Last updated: 30 September 2026
PAT Monitor is a pet and baby monitor that runs on your own Windows PC. The developer runs no service for it, and the program sends nothing to the developer. Video, audio and recordings are sent to the devices you sign in from. The live stream is always encrypted. At home, the pages and the recordings travel over your own network without encryption. From outside the house, everything travels over HTTPS.
This page describes what the program does with information, as the Microsoft Store requires. It covers every version; where the Store version differs, it says so.
While running, the program captures the chosen camera and microphone, or the default ones if none is chosen. It streams them to signed-in browsers over WebRTC, encrypted end to end. The stream goes only to those browsers and to the recording feature described below.
So that a clip can include the moments before it starts, the last few seconds of video and audio are kept in memory and constantly overwritten. They reach the disk only if a clip is made, and are gone when the program stops.
Windows decides whether the program may use the camera and the microphone (Settings > Privacy & security). If you withdraw a permission, the program loses that source and says so.
When you turn on talk-back from the page, your browser uses your device’s microphone, with that browser’s permission, and your voice plays from the PC’s speaker over the same encrypted connection. The program does not save the voice it receives. While you talk, the room’s audio is not sent to viewers, but the PC’s microphone keeps recording the room, so your voice from the speaker can end up in a clip made at that time.
Sound and motion detection run inside the program, on your PC, with a model built into the executable. The detectors send nothing over the network. Their alerts appear on the monitor’s pages and in the log, and as notifications on the devices where you turn those on (see below).
A clip is made when an event is detected, if that detection is on, or when you
press the record button. Clips are MP4 files, with audio when a microphone is
capturing, saved in the PAT Monitor folder in your Videos folder. If
that folder is not available, they are saved in a video folder next
to the settings. The program uploads them nowhere. The page plays them, and can
download them, on the device you sign in from.
Deleting a clip from the page removes the file permanently. Clips are also deleted automatically when they are older than the retention period or exceed the size limit (by default 14 days or 1000 MB). Clips marked as kept are never deleted automatically, and clips you record by hand start out marked as kept.
If your Videos folder is synchronised to OneDrive or to a backup, your clips are too, and deleting one here may leave a copy there. That synchronisation is not done by PAT Monitor.
Outside the Store, the settings are in
%APPDATA%\PAT Monitor\config.yaml. In the Store version they are
there too if that folder already exists; otherwise Windows keeps them in the
app’s private folder under %LOCALAPPDATA%\Packages. They hold
your configuration, including camera, microphone and speaker as Windows device
identifiers, the name used for the public address, and the rest of your
feature choices. The monitor password itself is not stored, only a hash of it. A
Tailscale authentication key is stored there only if you put it there
yourself, as plain text.
If you turn on access from outside, Tailscale’s own data for this PC (its
keys, its certificate and its log files) is kept in a tsnet folder
with the program’s other files on this PC.
If you turn notifications on for a device, a push.json file in
the same place keeps, for each such device, the address its browser’s push
service gave it, the keys that encrypt messages to it, the language of its page
and when it was last reached, plus a key of the program’s own that signs its
messages. Turning notifications off on a device removes that device from the
file.
Your browser keeps a sign-in cookie and your language choice. On a device where you turn notifications on, it also keeps the notification permission, and a small script (a service worker) that shows them; turning them off removes the script.
The program writes a plain text log in the log folder next to the
settings, in rotating files. It records what the monitor did, including
viewer connections and sign-ins, with the network address and device type of
each. With access from
outside on, it also records the public address. With notifications on, it
records which push service each device uses, what the service answered and how
long a notification took to appear. Folder paths in it include your
Windows user name. It contains no video or audio. You can read it, and delete it
after quitting the program.
Each time a viewer connects, the PC and the browser ask a public STUN server
for their public address. By default these are run by Google and by Cloudflare.
The server receives the public IP address and port of whoever asks. The request
from the PC carries nothing else; what your browser sends is up to your browser.
Those companies’ own privacy policies apply. You can replace the servers in the
stun_servers setting. An empty list restores the defaults.
