Privacy Policy

Last updated: September 3, 2026

This Privacy Policy reflects how Ethereal Network Sciences PBC, DBA Hintjen ("Hintjen," also "we," "us," "our") processes the personal data of users of Homerun Desktop, Homerun Go and our web dashboard (together, the "Application" or "Platform"). Homerun Desktop is a self-hosting application for Windows. Homerun Go is the same thing for iOS and Android: it hosts a game server on the phone itself. The web dashboard lets you watch and control your servers from a browser. This policy explains how we collect and use your personal data and covers your rights regarding such personal data processing.

This Privacy Policy is a part of the Terms and Conditions for using the Application.

A note on scope. Homerun Desktop and Homerun Go let you run game servers on your own hardware. Because of that, this policy covers three different groups of people: people who use the Application, people who visit our website, and people who connect to a server that someone else hosts using Homerun Desktop or Homerun Go. If you are in that third group, Section 2.7 is the part that concerns you.

One interface, updated over the air. Homerun Desktop and Homerun Go show you the same interface. On a phone, Homerun Go downloads that interface from our content delivery network and updates it on its own, independently of the app store, after checking a signature we put on it. The download itself carries no account or device identifier. What the interface does with your data is the same on every platform, and it is what this policy describes.

1. Who We Are

Your data is processed by Ethereal Network Sciences PBC, DBA Hintjen, the developers of Homerun Desktop and Homerun Go. We are the data controller for the processing described in this policy.

The primary point for contacting us is via email at [email protected].

2. Data We Process

2.1 System Information

To install the Application correctly and to diagnose installation and runtime failures, Homerun Desktop collects technical information about your Windows system and transmits it to our servers, where we store it. This includes:

  • Operating system details: Windows version, build number, edition, architecture, display version and installation date.
  • Hardware information: manufacturer, model, processor type and core counts, total and installed physical memory, BIOS version and manufacturer, and whether virtualization is present.
  • Computer and account identifiers: your computer name, the network domain or workgroup it belongs to, the name and organization registered to your Windows installation, and your Windows product ID.
  • System configuration: system directory location, the list of installed Windows updates, startup state, and your time zone.
  • Timing information: when Windows was installed and when the computer was last started.
  • Diagnostic output: when an installation or system operation fails, we also transmit the error message, the technical stack trace, and the Application's own recent log output.

This information is sent when you install the Application, on each step of an installation you have started, and again whenever a system-level operation fails while the Application is in use. It is not sent on a continuous schedule, but it is not limited to a single moment at install time either.

Your computer's name is also used as the default display name for the device in your Homerun account, so that you can tell your devices apart. You can rename a device at any time.

On a phone, Homerun Go does not collect a system report of this kind. It reads your device's model, operating system version and free storage to decide what your phone can run and how large a server to start; the free-storage figure never leaves the phone. The device model and operating system version are attached to the crash and error reports described in Section 2.6. A phone's default name in your account is its model — on iOS, followed by a short fragment of an identifier Apple assigns to our app on your device, so that two phones of the same model can be told apart.

2.2 Network Information

We collect and store IP addresses in several places: when you create an account or sign in, when you join our waitlist, when a server you host reports its status, and when you open or click a link in an email we send you. Our analytics and error-reporting providers also receive your IP address as part of ordinary request handling, and derive an approximate location from it.

We use this information to operate and troubleshoot the Platform, to secure accounts against unauthorized access, to understand how the Application is used, and to measure whether our emails are being received. The Application also determines your public IP address (by querying a third-party lookup service, named in Section 6.1) so that connection details for the servers you host can be displayed and diagnosed. On a phone, that is the phone's public address — usually your mobile carrier's or your home network's — and it changes as the phone moves between networks.

2.3 Email Address

We collect your email address when you register, sign up for our waitlist or mailing list, accept an invitation to someone else's server, or contact support. Your email address is central to how the Platform works: it is the identifier you sign in with, and it links your account across our systems.

