Privacy Policy
Effective
This policy explains how the current Hovermate Windows application, its optional integrations, legal pages and support form handle information.
Hovermate is provided by Paliverse Apps LLC, based in United States of America ("we", "us"). For privacy questions or requests, contact paliverse@outlook.com.
1. Your device and local data
The current application keeps profiles, crosshairs, menus, shortcuts, imported assets and application preferences on your computer. There is no separate Hovermate account registration. Licensed Steam builds require Steam verification as described below. There is currently no automatic first-party cloud synchronization of profiles; Steam Workshop sharing is a separate action you choose.
To provide features you enable, Hovermate processes local information such as application and window identifiers and titles, screen layout, keyboard shortcuts, pointer position, selected files and configured actions. Selection-aware integrations can read selection ranges, formatting and application state. Configured shortcuts can ask another application to act on your selection or take a screenshot; that application handles the content. Hovermate also captures its own rendered overlay content for display or previews and passes frames between its components, including its Game Bar widget, on your device.
The application also writes local diagnostic information, including errors and integration status. Logs can contain file paths, application details and information included in an error. The current first-party application does not automatically upload these logs, run an advertising tracker or send product-usage analytics to us.
2. Steam and license verification
In licensed Steam builds, Hovermate sends a short-lived Steam authentication ticket and a random request identifier to accounts.hovermate.gg over HTTPS. Our server uses Steam to authenticate the account and check ownership of Hovermate (App ID 5251790). It processes your Steam ID, any returned owner Steam ID, ownership status and temporary-license expiry, then returns a signed result with issuance and expiry times. The network connection also exposes your IP address to the hosting infrastructure.
The license service does not maintain an account or entitlement database or persist Steam tickets. We do not intentionally log tickets, request bodies or secret keys. Operational service logs contain limited diagnostic events. Routine access logging is disabled. Service diagnostic logs rotate daily and retain up to seven days of archived entries plus the current log; web-server errors use the same rotation as the legal website. Infrastructure backups can retain earlier copies until those backups expire. Records needed for an active security incident or legal obligation may be preserved separately.
A signed result is stored locally in protected form for offline verification, for up to its expiry (currently at most 28 days). Local clock and key-generation markers help validate that cache. A device-bound storage key may use the Windows TPM where available; the service does not receive a hardware fingerprint or TPM attestation in the current protocol.
Steam separately handles store purchases, payments, refunds, account information and Workshop. When you browse, subscribe to, download or intentionally publish Workshop items, Steam processes the corresponding requests, Steam account identifiers, item metadata and content you choose to upload. We do not receive your Steam password or payment-card details. See the Steam Privacy Policy.
3. Optional Discord integration
The integration has a dedicated Discord Integration Privacy Policy, including its requested permissions, token handling and removal instructions.
Discord integration is optional. It connects Hovermate to your Discord desktop client so that supported actions, such as microphone mute, deafen and voice controls, can be available from your menus. Availability depends on Discord permissions, the client and the features Discord makes available to the application.
- Authorization: you sign in and grant access on Discord's own authorization page. Hovermate does not ask for or receive your Discord password.
- Permissions: the current authorization flow requests
rpc,rpc.voice.readandrpc.voice.write. These support communication with the desktop client and reading or changing supported voice settings. We do not request access to message history through this flow. - Tokens: the application processes the authorization code, access token, refresh token, expiry and granted scopes. Tokens are exchanged directly with Discord over HTTPS and saved locally using Windows protection tied to the current Windows user. This protection does not make a compromised computer secure.
- Local client data: Discord may return account identifiers and profile information during authentication, together with voice settings and action responses. The current implementation uses the information needed to connect and perform your requested controls; it does not operate a server-side Discord profile database.
- Our server: the current Discord connection does not send your Discord authorization tokens or voice-control data through the server hosting these legal pages. Discord and your Discord desktop client still process information under their own terms and privacy policy.
