Privacy Policy

Last updated: June 21, 2026

Tezeract is a motion-controlled gaming device with a camera that sits in your living room. We take privacy seriously because we have to. This policy explains what we collect, what we don't, and what your choices are.

The short version

  • Camera frames never leave your device.Motion tracking runs entirely on the Tezeract's hardware. Frames are processed in memory and discarded within milliseconds.
  • Biometric data stays local.The body, hand, and (optional) face keypoints used for gameplay are computed on-device and never sent to our servers. See "Biometric information" below for the formal disclosures required under the Illinois Biometric Information Privacy Act (BIPA) and California Consumer Privacy Act (CCPA).
  • We collect what we need to fulfill your order, keep your account, and answer support questions.
  • We don't sell your personal information. We share it only with the vendors that help us run the business (Stripe, our email provider, our hosting provider).
  • You can ask us for a copy of your data, or to delete it, at any time.

Who we are

"Tezeract", "we", and "us" refer to Tezeract, Inc., a Delaware corporation. You can reach us at privacy@tezeract.com.

What we collect

From every visitor

  • Basic request data — IP address, browser type, referring page. Most of this is stored hashed or aggregated.
  • Marketing-attribution parameters (UTM tags) when you arrive from an ad or link.

When you buy something

  • Email address, name, shipping address.
  • Payment information is collected and stored by Stripe, our payment processor. We never see or store full card numbers.
  • Order history and shipping status.

When you join our waitlist

  • Email address and an opaque hash of your IP for dedup.

When you use your Tezeract device

  • Camera frames stay on the device.The motion engine runs on the Tezeract's GPU. Frames are processed, the pose keypoints are sent to whichever app is running, and the raw frame is then discarded — it's never written to disk or uploaded.
  • Basic device telemetry — software version, uptime, crash reports — so we can ship updates and fix bugs. Opt-out coming in a future update.
  • If you opt into Tezeract+ cloud DVR, motion-triggered video clips are uploaded to our hosting (Cloudflare R2) and kept for 30 days. This feature is off by default.

How we use it

  • Fulfill your order and ship your device.
  • Provide your account and any subscription services.
  • Answer your support emails and contact you about your order.
  • Send service emails (receipts, shipping updates, security notifications). These are not marketing emails.
  • Send marketing emails only if you opted in via the waitlist or a separate signup. You can unsubscribe at any time.
  • Detect, prevent, and respond to fraud, abuse, or technical problems.
  • Improve the product — aggregated, de-identified usage data only.

Biometric information

The Tezeract device uses its camera to detect your body posture, hand position, and (for some games) facial landmarks. Under certain state laws — notably the Illinois Biometric Information Privacy Act (BIPA) and the California Consumer Privacy Act (CCPA) — that data can qualify as "biometric information." This section explains exactly what happens with it.

What we capture

  • Body pose keypoints — a stream of 33 joint coordinates per video frame (shoulders, elbows, hips, knees, etc.), produced by an on-device machine-learning model.
  • Hand keypoints — 21 finger and palm coordinates per hand, when a game opts into hand tracking.
  • Face landmarks — up to 478 coordinates describing the position and shape of your facial features, when a game opts into face tracking. We do not run face recognition or compare your face to any database. The landmarks are used to detect expressions (e.g. smile, open mouth) and gaze direction, never identity.
  • Raw camera video frames — held in device memory only long enough to run the keypoint extraction, then immediately discarded. Raw frames are never written to disk, never uploaded to our servers, and never shared with the games installed on your device.

Where it is processed

All biometric extraction runs on the Tezeract console's GPU.No biometric data is transmitted to Tezeract's servers or to any third party. Games running on your device receive the derived keypoint streams (not the raw video) and process them locally to power gameplay.

We do not store, sell, lease, trade, or otherwise profit from biometric identifiers or biometric information. We do not use biometric data to identify you, build a profile, or target advertising.

Retention

Raw camera frames are retained in volatile device memory for less than 50 milliseconds, only as long as needed to compute keypoints, then overwritten. Keypoint streams are passed to the active game in real time and are not persisted by the operating system.