We use it to:

  • Send you sign-in links, invitations and other messages necessary to operate your account.
  • Send product updates, onboarding guidance and other marketing email. These messages contain tracking: we record when you open them and which links you click, together with the IP address and browser user agent used to do so.
  • Identify you in our analytics tools, so that behaviour can be linked to an account rather than an anonymous device.
  • Group users for product experiments and to decide which in-application messages you are shown.

Every marketing email includes an unsubscribe link, and unsubscribing stops further marketing messages. Messages that are necessary to operate your account — such as sign-in links — are not marketing and will continue.

If you join our waitlist, we also record the IP address and browser user agent used to sign up, and whether you have subsequently opened our email or downloaded the Application.

How you sign in. You can sign in with a link we send to your email address, or with a Google or Apple account. If you use Google or Apple, we receive from them the email address on that account, your name, and the identifier the provider uses for you; we do not receive your password. If you use Apple's option to hide your email, the address we receive is the relay address Apple creates for you, and email we send you passes through Apple.

Guest accounts. You can also use the Application without giving us an email address at all. A guest account has no email address and no way to recover it: it exists on the device it was created on, and if you uninstall the Application or lose the device, the account and the servers it hosts cannot be recovered. You can claim a guest account at any time with an email address or a Google or Apple sign-in, and everything on it moves to the claimed account. A guest account is otherwise treated like any other account in this policy.

Where you came from. If you installed the Application from a link shared by a creator or partner we work with, we record that referral against your account when the account is created, so that we can honour our arrangement with them.

2.4 Matrix ID and Display Name

Upon registration, you are assigned a Matrix ID (a unique identifier in the Matrix protocol). Additionally, you may provide a display name for your profile. Please be aware that:

  • Your Matrix ID will be shared with other Homerun Desktop and Homerun Go clients in your network
  • Your display name will be visible to other users of the Application
  • These identifiers are necessary for the communication functionality of the Platform
  • These Matrix IDs are not accessible from the broader Matrix network

Your display name is also shown publicly in some places outside the Application — see Section 6.2.

2.5 Product Analytics and Usage Data

We record how the Application and our web dashboard are used, in order to understand which features people use, where they get stuck, and whether changes we make are improvements. This analytics data is processed on our behalf by PostHog, Inc. (United States).

What is collected:

  • Events: a record of actions taken in the Application — for example opening a screen, creating or starting a server, installing a mod, changing a setting, or completing installation. Each event carries technical context such as the Application version, operating system, screen dimensions and browser user agent.
  • Identity: once you sign in, this activity is associated with your account and your email address. Activity recorded before you sign in is joined to your account when you do.
  • Approximate location, derived by our analytics provider from your IP address.
  • Experiments and feature targeting: which variant of a feature or message you were shown, and which group you were assigned to.
  • In-application messages: when we show you a notice, prompt or questionnaire in the Application, we record that it was shown and what you did with it.
  • Installation and uninstallation: including a record that the Application was removed.

We do not record your screen, and we do not automatically capture every click — only the specific events described above.

Guidance and questionnaires. Separately from the above, we run a service that decides which tips, achievements and questionnaires to show you and records what you did with them. It receives the event, your account, the platform and Application version you are using, and — where you answer a questionnaire — your answers.

On a phone, Homerun Go carries no analytics component of its own. The shared interface does the recording described above, and the app stores the identifier that ties those events together so that it survives an update. The app itself reports only a handful of facts about the app: that the interface finished loading, that you moved it to the foreground or the background, and that it recovered after the interface stopped responding.

Your choices. You can turn product analytics and crash reporting off, separately, at any time. On Homerun Go the setting is under More → Privacy; on Homerun Desktop it is in the account menu, under Privacy. If you are in the European Economic Area, the United Kingdom or Switzerland, we ask you before we send anything at all, and nothing is collected until you answer.

Turning something back on takes effect the next time you open the Application: what we do not collect is not collected by leaving the code out of the running app, rather than by asking it to stay quiet, so there is nothing to switch on again until it next starts. Turning something off applies immediately.

