This policy explains how the current Hovermate Windows application, its optional integrations, legal pages and support services handle information.
Hovermate is provided by Paliverse Apps LLC, based in United States of America ("we", "us"). For privacy questions or requests, contact support@hovermate.gg.
1. Your device and local data
The current application keeps profiles, crosshairs, menus, shortcuts, imported assets and application preferences on your computer. There is no separate Hovermate account registration. Licensed Steam builds require Steam verification as described below. There is currently no automatic first-party cloud synchronization of profiles; Steam Workshop sharing is a separate action you choose.
To provide features you enable, Hovermate processes local information such as application and window identifiers and titles, screen layout, keyboard shortcuts, pointer position, selected files and configured actions. Selection-aware integrations can read selection ranges, formatting and application state. Configured shortcuts can ask another application to act on your selection or take a screenshot; that application handles the content. Hovermate also captures its own rendered overlay content for display or previews and passes frames between its components, including its Game Bar widget, on your device.
The application also writes local diagnostic information, including errors and integration status. Logs can contain file paths, application details and information included in an error. The current first-party application does not automatically upload these logs, run an advertising tracker or send product-usage analytics to us.
2. Steam and license verification
In licensed Steam builds, Hovermate sends a short-lived Steam authentication ticket and a random request identifier to accounts.hovermate.gg over HTTPS. Our server uses Steam to authenticate the account and check ownership of Hovermate (App ID 5251790). It processes your Steam ID, any returned owner Steam ID, ownership status and temporary-license expiry, then returns a signed result with issuance and expiry times. The network connection also exposes your IP address to the hosting infrastructure.
The license service does not maintain an account or entitlement database or persist Steam tickets. We do not intentionally log tickets, request bodies or secret keys. Operational service logs contain limited diagnostic events. Routine access logging is disabled. Service diagnostic logs rotate daily and retain up to seven days of archived entries plus the current log; web-server errors use the same rotation as the legal website. Infrastructure backups can retain earlier copies until those backups expire. Records needed for an active security incident or legal obligation may be preserved separately.
A signed result is stored locally in protected form for offline verification, for up to its expiry (currently at most 28 days). Local clock and key-generation markers help validate that cache. A device-bound storage key may use the Windows TPM where available; the service does not receive a hardware fingerprint or TPM attestation in the current protocol.
Steam separately handles store purchases, payments, refunds, account information and Workshop. When you browse, subscribe to, download or intentionally publish Workshop items, Steam processes the corresponding requests, Steam account identifiers, item metadata and content you choose to upload. We do not receive your Steam password or payment-card details. See the Steam Privacy Policy.
3. Optional Discord integration
The integration has a dedicated Discord Integration Privacy Policy, including its requested permissions, token handling and removal instructions.
Discord integration is optional. It connects Hovermate to your Discord desktop client so that supported actions, such as microphone mute, deafen and voice controls, can be available from your menus. Availability depends on Discord permissions, the client and the features Discord makes available to the application.
- Authorization: you sign in and grant access on Discord's own authorization page. Hovermate does not ask for or receive your Discord password.
- Permissions: the current authorization flow requests
rpc,rpc.voice.readandrpc.voice.write. These support communication with the desktop client and reading or changing supported voice settings. We do not request access to message history through this flow. - Tokens: the application processes the authorization code, access token, refresh token, expiry and granted scopes. Tokens are exchanged directly with Discord over HTTPS and saved locally using Windows protection tied to the current Windows user. This protection does not make a compromised computer secure.
- Local client data: Discord may return account identifiers and profile information during authentication, together with voice settings and action responses. The current implementation uses the information needed to connect and perform your requested controls; it does not operate a server-side Discord profile database.
- Our server: the current Discord connection does not send your Discord authorization tokens or voice-control data through the server hosting these legal pages. Discord and your Discord desktop client still process information under their own terms and privacy policy.
Hovermate does not record the audio of your Discord calls through this integration. To revoke permission, remove Hovermate in Discord's User Settings → Authorized Apps. Turning off the integration in Hovermate stops its use but is not the same as revoking Discord's authorization or erasing the saved local token.
To remove the saved Discord token from your computer, close Hovermate and its Engine, then delete discord-auth.dat from the application's data folder. The current default folder is %LOCALAPPDATA%\Hovermate; a custom data-folder setting or older installation can change its location. This local deletion is separate from revoking permission in Discord.
