← Legal

Privacy Policy

Last updated: [EFFECTIVE DATE] · Provided by [LEGAL ENTITY NAME] ("HCKConnect", "we", "us").

⚠️ Draft pending legal review — replace the [bracketed] placeholders and have a qualified attorney review before relying on this document.

This policy explains what data HCKConnect collects, why, and your choices. HCKConnect lets you remotely view and control computers you own or are authorized to access.

1. Data we collect

DataWhy
Account: username, email address, password (stored only as an Argon2 hash)Create and secure your account.
Two-factor secret (if you enable 2FA)Verify TOTP codes at sign-in.
Machines: name, operating-system description, last-seen time, online statusShow your computers and route connections.
Sessions: which user connected to which machine, start/end times, statusOperate and account for remote sessions.
Organizations/Teams: team names, members, and email invitationsSharing machines with teammates (optional feature).
Operational logs: connection metadata and approximate IP addressSecurity, abuse prevention, and diagnostics.

2. What we do not collect or store

The contents of a remote session — your screen video, audio, keystrokes, mouse input, clipboard, and transferred files — are end-to-end encrypted between the controlled computer and the viewing device (X25519 key exchange, AES-256-GCM). Our relay transports this encrypted data to connect the two ends and does not record or store your screen content. Session recordings, if you make them, are saved locally on your own device, not on our servers.

We describe the media as encrypted in transit end-to-end. We do not market this as "zero-knowledge"; see the Security page for the precise model and its current limitations.

3. How we use data

To provide and secure the service, authenticate you, route connections, prevent abuse, and communicate with you about your account. We do not sell your personal data.

4. Sub-processors

We use third parties to operate the service, including [HOSTING PROVIDER, e.g. DigitalOcean] for infrastructure and [PAYMENT PROVIDER, e.g. Stripe] for billing (which processes payment details we do not store). A current list is available on request.

5. Retention

Account and machine records are kept while your account is active. Operational logs are retained for [RETENTION PERIOD, e.g. 30–90 days]. You may request deletion of your account and associated data (see Your Rights).

6. Security

We use TLS in transit, end-to-end encryption for session media/input, Argon2 password hashing, optional two-factor authentication, and login rate-limiting. See Security.

7. Your rights

Depending on your location (e.g. GDPR/UK GDPR, CCPA), you may have rights to access, correct, export, or delete your data, and to object to certain processing. Contact [PRIVACY EMAIL].

8. International transfers

Your data may be processed in [COUNTRY/REGION]. Where required, we rely on appropriate safeguards for cross-border transfers.

9. Children

HCKConnect is not directed to children under [16/13] and we do not knowingly collect their data.

10. Changes

We will post changes here and update the "Last updated" date; material changes will be notified to account holders.

11. Contact

[LEGAL ENTITY NAME], [REGISTERED ADDRESS]. Privacy questions: [PRIVACY EMAIL].