HCONet
HCONet Privacy Policy
Effective and last updated: August 27, 2026
This policy explains how HCONet accesses, uses, stores, and shares information when you use hconet.com, its product subdomains, and the Beside mobile app.
Google Sign-In data
When you choose Google Sign-In, Google makes a stable Google account identifier, your verified email address, and basic profile information such as your name available to HCONet under the openid, email, and profile scopes.
HCONet uses this information only to authenticate you, link or create your HCONet account, fill its initial display name, prevent duplicate accounts, and protect the sign-in flow. It is not used for advertising or user profiling.
HCONet never receives or stores your Google password. Google authorization codes and ID, access, or refresh tokens are used only to complete the current sign-in and are not persisted by HCONet.
Information HCONet processes or stores
- Account information you provide, such as email, username, display name, full name, optional phone number, avatar, and language preference.
- A stable Google account identifier, verified email, name used at account creation, and the time of the most recent Google login when you use Google Sign-In.
- Drive file and folder metadata on HCONet servers, plus the file content you upload to HCONet's private Backblaze B2 storage.
- Study content, sharing choices, support messages, and other content you intentionally submit.
- Beside relationship and membership information, including pairing-invite lifecycle, relationship status, sharing choices, and related entitlement or transaction records.
- Beside device and presence information you choose to share, which can include device type and name, battery and charging state, a supported signal level, current app and elapsed use reported through a user-configured automation, precise phone location, and observation timestamps.
- Session, request, IP, device, quota, and security-event information needed to operate the service, enforce limits, diagnose failures, and prevent abuse.
Beside mobile app and partner sharing
You can explore Beside as a guest without signing in; guest mode makes no authenticated request and does not collect partner presence or personal history. After you sign in and pair with another HCONet user, device presence, phone location, battery, charging state, and current-app sharing remain off until you enable each category separately.
When phone-location sharing is enabled, Beside can continue collecting precise location while you leave the app or lock the screen so the paired partner receives updates. Android shows a persistent location-sharing notification, and iOS shows the system background-location indicator when applicable. Beside does not use this information for advertising or tracking.
Current device state is available only to the active paired partner and is not made public. Active VIP membership may retain and expose shared phone-location samples for up to 30 days. Unpairing or account deletion ends the active relationship and purges its current device snapshots, location history, sharing policies, watch leases, and scoped current-app reporter credentials. Limited relationship, membership, payment, security, and legal audit records may be retained as reasonably required.
Passwords and verification secrets
HCONet never stores plaintext passwords. If you create an HCONet password, only a salted one-way password hash is stored. Email verification codes, password-reset tokens, OAuth state, and session credentials are also stored as hashes or short-lived protected values where the service design permits. HCONet cannot retrieve your original password from its database.
How information is used
- Create, authenticate, maintain, and secure your account.
- Provide Drive, Study, sharing, profile, email-verification, password-reset, and support features.
- Provide Beside pairing, membership, owner-selected device and location sharing, and the paired-partner dashboard.
- Measure storage and download usage, enforce account and platform limits, investigate failures, and prevent fraud or abuse.
- Comply with applicable law and protect users, HCONet, and the public.
Service providers and disclosure
HCONet does not sell or rent personal information and does not share it with third-party advertisers or data brokers.
Information is disclosed only as needed to operate HCONet: Google processes the sign-in you request; Backblaze B2 stores Drive file content; Apple supplies the iOS MapKit map service; and email, hosting, database, and network providers process the minimum information needed to deliver those services. HCONet may also disclose information when legally required or when you explicitly choose to share content or Beside data with your paired partner.
Private Drive transfers use authenticated or time-limited access. A service provider's own processing is governed by its terms and privacy notice.
Cookies and browser storage
HCONet uses essential HttpOnly session Cookies to keep you signed in and a short-lived HttpOnly binding Cookie to secure Google OAuth callbacks. Product JavaScript cannot read these credentials. Browser storage may hold non-secret interface preferences and temporary signup or reset state; HCONet does not put Google tokens or the active Web Session token in readable browser storage.
Retention, access, correction, and deletion
HCONet keeps account and content data while your account is active and for only as long as reasonably needed to provide the service, enforce security, resolve disputes, or meet legal obligations. Expired verification and OAuth challenges are not valid credentials. Deleted data may remain in restricted backups until normal backup rotation completes.
You can update profile information, remove Drive content, revoke HCONet in your Google Account, or delete your HCONet account through Account settings. Depending on applicable law, you may also request access, correction, export, restriction, or deletion by contacting HCONet.
Security
HCONet uses transport encryption in production, access controls, hashed credentials, short-lived signed storage access, and other safeguards appropriate to the service. No Internet service can guarantee absolute security, so report suspected account compromise promptly.
Contact and policy changes
Questions, privacy requests, or security concerns can be sent to [email protected]. Material changes will be reflected on this page by updating the effective date and, when required, by providing additional notice.