Stratorama
Privacy policy
Last updated: 9 October 2026
This policy explains what personal data Stratorama processes when you use the service, why, on what legal basis, who has access to it, and what rights you have under the GDPR.
Data controller
The data controller is JULIEN GUEDON CONSEIL, registered at 24 rue René Viviani, 44200 Nantes, France. Full company information is in the Legal notice.
For any privacy-related question or to exercise your rights, contact contact@stratorama.app.
What we collect, and why
Account data
- Email address
- Password (stored hashed - bcrypt - on our own servers; we never see it in plain text)
Purpose: create your account and authenticate you. Legal basis: performance of the contract (Art 6(1)(b) GDPR). Providing this data is required - without it, we can't create your account.
Your language, English or French, is stored with your account too. A new account takes the language of the sign-up page, or, for a sign-up with Google, GitHub or Discord, the language remembered by the browser you sign up in (see Cookies and local storage below), else that browser's preferred language if it is English or French. An account that has none takes the language on screen the next time it is used. After that, your language changes when you pick one with the language switch while signed in. Wherever you sign in, the app is shown in your language, and the emails we send you are written in it. So are the invitations you send, and each one stores the language it was sent in. Stripe receives it if you pay, or have paid, for a home (see below). Purpose: show you the service, and write to you, in your language. Legal basis: performance of the contract (Art 6(1)(b) GDPR).
Sign in with Google, GitHub or Discord (optional)
If you choose to sign in with one of these providers, it shares with us:
- Your account identifier at that provider
- Your email and name
Purpose: authenticate you without a password. Legal basis: performance of the contract. Alternative: use email + password sign-up instead.
Service content
- Floor plans (stages/floors, rooms, walls, doors, windows, lights, outlets, shutters - with positions and labels)
- User settings
- Bindings between your floor elements and your Home Assistant entities (entity identifiers)
- A long-lived token (
agent_token) issued when you pair the Stratorama Agent app in your Home Assistant
Purpose: deliver the service - store your plans and let you control your linked devices through your own Home Assistant. Legal basis: performance of the contract.
We do not store your Home Assistant credentials or the live state of your devices. Only the states of the devices on your floor plan - their readings, your doors' sensors and your device library included - reach our tunnel from version 1.4.0 of the Home Assistant app, plus the single value someone with edit access asks for in the device picker (below): everything else stays in your Home Assistant, who is home and where each phone is, your cameras, the value of every sensor you did not place or add to your device library. An older version still sends more (every light, switch, cover and sensor from 1.3.0, every state before that), and our tunnel drops what is not on your plan the moment it arrives, before any browser sees it. What crosses does so in memory only, on its way from the Home Assistant app to your browsers and wall tablets: nothing is written to disk on our side, and each browser or tablet is sent only the entities bound to the parts of the floor plan it may see, and only the names you gave those devices. Anyone with edit access to the home (you, and anyone you give it to) is sent more, on purpose: when they open the device picker, the names, kinds and units of your other lights, switches, covers and sensors, with no value, because the picker's job is to show what is not on the plan yet - and the value of one of them when they ask for it; and the devices of your device library not placed on any floor, with their names and states. That list, and those values, go to their browser and are kept nowhere. The Home Assistant app itself relays nothing but the calls Stratorama makes - reading entity states, and light, switch and cover service calls - and refuses any other request. From version 1.3.0 it also removes, before a state leaves your home, the tokens Home Assistant writes into some states (an access token, the token of a picture or stream link, including such a link copied into a sensor), and our tunnel removes them as each state arrives, whichever version sent it.
Shared homes
A home can be shared with other people and with wall tablets. When it is, we store:
- Who belongs to which home, and the level of access each person or tablet has been given
- The email address an invitation was sent to, before that person has accepted it - even if they never do, and even if they have no Stratorama account
- For each wall tablet: its name, a fingerprint of the long-lived credential that keeps it signed in to the home without belonging to a person (never the credential itself), and when it was paired, last seen and disconnected
- While a wall tablet is being paired: a fingerprint of its one-time pairing code, never the code itself
Purpose: let several people use one home and let its owner decide who sees what. Legal basis: performance of the contract, and legitimate interest (Art 6(1)(f) GDPR) for the invited address, which we hold on behalf of the person inviting you.
If somebody invites you to their home, they can see your name and the email address they invited, and they decide what you may see and control inside that home. They cannot see anything in your own home.
Device actions
We record an entry each time a device we classify as consequential is switched - today that means electro-valves, because opening one starts water running. Each entry holds who did it (a person or a named wall tablet), which device, and when. This applies to every home, shared or not.
Purpose: so a home's owner can see who acted on it. Without that record every action in a shared home is anonymous, which is a worse outcome for everyone in it. Legal basis: legitimate interest (Art 6(1)(f) GDPR).
Ordinary actions - a light, a shutter - are not recorded. The list of consequential types is ours and is the same for every home; it is not something an owner configures. Only the home's owner can read these entries.
