ReAccept Privacy Policy
Effective date: September 7, 2026
Publisher: REACCEPT
Privacy contact: support@re-accept.com
ReAccept connects an Android device to a Windows PC so that a user can receive Dota 2 ready-check and party-invite notifications and request an action remotely. This policy explains what data ReAccept processes, why it is processed, when it is shared, and how it can be deleted. It applies to the ReAccept Android app, Windows Agent, backend service, Telegram companion, and website.
Data we process
Service, device, and account data
ReAccept processes randomly generated installation and pairing identifiers, an anonymous
Firebase Authentication user identifier, a one-way hash derived on the device from
ANDROID_ID, device and PC public keys, the PC name supplied by Windows,
platform and app version, pairing and revocation records, online/Armed state, last-seen and
event timestamps, requested actions, and execution results. The hashed device identifier is
used to preserve the free-use counter after a normal reinstall; ReAccept does not receive
the original ANDROID_ID value.
The Firebase identity is an anonymous app-install identity. ReAccept does not require a name, email address, phone number, or Google sign-in for the Android service account.
For the Telegram companion, ReAccept similarly derives a one-way SHA-256 fingerprint from the Telegram user identifier. The original Telegram identifier is processed while the companion is linked as described below; the separate hash is used to preserve the same lifetime free-use counter if that Telegram account is linked again.
Match events and party-invite previews
Ready-check detection is performed locally by the Windows Agent. It does not upload a screenshot or captured pixels for a ready check.
For a party invite, the Agent may crop a small, bounded region of the invite dialog, never the full desktop. The crop can contain the inviting player's Steam display name and avatar. It is encoded as WebP (approximately 420×110 pixels and capped at 100 KB), uploaded to the backend, and relayed to the paired phone. If the user has linked Telegram, it can also be sent as a Telegram photo. The preview is excluded from the internal admin/support panel and is not written to application logs or metrics. If capture fails, ReAccept sends a text-only notification.
QR scanning and local app data
The Android app first uses the Google Play services code scanner. If that scanner is unavailable or fails to start, the app may request camera permission and use its bundled on-device QR scanner as a fallback. Camera frames and QR images are processed locally, are not stored or uploaded, and only the scanned, one-time pairing value is used. Pairing settings, preferences, and recent local history are stored on the device.
Stability diagnostics and product analytics
Firebase Crashlytics automatically processes crash stack traces, exception details, relevant application and device state, device model and operating-system information, app/version information, timestamps, and per-installation/session identifiers to diagnose crashes and application-not-responding errors. ReAccept does not attach a Firebase user ID, support ID, custom user ID, custom keys, or application logs to Crashlytics reports.
The Android app uses Google Analytics for Firebase with Advanced Consent Mode. Before consent is granted, or when enhanced analytics is declined in Settings, Google receives limited cookieless measurement events without a persistent app-instance, device, or advertising identifier. These limited events support basic aggregate measurement and behavioral or conversion modeling. If the user allows enhanced analytics, Google may process an app-instance and device/advertising identifiers, app and device information, approximate region derived from network information, and campaign/referrer attribution. Advertising personalization remains disabled in either mode. The product events measured are: pairing started/completed, match notification received, successful remote accept, remote game launch requested, free-use limit reached, paywall viewed, checkout begun, free/Premium state changed, and purchase restored. Google Analytics also collects its standard automatic app lifecycle and Google Play purchase events.
ReAccept sends only low-cardinality state, source, method, remaining-free-use, localized price, currency, product/base-plan, and notification-created parameters with those events. It does not set an Analytics user ID or send pairing codes, pairing or match event identifiers, PC names, Firebase Authentication identifiers, purchase tokens, or message/preview contents to Analytics.
Google Play subscriptions
When Google Play subscriptions are enabled and a user starts or restores a subscription, Google processes the payment method and billing transaction under Google's own terms and privacy policy. ReAccept does not receive or store the user's full card number, bank account details, or Google account password.
The app and backend process the subscription product ID, purchase token, order or transaction identifier when available, purchase time, purchase and acknowledgement state, auto-renewal and entitlement status, expiry time when applicable, environment, and verification timestamps. This data is linked to the anonymous Firebase identity and is used to verify the purchase with Google Play, grant or restore Premium access, prevent duplicate or fraudulent claims, process subscription state changes, and assist with refunds or support requests.
