DRAFT for lawyer review. Not in force until reviewed and published. Placeholders are in [brackets].

Hotshot Orchestrator Privacy Policy

Last updated: 2026-10-03

This policy explains what personal data the Hotshot Orchestrator app and the Hotshot Sync service handle, why, and what you can do about it. The data controller is Hüseyin Onur Tercan, trading as Hotshot Interactive, [PLACEHOLDER: postal address], Republic of Türkiye ("we", "us"). Contact: privacy@hotshotinteractive.com.

The short version

1. On your device

The app keeps its data in its data folder on your computer or phone:

We have no access to any of this. You can delete it by removing the data folder or uninstalling the app. "Report a problem" (when available) builds a file for you to send; nothing leaves your device unless you send it.

Agents act with your permissions. If you let an agent use the internet, your accounts or your screen (computer use), the data it sends goes to the services involved, not to us.

2. Updates and the download site

The app checks orchestrator.hotshotinteractive.com (served by Firebase Hosting, run by Google; also reachable as hotshot-orchestrator.web.app) for updates. Like any web server, it receives your IP address and the requested file; Google keeps such logs under its terms. We do not combine them with anything else.

3. Hotshot Sync

When you sign in to Hotshot Sync, the service stores:

DataWhy
Your e-mail address, and the account identifier from Firebase Authentication if you sign in with Google, GitHub or a linkTo identify your account and send sign-in codes
Device names, platforms and public keys of the devices in your space; their permission (View, Control, Full) and statusSo your devices can find and verify each other
Push tokens of your phones (Android, later Apple)To wake a phone when an agent needs you
Timestamps: account created, device joined, last seen, sessions' expiryTo run the service and remove stale data
Short-lived records for abuse limits: hashed sign-in codes, and your IP address and e-mail with the time of a sign-in attemptTo stop brute-force and spam; kept for about an hour
Your plan (for example "beta")To apply the plan's limits

Content is end-to-end encrypted: your devices encrypt every frame with keys only they hold (the server stores your space key only wrapped for each device). The server routes ciphertext; it cannot read your terminals, files, prompts or agent output. If you host your own server (hotshot-relay), none of the above reaches us.

4. Crash reports and usage statistics (opt-in)

Both are off by default (Settings → Privacy) and can be turned off again at any time.

Neither contains your name, e-mail, account, device identifier, IP address (it is not stored), file contents or prompts.

5. Retention

DataKept for
Sign-in sessionsuntil they expire or you sign out
A removed device's record30 days after removal, then deleted
Push delivery events (rate limiting)at most 7 days
Abuse-limit records (sign-in attempts, IP addresses)about an hour
Crash reports and usage statistics90 days
Your account and active devicesuntil you delete the account

6. Deleting and exporting your data

7. Who processes data for us

ProviderWhat forWhere
Cloudflare, Inc. (Workers, D1, Durable Objects)Runs the Hotshot Sync server and its databaseglobal network; [PLACEHOLDER: data location to confirm]
Google LLC, Firebase Authentication and Firebase HostingSign-in, the download and update siteUnited States and others
Resend, Inc.Sending e-mail sign-in codesUnited States
Google Firebase Cloud Messaging, Apple Push Notification serviceDelivering push notifications to phones (the payload carries no content)United States and others

Each acts under its data-processing terms. Some are outside Türkiye and the EU; transfers rely on [PLACEHOLDER: the lawyer to confirm the transfer basis under KVKK art. 9 (as amended in 2024) and GDPR Chapter V, e.g. standard contractual clauses].

We do not sell, rent or share personal data for advertising.

We process Sync account data to perform our contract with you (KVKK art. 5(2)(c); GDPR art. 6(1)(b)), abuse-limit records for our legitimate interest in a secure service (KVKK art. 5(2)(f); GDPR art. 6(1)(f)), and crash reports and usage statistics with your consent, which you can withdraw in the app (KVKK art. 5(1); GDPR art. 6(1)(a)).

9. Your rights (KVKK and GDPR)

Under the Turkish Personal Data Protection Law No. 6698 (KVKK, art. 11) and, where it applies, the EU General Data Protection Regulation, you can ask whether we process your data and for what; get access to it and a copy; have it corrected or deleted; object to or restrict processing; receive it in a portable format; learn which third parties received it; withdraw consent; and object to a result based solely on automated processing. Write to privacy@hotshotinteractive.com; we answer within 30 days (free of charge, as KVKK art. 13 requires). You may also complain to the Turkish Personal Data Protection Authority (KVKK, kvkk.gov.tr) or to the data protection authority where you live.

10. Children

The app and the service are not directed at children under 16, and we do not knowingly collect their data.

11. Security

Secrets stay in the operating system's keychain; Sync traffic is end-to-end encrypted and carried over TLS; the server stores hashes of session tokens and sign-in codes, not the values. To report a vulnerability, see SECURITY.md (security@hotshotinteractive.com).

12. Changes

We will announce material changes in the app or on our website before they apply, and keep the date at the top current.