Privacy Policy

Effective Date: June 5, 2026  |  Last Updated: September 13, 2026

Short version: An account needs a username, a password and an email address. The address is for resetting your password and for telling you when a machine is ready; it is never shown to other users and never sold or shared for marketing. Accounts made before we asked for one still work without it. We do not log your IP address, we do not use analytics or advertising trackers, and we do not sell or trade anything about you. One thing is likely to change as the service grows — drives may be recorded — and Section 11 explains what we will tell you before it happens.

1. Who We Are

Remote Construct ("we," "us," or "our") is an independently run platform for driving real machines over the internet. You can reach us at contact@remoteconstruct.io about anything in this policy, including a request to see or delete what we hold about you.

2. What We Collect

We collect as little as we can while still running the service. What we do hold falls into these categories:

  • Account information. The username you choose, your password (kept only as a one-way hash, so we cannot read it), when the account was created, what the account is allowed to do — for example whether it is a standard account, a supporter, a machine operator or an administrator — and whether it is currently subject to a moderation action.
  • Things you choose to send us. Messages to the admins, feedback you leave before and after a drive, problem reports, and answers you type into a form such as the beta programme application. If a form on the site asks you for something, what you type into it is what we keep.
  • Email address. Since September 2026 an email address is required to create an account. It is used for two things: to send you a link to reset your password if you forget it, and to send notifications you asked for — currently, telling beta testers that a machine is ready to drive. When you give us an address we send it a one-time link to confirm it is yours; until you open that link the address is kept but not used for either purpose, and you cannot take a turn on a machine. Driving requires a confirmed address so that every person at the controls of a real machine can be reached if something goes wrong. It is never shown to other users and never sold or shared for marketing. Accounts created before the requirement keep working without one for everything except driving; if you never add one, the things you cannot do are the two above and taking a turn on a machine. You can change or remove the address yourself on your profile. Removing it does not affect your account or your beta membership — it means we have no way to reach you, no way to reset your password by email, and you will need to add and confirm one again before your next drive.
  • What is needed to run a session. While you are signed in we keep a session so you stay logged in, your place in the queue while you wait, and which machine you are driving. If you report a problem, we record the machine's own status at that moment — things like speed, battery and signal strength. That describes the machine, not you or where you are.
  • An activity log, so the admins can run the service. The admin console keeps a short log of things that happen on the site: an account is created or signs in, a turn starts or ends, a machine comes online or goes offline, a moderation action is taken, a beta application is sent or decided, a help request or message is sent, a news post is published. Each entry says what happened, when, which account did it and which account or machine it concerned, plus a few words of detail (for example the reason given for a ban). It is there so that when something goes wrong we can see what led up to it, and so that admin actions are accountable. Entries are deleted after 90 days. We also note when your account was last active — the time of your most recent sign-in or connection — so we can tell dormant accounts from live ones. Neither of these records pages you looked at, what you clicked, or your IP address.
  • Progress in on-site features. If you take part in quests, challenges or similar, we keep your progress so it is still there next time.
  • How your turns at the wheel went. When you take a turn on a machine we keep one record of it: which machine, when it started, how long it lasted, how long you waited in the queue first, how it ended, how many control commands you sent, whether the video actually reached you and how long it took to arrive, how good the connection was while you drove (your browser measures the round trip to the machine, the frame rate and any dropped video every few seconds, and we keep a summary of those readings for the turn — the typical and worst lag, not a moment-by-moment trace), whether you were on a desktop or a phone, and the rough kind of connection your browser reports (such as “wifi” or “4g”). It is tied to your account, so we can tell whether people come back. This is here because we could not previously tell the difference between somebody who drove and enjoyed it and somebody whose video never loaded and who gave up — and the second of those is a fault we need to find and fix.

We do not collect:

  • IP addresses. We do not write them to our database or our logs. One may be held briefly in memory to slow down repeated failed logins, and is then gone.
  • Your location, or any device fingerprint or advertising identifier.
  • Payment card details (see Section 9).
  • Anything from your camera or microphone. The video is the machine's view of its own worksite, sent one way to you; nothing is captured at your end.

Beyond the turn record described above, we do not build a profile of what you do here. There is no page-by-page history, no record of what you clicked or read, no time-on-site, and nothing that follows you off this site. The turn record exists to tell us whether the machines are working for people, and it is deliberately the smallest thing that answers that: one row when you drive, and nothing at all when you are just looking around.

We also keep a plain daily count of how many people land on the signed-out home page. It is a number per day and nothing else — no cookie, no identifier, no row per visitor — so it can tell us how many visits it takes to produce a signup, and it cannot tell us anything about any individual visitor.

We do not currently keep a recording of the video from your drives, though we expect to introduce recording at some point — Section 11 covers what we will tell you first.

