Privacy Policy
Last Updated: July 15, 2026 · Version 2026-07-15
1. Introduction
This policy explains what data Strategic.GG ("we," "us"), operated by Mercury Stills, collects when you use the service, why we collect it, who we share it with, and how long we keep it. It applies to our website and to content you create or upload, including "Swis" canvases, replies, forks, profile fields, and uploaded images. We do not sell your personal data.
2. The Data We Collect
We collect the following categories of data:
- Account Data: your username, email address, and password. Your password is stored only as a salted cryptographic hash — we never store or see it in plaintext.
- Registration Acceptance Record: when you create an account, we keep an append-only receipt containing your numeric account identifier, the Terms and Privacy Policy versions displayed to you, a cryptographic digest of each server template used to render those documents, the server-recorded acceptance time, your minimum-age confirmation, the registration source, and your signup IP address. The receipt also records whether our proxy-chain configuration had been operator-verified at that time and the configured proxy-hop depth, so an uncalibrated address is not later mistaken for verified visitor-IP evidence. We use this record to document your assent and protect the integrity of account registration.
- Security & Anti-Abuse Data: the IP address you sign up from and a normalized form of your email address (for example, with dot and "+tag" variations stripped). We use these to detect and prevent duplicate accounts, signup-velocity abuse, and fraud. See Section 4.
- Content & Media: the Swis canvases, replies, forks, profile fields (such as bio and social links), and any avatar or background images you upload. Uploaded images are stored on Cloudflare R2 in production.
- Billing Data: if you subscribe to a paid tier, your payment is processed by Stripe. We do not store your full card numbers. We retain only a Stripe customer/subscription reference and your plan status.
- API Credentials: if you generate an API token (e.g., for a posting bot), we store only a SHA-256 hash of it. The raw token is shown to you once and cannot be recovered by us.
- Usage Data: how you use the site, such as page views and navigation paths.
- Technical Data: IP address, browser type and version, time zone and approximate location, and operating system.
3. How We Use Your Data
We use your data to:
- Operate the service — create and authenticate your account, store and display your content, send transactional email, and resize or transcode images you upload.
- Maintain security and prevent abuse — detect duplicate or fraudulent accounts, rate-limit abusive signups, and enforce our Terms.
- Process billing for paid subscriptions via Stripe.
- Generate notifications, including scanning reply text for @username mentions to notify the user mentioned.
Where applicable law requires a lawful basis, we rely on performance of our agreement with you (operating the service and billing) and our legitimate interest in keeping the platform secure and free of abuse.
4. Anti-Abuse & Duplicate-Account Detection
To keep the platform safe, we perform automated processing on a limited set of signals. We compute and index a normalized form of your email so that multiple accounts sharing one underlying inbox can be detected, and we record your signup IP address to detect bursts of accounts created from one source. These signals are used only for fraud prevention and abuse mitigation under our legitimate interest, not for advertising.
5. Service Providers & Sharing
We share data only with the processors needed to run the service, and as required by law. We do not sell your personal data. Our processors include:
- Stripe — payment processing for paid subscriptions (handles all card data).
- Cloudflare R2 — storage and delivery of uploaded images.
- Resend — sending account-verification and notification email.
- ui-avatars.com — if you have not uploaded an avatar, we generate a default one from this third-party service keyed on your username, which sends your username to that host.
We also use third-party services to generate our own AI Content (the Society Map "In the News" lane). These process public news data and our prompts, not your account data:
- NewsData.io — third-party news source for our automatically generated "In the News" content.
- Google (Gemini) — the AI model that generates our first-party "In the News" maps.
We may also disclose data when required by law, such as in response to a valid subpoena, court order, or other legal process, or where necessary to investigate abuse, protect safety, or comply with reporting obligations (including mandatory reporting of child sexual abuse material under 18 U.S.C. 2258A).
6. Third-Party Embeds & Cookies
Some pages embed third-party content — including YouTube and Twitch (video), TradingView (finance charts), and Spotify (audio). These providers load their own scripts and may set their own cookies and collect data about you under their own privacy policies, which we do not control. You can set your browser to refuse some or all cookies, but parts of the site may then not function properly.
7. Reports & Abuse Records
Anyone can report content through our report channel. When you file a report, we store your IP address and any contact details you provide (such as your email and name), along with the report itself. Copyright (DMCA) notices and the information in them may be forwarded to the affected user as part of the notice-and-counter-notice process. Reports and their associated records are retained for safety, legal, and evidentiary purposes.
8. Data Retention & Preservation
We keep account and content data for as long as your account is active. You may delete your own Swis content, and its direct replies are removed with it. However, content is generally hidden rather than permanently erased: when content is taken down by our staff or is the subject of a report, we preserve it and the related records as evidence required for legal and safety purposes — including CSAM preservation, copyright (DMCA), and defamation matters. These staff preservation holds, abuse/report records, and the append-only registration acceptance receipt may survive both your own deletion of content and account deletion. If an account is deleted, the receipt's account link is removed but its numeric account-identifier snapshot and the other receipt fields remain. We retain this data only as long as needed for those purposes or as the law requires.
9. Children's Privacy
The service is not directed to children under 13, and you must be at least 13 years old to use it (consistent with our Terms of Service). We do not knowingly collect personal data from children under 13 in violation of the Children's Online Privacy Protection Act (COPPA). If you believe a child under 13 has provided us personal data, contact us at mercury@strategic.gg. We will investigate, disable access where appropriate, and delete or de-identify the child's personal data as applicable law requires. We may retain a minimal acceptance, security, or legal record only where applicable law permits or requires it, as described in Sections 7 and 8.
10. Your Choices & Contact
You can edit your profile and delete your own content from your account. To request access to or deletion of your personal data, email us at mercury@strategic.gg. Note that some data may be retained where we are required to preserve it for legal, security, or evidentiary reasons (see Sections 7 and 8). For any questions about this policy, contact us at the same address.
11. Changes to This Policy
We may update this policy from time to time. When we do, we will revise the "Last Updated" date above. Your continued use of the service after changes take effect constitutes acceptance of the updated policy.