Skip to content
Strata

Privacy Policy

Effective July 9, 2026

This policy explains what Strata collects, why we collect it, and where it goes. It was drafted from the actual behavior of our systems: if the app doesn't do something, we don't claim it here.

1. Who we are

Strata ("we", "us") — operated by the owner of stratafight.com — is a martial arts gym discovery and community platform, available at stratafight.com and as a mobile app. Questions about this policy go to support@stratafight.com.

2. What we collect

We collect what you give us to run your account and the features you use. Nothing is gathered in the background beyond what's listed here.

  • Account — your email address and password (stored only as a scrypt hash; we never see or store the plain-text password), or your Google account identity if you sign in with Google. Each sign-in session records the IP address and browser/device it came from, so unauthorized access can be spotted.
  • Profile — your display name, plus optionally: first and last name, phone number, gender, country, bio, avatar and cover photo, the martial arts you practice, your belt ranks, and social links. Everything beyond a display name is optional.
  • Content you create — posts, comments, reviews and helpful votes, likes, event RSVPs, gym membership requests, messages you send to gyms, trial-booking notes, and photos and videos you upload. If you claim a gym, the verification documents you submit are stored privately and used only to verify ownership.
  • Devices — if you enable push notifications on mobile, we store your device's push token. It is deleted when you sign out or delete your account.

3. Location

If you grant location access, your precise coordinates — and the map area you're looking at — are sent to our servers to answer "gyms near you" queries and to pick location-relevant sponsored placements. They are used to answer that request and are never stored.

If you don't share precise location, Cloudflare (our hosting provider) supplies a city-level estimate from your IP address for the same purpose. That estimate isn't stored either.

4. Payments

Payments (currently only gym promotion campaigns) are processed entirely by Stripe on Stripe's hosted checkout page. Your card details go to Stripe, not to us. We store only the amount, the currency, and Stripe's session and payment identifiers — never card numbers.

5. Sponsored placements

Gyms can pay to promote their listings; promoted listings are labeled "Sponsored". When a promotion is shown or clicked, we record the campaign, the placement, the event type, and a timestamp — no viewer identity. We can't tell a gym who saw or clicked their promotion, because we don't record it.

6. Service providers

We run on a small set of infrastructure providers. Each receives only what its job requires:

  • Cloudflare — hosting, TLS, and media storage/delivery (images, video, private documents). Sees IP-level traffic metadata and operational logs as part of serving the site.
  • PlanetScale — database hosting. Stores the application data described above.
  • Algolia — search. The search index holds your user id, display name, handle, avatar URL, and join date — nothing else from your profile — plus public gym data.
  • Mapbox — location search and map tiles load directly from your browser, so Mapbox receives your IP address and the text you type into location search.
  • Google — sign-in with Google, if you use it.
  • Apple — Sign in with Apple on mobile, where offered.
  • Apple and Google push services — your device's push token and the content of each notification we send.
  • Stripe — payment processing for gym promotions (see Payments above).
  • Resend — delivers our transactional email, so it receives the address, subject, and body of each message.
  • Axiom — stores our operational logs.

7. Cookies

We set three cookies: a session cookie and a short-lived signed session-data cookie (both HttpOnly, used only to keep you signed in), and a theme-preference cookie (light/dark). There are no advertising trackers and no third-party analytics scripts.

8. Email

We send transactional email only: address verification, password resets, trial-booking updates, and changes to events you've RSVPed to. We send no marketing email — which is why there's no marketing unsubscribe link. There's nothing to unsubscribe from.

9. Your controls

You control your visibility and your data from inside the app:

  • Per-section profile visibility — choose who can see your bio, martial arts, gym affiliations, social links, and follower counts.
  • Per-post audience — every post has its own audience setting.
  • Mutes — hide any user's or gym's posts from your feeds, silently.
  • Account deletion — delete your account from settings at any time. Deletion anonymizes your account (your public identity becomes "Deleted User"), deletes your personal data, relationships, and device tokens, and queues your uploaded media for deletion from cloud storage. Stated honestly: content you posted, such as reviews and posts, may remain visible in anonymized form.
  • Data export — we don't currently offer a self-serve export. If you need a copy of your data, email support@stratafight.com and we'll help.

10. Retention

We keep your data while your account exists; deleting your account works as described above. Sign-in session records are removed when you sign out or when the session expires. Operational logs held by our providers are retained for a limited period and then age out.

11. Children

Strata is not directed to children under 13, and we don't knowingly keep accounts for them. If we discover an account belongs to someone under 13, we delete it. If you believe a child under 13 has an account, email support@stratafight.com.

12. Changes to this policy

When this policy changes, we'll update the effective date at the top. For significant changes, we'll take reasonable steps to point them out — for example, a notice in the app. Continued use after a change means you accept the updated policy.

13. Contact

support@stratafight.com — for privacy questions, data requests, or anything else in this policy.