Technical logs
- IP address, request paths and timestamps, with the headers your browser sends (its user-agent, its preferred language, the page you came from; never its cookies), in our web server's HTTPS access logs at our hosting provider
- Authentication sessions (an identifier in an httpOnly cookie in your browser, matched against our database; the session row records the IP address and user-agent it was created from)
- Failed authentication attempts (anti-bruteforce, fail2ban)
- Crash reports from the app in your browser: when it hits an unexpected error, it sends us the error message, the code location (a stack trace), the page path and the build identifier so that we can fix it - never your account, your email or your plan data
Purpose: keep the service running, prevent abuse, investigate incidents. Legal basis: legitimate interest (Art 6(1)(f) GDPR) - operating a secure service.
Service emails
We send transactional emails via Resend, such as account confirmation, password reset, and the invitation somebody receives when a home's owner invites them into it. We do not send marketing emails.
Billing data (Household subscription, optional)
If you subscribe a home to Household, payment is handled by Stripe. Your card number goes to Stripe directly and never reaches our servers. Stripe collects your name, email, billing address and payment details; on our side we store the subscription's status, its renewal date, whether it is set to stop at the end of the period, whether it is a sale or a courtesy we granted by hand (with a short internal note saying why), Stripe's identifiers for your customer record and subscription, which account is paying and which home is being paid for, and - when a subscription has to be cancelled because the person paying for it deleted their account - the fact that it does and when we did it. No card number and no billing address ever reach us.
If somebody else pays for your home. A home's owner may let another person pay for its subscription. Each side is then shown what it takes to know where the arrangement stands, and no more. The owner sees the person's display name, the renewal or end date, and whether the payment is failing or has stopped - a home whose Household is about to lapse is the owner's business. The person paying sees the name of the home they pay for, the display name of its owner, and the same dates. Neither sees the other's email address, and paying for a home gives no access to it, to anything in it, or to the other's account.
Those last two - the home's name and its owner's name - are shown to whoever opens the payment link, before they have an account and whether or not they ever pay. A page that asks somebody for a card and cannot say whose home it is for would be indistinguishable from a fraudulent one, so this is the disclosure that makes the decision possible rather than an extra. Legal basis: for the person paying, performance of the contract, and before that a step taken at their request prior to entering into it (Art 6(1)(b) GDPR). For the home's owner, performance of the contract too: they asked for the arrangement, and cannot be given the service without being told whether it is paid for. Neither disclosure is something either of you could decline separately, because it is the arrangement itself.
The payment link itself. When an owner asks somebody else to pay, we store a record of that request: which home it is for, which account created it, when it expires, when it was last opened, when it was cancelled or paid, and which account claimed it. We do not store the link we gave the owner - only a one-way fingerprint of it, which is why we cannot show a link a second time. We never store who the owner sent it to; we have no way of knowing. Legal basis: performance of the contract for both of you, and a step taken at the request of whoever opens it before entering into one (Art 6(1)(b) GDPR).
Purpose: provide the paid tier, issue invoices, handle renewals and cancellation. Legal basis: performance of the contract, and our legal obligations for invoicing and accounting records.
How long we keep your data
- Account and content: as long as your account is active. After 3 years of inactivity (no sign-in), the account and its content are deleted or anonymized. If you share a home with somebody, read Deleting your account when you share a home below - the home itself may outlive your account.
- Why you deleted your account: if you answer the question we ask right after a deletion, your answer is kept with that account's email address, name and identifier for 12 months, then deleted automatically. If you don't answer, those details are deleted once the hour to answer is over. Either way, a daily database backup made while any of this was still stored keeps a copy until that backup expires (30 days on the server, one year for the encrypted off-site copy; see Security below).
- HA pairing token: until you disconnect Home Assistant (the
user_agentsrow is deleted on disconnect). - Server access logs: up to 12 months (the maximum recommended by French law for connection logs, LCEN Art 6-II).
- Auth failure logs: rolling window of about one week (fail2ban defaults).
- Device actions: kept for 90 days, then deleted automatically.
- Invitations: the invited email address is kept until the invitation is accepted, declined or cancelled. Decline or cancel one and the address goes with it.
- Billing records: subscription records and the invoices Stripe issues are kept 10 years, the retention French commercial law requires for accounting documents - including after the subscription ends or the account is deleted. The link to the account that was paying is not kept that long: when you delete your account, the record stops naming you the same day. What survives is the subscription itself and Stripe's own invoices, which Stripe keeps under its own obligations.
- Payment links: the record of a link an owner created is kept while it is live - 14 days at most - and then while it is history for the home, so an owner can see that one was used. It is not an accounting document and is not kept for 10 years; it goes with the home when the home goes. The link itself is never stored, only a fingerprint of it.
- Wall tablet credentials: until the tablet is disconnected or removed, or its home loses its owner. Its name, its access and the dates above stay with the home until the owner removes the tablet.
