01 — Our Data Posture
Built small, on purpose — here's what that actually means
Gray Room is a single-operator business. We don't have a security team, a SOC 2 certification, or a dedicated compliance department, and we won't claim otherwise. What we do have: encrypted connections (HTTPS/TLS) on every page and API call, passwords stored as one-way hashes (never in plain text), card payments handled entirely by Stripe (we never see or store your card number), and API access gated behind per-client keys with usage limits.
If your organization requires a formal security questionnaire, SOC 2 report, or signed Data Processing Agreement before integrating, tell us — we'll be upfront about what we can and can't provide at our current size, rather than pretend otherwise.
02 — What We Collect
The actual list, not a vague summary
03 — How We Use It
Operating the service, plus what we may build and sell from it
Most of this is what you'd expect: we use your account and usage data to run your subscription, enforce tier limits, and provide support. The part we want to state explicitly, rather than leave implicit, is this:
Aggregated and de-identified data about search, classification, and comparison activity across all users may be compiled into market intelligence products and sold or licensed separately from API access. For example: which games or types of games are most frequently searched, classified, or compared on Strata is commercially meaningful information — it can reveal what's gaining attention in the market, what studios and platforms are actively researching, and how player and industry interest is shifting. We may package these aggregate trends into reports, dashboards, or data licenses sold to studios, publishers, platforms, market researchers, and yes, potentially to a client's competitors, the same way search-trend and app-store-trend data is commercially sold by other companies today.
We may do this
Aggregate trend reporting
Compile de-identified, aggregate patterns — e.g. "comparisons involving open-world RPGs increased 30% this quarter" — into products sold to any interested party, including a client's competitors.
We may do this
Product improvement
Use query and usage patterns internally to improve the classification engine, the similarity algorithm, and the product roadmap.
We will not do this
Sell an identifiable client's specific activity
We will not sell or disclose a report saying "Client X searched/classified these specific titles" tied to that client's identity, without that client's explicit consent.
We will not do this
Expose unreleased-game submissions
See Section 04 — confidential and unreleased-title classifications are held to a stricter standard than general usage data.
04 — Confidential & Unreleased Submissions
The one category we treat completely differently
Professional and Enterprise tier clients can classify unreleased or unannounced games. That's not the same kind of data as "someone searched Elden Ring" — it can be commercially sensitive, confidential information about a specific studio's unannounced product.
Unreleased-title classifications are not included in aggregate trend reporting, are not merged into the public or shared similarity database where other clients could discover them, and are not sold, licensed, or disclosed to any third party. They exist only to return a result to the client who submitted them, and are treated as confidential by default.
05 — Data Retention
What we keep, and for how long
06 — Third-Party Processors
Who else touches your data, and why
Railway
Hosts the live engine and the PostgreSQL database. All data in transit and at rest sits on Railway's infrastructure.
Stripe
Processes all payments. Stripe holds your card details directly — Gray Room never sees or stores full card numbers.
Anthropic (Claude API)
Performs the AI classification and synopsis generation. Game titles and classification prompts are sent to Anthropic's API under their standard commercial API terms, which exclude using submitted content to train their models.
RAWG
Public game metadata source used by the automated pipeline to discover new titles to classify. No client or account data is sent to RAWG.
Formspree
Processes the "Request API access" contact form on grayroom.gg.
07 — Your Rights & Data Deletion
How to get your data, or have it removed
You can request a copy of your account data, request deletion of your account and associated usage history, or request deletion of a specific unreleased-title submission, at any time by emailing cgamld1110@gmail.com. Deletion of released-game classifications from the shared public database is generally not possible, since that data is the shared product itself — but account-level and unreleased-submission data can be removed on request.
08 — Changes to This Page
If this changes, you'll be able to tell
This page will be updated as the business grows and as formal legal documents (a finalized Privacy Policy, Terms of Service, and Data Processing Agreement) are put in place. The "last updated" date at the top will always reflect the most recent change. Material changes — particularly to Section 03 on commercial data use — will be communicated directly to active clients, not just silently updated here.