Privacy Policy
Effective 15 September 2026.
1. Scope
This policy covers this website, the hall-e desktop application, and the analysis service the application can call. The person responsible for the data described here is the developer of hall-e, reachable through the contact form.
2. This website
This website sets no cookies, runs no analytics, embeds no advertising, and loads no fonts, scripts or images from another company's servers. Nothing you do here is profiled. Our hosting provider, and the storage provider that serves the Windows installer when you download it, keep ordinary server logs, which include IP addresses and requested paths, for the security and operation of the site. A message sent through the contact form is delivered to our mailbox, where we hold it and our reply. To stop that form being used to send mail repeatedly, we record a one-way hash of your IP address for up to an hour, and nothing else about the request.
3. What stays on your computer
A capture is written to hall-e's application data directory on your machine, as a file of input events, a file of depth samples where depth was read, and a manifest holding the locally computed summary and its diagnostics. None of it is uploaded. hall-e keeps the 20 most recent captures and deletes older ones from disk. Your game selection is recorded in that manifest for your own reference.
Also on your machine: an installation identifier, which is a random value generated at installation and never derived from your hardware, and, if you sign in, a sign-in token sealed by Windows to your Windows account so that it is inert on another machine and under another user. Signing out deletes that token. hall-e performs no hardware fingerprinting.
4. What leaves your computer, and when
Nothing leaves your computer because of a capture. Data leaves only when you sign in or request an analysis, and then only:
- the locally computed summary of that capture, which is a set of timing statistics such as median and percentile intervals, counts, durations, and normalised depth statistics where depth was read;
- your account credentials and the session tokens they produce;
- the installation identifier, used so that a first free analysis can be allowed once per installation as well as once per account.
Raw input events and depth samples never leave your machine. Your selected game is not part of the summary. hall-e never collects game state, memory, network packets, video, screenshots, process lists, match results, keystrokes other than the four movement keys, mouse movement, scrolling, or buttons other than Mouse1, because it never records them in the first place.
5. Account data we hold
For an account: your email address, a stored password verifier rather than your password, the timestamps of account creation and sign-in, a ledger of credits granted, reserved, consumed and released, the payment reference a purchased credit came from, and a record of each analysis run with the summary it was given and the recommendations it returned. We never receive or store your card details. We use this to operate accounts, to run analyses, to answer your support email, and to detect abuse of the service.
6. Legal bases
Where the law of your country requires a legal basis, ours are: performance of our agreement with you, for accounts, analyses and credits; our legitimate interest in a secure and working service, for server logs and abuse prevention; and your consent where you give it, such as by emailing us. We do not rely on advertising or profiling interests, because we do neither.
7. Who processes data for us
We keep the number of third parties small and name them:
- a self-hosted database and authentication server, running on a private server operated for hall-e rather than shared with other products, in Malaysia;
- an application hosting provider that runs the analysis service, in that provider's Singapore region;
- the provider of the language model that produces recommendations, which receives the summary of a capture and nothing that identifies you beyond what that summary contains;
- our payment provider and the merchant of record behind it, who take the payment when you buy credits, hold whatever billing details you give them under their own policies, and tell us only that a payment for your account succeeded or was reversed.
These providers process data on our instructions to deliver the service. We do not sell personal data, and we do not share it for advertising.
8. International transfers
Because of the arrangement above, data you send us is processed on servers in Malaysia and Singapore, and the model provider may process a summary elsewhere. If you are in a region that restricts such transfers, using the analysis service means accepting that it happens.
9. Retention
Captures on your machine are kept until the rolling window of 20 removes them or you delete them yourself. Account records, the credit ledger and analysis runs are kept while your account exists, and the ledger is kept after closure only for as long as we need it for accounting and dispute handling. Server logs are kept for a short operational period. Email correspondence is kept until it is no longer useful for support.
10. Deleting your data
Delete hall-e's application data directory and every recording is gone from your machine, along with the installation identifier and any stored sign-in token. To close your account and have its records deleted, email us from the address on the account and we will confirm when it is done.
11. Your rights
Depending on where you live, you may have the right to ask what we hold about you, to receive a copy, to correct it, to delete it, to restrict or object to certain processing, and to complain to your data protection authority. Ask by email and we will answer. We will not charge you for asking and we will not treat you differently for having asked.
12. Security
Sign-in tokens on your machine are sealed by Windows to your account, and the access token used for requests is never exposed to the application's web view. On the server, access rules deny by default, the credit ledger and the analysis records cannot be written by a client, and service credentials and model provider keys stay on the server. No system is perfectly secure, and we do not claim otherwise. If a breach affects your data, we will tell you and the relevant authority where the law requires it.
13. Children
hall-e is not directed to children under 13, and we do not knowingly create accounts for them. If you believe a child holds an account with us, email us and we will remove it.
14. Changes to this policy
When this policy changes, the effective date above changes with it. If a change materially affects how we handle data you have already given us, we will tell account holders by email before it takes effect.
15. Contact
Privacy questions and requests go through the contact form, sent from the address on your account. The Terms of Service cover the rest of the arrangement.