HireApp Robotics · Legal

Privacy Policy

Effective and last updated: September 27, 2026

How HireApp Robotics handles information from Platform users and people who may appear in recordings.

Apps and dedicated capture hardware. The same privacy limits apply across supported capture methods. Approved capture covers video, images, and specified non-audio sensors for physical robotics; adding a device does not authorize new collection or uses.

On this page

1. Who this policy covers

HireApp Technologies, Inc., a Delaware corporation (“HireApp,” “we,” “us,” or “our”), provides HireApp Robotics. This policy explains how we handle personal information through capture applications, dedicated capture hardware, supported connected devices, device software and firmware, upload and synchronization tools, the customer dashboard, viewer, and related services (“Platform”). It covers people who capture or upload data, customers and other authorized users who access the Platform, and anyone whose information appears in recordings or related data, whether or not they have an account. It applies regardless of the person’s relationship with HireApp, a customer, or another Platform user.

“Capture Equipment” includes approved mobile devices, dedicated wearable or body-mounted recorders, fixed or site-mounted cameras, multi-camera or depth-sensing rigs, connected task sensors, and associated accessories and gateways. This policy applies to supported replacements, upgrades, and integrations. Equipment may be supplied by HireApp, a customer, or an authorized third party. Available features and the collection permitted for a deployment depend on the equipment and project; this policy does not mean that every device collects every category listed below.

Our contact details are in section 15. This policy describes our information practices; it does not itself authorize recording, establish consent, or waive individual rights. A customer master services agreement, statement of work, or data protection agreement (“Customer Agreement”) may impose stricter restrictions. A policy update cannot remove those restrictions or replace a required individual notice.

2. Our role and customer responsibilities

Where HireApp determines the purposes and means of processing, including account administration, Platform security, and our authorized robotics development activities, we act as a controller or business under applicable law. Where we process information solely on a customer’s documented instructions, we act as its processor or service provider under the applicable data protection terms. Ownership of recordings or intellectual property does not determine these privacy roles.

A customer or other person or organization managing a capture project or account may separately arrange recording, manage user access, provide information about you, or use permitted dashboard information. That party is responsible for its own notices, permissions, and uses. Where relevant, contact the party managing the project or account about its privacy practices. You may also contact HireApp directly about any information we handle; an account is not required.

3. Information we collect and its sources

We receive information directly from users, customer administrators and site contacts, approved Capture Equipment and its operators, authentication providers where used, and operation of the Platform. A device may be associated with a site, organization, or assigned operator without requiring an individual app sign-in. Device identifiers, timestamps, and assignments can link a recording to a person. The categories actually collected, enabled sensors, recording periods, and local or cloud processing must be explained for the approved deployment before collection.

No audio capture. The authorized program is limited to video, images, and approved non-audio task sensor data across apps and Capture Equipment. Audio collection must be disabled on any audio-capable equipment used for the program. Hardware capability is not permission to record audio. Before any future audio collection, we would need a separate written agreement or amendment, advance updated privacy information, and all legally required permissions. We do not perform facial recognition or create biometric identification templates. Face detection may locate faces for masking. Hand and motion analysis is intended to represent tasks for robotics, not identify individuals; applicable protections still apply to sensitive or biometric information as defined by law.

Capture is not intended to collect government identifiers, financial account details, health information, private communications, or other unrelated sensitive information. If such information is incidentally captured, we restrict it and assess redaction, exclusion, or deletion. The capture rules require operators to avoid private areas and unnecessary sensitive content.

4. How we use information

  • Provide the Platform: Create and administer accounts, authenticate users and devices, apply access permissions, provision and associate approved Capture Equipment with the relevant project, transfer and store files, and make permitted review and download functions available.
  • Develop robotics: Prepare, annotate, train, evaluate, improve, simulate, validate, and deploy models intended to operate physical robotic hardware, subject to agreed purpose, privacy, and confidentiality limits.
  • Protect information: Detect and redact identifying or confidential content, check sanitization quality, investigate security incidents, prevent misuse, and remediate affected data or outputs.
  • Operate and support services: Diagnose errors, check device health, maintain approved device configurations and firmware, manage uploads and processing, respond to support requests, communicate service changes, and maintain reliability. Operational diagnostics do not authorize collecting unrelated footage or expanding the robotics purpose.
  • Meet obligations: Handle privacy requests, comply with applicable law and Customer Agreements, maintain necessary records, and establish or defend legal claims.