2.6 Crash and Error Reporting

When the Application encounters an error or crashes, we collect a diagnostic report so the fault can be found and fixed. These reports are processed on our behalf by Sentry (Functional Software, Inc., United States) and include the error message and stack trace, the Application version and platform, a trail of recent activity leading up to the fault, your account and device identifiers, and — because of how the reporting is currently configured — your IP address and request headers.

When a game server you host crashes, the Application also uploads that server's log output and configuration so we can diagnose the failure. Server logs can contain the names of players who were connected at the time. Before that log leaves your device we remove the IP addresses and the chat messages in it; players' names remain, because a fault that only happens when a particular player joins is otherwise impossible to describe.

On a phone, Homerun Go reports errors to us rather than to Sentry. Such a report carries the error message and where in the Application it happened, the Application and interface versions, the device model and operating system version, and your device identifier. Before it is sent, the Application removes access tokens, the query part of any web address, email addresses, and IP addresses from the text.

Crash and error reports are delivered into internal channels operated on third-party messaging infrastructure, so that our team sees them and can respond.

2.7 Servers You Host, and Players Who Join Them

This section describes information about your game servers, and about the people who connect to them. If you host a server, please read Section 10 as well — you have obligations to your own players.

While a server you host is running, the Application reports to us approximately every two minutes, and additionally whenever a player joins or leaves:

  • Server resource usage, uptime, and network responsiveness.
  • The number of players connected.
  • For each connected player: their in-game username, their Minecraft account identifier (UUID), the platform they are playing on, and — for players connecting from a console or mobile edition — their Xbox user identifier (XUID).
  • The public IP address of the machine hosting the server — on a phone, this is your phone's public address. It is what tells another player's game where to connect. To learn it, the Application asks a third-party service that answers with the address it sees.

If you run one of our built-in minigames, we additionally receive per-match statistics for each participating player — eliminations, wins, time played and similar in-game figures — recorded against that player's Minecraft account identifier.

We use this to operate and support the hosting service, to display server status and player lists to the host, to produce leaderboards and in-game achievements, and to understand how the Platform is used.

Remote support and your own console. A server's console is shown to you in our web dashboard, and our support team can ask a device you own for the Application's own log. Both travel from your device to us. Console lines have IP addresses and chat removed first, and the Application's log has access tokens, web-address query strings, email addresses and IP addresses removed, in each case by the same rules used for a crash report.

Please note: this information is collected about every player who connects to a Homerun-hosted server, including players who do not have a Homerun account and have never used our Application. Where a player later links their Minecraft account to a Homerun account, statistics previously recorded against that Minecraft identifier are associated with that account. Leaderboards display players' in-game usernames publicly.

We currently retain these records indefinitely. If you are a player who has connected to a Homerun-hosted server and you want your information removed, contact us at [email protected].

2.8 Website Analytics

Our website, including this page, uses Plausible Analytics to count visits and measure which pages, download links and outbound links are used. Plausible does not set cookies and does not track visitors across websites; it records the page visited, the referring site, and coarse device and country information derived from your IP address, which it does not retain.

Some pages also load styling and font resources from third-party content delivery networks, which necessarily receive your IP address in order to serve those files.

2.9 Linked Accounts and Integrations

If you choose to connect other accounts, we store the identifiers needed to operate that connection:

  • Discord: your Discord user ID and an access token, used to show your server status in Discord and, with your agreement, to add you to our community server.
  • Minecraft / Xbox: your Minecraft account identifier, Xbox user identifier and gamertag, used to link in-game activity and achievements to your Homerun account. Signing in to Minecraft through the Application takes place directly with Microsoft. Your Minecraft sign-in tokens are kept on your device — in the system keychain on iOS, and in encrypted storage on Android — and are not sent to us.

When you type a player's name into an operator, whitelist or ban list, or look up an Xbox gamertag, the Application asks Mojang or a public lookup service to turn that name into an account identifier, because that is what a game server's own files require. Displaying a player's avatar likewise fetches an image from a third-party service using that player's identifier.

2.10 Feedback, Surveys and Support

If you submit feedback, answer a questionnaire or survey, report a bug, suggest an application, or contact support, we store what you wrote along with your account identifier. Please avoid including sensitive personal information in free-text fields.

