming aware of it where the breach is notifiable.
The Service is for adults. Our Terms of Service require you to be at least 18 years old and to be the owner of, or authorized to operate, the Ring cameras and Ring account you connect. We do not offer the Service to children and we do not knowingly create accounts for them.
What we will not claim. We cannot say that no child's data is ever processed. An outdoor camera can capture a child as a passer-by or a visitor, and where the Amazon Rekognition fallback runs, a generic scene label such as "child" can be stored alongside the sighting (see §2.3). We do not identify that child, do not attempt to, and could not do so with the systems we run. If you believe we hold information about a child and you want it removed, contact us and we will delete it.
Your account data and your stored snapshots are held in the United States, in
Amazon Web Services region us-east-1. Species classification runs on Amazon Bedrock in
AWS's United States regions (Bedrock may serve a request from any US region in the
inference profile we use, so we do not claim it is pinned to a single one).
One processing step happens outside the United States, and it involves two countries. The brief animal-presence check described in §2.2.1 does not run in the US. The image is transmitted over an encrypted connection to a reverse proxy hosted on rented server capacity in Germany, and from there to a dedicated GPU inference server owned and operated by Erbacci LTD in the United Arab Emirates, where the yes/no check is performed. Your snapshot therefore transits Germany and is processed in the United Arab Emirates. Both facts are stated here because both are true: routing the image through Germany is itself a processing of it, and the analysis itself happens in the UAE.
What crosses the border, and what does not. Only the single still frame crosses,
and only for the binary "is there an animal, yes or no" pre-filter. No name, email address, account
identifier or camera name is sent with it. The species classification does not happen
abroad — the animal is named by Amazon Bedrock inside AWS in the United States — and the
snapshot you can review in the app is stored, and stays, in AWS us-east-1 in the United
States.
If you are in the EEA or the UK. EU and UK data protection law applies to this processing — including because Erbacci LTD is established in Cyprus, an EU Member State. Two transfers out of the EEA/UK are involved, and we describe both.
1. Your account data and snapshots, to the United States. Everything we store — your account record, your sighting history and your snapshot images — is held in AWS in the United States, and the species classification runs there. This is a restricted transfer under Chapter V. Amazon Web Services is certified under the EU–US Data Privacy Framework (and its UK extension) and additionally offers Standard Contractual Clauses; those are the mechanisms relied on for the AWS leg.
2. The single frame, to the United Arab Emirates. The United Arab Emirates is not part of the EEA, and the European Commission has not adopted an adequacy decision for it (nor has the UK government issued UK adequacy regulations for it). Sending the frame there is therefore a restricted international transfer under Chapter V of the GDPR / UK GDPR. The German leg is inside the EEA and is not itself a restricted transfer.
We will not overstate the safeguards for that second transfer. An Article 46 transfer instrument for the UAE leg is being put in place and is not yet finalised. Because the receiving equipment is Erbacci's own rather than a separate company's, standard Standard Contractual Clauses cannot simply be signed between two counterparties, and we are taking legal advice on the correct instrument. Until that instrument is executed, we are not claiming to have one.
What is true today is that the following measures apply to that transfer: it carries the image and nothing else — no name, email, account identifier or camera name; it is encrypted in transit (TLS) and authenticated with a secret token; the only question asked is binary; no storage is requested; and the entire step can be switched off, in which case the frame never leaves AWS and the check is performed by Amazon Rekognition in the United States instead.
You can ask us about the current status of the transfer mechanism, and request details of the safeguards in place, by writing to info@erbacciltd.com. If you would prefer that your frames not be sent for that check, contact us.
If you are in the United States. This one step is still a transfer of your image outside the United States — to Germany in transit and to the United Arab Emirates for the check — and it is governed by the laws of those countries while it is there. We state it plainly rather than describe the Service as US-only processing, which it is not.
We may update this Privacy Policy. If changes are material, we will notify you in-app before they take effect.
Erbacci LTD, the data controller · info@erbacciltd.com
Registered office: Strovolou 77, Strovolos Center, Office 301, Strovolos 2018, Nicosia, Cyprus (Company No. HE 457237).
Erbacci LTD is established in Cyprus, an EU Member State. GDPR therefore applies to this processing by virtue of that establishment, wherever you live. Our lead supervisory authority is the Office of the Commissioner for Personal Data Protection of the Republic of Cyprus. Because we are established in the Union, no Article 27 EU representative is required.
Billing for the Dangerous Animal Alert subscription is handled by Erbacci LLC (Wyoming, USA) through the Ring Billing System, as described in the Terms of Service. Erbacci LTD, not Erbacci LLC, is the controller of the personal data described in this policy.