Capture information is not used for advertising, monitoring, profiling, or making consequential decisions about individuals, biometric identification, or training general-purpose AI unrelated to robotic hardware. We do not use the Platform to make solely automated decisions about individuals that produce legal or similarly significant effects. Task and motion outputs describe activities for robotics development; they may be inaccurate and must not be used to evaluate or rank individuals.

5. Legal grounds and capture permissions

Where a law requires a legal basis, we identify it for the relevant processing. Account and service activities may be necessary to perform a contract with you, or based on legitimate interests in delivering and securing the Platform for customers and authorized users. Approved robotics processing may rely on legitimate interests in developing physical robotics only where lawful, necessary, and not overridden by individual rights. Processing required by law relies on legal obligations. Where consent is required, including for particular recording, precise location, or other sensitive-data activities, the necessary consent must be obtained before processing.

An agreement with a customer or another Platform user does not by itself establish your consent or provide every legal permission needed to process information about you. Recording notices and data protection arrangements must address the actual people, location, purpose, and lawful basis involved. Device permissions control device access; they do not by themselves supply every required legal permission. Dedicated equipment may have no screen or permission prompt, so notices must also reach affected people through appropriate site notices, signage, briefings, or another suitable channel. Owning, wearing, pairing, or being near a device does not by itself establish consent.

For app-based capture, you may decline or revoke available camera or location permissions in device settings, although this may prevent affected features from working. For dedicated equipment, follow its documented capture controls or contact the assigned operator, site administrator, or HireApp to request that capture stop or to raise an objection. Controls differ by device; an app setting may not control separate equipment. Operators must follow approved recording periods and stop procedures, including for any approved scheduled or remotely initiated capture. Where we rely on consent, you may withdraw it through the contact below without affecting the lawfulness of earlier processing. Stopping capture, revoking a permission, or disconnecting equipment does not automatically erase retained data or cancel queued uploads; contact us about deletion or a pending transfer.

6. Raw recordings and sanitization

Depending on the approved configuration, Capture Equipment or a local gateway may temporarily store, compress, synchronize, or analyze recordings before transfer to the cloud. Uploads may be direct or occur later after offline capture. Local processing, storage, and delayed transfer remain subject to the same approved purpose, access restrictions, and retention duties as cloud processing. We do not assume that every device sanitizes recordings at the point of capture.

Raw recordings may contain identifiable people and confidential site information before processing. Post-upload blurring does not replace lawful collection. Before training, identifiable faces must be blurred where applicable, other identifying features obscured as needed, and incidental confidential documents, screens, credentials, and unrelated sensitive content removed. Approved workflow information may remain in internal training data only within the customer’s authorized program.

“Sanitized Data” must exclude customer confidential information and information that identifies or reasonably permits identification of individuals. Customer review copies and robotics-partner disclosures must meet this standard, with a documented quality check before release. Sharing beyond a customer program also requires removal of site-identifying details unless the customer has given written permission. Inadequately protected material must be withheld.

Face blurring, replacing names, or removing account identifiers alone does not establish anonymization. We treat data as personal information whenever applicable law requires, including where other details allow identification. Where we maintain legally de-identified information, we commit to maintaining and using it in de-identified form and not attempting re-identification, except where law permits testing the de-identification safeguards. Recipients must follow corresponding restrictions.

Compliant Sanitized Data and Project Models may be combined, licensed, or used commercially across customers and robotic platforms within the Robotics Purpose and contractual limits. This does not authorize selling identifiable footage or disclosing protected information through model outputs. We must restrict and remediate releases found to expose protected information, including affected models where required.

