Legal
Privacy Policy
Effective date: June 1, 2026 · Last revised: June 12, 2026
1. Data controller
The data controller for all personal data processed through StrataView is:
StrataView, Inc.
The Mezz, 2001 15th St, Detroit, Michigan 48216, United States
Email: privacy@strataview.earth
2. What we collect and why
2.1 Account information
When you create a StrataView account, we collect your email address, password (stored as a bcrypt hash by Supabase Auth, so we never see it in plaintext), full name (optional), and organizational affiliation (optional). This data is necessary to provide authenticated access to the service.
2.2 Audit log data
Every action you take as an authenticated user (queries, exports, login events) is recorded in a hash-chained audit log. This is a core feature of StrataView, not an ancillary collection. Audit logs are retained for the lifetime of your account and for a minimum of 7 years after account closure to support evidentiary use. You may request a copy of your audit log at any time (see Section 7).
2.3 Public analytics (visitor data)
We operate self-hosted, privacy-preserving analytics in our own Supabase database. We do not use Google Analytics, Meta Pixel, or any third-party tracking service. Our analytics collect:
- A per-visitor random identifier (not linked to any personal data)
- Page URL and referrer (referrer origin only, not full URL)
- Browser type and operating system (from User-Agent)
- Country of origin (derived from IP address; IP address itself is not stored beyond 30 days)
- Session duration and page dwell time
- Persona and intent selections (from the voluntary intent modal, if submitted)
IP addresses are purged after 30 days. Visitor identifiers are reset on each new browser session and are not linked to account data. Analytics data is never sold or shared with third parties.
2.4 Contact form data
When you submit the contact form, we collect your name, email, organizational affiliation, message content, and selected subject. This data is stored in our database and used solely to respond to your inquiry. We retain contact messages for 2 years.
2.5 Policy brief request data
When you request a policy brief, we collect your name, email, organization, and role. This information is used to send the download link, to understand who is accessing our research, and (with your consent) to notify you of new briefs. Download records are retained for 2 years.
3. Legal basis
For users in jurisdictions that require a legal basis for processing:
- Account information: Performance of a contract (providing the service you signed up for).
- Audit logs: Legitimate interests (maintaining data integrity for evidentiary use) and legal obligation (record-keeping).
- Public analytics: Legitimate interests (understanding how our service is used to improve it), limited to non-identifying data. You may opt out by disabling JavaScript or using a browser-level blocking tool.
- Intent modal responses: Consent (the modal is voluntary and includes an explicit opt-in for follow-up communications).
- Contact and brief request data: Legitimate interests (responding to inquiries and delivering requested documents).
4. Data retention
| Data category | Retention period |
|---|---|
| Account credentials | Until account deletion + 90 days |
| Audit logs | 7 years minimum |
| Public analytics (anonymized) | Indefinite (no PII retained beyond 30 days) |
| IP addresses | 30 days maximum |
| Contact messages | 2 years |
| Brief request records | 2 years |
| Intent modal responses | 2 years |
5. Sub-processors
We share data with the following sub-processors as required to operate the service:
- Supabase, Inc. (authentication, database, file storage): processes account credentials, audit events, and analytics data on AWS us-east-1 infrastructure.
- Netlify, Inc. (web hosting and CDN): processes request logs including IP address (standard web server logging; Netlify's retention policy applies).
- Transactional email provider (brief download links and contact confirmations): processes name and email address only for message delivery. Provider is specified in our deployment configuration and available on request.
We do not use advertising networks, data brokers, or behavioral analytics platforms.
6. Cookies and local storage
StrataView uses the following browser storage:
- Supabase Auth session tokens: stored in
localStorageunder the site origin for authenticated users. These are necessary for session persistence and cannot be disabled while using an authenticated account. - Analytics visitor ID: a random identifier stored in
localStorageto distinguish unique visitors for analytics. Not linked to any personal data. You may clear this at any time via browser developer tools. - Intent modal dismissed flag: stored in
localStorageto avoid showing the modal repeatedly.
We do not use advertising cookies, cross-site tracking cookies, or fingerprinting.
7. Your rights
You have the following rights with respect to your personal data. To exercise any of these rights, email privacy@strataview.earth. We will respond within 30 days.
- Access: Request a copy of all personal data we hold about you.
- Correction: Request correction of inaccurate data.
- Deletion: Request deletion of your account and personal data (subject to legal retention obligations, including the 7-year audit log retention).
- Portability: Request your data in a structured, machine-readable format (JSON).
- Restriction: Request that we restrict processing of your data in certain circumstances.
- Objection: Object to processing based on legitimate interests. Analytics collection can be effectively halted by blocking JavaScript.
- Withdraw consent: Where processing is based on consent (intent modal follow-up), you may withdraw at any time by emailing us.
8. International transfers
Data is stored and processed in the United States (AWS us-east-1 via Supabase; Netlify's US infrastructure). If you are accessing StrataView from the European Economic Area, United Kingdom, or Switzerland, your data will be transferred to the United States. We rely on standard contractual clauses where required by applicable data protection law.
9. Third-party trackers
We do not use Google Analytics, Meta Pixel, LinkedIn Insight Tag, or any third-party behavioral analytics or advertising technology. All analytics are self-hosted in our own Supabase database. This policy is enforced at the technical level via our Content Security Policy header, which prohibits loading scripts from analytics or advertising domains.
10. Security
We implement the security controls described in our Trust Center, including TLS 1.3 in transit, AES-256 at rest (Supabase managed), row-level security, and TOTP MFA. No transmission over the internet is guaranteed to be 100% secure, and we cannot guarantee the security of information transmitted to us.
11. Children
StrataView is not directed at children under 13 and we do not knowingly collect data from children. If you believe we have inadvertently collected such data, please contact us at privacy@strataview.earth.
12. Changes to this policy
We may update this policy. Material changes will be communicated by email to registered users and by posting the revised policy with an updated effective date. Continued use after the effective date constitutes acceptance.
13. Contact
Privacy questions and data subject requests: privacy@strataview.earth
General inquiries: hello@strataview.earth
StrataView, Inc. · The Mezz, 2001 15th St, Detroit, MI 48216