Hovermate does not record the audio of your Discord calls through this integration. To revoke permission, remove Hovermate in Discord's User Settings → Authorized Apps. Turning off the integration in Hovermate stops its use but is not the same as revoking Discord's authorization or erasing the saved local token.
To remove the saved Discord token from your computer, close Hovermate and its Engine, then delete discord-auth.dat from the application's data folder. The current default folder is %LOCALAPPDATA%\Hovermate; a custom data-folder setting or older installation can change its location. This local deletion is separate from revoking permission in Discord.
4. Other integrations and external content
When you enable another integration or invoke an action, Hovermate communicates with the application or endpoint needed for that feature. This can include local OBS or Streamlabs connections, Office applications, a Figma companion or media controls. Settings can include local addresses, identifiers, pairing information and credentials. For example, the Figma companion sends document and page names, selection counts and available-action state to the local Hovermate application. Which information is used depends on the integration you configure.
Widgets and streaming: widgets can display the text, images, media metadata, selected integration values and application-performance information you configure. A stream-widget link makes that widget's content and selected live values available to a browser source, such as OBS, on your computer. The current service listens only on the loopback interface and uses local HTTP addresses under local.hovermate.gg/stream/; it does not upload your widget to our public website. Treat the full widget link as private, because another program on your computer with that link may read its output. Closing Hovermate and its Engine stops this local service. Your broadcasting or recording software can capture the output and disclose it to its audience or platform when you stream, record or share it.
External content: a configured web widget, external image URL or website link can contact the selected third-party host from your device. The host receives network information such as your IP address and the requested URL and may use cookies or browser storage where the browser permits them. URLs you enter may themselves contain personal information or access tokens. Use sources you trust, avoid embedding credentials and review widgets before displaying or broadcasting them. These third-party requests are separate from Hovermate's static legal pages.
Third-party applications and websites you open follow their own policies, including their handling of account information, network requests, cookies and browser storage. We do not control their independent processing.
Exporting a profile or module creates a file for you to share. Its configuration and included assets may contain information you added. Review exported content before sending it to someone else. A local export does not itself upload the package to us.
5. Website visits and support
These legal pages are static and use locally hosted artwork and styles. They do not add analytics, advertising scripts, contact forms, tracking cookies or third-party fonts.
Our web server processes your IP address and the requested address to deliver pages. Routine access logging is disabled. Error logs may contain connection details, including IP addresses and requested paths, when a request fails.
The pages and license service are hosted on a DigitalOcean server in Frankfurt, Germany. DigitalOcean processes infrastructure information to provide its hosting service; see its Privacy Policy. When you follow an external link, the destination handles that visit under its own policy.
Support form: at support.hovermate.gg, we receive your email address, the category, subject and description of your request, and any optional name or application version you provide. The form does not accept attachments. We use these details to handle your request, contact you, investigate reported problems and improve the affected functionality. Do not include passwords, access tokens, payment-card information or unrelated private content.
The support service runs on our DigitalOcean server and queues your submission for delivery to a private issue in our Hovermate repository on GitHub. The submitted details are available to authorized people and services with access to that repository; the issue is not a public forum post. GitHub processes the information to provide its service; see its Privacy Statement. You do not need a GitHub account to submit the form. GitHub and our communication providers may process information outside Germany or your country.
The form uses a security cookie, hm_support_security, with a two-hour lifetime and a form token to protect submissions against forgery and abuse. This cookie is needed to submit the form; it is not used for advertising or analytics. Your IP address is used for operational request limits. Routine access logging is disabled, and the application does not include request contents in its error messages. The support service does not run product analytics, send submissions to an AI model or use them for model training.
The receipt page shows a random reference number and delivery status, without displaying your email address, message or private GitHub issue address. Keep the receipt link for follow-up. Receipt or delivery confirmation does not mean that someone has reviewed or resolved the request. Replies are currently sent manually to the email address you provide; the service does not send automatic email confirmations.