Per BIPA § 14/15(a), any biometric identifiers that may be retained (e.g. for crash-report diagnostics during a critical bug) will be permanently destroyed when the initial purpose for collection has been satisfied or within one (1) yearof the individual's last interaction with the device, whichever occurs first.

Consent

By powering on a Tezeract device and proceeding past the first-boot setup screen, you provide informed consent for the on-device collection of biometric data as described in this section. You can withdraw consent at any time by disabling motion tracking in Settings → Motion controls → Off; this stops the camera from being read and prevents any further biometric processing. You can also unplug the camera (USB) or factory-reset the device.

Each Tezeract device ships with a printed setup guide that describes the camera's biometric processing in plain English, and the first-boot wizard requires affirmative consent before any tracking is enabled.

Children under 13

The device's biometric processing operates on whoever is in front of the camera, including children. Parents are the account holders and provide consent on behalf of their household. We do not associate biometric data with named children, and no biometric data leaves the device.

California residents

For purposes of the CCPA / CPRA, biometric information is "sensitive personal information." You have the right to limit our use of your sensitive personal information to what is necessary to provide the product. Because all biometric processing already happens on-device and we receive none of it, no additional limitation is needed — but if you have concerns, contact privacy@tezeract.com and we'll respond within 15 business days.

Illinois residents

For purposes of BIPA, Tezeract's written retention schedule and destruction guidelines are: keypoint and landmark data shall not be retained beyond the active gameplay session, and any incidental biometric identifiers captured for diagnostic purposes shall be destroyed no later than one year after the individual's last device interaction or upon the individual's written request, whichever occurs first. We do not disclose, redisclose, or otherwise disseminate biometric identifiers to any third party.

Who we share it with

We share data only with vendors who help us operate Tezeract:

  • Stripe — payment processing. They get your name, email, billing address, and payment method.
  • Resend — transactional email (order confirmations, password resets). They get your email and the email content.
  • Supabase — database hosting. Your account and order data live here.
  • Cloudflare — web hosting, image storage, DDoS protection. They see your IP and basic request data.

We never sell your personal information. We don't share with advertisers in a way that would qualify as a "sale" under CCPA. If that changes, we'll give you advance notice and a clear opt-out.

We may also share information if compelled by law (e.g., a valid subpoena), to protect our rights, or in a corporate transaction (merger, acquisition). In any sale or merger we'll require the acquiring party to honor this policy.

Cookies and tracking

We use a small number of strictly necessary cookies to keep you signed in and to remember your cart. We don't set advertising or cross-site tracking cookies on this site.

Once we enable product analytics, we'll add a cookie banner and the option to opt out. Until then there's nothing to consent to.

Children

Tezeract is designed for family living rooms and many of our games target ages 6+. The device is intended to be set up by a parent or guardian. We don't knowingly collect personal information from children under 13 outside of a parent-managed account. If you believe a child's information has been collected without parental consent, email privacy@tezeract.com and we'll delete it.

Your rights

Depending on where you live, you may have the right to access, correct, delete, or export the personal information we hold about you, and to object to certain uses. To make a request, email privacy@tezeract.com from the address on file. We'll respond within 30 days.

California residents have additional rights under the CCPA, including the right to know what categories of personal information we've collected, the right to delete, and the right to opt out of any "sale" (we don't sell, so this is already the default).

Data retention

We keep account information for as long as your account is active. We keep order information for 7 years to comply with tax and accounting requirements. We delete the rest when it's no longer needed for the purpose collected.

Security

We use TLS for everything in transit, encrypted storage at rest, and least-privilege access controls. No system is perfect, but we treat your data with the seriousness it deserves. If we ever have a breach affecting your information, we'll notify you and the relevant regulators promptly.

Changes

We'll update this policy as the product evolves. Material changes will be highlighted on this page with at least 30 days of notice before they take effect, and we'll email registered users when we can.

Contact

Privacy questions: privacy@tezeract.com
Mailing: Tezeract, Inc., 1209 Orange Street, Wilmington, DE 19801, USA