Privacy

HitLight stores your account and show data. Show data is visible only to its collaborators, website analytics stay off until you consent, and you can delete any show or your whole account from Settings.

What does HitLight store?

HitLight stores account identity, beta-access state, show configuration, collaboration state, and the diagnostics needed to operate the public beta. Show data is visible only to its collaborators.

To offer our Discord community invitation once after three app sessions in seven days, your private account also keeps the three latest app-session start times and whether the invitation has been offered. Reloading a window does not count as another session. This works independently of optional analytics and stores no Discord identity or membership information.

AI requests are processed by OpenAI. Raw per-turn operational diagnostics expire after 30 days. Submitted support and chat-quality reports expire after 90 days; they can contain the instruction and show context the reporter chooses to send. Uploaded fixture manuals remain private to the show and are available only to the profile-generation service and authorised reviewers. HitLight asks OpenAI not to store its responses to these requests; OpenAI’s own abuse-monitoring retention still applies.

Structured events are retained for one year and optional recordings for 30 days, within PostHog’s free allowances. Consented events may wait on your device for up to seven days while offline. Turning metrics off clears pending events. Website and app choices are separate.

What about website analytics?

Website analytics and error reporting are optional and disabled until you consent. Website events are anonymous when collected. If you later sign in to the HitLight product in the same browser, PostHog may associate those earlier events with your internal Firebase user ID. HitLight does not send your name or email to PostHog.

With website analytics on, your first measured visit also sets a first-touch cookie (hl_first_touch, on hitlight.app, 90 days). It holds only three category codes: the kind of site that referred you (none, HitLight, an AI assistant, or another site), which page you landed on, and a registered campaign name if the link carried one. It stores no URL, referrer address, search terms or identifier. If you sign up in the same browser, the app adds those three codes to its sign-up event. Turning website or product analytics off deletes it. After sign-up, the app may ask how you heard about HitLight; answering is optional and only the choice you tap is recorded.

Optional product analytics use that internal ID across the hosted app, desktop app and iOS remote. Analytics error reports are stripped of raw messages, URL queries, invite codes, and page content. There is no click or form autocapture. Session recordings require a separate opt-in. Inputs and dynamic text are masked; chat, account details, files, images and stage previews are blocked. Recordings contain no console logs or network payloads. Analytics never include show names, DMX values, fixture manuals, or generated fixture definitions.

On the iOS remote, crash reports (Firebase Crashlytics) and error logs are sent only after you opt into product metrics, and stop when you opt out; a crash recorded while you had not opted in is deleted on the device, never sent. Error logs contain your internal account ID, the current show’s ID and name, the error message and its technical details, where in the app it occurred, the app and OS version and the device model, but no device name. They are visible to the show owner and expire after 30 days.

Error reports from the app, the desktop host, our servers and the iOS remote are processed by Sentry (EU region) only after you opt into product metrics, and stop when you opt out. They contain the error type and message with emails, credentials, web addresses, file-system user names, IP addresses and quoted names removed, the code location, the app version and your internal account ID. They never contain screenshots, recordings, chat, show content or your name or email.

When a product user opts into product metrics, assistant traces contain performance, token, outcome, and tool-name metadata only. Prompts, replies, shared chat history, system prompts, tool arguments and results, show state, DMX data, fixture-source content, and Auto Show vibe or palette text are excluded. More detail is on AI and your data.

Optional analytics

No analytics preference has been saved on this browser.

How do I delete my data?

You can delete shows or your account from Settings. Account deletion removes owned shows, private profiles, membership, the account's owned invite, and PostHog data associated with the internal user ID; people previously admitted by that invite keep their own access.

Questions: privacy@hitlight.app.

Last verified .