Data Use & Security

What Gray Room collects from grayroom.gg visitors and Strata API clients, what it's used for — including potential commercial uses, stated plainly rather than buried — and what stays off-limits.

Last updated: June 2026 · Questions about this page: grayroomllc@gmail.com

This page is a plain-language disclosure, not yet a finalized legal Privacy Policy or Terms of Service. Gray Room is a solo-operated business. Anything that creates a binding legal obligation on this page should be treated as a draft pending review by an attorney before it governs a real client relationship or payment.

01 Our data posture 02 What we collect 03 How we use it 04 Confidential & unreleased submissions 05 Data retention 06 Third-party processors 07 Your rights & data deletion 08 Changes to this page

01 — Our Data Posture

Built small, on purpose — here's what that actually means

Gray Room is a single-operator business. We don't have a security team, a SOC 2 certification, or a dedicated compliance department, and we won't claim otherwise. What we do have: encrypted connections (HTTPS/TLS) on every page and API call, passwords stored as one-way hashes (never in plain text), card payments handled entirely by Stripe (we never see or store your card number), and API access gated behind per-client keys with usage limits.

If your organization requires a formal security questionnaire, SOC 2 report, or signed Data Processing Agreement before integrating, tell us — we'll be upfront about what we can and can't provide at our current size, rather than pretend otherwise.

02 — What We Collect

The actual list, not a vague summary

Account information: email address, hashed password, subscription tier, and Stripe customer/subscription IDs (Stripe holds your actual payment details, not us)
Usage metadata: which endpoints you call, how often, and your monthly call count against your tier's limit
Search and classification queries: the game titles you search, classify, or compare through grayroom.gg or the API
Library data: games you explicitly save to your personal or organizational library
Standard web logs: IP address, browser type, and timestamps, collected automatically by our hosting infrastructure (Railway) for rate-limiting and abuse prevention

03 — How We Use It

Operating the service, plus what we may build and sell from it

Most of this is what you'd expect: we use your account and usage data to run your subscription, enforce tier limits, and provide support. The part we want to state explicitly, rather than leave implicit, is this:

Aggregated and de-identified data about search, classification, and comparison activity across all users may be compiled into market intelligence products and sold or licensed separately from API access. For example: which games or types of games are most frequently searched, classified, or compared on Strata is commercially meaningful information — it can reveal what's gaining attention in the market, what studios and platforms are actively researching, and how player and industry interest is shifting. We may package these aggregate trends into reports, dashboards, or data licenses sold to studios, publishers, platforms, market researchers, and yes, potentially to a client's competitors, the same way search-trend and app-store-trend data is commercially sold by other companies today.

We may do this

Aggregate trend reporting

Compile de-identified, aggregate patterns — e.g. "comparisons involving open-world RPGs increased 30% this quarter" — into products sold to any interested party, including a client's competitors.

We may do this

Product improvement

Use query and usage patterns internally to improve the classification engine, the similarity algorithm, and the product roadmap.

We will not do this

Sell an identifiable client's specific activity

We will not sell or disclose a report saying "Client X searched/classified these specific titles" tied to that client's identity, without that client's explicit consent.

We will not do this

Expose unreleased-game submissions

See Section 04 — confidential and unreleased-title classifications are held to a stricter standard than general usage data.

04 — Confidential & Unreleased Submissions

The one category we treat completely differently

Professional and Enterprise tier clients can classify unreleased or unannounced games. That's not the same kind of data as "someone searched Elden Ring" — it can be commercially sensitive, confidential information about a specific studio's unannounced product.

Unreleased-title classifications are not included in aggregate trend reporting, are not merged into the public or shared similarity database where other clients could discover them, and are not sold, licensed, or disclosed to any third party. They exist only to return a result to the client who submitted them, and are treated as confidential by default.

05 — Data Retention

What we keep, and for how long

Account data is retained for the life of your subscription, plus a reasonable period after cancellation for billing and support records
Classified game data for released titles is retained permanently as part of the shared database — that's the core product
Unreleased-title classifications are retained only as long as needed to serve the requesting client, and deleted on request
Usage logs and query history are retained for as long as reasonably useful for billing, abuse prevention, and the aggregate analysis described in Section 03

06 — Third-Party Processors

Who else touches your data, and why

Railway

Hosts the live engine and the PostgreSQL database. All data in transit and at rest sits on Railway's infrastructure.

Stripe

Processes all payments. Stripe holds your card details directly — Gray Room never sees or stores full card numbers.

Anthropic (Claude API)

Performs the AI classification and synopsis generation. Game titles and classification prompts are sent to Anthropic's API under their standard commercial API terms, which exclude using submitted content to train their models.

RAWG

Public game metadata source used by the automated pipeline to discover new titles to classify. No client or account data is sent to RAWG.

Formspree

Processes the "Request API access" contact form on grayroom.gg.

07 — Your Rights & Data Deletion

How to get your data, or have it removed

You can request a copy of your account data, request deletion of your account and associated usage history, or request deletion of a specific unreleased-title submission, at any time by emailing cgamld1110@gmail.com. Deletion of released-game classifications from the shared public database is generally not possible, since that data is the shared product itself — but account-level and unreleased-submission data can be removed on request.

08 — Changes to This Page

If this changes, you'll be able to tell

This page will be updated as the business grows and as formal legal documents (a finalized Privacy Policy, Terms of Service, and Data Processing Agreement) are put in place. The "last updated" date at the top will always reflect the most recent change. Material changes — particularly to Section 03 on commercial data use — will be communicated directly to active clients, not just silently updated here.

Questions about your data?

Email us directly — we'll answer plainly, the same way this page is written.