7. Who may receive information

  • Customers and authorized users: People authorized for the relevant project or account may receive account and access information, capture activity and upload status, and sanitized review material, according to their permissions and the Customer Agreement. Recipients are responsible for handling downloaded copies in accordance with applicable law and contractual restrictions.
  • Authorized personnel: Only people with an approved need to know, confidentiality duties, and access permitted by the Customer Agreement may handle unredacted recordings or confidential information for HireApp. Operators may access recordings only as needed for authorized capture and upload. General role descriptions in this policy do not expand access beyond a Customer Agreement’s restrictions.
  • Operational providers: We use providers for hosting, storage, authentication, databases, delivery, and technical operations. AWS provides recording storage and related infrastructure; Supabase provides account authentication and database services. This description is not permission to give a provider raw footage or confidential workflow data. Except for AWS or other access expressly authorized by the Customer Agreement, access to those materials requires prior written customer approval of the provider’s identity, access location, and purpose. Providers must act on authorized instructions and receive no independent rights to use capture Data. A hardware manufacturer, installer, or repair provider does not automatically receive recordings or associated personal information. Any access for provisioning, diagnostics, or repair must be specifically authorized, minimized, and subject to the applicable customer approvals and access restrictions.
  • Robotics partners: Partners may receive only Sanitized Data under written restrictions limiting use to physical robotics, prohibiting re-identification and unauthorized onward sharing, and preserving applicable ownership and confidentiality protections. Public releases require the relevant customer’s written consent.
  • Legal and professional recipients: We may provide necessary information to professional advisers, authorities, or courts as authorized or legally required. Raw or confidential capture content remains subject to its stricter access limits unless disclosure is legally required. We limit compelled disclosure and provide notice where lawful.
  • Business successors: A permitted merger or transfer may involve necessary information subject to applicable confidentiality, purpose, and legal restrictions. It does not authorize broader access or remove required customer approvals.

We do not sell personal information or share it for cross-context behavioral advertising. Commercial licensing of capture data is limited to material meeting the contractual sanitization standard and any applicable legal de-identification standard; merely labeling footage “sanitized” is insufficient.

8. Cookies, local storage, and maps

The web Platform uses cookies for authentication and session continuity and local storage for preferences such as appearance and navigation. Clearing or blocking them may sign you out or reset preferences. Capture applications, dedicated equipment, removable media, and approved gateways may also hold recordings, sensor files, device settings, and queued-upload information locally. These are distinct from browser cookies and remain subject to the capture and retention limits in this policy. We do not use advertising cookies or cross-site advertising trackers in the Platform.

When a recording-location map is displayed, your browser requests map tiles from OpenStreetMap. Those requests reveal your IP address and the requested map area to the map provider. Opening the full map sends the selected coordinates in the destination URL. OpenStreetMap handles those requests under its privacy policy. These features must be used consistently with the applicable site and location-sharing permissions.

We do not change our practices in response to browser “Do Not Track” signals. We honor legally applicable opt-out preference signals where required. Because we do not sell personal information or share it for behavioral advertising, there is no such sale or advertising sharing to opt out of under our current practices. You can still contact us to exercise any applicable right.

9. Storage, access locations, and safeguards

Cloud recording storage is in private Amazon S3 buckets in the US East (N. Virginia) region. Approved local storage on Capture Equipment, removable media, and gateways may precede upload and remains restricted under the same project arrangements. A device deployment does not add an approved processing country. Public and anonymous access to recording storage is prohibited. The approved countries for recording processing and remote access are the United States and the Republic of Serbia; changes require prior written agreement under the relevant Customer Agreement. Account and operational information may also be handled in the countries where authorized service providers operate, subject to applicable law and contractual restrictions.

Our recording safeguards require encryption in transit and at rest, restricted credentials, least-privilege access, multifactor authentication for administrative access, appropriate access logging, and access-controlled capture devices. Device credentials, local copies, and removable media must also be protected against unauthorized access. Before equipment is returned, reassigned, serviced, or disposed of, authorized personnel must secure or remove local data and credentials under the agreed procedure, subject to applicable upload, retention, and preservation duties. Providers and personnel must follow applicable confidentiality and access restrictions. No system can guarantee absolute security.

Where an international transfer requires additional safeguards, the parties must put the legally required transfer mechanism and data protection terms in place before the transfer, such as applicable standard contractual clauses and additional safeguards where needed. A customer’s approval of an access country does not itself satisfy transfer law. Contact us for information about safeguards applicable to your information.

For an incident involving unauthorized access to or disclosure of customer Data or confidential information, we must notify the affected customer without undue delay and within 24 hours after awareness, or sooner where law requires, subject to any stricter Customer Agreement. We investigate, contain, and remediate incidents and provide required notifications to affected individuals and authorities. Customer notification does not replace independent legal notification duties.

10. How long we retain information

Retention depends on the information and its permitted use. A perpetual intellectual property right does not justify perpetual retention of identifiable personal information.