Submissions are routed into internal channels operated on third-party messaging infrastructure so that our team is notified and can respond.

2.11 Push Notifications

If you allow notifications, your device gives the Application a push token — an address for that installation, issued by Apple or Google — and we store it with the platform, the Application version, your device and your language, so that we can send you a notification and know which language to write it in. Notifications are delivered through Firebase Cloud Messaging, operated by Google, which necessarily receives the token and the message in order to deliver it.

You can turn notifications off at any time in your device's settings. Signing out removes the token from our records, so a phone that someone else signs into does not receive the previous person's notifications.

3. Purpose for Processing Data

We collect and process your data for the following purposes:

3.1 Providing and Improving Our Application

  • To provide you with access to all features and functionality of the Application
  • To ensure the Application runs efficiently on your system
  • To identify and fix technical issues and bugs
  • To improve the Application based on usage patterns and system configurations
  • To run product experiments and measure whether changes are improvements
  • To facilitate communication between users through the Matrix protocol

3.2 Technical Support

  • To help troubleshoot issues when you contact our support team
  • To verify your identity when handling support requests
  • To analyze system information for resolving technical problems

3.3 Security and Fraud Prevention

  • To protect your account and data from unauthorized access
  • To detect and prevent fraudulent activities
  • To maintain the security and integrity of your self-hosted applications and our Platform

3.4 Communication and Marketing

  • To send you messages necessary to operate your account
  • To send product updates and marketing email, and to measure whether those messages were opened and acted on
  • To decide which in-application messages, prompts and questionnaires to show you

3.5 Legal Compliance

  • To comply with applicable laws and regulations
  • To respond to legitimate legal requests from authorities
  • To establish, exercise, or defend legal claims

4. Legal Basis for Processing Data

We process your personal data on the following legal bases:

  • Performance of Contract: Processing necessary for the performance of our contract with you to provide the Application — including account creation, operating the servers you host, and backing up your data
  • Legitimate Interests: Processing necessary for our legitimate interests, such as diagnosing installation failures, securing the Platform, understanding how the product is used, and providing support
  • Legal Obligation: Processing necessary for compliance with our legal obligations
  • Consent: Where applicable, we process data based on your consent

Product analytics and crash reporting rest on different bases in different places. In the European Economic Area, the United Kingdom and Switzerland we ask for your consent before either is collected, and nothing is sent unless you give it; you can withdraw it at any time in the setting described in Section 2.5, and withdrawing is as easy as giving it. Everywhere else we rely on legitimate interests — understanding how the product is used and diagnosing faults — and the same setting lets you object by simply turning it off.

5. Storage of Data

We aim to keep personal data only for as long as it is needed. We want to be straightforward about where we currently fall short of that aim.

Retained for as long as your account exists: your account record, email address, display name, Matrix ID, linked account identifiers, and the devices and servers associated with your account.

Currently retained indefinitely: most operational and diagnostic records, including sign-in records (with IP address and browser user agent), system and installation reports, error and crash reports, server status reports and the player information described in Section 2.7, waitlist records, feedback and survey responses, and email delivery and engagement records. We do not yet run automated deletion for these categories.

Retained on a shorter cycle: backups of your self-hosted server data are kept on a rolling schedule of roughly thirty days of snapshots.

You may ask us to delete or anonymize your personal data at any time, and we will do so — see Section 9. We are working to introduce defined retention periods and automated deletion, and this section will be updated when they are in place.

6. Sharing Your Information

We do not sell your personal data. We share it in the circumstances described below.

6.1 Service Providers

We use the following providers to operate the Platform. Each receives only what it needs for its function, and processes it on our behalf.