Managing or cancelling a Google Play subscription takes place through Google Play. Deleting ReAccept data does not itself cancel an active Google Play subscription or delete records held by Google.
Optional Telegram companion and purchases
If a user links the optional Telegram companion, ReAccept processes the Telegram user and chat identifiers, available display name, link status and timestamps, messages and button actions sent to the bot, and notification delivery state. Telegram receives the messages, notifications, and optional party-invite previews needed to provide this feature.
If a user makes a Telegram Stars purchase, Telegram processes the payment. ReAccept receives and stores the Telegram payment charge identifier, selected product/tier, linked Telegram identity, purchase time, and resulting entitlement so the purchase can be granted once and supported later. ReAccept does not receive the user's underlying payment-card details.
Connection metadata and website
The production backend runs on a QDE KVM VPS with Cloudflare in front for DNS, TLS termination, reverse proxying, and DDoS protection. The origin server's request/access logging is intentionally disabled. Cloudflare and other network providers may process ordinary connection metadata such as IP addresses and request timestamps under their own logging and retention practices.
ReAccept marketing pages use a Google Ads tag to measure campaign visits and Windows desktop downloads. Analytics and advertising storage are denied by default. If the visitor selects Allow measurement, Google may store or access analytics and advertising identifiers needed for campaign and conversion measurement. ReAccept keeps ad personalization denied and does not use this data for personalized advertising. The visitor's measurement choice is stored in the browser's first-party local storage. Privacy Policy, Terms of Use, and Disclaimer pages do not load the Google tag.
When a consented Google Ads visit contains a Google click identifier, ReAccept temporarily stores that identifier encrypted on the backend and an opaque attribution token in the visitor's browser. On the first launch of a newly installed desktop app, a one-time browser handoff may associate the visit with the anonymous desktop installation. ReAccept then sends the first desktop registration and first successful Android or Telegram pairing as conversion events to Google Ads. Unclaimed attribution sessions expire after 7 days; one-time handoffs expire after 10 minutes. ReAccept does not use IP-address matching for this attribution.
How we use data
ReAccept uses data to:
- authenticate installations and pair a phone with a PC;
- relay connection state, ready checks, party invites, and requested actions;
- enforce free and paid feature entitlements and restore verified purchases;
- prevent replay, duplicate purchase claims, fraud, and abuse;
- diagnose crashes, reliability problems, and support requests;
- measure acquisition sources, activation, feature use, and subscription conversion so ReAccept can improve the product and understand how users discover it; without enhanced-analytics consent, this is limited to cookieless measurement and modeling;
- maintain service security and comply with legal obligations.
ReAccept does not sell personal data or display third-party ads. ReAccept links its Google Analytics property to Google Ads. Consented identifier-based data and limited cookieless signals are used, as permitted by the applicable consent state, to attribute or model app installs, measure campaign performance and subscription conversions, and optimize ReAccept acquisition campaigns. Analytics data is not used for personalized advertising, remarketing, or cross-service tracking.
Service providers and sharing
Data is shared only when needed to operate a requested feature, maintain the service, or comply with law. Current service providers and recipients for the described features are:
- QDE: production VPS hosting;
- Cloudflare: DNS, TLS termination, reverse proxy, and DDoS protection;
- Google Firebase: anonymous authentication, Crashlytics stability diagnostics, and Google Analytics measurement governed by the user's enhanced-analytics consent state;
- Google Ads: install attribution or modeling, campaign and conversion measurement, and non-personalized acquisition-campaign optimization using consented identifier-based data and limited cookieless signals;
- Google Play: app distribution, subscription checkout, purchase verification, and subscription lifecycle notifications when Play Billing is enabled;
- Telegram: the optional bot, notifications, party-invite previews, and Telegram Stars purchases when the user chooses those features.
These providers may process data in countries other than the user's country and apply their own privacy and retention terms. ReAccept may also disclose data when required by law or when necessary to protect users, the service, or legal rights.
