Legal

Privacy Policy

Effective date: June 1, 2026 · Last revised: June 12, 2026

1. Data controller

The data controller for all personal data processed through StrataView is:

StrataView, Inc.
The Mezz, 2001 15th St, Detroit, Michigan 48216, United States
Email: privacy@strataview.earth

2. What we collect and why

2.1 Account information

When you create a StrataView account, we collect your email address, password (stored as a bcrypt hash by Supabase Auth, so we never see it in plaintext), full name (optional), and organizational affiliation (optional). This data is necessary to provide authenticated access to the service.

2.2 Audit log data

Every action you take as an authenticated user (queries, exports, login events) is recorded in a hash-chained audit log. This is a core feature of StrataView, not an ancillary collection. Audit logs are retained for the lifetime of your account and for a minimum of 7 years after account closure to support evidentiary use. You may request a copy of your audit log at any time (see Section 7).

2.3 Public analytics (visitor data)

We operate self-hosted, privacy-preserving analytics in our own Supabase database. We do not use Google Analytics, Meta Pixel, or any third-party tracking service. Our analytics collect:

  • A per-visitor random identifier (not linked to any personal data)
  • Page URL and referrer (referrer origin only, not full URL)
  • Browser type and operating system (from User-Agent)
  • Country of origin (derived from IP address; IP address itself is not stored beyond 30 days)
  • Session duration and page dwell time
  • Persona and intent selections (from the voluntary intent modal, if submitted)

IP addresses are purged after 30 days. Visitor identifiers are reset on each new browser session and are not linked to account data. Analytics data is never sold or shared with third parties.

2.4 Contact form data

When you submit the contact form, we collect your name, email, organizational affiliation, message content, and selected subject. This data is stored in our database and used solely to respond to your inquiry. We retain contact messages for 2 years.

2.5 Policy brief request data

When you request a policy brief, we collect your name, email, organization, and role. This information is used to send the download link, to understand who is accessing our research, and (with your consent) to notify you of new briefs. Download records are retained for 2 years.

3. Legal basis

For users in jurisdictions that require a legal basis for processing:

  • Account information: Performance of a contract (providing the service you signed up for).
  • Audit logs: Legitimate interests (maintaining data integrity for evidentiary use) and legal obligation (record-keeping).
  • Public analytics: Legitimate interests (understanding how our service is used to improve it), limited to non-identifying data. You may opt out by disabling JavaScript or using a browser-level blocking tool.
  • Intent modal responses: Consent (the modal is voluntary and includes an explicit opt-in for follow-up communications).
  • Contact and brief request data: Legitimate interests (responding to inquiries and delivering requested documents).

4. Data retention

Data categoryRetention period
Account credentialsUntil account deletion + 90 days
Audit logs7 years minimum
Public analytics (anonymized)Indefinite (no PII retained beyond 30 days)
IP addresses30 days maximum
Contact messages2 years
Brief request records2 years
Intent modal responses2 years

5. Sub-processors

We share data with the following sub-processors as required to operate the service:

  • Supabase, Inc. (authentication, database, file storage): processes account credentials, audit events, and analytics data on AWS us-east-1 infrastructure.
  • Netlify, Inc. (web hosting and CDN): processes request logs including IP address (standard web server logging; Netlify's retention policy applies).
  • Transactional email provider (brief download links and contact confirmations): processes name and email address only for message delivery. Provider is specified in our deployment configuration and available on request.

We do not use advertising networks, data brokers, or behavioral analytics platforms.

6. Cookies and local storage

StrataView uses the following browser storage:

  • Supabase Auth session tokens: stored in localStorage under the site origin for authenticated users. These are necessary for session persistence and cannot be disabled while using an authenticated account.
  • Analytics visitor ID: a random identifier stored in localStorage to distinguish unique visitors for analytics. Not linked to any personal data. You may clear this at any time via browser developer tools.
  • Intent modal dismissed flag: stored in localStorage to avoid showing the modal repeatedly.

We do not use advertising cookies, cross-site tracking cookies, or fingerprinting.

7. Your rights

You have the following rights with respect to your personal data. To exercise any of these rights, email privacy@strataview.earth. We will respond within 30 days.

  • Access: Request a copy of all personal data we hold about you.
  • Correction: Request correction of inaccurate data.
  • Deletion: Request deletion of your account and personal data (subject to legal retention obligations, including the 7-year audit log retention).
  • Portability: Request your data in a structured, machine-readable format (JSON).
  • Restriction: Request that we restrict processing of your data in certain circumstances.
  • Objection: Object to processing based on legitimate interests. Analytics collection can be effectively halted by blocking JavaScript.
  • Withdraw consent: Where processing is based on consent (intent modal follow-up), you may withdraw at any time by emailing us.

8. International transfers

Data is stored and processed in the United States (AWS us-east-1 via Supabase; Netlify's US infrastructure). If you are accessing StrataView from the European Economic Area, United Kingdom, or Switzerland, your data will be transferred to the United States. We rely on standard contractual clauses where required by applicable data protection law.

9. Third-party trackers

We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, or any third-party behavioral analytics or advertising technology. All analytics are self-hosted in our own Supabase database. This policy is enforced at the technical level via our Content Security Policy header, which prohibits loading scripts from analytics or advertising domains.

10. Security

We implement the security controls described in our Trust Center, including TLS 1.3 in transit, AES-256 at rest (Supabase managed), row-level security, and TOTP MFA. No transmission over the internet is guaranteed to be 100% secure, and we cannot guarantee the security of information transmitted to us.

11. Children

StrataView is not directed at children under 13 and we do not knowingly collect data from children. If you believe we have inadvertently collected such data, please contact us at privacy@strataview.earth.

12. Changes to this policy

We may update this policy. Material changes will be communicated by email to registered users and by posting the revised policy with an updated effective date. Continued use after the effective date constitutes acceptance.

13. Contact

Privacy questions and data subject requests: privacy@strataview.earth

General inquiries: hello@strataview.earth

StrataView, Inc. · The Mezz, 2001 15th St, Detroit, MI 48216