3. How We Use It

  • To sign you in and keep you signed in
  • To run the queue and give you your turn on a machine
  • To keep the machines and the people near them safe, and to work out what went wrong when something breaks
  • To reply to messages you send us
  • To send you a password-reset link when you ask for one, and a confirmation link when you give us an email address
  • To send notifications you asked for, such as a beta announcement
  • To enforce our Terms of Service
  • To decide what to improve — from the feedback you choose to leave, and from the turn records described in Section 2: how often turns end early, how long people wait, how often the video fails to arrive, and how laggy the drives that did connect were
  • To find faults that nobody reports, particularly a drive where the video never connected — that failure is invisible to us unless it is recorded

We do not use your information to advertise to you, and we do not give it to anyone who will.

4. Cookies

We set one first-party cookie, and its only job is to keep you signed in. It is strictly necessary — the site cannot work without it — and it is restricted to our own site, not readable by scripts in the page, and sent over an encrypted connection. We set no advertising, analytics or tracking cookies, so there is nothing to consent to and no banner to dismiss.

Pages that display content hosted by another company (see Section 5) may cause that company to set cookies of its own.

5. Third Parties

We do not sell, rent or trade your information, and we do not use third-party analytics or advertising services. A small number of outside services are involved in running the site:

  • Service providers. We use providers for jobs we cannot do ourselves — for example, delivering the beta announcement email if you gave us an address. A provider receives only what it needs for that job and is not permitted to use it for its own purposes. We apply the same condition to anything we add later.
  • Embedded content. Some pages display content hosted elsewhere, currently the Instagram thumbnails on our news page. Your browser fetches those from the host directly, so the host can see technical details such as your IP address and may set its own cookies. That is their handling under their policy, not ours.
  • Links out. Links to services such as Ko-fi or Discord take you somewhere with its own privacy policy. Once you are there, this one no longer applies.

We may also disclose information where the law requires it, or where it is genuinely necessary to protect someone's safety or to defend the service against abuse.

6. Storage and Security

Your data is held on servers we control rather than scattered across third-party platforms. Passwords are stored only as a one-way hash and never in readable form. The site is served over HTTPS, failed logins are rate-limited, and administrative access is limited to the people who run the service.

No system is perfect. If you believe your account has been compromised, contact us and we will help you secure it.

7. Keeping and Deleting Data

We keep your account for as long as you have one. You can ask us to delete it at any time by emailing contact@remoteconstruct.io, and we will do so within a reasonable time.

Anything we introduce that is kept on a clock rather than for the life of your account — drive recordings being the obvious candidate — gets its retention period stated here before it starts.

The turn records in Section 2 are the first of those: they are kept for 24 months and then deleted. The activity log in Section 2 is kept for 90 days. If you delete your account, your turn records are deleted with it — they are keyed to your account and nothing re-links them once it is gone.

Three honest exceptions. Feedback and problem reports may be kept after deletion with your name detached from them, because they describe how a machine behaved rather than who was driving. Activity log entries that mention the account are not removed early; they age out at 90 days like the rest of the log. And where an account was banned, we keep the minimum record needed to enforce that.

8. Your Choices

  • Change your username or password from your profile at any time.
  • Change or remove your email address on your profile. Removing it stops every email immediately and changes nothing else about your account — it only means a forgotten password cannot be reset by email.
  • Sign in with either your username or your email address.
  • Ask us for a copy of what we hold about you, or ask us to correct or delete it.

Depending on where you live, you may have further rights over your data. We would rather honour a reasonable request than argue about which law applies, so just ask.

9. Payments

The service is free to use, and we do not handle card details. If you support us through Ko-fi, that transaction is handled entirely by Ko-fi. Should we introduce paid sessions or similar in future, payment will be handled by an established payment processor, card numbers will never be stored on our servers, and this policy will be updated before that goes live.

10. Age Restriction

Remote Construct is intended for users aged 13 or over. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us and we will remove it promptly.

11. Changes to This Policy

This is an actively developed project, and new features arrive regularly. Some of them will involve information this policy does not describe yet; when that happens we update the policy and change the "Last Updated" date above. If a change materially expands what we collect or what we do with it, we will say so on the site rather than leave you to spot the edit.

Some things are not going to change, and they are worth stating plainly: we will not start selling your data, we will not add advertising or third-party analytics trackers, and we will not quietly repurpose something you gave us for one reason to do something else with it.

An earlier version of this policy said an email address might become required, and in September 2026 it did — for new accounts only, for the two purposes in Section 2, and on the terms promised then: existing accounts were not asked to add one, and an address is still never sold, shared for marketing or shown to other users.

One change we can already see coming, named here so it is not a surprise:

  • Recorded drives. We may begin keeping a recording of the machine's camera during a session — to work out what happened when a machine is damaged or misused, to settle a dispute, and to show what the machines have been doing. Before that starts, this policy will say what is recorded, why it is kept, how long it is kept for, and who can see it. Recording would cover the machine's view of its worksite. It would never involve your own camera or microphone.

Continued use of the service after a change is posted means you accept the updated policy.

12. Contact

For anything about this policy, including a request to see or delete your data, email contact@remoteconstruct.io, use the Contact Admin form on your profile page (login required), or find us on our community Discord.