4. Other integrations and external content
When you enable another integration or invoke an action, Hovermate communicates with the application or endpoint needed for that feature. This can include local OBS or Streamlabs connections, Office applications, a Figma companion or media controls. Settings can include local addresses, identifiers, pairing information and credentials. For example, the Figma companion sends document and page names, selection counts and available-action state to the local Hovermate application. Which information is used depends on the integration you configure.
Widgets and streaming: widgets can display the text, images, media metadata, selected integration values and application-performance information you configure. A stream-widget link makes that widget's content and selected live values available to a browser source, such as OBS, on your computer. The current service listens only on the loopback interface and uses local HTTP addresses under local.hovermate.gg/stream/; it does not upload your widget to our public website. Treat the full widget link as private, because another program on your computer with that link may read its output. Closing Hovermate and its Engine stops this local service. Your broadcasting or recording software can capture the output and disclose it to its audience or platform when you stream, record or share it.
External content: a configured web widget, external image URL or website link can contact the selected third-party host from your device. The host receives network information such as your IP address and the requested URL and may use cookies or browser storage where the browser permits them. URLs you enter may themselves contain personal information or access tokens. Use sources you trust, avoid embedding credentials and review widgets before displaying or broadcasting them. These third-party requests are separate from Hovermate's static legal pages.
Third-party applications and websites you open follow their own policies, including their handling of account information, network requests, cookies and browser storage. We do not control their independent processing.
Exporting a profile or module creates a file for you to share. Its configuration and included assets may contain information you added. Review exported content before sending it to someone else. A local export does not itself upload the package to us.
5. Website visits and support
These legal pages are static and use locally hosted artwork and styles. They do not add analytics, advertising scripts, contact forms, tracking cookies or third-party fonts.
Our web server processes your IP address and the requested address to deliver pages. Routine access logging is disabled. Error logs may contain connection details, including IP addresses and requested paths, when a request fails.
The pages and license service are hosted on a DigitalOcean server in Frankfurt, Germany. DigitalOcean processes infrastructure information to provide its hosting service; see its Privacy Policy. When you follow an external link, the destination handles that visit under its own policy.
Support form: at support.hovermate.gg, we receive your email address, the category, subject and description of your request, and any optional name or application version you provide. The form does not accept attachments. We use these details to handle your request, contact you, investigate reported problems and improve the affected functionality. Do not include passwords, access tokens, payment-card information or unrelated private content.
Private support system: the form queues your submission for delivery to our private support system at desk.hovermate.gg, hosted on DigitalOcean. Support requests submitted through the website, available support options in the application or our dedicated support mailbox are handled there by authorized staff and integrations. Records can include the request, contact details, correspondence, attachments, staff notes, drafts, status and delivery history. The conversation and files are not publicly accessible. You do not need a separate support account to send a request.
Email: our dedicated mailbox is support@hovermate.gg. We use Zoho Mail's EU service to receive email and send receipt notifications and replies from the support team. Zoho processes the sender and recipient addresses, message contents, attachments and mail-delivery information needed to provide that service; see the Zoho Privacy Policy. Incoming email and its attachments can be imported into the private support system and linked to your request. The support connector reads the designated support mailbox. Review logs, screenshots and other files before emailing them, and remove passwords, tokens and unrelated private content. Our providers may process information in other countries under the applicable service and transfer arrangements; using an EU mailbox does not make all processing exclusively local to your country.
Technical follow-up: when a report needs development work, authorized staff or integrations can link it to a private Hovermate issue in our Mantis bug tracker. A selected technical summary and description, together with an internal support reference, are sent for that purpose. The integration does not automatically copy the complete conversation or its attachments. Staff should omit contact details and other personal information that the technical task does not need.
Cookies and security: the public form uses hm_support_security, a security cookie with a two-hour lifetime, and a form token to prevent forged submissions. Authorized staff use separate session and security cookies on the private desk; staff sessions have an eight-hour lifetime. These cookies support access and request security, not advertising or analytics. IP addresses are processed for connection delivery and operational request limits. Routine access logging is disabled; limited diagnostic logs can record failures and connection information.
Automation: access by our integrations uses keys with specific permissions that can expire or be revoked. Authorized automation can create or read requests and perform the actions its permissions allow. API-created reply drafts require staff review and approval before they are sent; staff and integration actions can be recorded for accountability. This support workflow currently has no external AI provider connected. We do not use support submissions to train AI models or add advertising or product-usage analytics to the support form.