Provider Purpose Data involved
PostHog (US)Product analytics, experimentsUsage events, account identifier, email address, IP-derived location
Sentry (US)Crash and error reportingError reports, account and device identifiers, IP address, request headers
Plausible (EU)Website analyticsPage views, referrer, coarse device and country data
Amazon Web Services (US)Email delivery, file storage, backupsEmail addresses and message content, application downloads, stored server data
Cloudflare (US)Network delivery and protectionConnection metadata, including IP address
Twilio (US)SMS, for event sign-ups onlyName and phone number
Discord (US)Community features, internal notificationsDiscord identifiers; feedback and survey submissions; diagnostic logs; public server listings
Anthropic (US)AI-assisted analysis of support and error dataError reports and account records examined during investigation
Microsoft / MojangMinecraft account sign-in and lookupMinecraft usernames and account identifiers
Google — Firebase Cloud Messaging (US)Delivering push notifications to phonesPush token and the content of the notification
playerdb.co, GeyserMCTurning a username or gamertag you type into an account identifierThe Minecraft username or Xbox gamertag entered
mc-heads.netRendering player avatarsMinecraft account identifiers and usernames; your IP address, as with any image a page loads
ipifyTelling a hosting device its own public addressThe IP address of the device, which the service reads from the request itself
Let's EncryptIssuing the certificate a hosting device serves its console withThe device's public host name. No email address is given.
Modrinth, GitHub, Mojang, PaperMC, and other download hostsFetching game servers, mods, modpacks and runtimes you choose to installWhat you searched for or chose, and the IP address any download discloses
Google Play (Android)Delivering the Java runtime on demandThe installation telemetry Google Play collects for any such download

We also disclose personal data when required by law or valid legal process, to protect our rights, privacy, safety or property, and in connection with a business transfer, merger or acquisition.

6.2 Information Visible to Other People

  • Your Matrix ID and display name are shared with other clients of the Application in your network.
  • If you list a server publicly, your display name, the server's name and description, and its connection address are shown on our public servers page and may be posted to our community Discord.
  • If you share a server link, the page it opens shows the server's name and its host's display name.
  • Leaderboards display players' in-game usernames.

6.3 International Transfers

We are based in the United States, and most of the providers listed above process data there. If you are located in the European Economic Area, the United Kingdom or Switzerland, your personal data is transferred outside your home jurisdiction.

For those transfers we rely on the EU–US Data Privacy Framework, together with its UK Extension and the Swiss–US Data Privacy Framework. PostHog, Sentry and Amazon Web Services each self-certify their adherence to it with the US Department of Commerce, and their participation can be checked on the public Data Privacy Framework List. Where a provider is not covered by that framework, or as an additional safeguard, we rely on the European Commission's Standard Contractual Clauses.

You can contact us for further detail on the safeguards applying to a specific provider.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Access controls and authentication mechanisms
  • Regular security assessments
  • Staff training on data protection
  • Automated security measures, such as anomaly detection and log analysis

About your backups. Backups of your self-hosted server data are stored on infrastructure we operate. We hold the keys to those backups, which means our systems — and authorised personnel — are technically capable of reading their contents. We access them only where necessary to operate or support the service. If you host data you would prefer we could not read, please keep that in mind.

8. Your Rights

You have the following rights regarding your personal data:

  • Right to be informed about how we collect and use your data
  • Right to access your personal data
  • Right to rectification of inaccurate or incomplete data
  • Right to erasure ("right to be forgotten")
  • Right to restrict processing of your data
  • Right to data portability
  • Right to object to processing of your data
  • Rights related to automated decision-making and profiling

These rights apply whether or not you have a Homerun account. If you are a player who has connected to a server hosted with the Application, you can exercise them in respect of the information described in Section 2.7.

9. How to Exercise Your Rights

Deleting your account. You can ask us to delete your account from within the Application — in Homerun Go, under More; in Homerun Desktop, from the account menu — or by emailing [email protected]. We send a confirmation link to your email address; nothing is deleted until you open it. Deletion removes your account record, your sign-in identity, your devices and the servers you host (other players lose access to them), the backups of those servers, and the reports and feedback tied to your account. This does not yet reach our analytics and error-reporting providers: records held there, including your email address at our analytics provider, are not erased automatically when you delete your account. We are building that. Until it is done, ask us at [email protected] and we will erase them for you. If you have uninstalled the Application, the instructions at gethomerun.app/account/delete apply. A guest account has no email address to send a confirmation to, so it is deleted immediately when you confirm in the Application.

