PAT Monitor Privacy Policy

Last updated: 30 September 2026

PAT Monitor is a pet and baby monitor that runs on your own Windows PC. The developer runs no service for it, and the program sends nothing to the developer. Video, audio and recordings are sent to the devices you sign in from. The live stream is always encrypted. At home, the pages and the recordings travel over your own network without encryption. From outside the house, everything travels over HTTPS.

This page describes what the program does with information, as the Microsoft Store requires. It covers every version; where the Store version differs, it says so.

In short

What the program handles

Video and audio

While running, the program captures the chosen camera and microphone, or the default ones if none is chosen. It streams them to signed-in browsers over WebRTC, encrypted end to end. The stream goes only to those browsers and to the recording feature described below.

So that a clip can include the moments before it starts, the last few seconds of video and audio are kept in memory and constantly overwritten. They reach the disk only if a clip is made, and are gone when the program stops.

Windows decides whether the program may use the camera and the microphone (Settings > Privacy & security). If you withdraw a permission, the program loses that source and says so.

Talk-back

When you turn on talk-back from the page, your browser uses your device’s microphone, with that browser’s permission, and your voice plays from the PC’s speaker over the same encrypted connection. The program does not save the voice it receives. While you talk, the room’s audio is not sent to viewers, but the PC’s microphone keeps recording the room, so your voice from the speaker can end up in a clip made at that time.

Detection

Sound and motion detection run inside the program, on your PC, with a model built into the executable. The detectors send nothing over the network. Their alerts appear on the monitor’s pages and in the log, and as notifications on the devices where you turn those on (see below).

Recordings

A clip is made when an event is detected, if that detection is on, or when you press the record button. Clips are MP4 files, with audio when a microphone is capturing, saved in the PAT Monitor folder in your Videos folder. If that folder is not available, they are saved in a video folder next to the settings. The program uploads them nowhere. The page plays them, and can download them, on the device you sign in from.

Deleting a clip from the page removes the file permanently. Clips are also deleted automatically when they are older than the retention period or exceed the size limit (by default 14 days or 1000 MB). Clips marked as kept are never deleted automatically, and clips you record by hand start out marked as kept.

If your Videos folder is synchronised to OneDrive or to a backup, your clips are too, and deleting one here may leave a copy there. That synchronisation is not done by PAT Monitor.

Settings

Outside the Store, the settings are in %APPDATA%\PAT Monitor\config.yaml. In the Store version they are there too if that folder already exists; otherwise Windows keeps them in the app’s private folder under %LOCALAPPDATA%\Packages. They hold your configuration, including camera, microphone and speaker as Windows device identifiers, the name used for the public address, and the rest of your feature choices. The monitor password itself is not stored, only a hash of it. A Tailscale authentication key is stored there only if you put it there yourself, as plain text.

If you turn on access from outside, Tailscale’s own data for this PC (its keys, its certificate and its log files) is kept in a tsnet folder with the program’s other files on this PC.

If you turn notifications on for a device, a push.json file in the same place keeps, for each such device, the address its browser’s push service gave it, the keys that encrypt messages to it, the language of its page and when it was last reached, plus a key of the program’s own that signs its messages. Turning notifications off on a device removes that device from the file.

Your browser keeps a sign-in cookie and your language choice. On a device where you turn notifications on, it also keeps the notification permission, and a small script (a service worker) that shows them; turning them off removes the script.

Log

The program writes a plain text log in the log folder next to the settings, in rotating files. It records what the monitor did, including viewer connections and sign-ins, with the network address and device type of each. With access from outside on, it also records the public address. With notifications on, it records which push service each device uses, what the service answered and how long a notification took to appear. Folder paths in it include your Windows user name. It contains no video or audio. You can read it, and delete it after quitting the program.

