Last updated: 11 August 2026.
This Privacy Policy explains how School Bus Home ("we", "us"), operated by Erbacci LLC, collects and uses information. Contact: info@erbacciltd.com.
School Bus Home checks your linked Ring entry camera or doorbell for a school bus during the time windows you define on school days.
It is an arrival-awareness convenience — not a childcare, supervision, security, or life-safety service. It detects a school bus (a vehicle type), not people, and a detection is best-effort: a bus may stop out of camera view. Neither a detection nor its absence confirms that any person is or is not home, or where anyone went.
When a motion or doorbell event arrives inside one of your windows — the after-school window, or the morning window if you turned it on — we run one check on that event. A check retrieves up to three still image snapshots from your Ring device through the Ring Partner API, taken two seconds apart at the moment of the event, and looks at each one in two steps, stopping as soon as it can answer. (We take more than one because Ring's upload can lag and because a bus can be mid-turn or out of frame in the first picture.) Both windows use exactly the same path, the same two steps and the same discard-immediately rule; nothing extra is fetched, kept, or looked at for the morning.
vision.erbacciltd.com/schoolbushome/classify, and that address involves two
hops:
403). The only thing this step is asked is whether the picture shows a US
yellow school bus, and the only thing it returns is that yes/no with a confidence value. It
never identifies anyone: no faces, no ages, no names, no licence plates. The
picture is written to disk at neither hop — it is held only for the moment the check takes and then
discarded, and the logs there record the decision, a confidence value and a timing, never image
data. If this step is slow, unreachable, or returns an error, the answer falls back
automatically to Amazon Bedrock running Anthropic's Claude model inside AWS — in
which case the picture never leaves AWS at all — and after 5 consecutive failures the app stops
calling our server and uses Bedrock until it recovers.Pictures that do not show a school bus are discarded immediately after classification — they are never written to file storage or to any database. When a school bus is confirmed, we keep that one picture, so you can see the evidence behind the alert: one image for the after-school window and, if you turned it on, one for the morning window. It is stored encrypted, is never public, and is deleted automatically after 31 days — the same horizon as the daily record it belongs to — or immediately when you delete your account. Alongside it we keep the derived result: a yes/no "school bus present", a confidence value and the timestamp. We do not access, request, or store any recorded video, media clips, live view, audio, or biometric data. No video is stored. We use no facial recognition and do not identify, describe, or track any person. Each step is asked its one question about the one picture in front of it and nothing more: we do not use your images to train, fine-tune, or improve any model, neither the model on our own step-2 server nor the models we call inside AWS. And the step-2 server is ours: each picture is held there only for the moment the school-bus check takes and is not kept.
How many pictures this adds up to. We count our budget in checks (we call them vision attempts), and a check is not one picture — it is up to three. Each window has its own daily budget: 12 checks for the after-school window and 4 for the morning window, and each window stops for the day as soon as a school bus is confirmed. So a worst-case school day is around 36 still images from your camera with the morning window off (12 × 3), and around 48 with it on (16 × 3). Most days are far below that, because a confirmed bus ends the window and most checks stop at the first picture. To be precise about what those budgets are: they are spending limits, not a hard shutter. We count a check once it has finished, so if your camera fires a burst of events at once a window can run a few checks past its budget before the count catches up and closes it. Whatever the number, every one of those images is classified in memory and discarded — the retention table in section 5 does not change with the count.
School Bus Home needs a Ring device with an active cloud recording (Ring Protect) plan so that a still image exists at the moment of the event; without one, the app tells you detection is unavailable for that camera rather than reporting a false result.
We collect no information from or about children; your schedule describes your household's door, not a person.
We use the data solely to check your windows for a school bus, deliver the notifications you enabled, and run your account. We do not sell or share personal information for advertising, and we do not use it to train AI models.
The third parties that receive data are: Amazon Web Services (hosting, the Amazon Bedrock inference service and Amazon Rekognition when it acts as the pre-scan fallback, push via SNS), Anthropic (its Claude model runs the school-bus classification inside Amazon Bedrock — a sub-processor of that inference; it does not retain the image or train on it), Contabo GmbH (the German hosting provider whose rented virtual server runs the reverse proxy in front of the step-1 pre-scan described in section 2 — it carries the picture in transit and performs no analysis), Resend (email delivery), Apple/Google (push transport), and Ring (Amazon) (identity, event webhooks, and the still-image snapshot). The step-1 analysis itself runs on a server Erbacci LLC owns and operates in the United Arab Emirates: that is not an outside company, but it is a processing location outside the United States, which section 8 sets out. We disclose information only where required by valid legal process.
| Data | Retention |
|---|---|
| Account & settings (including your schedule) | Until you delete your account |
| Device list & live status | Until the device is removed or account deleted |
| Image snapshots that show no school bus — on our app systems | Not stored — classified in memory, discarded immediately (0 days) |
| The single snapshot that confirmed a school bus — on our app systems | 31 days (rolling, automatic expiry), encrypted and private; deleted at once if you delete your account. At most one per window per day |
| Image snapshots — passing through the step-1 reverse proxy (Contabo, Germany) | Not stored — forwarded only, for the moment the request takes (0 days) |
| Image snapshots — on the step-1 pre-scan server (Erbacci-owned, United Arab Emirates) | Not kept — held in memory only for the moment the vehicle check takes (0 days). The same no-image-retention commitment applies to it as to our AWS systems |
| Daily detection records (result, confidence, timestamps, and any morning sighting time — no image) | 31 days (rolling, automatic expiry) |
| Push tokens | Until unregistered or account deleted |
| Sign-in one-time codes | 10 minutes |
| Webhook idempotency records | ~24 hours |
| Diagnostic logs | 30 days |
| Family waitlist email (only if you joined it) | Until Family launches and we send you that one message, or until you ask us to remove it — whichever comes first |
Delete your account and all associated data any time from Settings → Delete account, or email info@erbacciltd.com. Removing the integration from your Ring app revokes our access immediately.
TLS in transit, AWS-managed encryption at rest, HMAC verification on every Ring webhook, short-lived signed session tokens, and least-privilege IAM. The call to the step-1 pre-scan described in section 2 is also encrypted in transit (HTTPS/TLS) and authenticated with a secret access key, which the endpoint requires before it will answer at all. To be exact about what that encryption does and does not cover: the connection is terminated at the reverse proxy in Germany and re-established onward to the pre-scan server, so the picture is protected against interception on the public internet, but it is not end-to-end encrypted from AWS all the way to the machine that analyses it.
School Bus Home is not directed to children under 13. It is used by adults to receive notifications about their own home; it has no features for children, collects no information from children, and does not identify any person in the images it classifies.
School Bus Home is operated by Erbacci LLC, a company registered in Wyoming, United States, and the app is distributed to users in the United States. Its cloud systems run in Amazon Web Services' us-east-1 (United States) region: your account, credentials, schedule, notification settings and detection history are stored there and nowhere else, and the school-bus answer in step 2 is produced there.
One processing step crosses borders — the step-1 pre-scan described in section 2. That step sends the still image out of AWS, through a reverse proxy hosted in Germany, to a server we own and operate in the United Arab Emirates, which returns only a yes/no and a confidence value. No image is stored at either place. So a picture from your camera can be transmitted outside the United States for the moment that check takes. If that path is unavailable, the pre-scan falls back to Amazon Rekognition inside AWS and the picture never leaves the United States. By using the app you consent to that transfer; unlinking the integration or deleting your account stops all processing immediately.
Erbacci LLC · info@erbacciltd.com