Google explains how it processes data from apps that use its services at Google's Business Data Responsibility site.
Storage, security, and retention
Android private keys are generated in Android Keystore and are not sent to the backend. The Windows Agent pins the backend command-signing public key. Pairing values are random, single-use, expire after three minutes, and are stored by the backend as hashes. Production clients require encrypted HTTPS/WSS transport. Access to production systems is restricted.
ReAccept applies the following retention rules:
- terminal match events, party invites, their associated commands, and party-invite preview images are automatically hard-deleted after 40 days;
- once a week, Android anonymous identities and their installation, pairing, entitlement, and expired purchase-verification records are automatically deleted after 40 days with no device activity, provided no active subscription remains. Inactive desktop installations and their system-scoped links are also deleted after 40 days. One-way fingerprint/free-use records are retained separately as described below. Telegram identities are not automatically classified as inactive because Telegram does not provide a reliable last-activity signal;
- expired pairing sessions, old revoked/unlinked relationships, and processed Google Play notification deduplication records are automatically deleted after 40 days;
- unclaimed advertising-attribution sessions expire after 7 days, one-time browser handoffs expire after 10 minutes, and claimed attribution and conversion-delivery records are deleted after 90 days once no delivery retry remains pending;
- after a verified deletion request, ReAccept retains the existing one-way hashed Android or Telegram fingerprint and highest free-use count without the former Firebase UID, Telegram user ID, device ID, system ID, PC name, pairing, purchase token, or event history. This minimal record is used only to prevent repeated resets of the lifetime free-use allowance and is retained while that free tier and anti-abuse purpose remain in operation;
- subscription and payment records required for accounting, fraud prevention, refunds, disputes, or legal compliance may be retained after service-data deletion and are removed when the applicable purpose or retention obligation ends;
- local Android data remains until it is cleared in system settings or the app is uninstalled;
- Google Analytics data is retained according to the Firebase/Google Analytics property settings and Google's applicable retention practices. Switching off enhanced analytics resets the app's local Analytics identity and continues only limited cookieless measurement; previously processed aggregate or provider records may remain for their configured retention period;
- the website measurement preference remains in the browser until the visitor changes it through Measurement settings in the website footer or clears browser storage;
- Firebase states that Crashlytics crash traces and associated Crashlytics/Firebase installation identifiers are retained for 90 days before removal from live and backup systems begins;
- infrastructure providers retain connection and transaction records according to their own policies.
User choices, access, and deletion
Users can enable identifier-based enhanced analytics or select limited cookieless measurement, Disarm event delivery, unlink Telegram, or Unpair the phone and PC in Settings. Advertising personalization remains disabled in both analytics modes. Website visitors can change their Google Ads measurement choice through Measurement settings in the footer of any marketing page. Unpairing or unlinking revokes that connection but does not by itself erase historical backend or provider records.
To request access, correction, or deletion of ReAccept data, email support@re-accept.com with the subject Privacy request and include the Support ID shown in the app where available. ReAccept may ask for additional proof tied to the installation or pairing to avoid deleting another user's data. After verification, ReAccept will delete associated service data without an intentional waiting period, except for the minimized hashed Android or Telegram fingerprint/free-use record described above and any records whose retention is required for accounting, refunds, security, fraud prevention, dispute resolution, or law. ReAccept will respond within the period required by applicable law.
Clearing app data or uninstalling removes local data but may leave backend records. A Google Play subscription must be cancelled separately in Google Play, and a Telegram relationship may also leave records controlled independently by Telegram.
Depending on location, users may have additional rights to object to or restrict processing or to lodge a complaint with a data-protection authority. Contact the privacy address above to exercise an applicable right.
Children
ReAccept is not directed to children under 13, or the higher minimum age required in a user's country, and does not knowingly collect personal data from children. Contact support@re-accept.com if you believe a child has provided data so it can be reviewed and deleted as appropriate.
Changes to this policy
Material changes will be published at the same stable URL with an updated effective date. Continued use after the effective date is subject to the updated policy where permitted by law.
Independent application and trademarks
ReAccept is an independent third-party application and is not affiliated with or endorsed by Valve Corporation. Dota and Dota 2 are trademarks of Valve Corporation.