Privacy

Operator details are not published yet. This site is pre-launch and the operating entity has not been registered on these pages. Until it is, questions go to [email protected], and purchases are handled by Stripe, who identify themselves on your receipt.

No precise location, by construction. Placements snap to coarse H3 cells server-side; raw coordinates are never stored or logged, and an automated test fails the build if any code path tries. Viewports are snapped before they touch a URL.

Identity. A random browser cookie is who you are. No email is required to play. Optional accounts store a display name and a password hash; connecting Google stores only its opaque user id — never your email.

Optional recovery email. You may add an email address to an account. It is used for account recovery — sending you a sign-in link if you lose your password and your recovery code — and for nothing else unless you ask.

If you turn on mural notifications, we will also use it to tell you when a mural you painted is finished, or when somebody paints over it: at most one email a day, never anything else, and one click turns it off. That switch is off unless you turn it on.

The address is stored only after you click a link we send to it, is never shown to other players, never used for marketing, and never sold. Removing it removes it. An account works forever without one — “no email required” is a promise about what we demand, not a limit on what you may choose to give us.

Addresses. Network addresses are used for rate limiting as keyed one-way hashes (HMAC) of a coarsened prefix; a database dump alone cannot yield an address.

The ledger. Every painted pixel and placement writes an immutable audit record tied to your cookie identity — that record is what moderation, timelapses and leaderboards read. It is never sold and never joined with anything that could de-anonymise it.

Payments. Payments are processed by Stripe: your card details go to Stripe, not to us. We receive the transaction id, the amount and what it bought.

Analytics. Product analytics (PostHog) record feature events; no precise location, no message contents. It runs COOKIELESS: the analytics id lives in memory for the page session only and nothing is written to your device — no analytics cookie, no local storage. That is why this site shows no cookie banner. The cost is ours, not yours: we cannot measure whether people come back across days, and we would rather not know than ask everybody for permission on arrival.

Fair play. Where coins are involved, we look for automated painting. Almost every signal is derived from data already described above — the times and grid positions in the pixel ledger, the one-way network hash used for rate limiting, and how old an account is. We derive: how regular the gaps between placements are, whether they track the recharge interval, how long an identity paints without a break, whether pixels are placed in scan-line order, and whether several identities behind one network address place in lockstep. One signal is collected rather than derived: which ninth of a painted pixel your tap landed in. That is a position on your own screen relative to the pixel you chose — it is not a location, it says nothing about where you are, and it is deliberately too coarse to identify anyone. All of it opens a case for a person to read; nothing here bans anybody automatically, and painting itself is never gated.

Your rights. Ask and we will delete the data tied to your cookie or account, subject to the immutable moderation ledger where the law requires keeping it. GDPR requests: [email protected].

Back to the map