Email support: you can also contact paliverse@outlook.com. We receive the contact details, messages and files you choose to send, together with delivery information provided by the communication service. We use them to answer your request, investigate an issue or handle a privacy request. Review logs and screenshots before emailing them and remove passwords, access tokens and unrelated private content.
6. Why information is processed
Information is used to provide features you request, maintain the application and website, investigate failures or abuse, respond to support and comply with applicable legal obligations. Local processing does not mean that we remotely receive or can inspect those files.
Where data-protection law requires a legal basis, we rely on performing the service you request for necessary functionality and support; our legitimate interests in operating and securing the website and resolving problems where those interests are not overridden by your rights; consent where required for optional processing; and legal obligations where applicable. You can withdraw consent for processing that relies on it, without affecting earlier lawful processing.
We do not sell personal information, use Discord API data for advertising or use it to train machine-learning models. Information we actually receive may be accessible to hosting or communication providers who help deliver those services, or disclosed when legally required. Any additional sharing of Discord API data must comply with Discord's rules and applicable law. Service providers may process data in countries other than your own; applicable transfer protections must be used where the law requires them.
7. Retention, security and deletion
- Local settings and content: remain until you remove them. Removing a profile may retain its authored asset files. Uninstalling or replacing the application does not necessarily erase its data folder, separate Game Bar data, exports or backups.
- Local credentials: may remain saved until removed or invalidated by the application. Revoking authorization at the provider prevents further authorized use but does not erase copies of data from your disk. To erase all local application data, close Hovermate and its Engine, then remove the application data you no longer want. Contact us for help locating it if you use a custom data folder.
- Website records: Error logs are rotated daily, retaining up to seven rotated files plus the current log. Infrastructure backups can retain earlier copies until those backups expire. Information needed for an active security incident or legal obligation may be preserved separately for that purpose.
- Support delivery queue: after GitHub confirms delivery, the local queued message and contact details are removed. A limited delivery record remains, including the request identifier, content hash, status, internal GitHub issue number and operational timestamps. Message and contact details for requests that have not been delivered, or whose delivery is uncertain, are removed by scheduled cleanup after seven days from submission; the remaining delivery records are removed after 30 days from submission.
- Support records on GitHub and in email: are kept while needed to answer the request, investigate or fix a problem and handle related follow-up, disputes, security issues or legal obligations. GitHub issues are not automatically deleted when the delivery queue or receipt expires, or when an issue is closed. Request correction or deletion by emailing paliverse@outlook.com, preferably with your receipt reference; we remove information no longer needed unless a legal obligation requires retention.
- Support operational logs: are limited diagnostic records with seven-day archived retention. Web-server error logs follow the website rotation described above. Infrastructure backups may retain earlier copies until those backups expire.
We use measures appropriate to the information involved, including HTTPS for these pages and Discord token exchange and Windows user-bound protection for saved Discord tokens. No storage or transmission method is guaranteed to prevent all unauthorized access.
8. Your choices and rights
You can use core features without enabling Discord, disable optional integrations, revoke access through a connected provider, remove local data or stop using Hovermate.
Depending on the law that applies, you may have rights to access, correct, delete or receive a copy of personal information we hold, restrict processing, withdraw consent or complain to your local data-protection authority. You may also object to processing based on legitimate interests, subject to applicable law.
Send a request to paliverse@outlook.com with the subject "Hovermate privacy request". Explain what information or interaction the request concerns. We may ask for only the information reasonably needed to verify the request and will respond within the period required by applicable law. We cannot remotely delete files that exist only on your computer, but we can explain how to remove them. For data held independently by Discord or another provider, contact that provider as well.
9. Children and policy updates
Hovermate is not intended for children under 13, or below a higher minimum age required for the relevant service or by applicable law. If you believe a child has sent us personal information that should be removed, contact us.
This policy covers the features described here when enabled in the applicable Hovermate release. Future cloud synchronization, direct payments, telemetry or additional account services require an updated description before they begin processing data. We will update this page when practices change and provide additional notice or consent where required. Previous published versions remain available in the legal archive.