DRAFT — not reviewed by a lawyer. Must be approved before launch.

Privacy Policy

MapMog is operated by Arya Studios LLC.

Contact us: [contact email — founder to fill] · [postal address — founder to fill]

The browser token

When you first visit, your browser generates a random token and stores it in your browser's local storage (never a cookie). We never see or store that raw token. Every request you send is matched against a one-way SHA-256 hash of the token instead, so the server only ever holds the hash, not the value that identifies you in your browser.

What we store, and why

  • Your browser token's hash — to attribute your placements to you, apply charges/cooldowns, and check bans.
  • Your IP address's hash — never the IP itself — to enforce per-network flood limits (a cap on placements and visits from one network in a time window) that stop bots and abuse.
  • Every pixel you place — its position, color, your token's hash, your IP's hash, and the time — kept as a permanent, append-only history. This is how the canvas's replay and current state are computed; individual placements are never edited or deleted, only superseded by later placements at the same position.
  • Coins and purchases — a ledger of coin-earning and coin-spending events (paint credit, level-up bonus, palette color unlocks, capacity purchases), tied to your token's hash.
  • Shield click counts — which shield's link you tapped and when, tied to your token's hash, used to report engagement to advertisers.
  • Visit records — one row per session start: your token's hash, your IP's hash, and where you came from (referral source/medium/campaign and landing page), used to measure how people find the canvas.
  • Admin actions — records of operator actions (rollbacks, clears, bans) taken on the canvas, kept as a permanent history for accountability.
  • Reports you send — when you report art: its position, the reason you picked, the time, your token's hash and your IP's hash, used to show the operator what needs review and to stop report flooding. The operator's report list never shows either hash.
  • Shields (only when this feature is on) — a shield's area and shape, start and end time, label and link, who owns it (a player's token hash, a group, or a brand), and the token hashes of the players who share it, used to protect that area from being painted over.
  • Map growth history (only when the growing map is on) — each time the map grows: when, by which rule, how many cells were added and where, and our own follower count at that moment. Nothing about you.
  • Our follower counts (only when the growing map is on) — readings of our OWN social accounts' follower totals (source, number, time, status). No visitor data.
  • Replay snapshots — periodic pictures of the public canvas, used for the Replay tab and timelapse videos. They hold only the colors on the map at that moment: no token, no IP and nothing else about you.

How long we keep it

Not yet decided. As of this draft, nothing above is automatically deleted — the canvas's design depends on being able to replay its full history. We will update this policy once a retention period is set. [founder to confirm — see GAPS]

Third parties

The map background is served by OpenFreeMap (tiles.openfreemap.org); loading the map sends your IP address to that service, outside our control. If you're asked to complete a bot check, that check is served by Cloudflare Turnstile, which also sees your IP address; the bot check only loads when it is actually needed. We do not use advertising trackers, analytics pixels, or cookies of our own. All fonts, the map library, and every other script on this page are self-hosted by us.

Questions

Contact [contact email — founder to fill] or write to [postal address — founder to fill] with any privacy question.

← Back to the canvas