DRAFT for lawyer review. Not in force until reviewed and published. Placeholders are in [brackets].
Hotshot Orchestrator Privacy Policy
Last updated: 2026-10-03
This policy explains what personal data the Hotshot Orchestrator app and the Hotshot Sync service handle, why, and what you can do about it. The data controller is Hüseyin Onur Tercan, trading as Hotshot Interactive, [PLACEHOLDER: postal address], Republic of Türkiye ("we", "us"). Contact: privacy@hotshotinteractive.com.
The short version
- The app works offline and without an account. What it stores stays on your device.
- Hotshot Sync, if you use it, stores what it needs to know which devices are yours. Everything your devices send each other (terminals, files, messages, agent lists) is end-to-end encrypted: our server cannot read it.
- Crash reports and usage statistics are off unless you turn them on, and carry no identifiers.
- We do not sell personal data or use it for advertising.
1. On your device
The app keeps its data in its data folder on your computer or phone:
state.json: your workspaces, agents, settings, paired devices and the counters of how often each view is used (these counters stay on your device unless you turn on usage statistics);- logs of what the app did, rotated by size, used to diagnose problems;
- agent sessions: the agent programs you run (Claude Code, Codex and others) keep their own conversation history in their own folders, under their makers' privacy terms; the app keeps terminal output and the hub's plans, messages and shared memory for its agents;
- secrets (OAuth tokens for services you connect, Sync device keys and the account session) in your operating system's keychain, never in
state.jsonor the logs.
We have no access to any of this. You can delete it by removing the data folder or uninstalling the app. "Report a problem" (when available) builds a file for you to send; nothing leaves your device unless you send it.
Agents act with your permissions. If you let an agent use the internet, your accounts or your screen (computer use), the data it sends goes to the services involved, not to us.
2. Updates and the download site
The app checks orchestrator.hotshotinteractive.com (served by Firebase Hosting, run by Google; also reachable as hotshot-orchestrator.web.app) for updates. Like any web server, it receives your IP address and the requested file; Google keeps such logs under its terms. We do not combine them with anything else.
3. Hotshot Sync
When you sign in to Hotshot Sync, the service stores:
| Data | Why |
|---|---|
| Your e-mail address, and the account identifier from Firebase Authentication if you sign in with Google, GitHub or a link | To identify your account and send sign-in codes |
| Device names, platforms and public keys of the devices in your space; their permission (View, Control, Full) and status | So your devices can find and verify each other |
| Push tokens of your phones (Android, later Apple) | To wake a phone when an agent needs you |
| Timestamps: account created, device joined, last seen, sessions' expiry | To run the service and remove stale data |
| Short-lived records for abuse limits: hashed sign-in codes, and your IP address and e-mail with the time of a sign-in attempt | To stop brute-force and spam; kept for about an hour |
| Your plan (for example "beta") | To apply the plan's limits |
Content is end-to-end encrypted: your devices encrypt every frame with keys only they hold (the server stores your space key only wrapped for each device). The server routes ciphertext; it cannot read your terminals, files, prompts or agent output. If you host your own server (hotshot-relay), none of the above reaches us.
4. Crash reports and usage statistics (opt-in)
Both are off by default (Settings → Privacy) and can be turned off again at any time.
- Crash reports contain the app version, operating system and version, processor architecture, the error message and the stack trace.
- Usage statistics contain the app version, operating system, architecture, the kinds of workspace in use (for example "code", "unreal") and the view counters (how often Mixed and Modes were used).
Neither contains your name, e-mail, account, device identifier, IP address (it is not stored), file contents or prompts.
5. Retention
| Data | Kept for |
|---|---|
| Sign-in sessions | until they expire or you sign out |
| A removed device's record | 30 days after removal, then deleted |
| Push delivery events (rate limiting) | at most 7 days |
| Abuse-limit records (sign-in attempts, IP addresses) | about an hour |
| Crash reports and usage statistics | 90 days |
| Your account and active devices | until you delete the account |
6. Deleting and exporting your data
- Delete: Settings → Hotshot Sync → Delete account removes your account, space, devices, keys and push tokens from the service at once (the API is
DELETE /v1/me). Backups of the service's database, if any, roll over within [PLACEHOLDER: 30] days. - Export: you can ask for a copy of the data the service holds about you (the same endpoint family, or by e-mail to privacy@hotshotinteractive.com). Encrypted content is not stored, so there is none to export.
- Data on your devices is yours to delete at any time.
7. Who processes data for us
| Provider | What for | Where |
|---|---|---|
| Cloudflare, Inc. (Workers, D1, Durable Objects) | Runs the Hotshot Sync server and its database | global network; [PLACEHOLDER: data location to confirm] |
| Google LLC, Firebase Authentication and Firebase Hosting | Sign-in, the download and update site | United States and others |
| Resend, Inc. | Sending e-mail sign-in codes | United States |
| Google Firebase Cloud Messaging, Apple Push Notification service | Delivering push notifications to phones (the payload carries no content) | United States and others |
Each acts under its data-processing terms. Some are outside Türkiye and the EU; transfers rely on [PLACEHOLDER: the lawyer to confirm the transfer basis under KVKK art. 9 (as amended in 2024) and GDPR Chapter V, e.g. standard contractual clauses].
We do not sell, rent or share personal data for advertising.
8. Legal bases
We process Sync account data to perform our contract with you (KVKK art. 5(2)(c); GDPR art. 6(1)(b)), abuse-limit records for our legitimate interest in a secure service (KVKK art. 5(2)(f); GDPR art. 6(1)(f)), and crash reports and usage statistics with your consent, which you can withdraw in the app (KVKK art. 5(1); GDPR art. 6(1)(a)).
9. Your rights (KVKK and GDPR)
Under the Turkish Personal Data Protection Law No. 6698 (KVKK, art. 11) and, where it applies, the EU General Data Protection Regulation, you can ask whether we process your data and for what; get access to it and a copy; have it corrected or deleted; object to or restrict processing; receive it in a portable format; learn which third parties received it; withdraw consent; and object to a result based solely on automated processing. Write to privacy@hotshotinteractive.com; we answer within 30 days (free of charge, as KVKK art. 13 requires). You may also complain to the Turkish Personal Data Protection Authority (KVKK, kvkk.gov.tr) or to the data protection authority where you live.
10. Children
The app and the service are not directed at children under 16, and we do not knowingly collect their data.
11. Security
Secrets stay in the operating system's keychain; Sync traffic is end-to-end encrypted and carried over TLS; the server stores hashes of session tokens and sign-in codes, not the values. To report a vulnerability, see SECURITY.md (security@hotshotinteractive.com).
12. Changes
We will announce material changes in the app or on our website before they apply, and keep the date at the top current.