Access from outside the house is off until you turn it on, and it does not start while no password is set. It uses your own Tailscale account. Tailscale provides the public address, obtains its HTTPS certificate and carries visits to that address to your PC. Those visits, meaning the pages, the recordings and the setup of each video call, cross Tailscale’s servers encrypted and are decrypted only on your PC and on your device (see how Funnel works). The live video and audio do not use the public address. If the Tailscale app is also installed on your PC and your phone, the live stream can travel over your Tailscale network, and Tailscale may relay it, still encrypted.
While access from outside is on, the Tailscale software built into PAT Monitor sends its own diagnostic logs and usage counters to Tailscale, as Tailscale’s app does. They describe the connection, including network addresses and attempts to reach other devices, not the video, the audio or the pages (see Tailscale’s logging overview). PAT Monitor adds nothing about you or your camera to them. Tailscale’s privacy policy covers all of this.
To turn access from outside off, set funnel_enabled to
false in the settings and restart the program. The PC stays listed
in your Tailscale account until you remove it there.
Notifications are off until you turn them on, one device at a time, from the monitor’s page. When an alert appears, the PC sends a message for each such device to the push service that device’s browser uses: Apple for Safari, Google for Chrome and most Android browsers, Mozilla for Firefox, Microsoft for Edge. The message is encrypted for that device, and the push service cannot read it. The service sees the PC’s public IP address, the device’s address at that service, when the message was sent and its size, and the project’s web address, which identifies the sender. The program adds nothing about you, your camera or your network. Each company’s own privacy policy applies. Removing the web app from a phone’s Home Screen, or turning notifications off on the page, ends it.
The Store version has none. The version distributed outside the Store asks
GitHub whether a newer release exists, a few minutes after it starts and then
once a day while it runs. The request carries your public IP address and the
version number, and nothing about your configuration, your network or who is
watching. Only the description of the latest release is fetched; no program file
is downloaded. The update_check setting turns it off.
Installation and updates from the Store are handled by Microsoft under the Microsoft Privacy Statement. The developer receives aggregate reports from Microsoft (installations, ratings and reviews, crash counts) and no contact details or identity. A review you write is public, under the display name you chose. The program itself sends nothing to Microsoft.
A baby monitor is pointed at a child. The program sends the developer nothing about a child or anyone else. PAT Monitor asks for no name, e-mail address or date of birth; signing in takes only the password you chose. The only account involved is your own Tailscale account, and only if you turn on access from outside.
clips_max_days and
clips_max_mb in the settings and restart; 0 means no
limit.%APPDATA% and
%LOCALAPPDATA% removes the settings, the log, Tailscale’s
data and any clips saved there. In the
Store version, uninstalling deletes the app’s private folder and what is
in it. A PAT Monitor folder in %APPDATA% or
%LOCALAPPDATA%, if one was used, and
clips in your Videos folder stay until you delete them.The password can be set only on the PC itself. After that, every page requires signing in. Failed sign-ins are slowed down. A session ends after 7 days without use, when the program stops, or when the password changes. At home, the password travels over your own network without encryption; from outside, over HTTPS.
Where the camera points, what is recorded and who can reach it are your choices. Recording in a workplace, a business or premises other people visit, or with a camera that covers a street, a shared entrance or a neighbour’s property, can carry obligations under data protection law.
Sound needs particular care. A microphone picks up conversations the camera does not see, and in some countries recording what people say (for example a babysitter, a carer or a guest) without their consent can be a crime, even in your own home. Tell the people who come into your home that a monitor is on and that it picks up sound. For the picture without the sound, withhold the microphone in Windows (Settings > Privacy & security).
This page is static: no cookies, no scripts, nothing loaded from elsewhere. It is hosted on GitHub Pages, whose servers receive the request for it.
This page changes when the program’s handling of information changes, and the date at the top shows the last change. A change applies from its date. Every version is kept as a dated revision in the project’s public repository.
Questions about this page: patmonitor@outlook.com.