Connections, and what the other end sees

STUN servers

Each time a viewer connects, the PC and the browser ask a public STUN server for their public address. By default these are run by Google and by Cloudflare. The server receives the public IP address and port of whoever asks. The request from the PC carries nothing else; what your browser sends is up to your browser. Those companies’ own privacy policies apply. You can replace the servers in the stun_servers setting. An empty list restores the defaults.

Tailscale, only if you turn on access from outside

Access from outside the house is off until you turn it on, and it does not start while no password is set. It uses your own Tailscale account. Tailscale provides the public address, obtains its HTTPS certificate and carries visits to that address to your PC. Those visits, meaning the pages, the recordings and the setup of each video call, cross Tailscale’s servers encrypted and are decrypted only on your PC and on your device (see how Funnel works). The live video and audio do not use the public address. If the Tailscale app is also installed on your PC and your phone, the live stream can travel over your Tailscale network, and Tailscale may relay it, still encrypted.

While access from outside is on, the Tailscale software built into PAT Monitor sends its own diagnostic logs and usage counters to Tailscale, as Tailscale’s app does. They describe the connection, including network addresses and attempts to reach other devices, not the video, the audio or the pages (see Tailscale’s logging overview). PAT Monitor adds nothing about you or your camera to them. Tailscale’s privacy policy covers all of this.

To turn access from outside off, set funnel_enabled to false in the settings and restart the program. The PC stays listed in your Tailscale account until you remove it there.

Push services, only on devices where you turn notifications on

Notifications are off until you turn them on, one device at a time, from the monitor’s page. When an alert appears, the PC sends a message for each such device to the push service that device’s browser uses: Apple for Safari, Google for Chrome and most Android browsers, Mozilla for Firefox, Microsoft for Edge. The message is encrypted for that device, and the push service cannot read it. The service sees the PC’s public IP address, the device’s address at that service, when the message was sent and its size, and the project’s web address, which identifies the sender. The program adds nothing about you, your camera or your network. Each company’s own privacy policy applies. Removing the web app from a phone’s Home Screen, or turning notifications off on the page, ends it.

Update check

The Store version has none. The version distributed outside the Store asks GitHub whether a newer release exists, a few minutes after it starts and then once a day while it runs. The request carries your public IP address and the version number, and nothing about your configuration, your network or who is watching. Only the description of the latest release is fetched; no program file is downloaded. The update_check setting turns it off.

Microsoft Store

Installation and updates from the Store are handled by Microsoft under the Microsoft Privacy Statement. The developer receives aggregate reports from Microsoft (installations, ratings and reviews, crash counts) and no contact details or identity. A review you write is public, under the display name you chose. The program itself sends nothing to Microsoft.

Children

A baby monitor is pointed at a child. The program sends the developer nothing about a child or anyone else. PAT Monitor asks for no name, e-mail address or date of birth; signing in takes only the password you chose. The only account involved is your own Tailscale account, and only if you turn on access from outside.

What you control

Signing in

The password can be set only on the PC itself. After that, every page requires signing in. Failed sign-ins are slowed down. A session ends after 7 days without use, when the program stops, or when the password changes. At home, the password travels over your own network without encryption; from outside, over HTTPS.

Recording other people

Where the camera points, what is recorded and who can reach it are your choices. Recording in a workplace, a business or premises other people visit, or with a camera that covers a street, a shared entrance or a neighbour’s property, can carry obligations under data protection law.

Sound needs particular care. A microphone picks up conversations the camera does not see, and in some countries recording what people say (for example a babysitter, a carer or a guest) without their consent can be a crime, even in your own home. Tell the people who come into your home that a monitor is on and that it picks up sound. For the picture without the sound, withhold the microphone in Windows (Settings > Privacy & security).

This page

This page is static: no cookies, no scripts, nothing loaded from elsewhere. It is hosted on GitHub Pages, whose servers receive the request for it.

Changes

This page changes when the program’s handling of information changes, and the date at the top shows the last change. A change applies from its date. Every version is kept as a dated revision in the project’s public repository.

Contact

Questions about this page: patmonitor@outlook.com.