  • Local capture copies: Authorized operators or administrators must delete local video copies from mobile devices, dedicated equipment, removable media, and approved gateways after verified upload and no later than seven days afterward, subject to legally required preservation. Offline copies awaiting upload must be protected and reviewed for continued need. Other local sensor files, session metadata, and upload records may remain only as necessary for the permitted operational purpose. Powering off, unpairing, or returning equipment is not a guarantee that local data has been deleted.
  • Cloud capture data: Raw originals, processed recordings, annotations, and datasets may be retained for as long as reasonably necessary for authorized robotics training, evaluation, improvement, and reprocessing. Necessity depends on the ongoing project, need to validate or correct processing, sensitivity, available sanitized alternatives, and legal obligations. We must periodically review identifiable and confidential material and delete or sanitize it when no longer reasonably necessary.
  • Accounts and operations: Account information is kept while needed to manage authorized access and thereafter only as needed for support, security, legal obligations, or claims. Logs and correspondence are retained according to their diagnostic, security, contractual, or legal purpose, rather than indefinitely by default.
  • Sanitized data and models: Legally de-identified data and compliant models may be retained for ongoing permitted robotics use. If they contain protected information, the corresponding privacy and remediation obligations continue.
  • Backups and preservation: Information subject to a legal hold may be kept for that obligation. Residual backup copies remain restricted and are removed under the applicable backup lifecycle. Required deletion must be respected if a backup is restored.

Completion of sanitization, stopping recording, closing an account, or terminating a Customer Agreement does not by itself require deletion of all previously collected data. Continued retention and use remain limited by necessity, the agreed purpose, confidentiality, and law. Lawful deletion or remediation requests may require further action, including to derived materials or affected models where required. Contact us for retention information about a particular category or project.

11. Your choices and privacy rights

Depending on where you live, the context, and applicable law, you may have rights to learn whether and how information is processed; access or receive a copy; correct inaccuracies; request deletion; obtain portable information; object to or restrict processing; withdraw consent; or opt out of certain sales, targeted advertising, or profiling. Some laws also permit limiting particular uses or disclosures of sensitive information. These rights have legal conditions and exceptions that depend on the context and the scope of the applicable law.

California residents, where the California Consumer Privacy Act applies, may request the categories and specific pieces of personal information held, sources, purposes, and recipient categories; correction or deletion; and applicable sale, sharing, or sensitive-information choices. The collection, use, and disclosure sections above describe the Platform’s categories and practices. We do not sell personal information or share it for cross-context behavioral advertising.

If EEA, UK, or other applicable data protection law governs your information, you may also have rights to object to legitimate-interest processing, restrict processing, and complain to the relevant supervisory authority. Where a US state law provides an appeal right, you may appeal a denied request as described below. Nothing here limits nonwaivable rights.

12. How to make a request

Email [email protected] with the subject “Privacy request,” or write to the address in section 15. You may request account deletion through the same channels. You do not need a Platform account to contact us. Explain the right you want to exercise and enough context to locate the information, such as the account email or site and approximate recording date. Do not send passwords or unnecessary identity documents.

We may request proportionate information to verify identity or an authorized agent’s authority and protect other people’s information. If we act as a processor for another party, we will coordinate with that party as required, rather than treat that as permission to ignore your request. We respond within the time required by applicable law and explain any lawful refusal, exception, or extension.

Where you have an appeal right, reply with “Privacy appeal” and the original request details. We will review the decision and respond within the applicable statutory period, including available complaint options if the appeal is denied. You may complain directly to your relevant privacy regulator or attorney general without first appealing to us. We will not unlawfully discriminate or retaliate against you for exercising privacy rights.

For accidental recording or urgent exposure, use “Recording privacy concern” and identify the affected session if known. We can assess restrictions, redaction, exclusion, or deletion without requiring you to download or redistribute the footage.

13. Children and sensitive settings

The Platform is intended for adults, not children. Operators must not knowingly record children or record private or excluded areas. If you believe a child’s information or other improperly captured sensitive information has reached the Platform, contact us so we can investigate, restrict access, and delete or otherwise remediate it as required. A parent or guardian may contact us on a child’s behalf.

14. Changes to this policy

We will post changes here with an updated date and provide additional notice of material changes where required. New equipment, sensors, firmware, or integrations do not automatically authorize additional collection. Before introducing a new category of personal information or a materially different use, we must explain the collection and purpose through an updated policy or appropriate deployment-specific notice and obtain any legally required permission and contractual amendment. Changes do not retroactively expand an agreed robotics purpose, permit disclosure of protected information, or override a Customer Agreement. Continued Platform use is not consent to unrelated processing.

15. Contact

HireApp Technologies, Inc.
651 N Broad St
Middletown, Delaware 19709, United States
Email: [email protected]
Attention: Legal and Privacy

For questions about a particular capture project or account, you may also contact the customer or administrator responsible for it. HireApp remains available for questions about the information it handles.