1. Status of this notice
This is pre-launch review draft 2026-08-03-review.3, last updated 2026-08-03. It is published for transparency and review, but it is not an approved launch notice and has no effective date.
The active bilingual pack uses retention registry 2026-08-03-review.1. Public registration and live billing remain blocked while 5 internal retention decisions and 6 provider-retention decisions remain unresolved, and until independent English legal and Spanish legal-language review are recorded.
2. Controller and contact
The intended controller and service operator is Rogue Terrapin, trading as Hōkime, a self-employed business (autónomo) established in Spain. Tax/identity reference: X-8232663-C. Service address: C/Espinosa, San Luis De Sabinillas, 29692, Málaga, Spain.
Privacy and legal enquiries, including requests to exercise data-protection rights, may be sent to hello@rogueterrapin.io. Hōkime aims to respond without undue delay and ordinarily within one month after receiving a sufficiently verified request.
3. Financial workspace data stays under device control
Accounts, balances, transactions, recurring transactions, imports, categories, forecasts, scenarios and related financial records are encrypted and stored on your authorised device or devices. The active Hōkime server schema and APIs do not retain readable financial workspace records or usable workspace decryption keys.
Financial records are decrypted locally only while an authorised Hōkime application is open. Hōkime staff and support cannot browse the encrypted financial workspace through the account service.
4. Non-financial data Hōkime processes
Hōkime processes the limited non-financial information required to create and secure your account, administer entitlement and billing, coordinate authorised-device transfer, provide approved support capabilities and operate the service.
- Identity and account data, including your name, email address, supported sign-in identity and account settings.
- Authentication and security data, including sessions, device-authorisation records, IP address, user agent, rate-limit records and privacy-safe security events.
- Subscription data, including Stripe customer, subscription and price identifiers, entitlement status, verified billing events and cancellation state. Payment-card details are handled directly by Stripe and do not pass through Hōkime application code.
- Bounded device-transfer rendezvous metadata and end-to-end encrypted signalling or ciphertext when direct connectivity requires Hōkime-operated signalling or TURN relay.
- Support messages and attachments that you deliberately submit after the support capability is approved and enabled. Do not send financial records, recovery keys or other secrets to support.
- Limited operational logs and diagnostics needed to secure, maintain and troubleshoot the service. Decrypted financial records, recovery keys, authentication secrets and payment credentials must not be included.
5. Direct device transfer
When you choose to transfer a workspace, the source and destination devices establish an authenticated end-to-end encrypted session. Hōkime-operated rendezvous, signalling and TURN infrastructure may carry bounded metadata and encrypted ciphertext, but readable financial records and usable workspace keys do not pass through or remain on Hōkime servers.
Transfer invitations expire after ten minutes, claimed sessions expire after thirty minutes, and terminal rendezvous records are deleted after twenty-four hours. The separate privacy-safe transfer-audit retention period still requires legal approval before launch.
6. Encrypted backup, restore and recovery
A supported backup is encrypted on the authorised device before export. You choose where to store it; Hōkime does not upload the backup or recovery key as part of the supported backup flow.
Restore verifies the encrypted bundle and recovery key locally, stages ciphertext separately and activates only into an empty workspace after complete validation. Hōkime does not merge or silently replace an existing authoritative workspace.
Hōkime does not provide managed recovery. If all authorised devices, exported backups and the recovery key are lost or unusable, Hōkime cannot decrypt or recreate the financial workspace.
7. Purposes and legal bases
The final independent review must confirm the precise legal basis for each live flow. The current intended purposes are limited to the following.
- Contract and pre-contract steps: creating and operating your account, administering the trial, entitlement and subscription, coordinating requested transfer, support, export and deletion.
- Legal obligations: accounting, tax, consumer, fraud-prevention, security-incident and lawful-request obligations where applicable.
- Legitimate interests: protecting Hōkime and its users, preventing abuse, diagnosing failures and maintaining service integrity, balanced against your rights and expectations.
- Consent: any non-essential analytics, marketing communications or non-essential terminal storage. These capabilities remain disabled until valid consent controls, provider review and retention decisions exist.
8. Providers, regions and transfers
Google supports sign-in; Stripe supports billing; DigitalOcean supports the website, account service and protected non-financial operational backups; GitHub and GHCR support source control and immutable releases; and Frankfurter supplies reference exchange rates. Planned support, email, diagnostics and analytics capabilities remain disabled until their separate controls are approved.
Exact provider roles, processing and backup regions, contracts, subprocessors and international-transfer safeguards remain recorded as open or partial in the provider evidence registry. Hōkime does not claim that all processing remains in Spain or the EEA while that evidence is incomplete.
9. Retention
Hōkime account sessions expire after thirty days unless revoked earlier. Device-transfer invitation, active-session and terminal-record windows are ten minutes, thirty minutes and twenty-four hours respectively. Reference exchange-rate cache entries expire after thirty minutes for current rates and thirty days for historical rates and contain no customer identity or financial amount.
Exact periods for transfer audit events, provider-side identity records, billing, tax, fraud and dispute records, operational backups and build-infrastructure logs remain unapproved and launch-blocking. Chatwoot support, GlitchTip diagnostics and non-essential analytics hold no production event data while their explicit enablement gates remain off.
10. Account deletion and local erasure
Erasing the current-device workspace and deleting the Hōkime account are separate actions. Local erasure removes encrypted records, mutation history, staging data, local projections and protected key material from the current installed application after explicit confirmation.
Account deletion requires recent authentication, explicit acknowledgement of the device boundary, safe cancellation or reconciliation of any active Stripe subscription, revocation of sessions, device authorisations, offline entitlement and transfer state, removal of deletable server records, and application of only approved legal or security exceptions.
A Hōkime server cannot reliably erase an offline copy on another device or an exported backup held by you. Those copies remain until erased from each device or storage location. Permanent server-side account deletion remains disabled until the reviewed executor and retention decisions are complete.
11. Your rights and complaints
Subject to applicable law, you may request access, correction, deletion, restriction, objection and portability for personal data processed by Hōkime, and may withdraw consent without affecting earlier lawful processing. Send requests to hello@rogueterrapin.io. Hōkime may require proportionate identity verification before acting.
You may complain to the Spanish Data Protection Agency (AEPD) or another competent supervisory authority, particularly after first giving Hōkime the opportunity to respond to the request.
12. Security and unavoidable endpoint risks
Hōkime uses authenticated local encryption, protected key wrappers, device authorisation, verified webhooks, controlled releases and tested backup, restore and local-erasure procedures. No system or customer device is risk-free.
Malware, an already-unlocked device, operating-system compromise, screen capture, insecure exported-backup storage or disclosure of a recovery key can expose information outside the protections of the Hōkime account service.
13. Changes
Material changes to architecture, providers, retention, pricing or legal wording require a new publication version and review record. The effective launch version must be tied to one immutable source commit and released snapshot.
