Privacy Policy
Last Updated:
Privacy Compliance: This platform uses only essential cookies (authentication, session management). No tracking, marketing, or analytics cookies are deployed without your explicit consent. Learn more about cookies.
Analytics cookies: Not yet decided
Privacy Policy – Stew.io
Effective Date: January 15, 2026
Last Updated: January 15, 2026
1. Introduction
Stew.io ("we," "us," "our," or "Company") operates the Stew.io platform, a community-driven sim racing incident review and stewarding application. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (the "Service").
Your Privacy Matters. We are committed to transparency and user control over personal data. Please read this policy carefully.
2. Information We Collect
2.1 Information You Provide Directly
- Account Data: Discord ID, Google ID, display name, bio, country, profile created date
- Incident Submissions: YouTube video URL, incident description, rule type category, steward comments
- Voting/Review Data: Incident verdicts cast, vote consensus contribution, reputation score, voting accuracy
- Communication: Support tickets, feedback forms, email correspondence
- Linked Accounts: Optional iRacing ID, ACC Customer ID for stats display (stored in linked_accounts JSONB)
2.2 Information Collected Automatically
- Usage Analytics: Page views, incident reviews, voting patterns, time spent on platform (anonymized via Posthog)
- Device/Browser: IP address, browser type, OS, device type, language preference
- OAuth Data: Discord/Google user ID (not email stored separately; managed by Supabase auth)
- Cookies/Session Data: Authentication tokens (Supabase JWT), user session preferences, CSRF tokens
2.3 Third-Party Integrations
- Discord & Google OAuth: We store your Discord ID or Google ID via Supabase Auth. We do NOT store passwords (managed by Discord/Google).
- YouTube: When you submit a YouTube URL, we store the URL and metadata (title, duration) only; we do not download or host video files.
- iRacing/ACC (Optional): If you link your iRacing or ACC account, we store your ID only; we query public APIs for stats display.
3. How We Use Your Information
3.1 Service Delivery
- Enable incident submission (YouTube link), review, and community consensus voting
- Display your reputation score, voting history, and leaderboard rank
- Optionally link iRacing/ACC accounts and display stats
- Provide account management (OAuth login, profile settings, data deletion)
- Generate public verdicts based on community consensus (80% threshold)
3.2 Community Moderation
- Detect and prevent abuse (spam, fraudulent incidents, vote manipulation)
- Enforce code of conduct and incident review standards
- Flag or remove inappropriate content
3.3 Improvement & Analytics
- Understand how incidents are reviewed (voting patterns, consensus thresholds)
- Improve UX (A/B testing, performance monitoring)
- Develop new features (e.g., AI-assisted incident tagging)
- Anonymized incident trends reporting
3.4 Legal & Safety
- Comply with legal obligations and court orders
- Investigate fraud, security breaches, or Terms of Service violations
- Protect against liability
4. Data Sharing & Disclosure
4.1 Public Information
Incident Submissions & Verdicts are PUBLIC by default:
- Submitted YouTube URLs, incident details, and consensus votes are visible to all users
- Your display name/steward ID is attributed to your reviews (reputation/leaderboard)
- Game/track/car names are disclosed
User can opt for Anonymous Reviewing (name hidden) when submitting or voting.
4.2 Third Parties
We do NOT sell personal data. We share information only:
- Service Providers: Hosting (Vercel), database (Supabase), analytics (Posthog), auth (Discord/Google OAuth)
- Legal Requests: Law enforcement, court orders, regulatory compliance
- Safety: If you pose imminent risk to others
4.3 Data Retention
- Active Users: Account data (Discord ID, Google ID, display name, bio) retained while account active + 90 days post-deletion
- Incidents: Submitted incidents and verdicts retained indefinitely (public record); user can request deletion of specific incidents (removed within 30 days but voting history retained for consensus)
- Voting Data: Votes retained indefinitely; anonymized after 6 months for trend analysis
- Logs: Server/access logs deleted after 30 days
5. User Rights & Control
5.1 Access & Portability
- Request your personal data in machine-readable format (email contact.stew.io@gmail.com)
- Response: 14 days
5.2 Correction & Deletion
- Update profile, display name, bio, country anytime in settings
- Request account deletion (anonymizes all past reviews, retains public incident summaries)
- Deletion irreversible after 30-day grace period
5.3 Opt-Outs
- Email notifications: Disable in settings
- Analytics tracking: Opt-out in privacy settings (essential analytics continue for legal compliance)
- Cookies: Browser settings (may impair Service functionality)
6. Data Security
- Encryption: OAuth tokens hashed, data in transit (HTTPS/TLS)
- Storage: Secure cloud infrastructure (Supabase, SOC 2 compliant)
- Access: Role-based; only admins access personally identifiable info
- Incident Response: Breach notification within 72 hours if data exposed
We are NOT liable for third-party breaches (Discord, Google, YouTube, Supabase).
7. Children & COPPA
Stew.io is not intended for users under 13 (COPPA compliance). We do not knowingly collect data from children. If discovered, data is deleted immediately.
8. International & GDPR
8.1 EU/UK Users (GDPR)
- Legal Basis: Legitimate interest (platform operation), user consent (account creation)
- Data Controller: Stew.io, [registered address TBD]
- Rights: Access, rectification, erasure, portability, object to processing
- DPA: Contact contact.stew.io@gmail.com
- Transfers: Data may transfer outside EU for hosting/processing (standard contractual clauses)
8.2 California (CCPA)
- Right to know, delete, opt-out of sale (we don't sell)
- Shine the Light Act: Third-party sharing list on request
9. Cookies & Tracking
- Essential Cookies: Authentication (Supabase JWT), session state
- Analytics Cookies: Posthog tracks anonymized usage patterns (no PII)
- User Opt-Out: Disable analytics in settings; essential cookies cannot be disabled (required for login)
10. Changes to This Policy
We may update this policy as the platform evolves. Material changes notified via email + in-app banner. Continued use = acceptance.
11. Contact Us
Questions or Data Requests:
- Email: contact.stew.io@gmail.com or contact.stew.io@gmail.com
- Response Time: 5-7 business days
- Data Subject Request (GDPR): contact.stew.io@gmail.com (reference "Data Request")
Address: [Company Address TBD]
DPO: [Data Protection Officer - TBD if GDPR applies]
12. Related Documents
- Terms of Service: /terms (separate policy)
- Code of Conduct: /conduct (community guidelines, reporting abuse)
End of Privacy Policy
Have questions about our privacy practices?
Contact Privacy Team