The public receipt page shows a random reference number and delivery status without displaying your email address, message or private desk address. Keep its link for follow-up. A receipt, delivery confirmation or automatic email acknowledgment does not mean that a person has reviewed or resolved the request. Subsequent correspondence is handled by email; the private desk is a staff workspace.
6. Why information is processed
Information is used to provide features you request, maintain the application and website, investigate failures or abuse, respond to support and comply with applicable legal obligations. Local processing does not mean that we remotely receive or can inspect those files.
Where data-protection law requires a legal basis, we rely on performing the service you request for necessary functionality and support; our legitimate interests in operating and securing the website and resolving problems where those interests are not overridden by your rights; consent where required for optional processing; and legal obligations where applicable. You can withdraw consent for processing that relies on it, without affecting earlier lawful processing.
We do not sell personal information, use Discord API data for advertising or use it to train machine-learning models. Information we actually receive may be accessible to hosting or communication providers who help deliver those services, or disclosed when legally required. Any additional sharing of Discord API data must comply with Discord's rules and applicable law. Service providers may process data in countries other than your own; applicable transfer protections must be used where the law requires them.
7. Retention, security and deletion
- Local settings and content: remain until you remove them. Removing a profile may retain its authored asset files. Uninstalling or replacing the application does not necessarily erase its data folder, separate Game Bar data, exports or backups.
- Local credentials: may remain saved until removed or invalidated by the application. Revoking authorization at the provider prevents further authorized use but does not erase copies of data from your disk. To erase all local application data, close Hovermate and its Engine, then remove the application data you no longer want. Contact us for help locating it if you use a custom data folder.
- Website records: Error logs are rotated daily, retaining up to seven rotated files plus the current log. Infrastructure backups can retain earlier copies until those backups expire. Information needed for an active security incident or legal obligation may be preserved separately for that purpose.
- Public support delivery queue: after the private desk confirms delivery, the queued message and contact details are removed from the public intake server. A limited delivery record remains, including the request identifier, content hash, status, internal ticket number and operational timestamps. Message and contact details for undelivered or uncertain requests are removed by scheduled cleanup after seven days from submission; the remaining intake delivery records and public receipt are removed after 30 days from submission.
- Private support records: tickets, correspondence and attachments in the private desk and Zoho mailbox, selected Mantis reports, staff notes, drafts and related delivery, duplicate-prevention and audit records are kept while needed to provide support, investigate or fix a problem and handle follow-up, disputes, security issues or legal obligations. They are not automatically deleted when the public receipt expires or a ticket is closed. Request correction or deletion by emailing support@hovermate.gg, preferably with your request reference. We review removal across the systems that hold the relevant information and remove what is no longer needed unless a legal obligation requires retention.
- Support diagnostic logs: have seven-day archived retention. Web-server error logs follow the website rotation described above. These diagnostic limits are separate from ticket history and staff audit records.
- Support backups: the private desk has access-restricted daily backups of its database and attachments, with snapshots older than seven days removed by the backup task. A separate restricted copy may be kept for a controlled backup or recovery check and removed when that check no longer requires it. Provider-managed backups can retain earlier copies until their own backup cycles expire. Deleting a live ticket does not immediately erase every backup copy.
We use measures appropriate to the information involved, including HTTPS for these pages and Discord token exchange and Windows user-bound protection for saved Discord tokens. No storage or transmission method is guaranteed to prevent all unauthorized access.
8. Your choices and rights
You can use core features without enabling Discord, disable optional integrations, revoke access through a connected provider, remove local data or stop using Hovermate.
Depending on the law that applies, you may have rights to access, correct, delete or receive a copy of personal information we hold, restrict processing, withdraw consent or complain to your local data-protection authority. You may also object to processing based on legitimate interests, subject to applicable law.
Send a request to support@hovermate.gg with the subject "Hovermate privacy request". Explain what information or interaction the request concerns. We may ask for only the information reasonably needed to verify the request and will respond within the period required by applicable law. We cannot remotely delete files that exist only on your computer, but we can explain how to remove them. For data held independently by Discord or another provider, contact that provider as well.
9. Children and policy updates
Hovermate is not intended for children under 13, or below a higher minimum age required for the relevant service or by applicable law. If you believe a child has sent us personal information that should be removed, contact us.
This policy covers the features described here when enabled in the applicable Hovermate release. Future cloud synchronization, direct payments, telemetry or additional account services require an updated description before they begin processing data. We will update this page when practices change and provide additional notice or consent where required. Previous published versions remain available in the legal archive.