To exercise any other right, including access and portability, please contact us at [email protected]. Data export is not yet self-service; requests are handled by our team, and we may need to verify your identity before acting on one.

We will respond to your request within 30 days. In some cases, we may extend this period by up to 60 additional days, in which case we will notify you.

If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection authority.

10. Self-Hosted Content and Services

When you use the Application to host your own applications and services:

  • We do not read or monitor the content you host as a matter of course, and we do not do so for advertising, profiling or any commercial purpose unrelated to running the service.
  • We do collect operational information about your hosted servers, and information about the players who connect to them, as described in Section 2.7.
  • When a hosted service fails, its logs and configuration — including environment variables — are uploaded to us for diagnosis.
  • Your hosted data is automatically replicated to our servers to enable the Platform's backup and collaborative hosting features. As explained in Section 7, we hold the keys to those backups.
  • For support purposes, our systems can request the Application's own diagnostic logs from your machine over an authenticated connection.
  • You are fully responsible for any data collection, storage, or processing that occurs within your self-hosted services.
  • You must ensure your hosted services comply with relevant privacy laws and regulations.
  • If other people connect to a server you host, you should tell them that connection information about them is collected, and point them at this policy.

Our privacy practices described in this policy apply to data we collect through the Application itself, not to the content of the services you choose to run.

11. Your System Environment

Homerun Desktop can run your servers in one of two ways: inside the Windows Subsystem for Linux (WSL), or natively on Windows. Which one is used depends on your system and the choices you make during setup. In both cases:

  • Windows and, where used, WSL are Microsoft products with their own data collection practices, governed by Microsoft's privacy policies
  • Container and virtualization technologies may have implications for data isolation and security
  • Your data's security depends in part on your system configuration and security practices

We recommend reviewing Microsoft's privacy documentation if you have concerns about how the underlying technology may impact your privacy.

On a phone, Homerun Go runs the server on the device itself. It reads the device's model, operating system version and free storage to decide what can be run and how much of it; the free-storage figure stays on the device. Apple and Google are the platform operators, each with their own privacy policies, and the app store you installed from collects its own information about that installation, which we do not control.

The Application checks for updates automatically. Update checks disclose your IP address, platform and current version to the service hosting the update files, and updates may be installed automatically. On a phone, the interface is updated separately from the app itself, as described at the top of this policy; that download identifies the installation to us so we can tell it which version to fetch, and discloses nothing to the network that serves the files.

12. For California Residents

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):

  • Right to know what personal information we collect about you
  • Right to delete personal information we have collected
  • Right to correct inaccurate personal information
  • Right to opt-out of the sale or sharing of personal information (note that we do not sell personal information)
  • Right to non-discrimination for exercising your privacy rights

To exercise these rights, please use the contact information provided in Section 16.

13. For Nevada Residents

Nevada law provides Nevada residents with the right to opt out of the sale of certain personal information. We do not sell your personal information as defined under Nevada law.

14. Children's Privacy

Our Application is not directed at children under the age of 14, and we do not knowingly collect personal information from children under 14 who use it.

Homerun Go is rated in the app stores for an audience above that age, is not enrolled in either store's programme for children's apps, and shows no advertising. We recognise that servers hosted with Homerun Desktop or Homerun Go may be played on by children, and that the information described in Section 2.7 is collected about anyone who connects, regardless of age. We do not use that information to build advertising profiles, and we do not sell it. If you are a parent or guardian and believe we hold information about your child that you would like removed, contact us at [email protected] and we will delete it.

It is also why the chat messages and IP addresses in a server's console are removed before any log leaves a hosting device, as described in Sections 2.6 and 2.7: the person hosting a server cannot agree on their players' behalf to send us what those players typed.

15. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons.

The current version will always be available at https://gethomerun.app/privacy/. For substantial changes, we will provide notice through the Application or by other means. Your continued use of our Application after such modifications constitutes your acknowledgment of the modified Privacy Policy.

16. Contact Us

If you have any questions or concerns about this Privacy Policy or our data practices, please contact us at [email protected].