- Wall tablet pairing codes: deleted as soon as they are used or replaced, and otherwise within 15 minutes of being created (a code stops working after 10).
- A home nobody owns: kept for 30 days, then the home and everything in it is deleted. This happens when the last person who could inherit it is gone (see below). A paired wall tablet does not postpone this: it is a device, not a member who could ask us to keep anything, and it is disconnected as soon as the home becomes unowned, together with the home's link to Home Assistant.
Deleting your account when you share a home
Deleting your account always deletes you: your sign-in details, your sessions, your settings, and your membership of every home. What happens to a home you own depends on who else is in it.
- Somebody else is in it: the home passes to them, and its floor plans, devices and history stay. They become its owner. We do this so that a shared home does not disappear from under the people still living in it - but it does mean the content you created there remains, under their control rather than yours.
- Nobody else is in it: the home is marked as unowned and deleted 30 days later, together with its floor plans, its device library, its pairing token and its action history. The delay exists so that an account deleted by mistake can be recovered by contacting us inside those 30 days. A wall tablet does not inherit a home and does not keep one alive: a paired tablet is disconnected as soon as the home becomes unowned, and the home is deleted on the same timetable. The home's link to Home Assistant is cut immediately, not after 30 days, so nothing in the house is being read during the delay.
If you pay for a home's Household subscription - yours or somebody else's - deleting your account also cancels it: at the end of the period already paid, or straight away when there is no such period. The subscription record and the invoices Stripe issued stay, for the ten years accounting law requires (see Billing records above).
A wall tablet never inherits a home, and neither does an invitation nobody has accepted.
You can delete your account at any time from inside the app: open the settings menu (the three-dot menu, top right) and choose Account → Delete my account. If you cannot sign in for any reason, you can also email contact@stratorama.app to request deletion.
Right after the deletion, we ask why. Answering is optional. If you answer, we keep what you wrote and the day it arrived together with the email address, name and identifier of the account you deleted, for 12 months, and then delete it. We never share it, and we use it for nothing but understanding why you left. If you don't answer, those details are held only for the hour the question stays open, so that an answer can carry them, and deleted when the hour is over. Either way, a daily database backup made while any of this was still stored keeps a copy until that backup expires (30 days on the server, one year for the encrypted off-site copy; see Security below).
Legal basis: your consent, given by answering (Art 6(1)(a) GDPR). You can withdraw it at any time by emailing contact@stratorama.app, and we delete your answer.
Who has access to your data (processors)
To operate Stratorama, we rely on a small set of carefully chosen processors:
- OVHcloud SAS
- VPS hosting (our backend, PostgreSQL database, and the static site), in Gravelines, France. Daily database backups are stored on the same VPS, and a copy is sent to Scaleway (below).
- Scaleway SAS
- Off-site storage of the daily database backups, in Paris, France. Each backup is encrypted on our server before it is sent (file names included); Scaleway holds only ciphertext and never the key. Copies are kept for one year.
- Resend, Inc. (United States)
- Transactional email delivery (account confirmation, password reset, and invitations to a home). The recipient's address and the message content transit their systems. For an invitation that address may belong to somebody with no Stratorama account, and the message carries the home's name and the name of the person inviting them. Transfers are safeguarded by EU Standard Contractual Clauses in their data processing agreement.
- Stripe Payments Europe, Ltd. (Ireland, optional)
- Payment processing for the optional Household subscription. Your payment details are collected by Stripe directly and never transit our servers. We give Stripe the language of an account that pays or has paid, and each later change to it, for its payment and billing pages, its emails, receipts and invoices. Stripe may transfer data to Stripe, Inc. (United States) under the EU-US Data Privacy Framework and EU Standard Contractual Clauses.
- Let's Encrypt
- Automatic issuance of TLS certificates. We share with them only the public domain name - no personal data.
- Google LLC, GitHub, Inc., Discord Inc. (United States, optional)
- Only if you choose to sign in with one of them. Each provider's own privacy policy applies to that flow, and transfers are covered by the EU-US Data Privacy Framework or equivalent safeguards.
Your data is never sold or rented to anyone. We use no advertising trackers and no third-party analytics: the audience measurement described in the next section runs on our own server, and nobody else sees it.
Where your data is stored
All your core data (account, plans, HA bindings, tokens) stays in the European Union, on our own infrastructure at OVH in Gravelines, France.
Three flows can leave the EU: the optional social sign-in (Google, GitHub or Discord), transactional emails delivered through Resend (United States), and - if you subscribe to Household - the payment data Stripe processes. All are covered by the safeguards listed in the processors section above.
Security
- Traffic between your browser, our tunnel, and the Home Assistant app runs over HTTPS / TLS 1.2+.
- Passwords are hashed (bcrypt) on our servers - we never see or store the plain text.
- The Home Assistant app opens an outbound connection to our tunnel; we never connect inbound to your Home Assistant. You don't need to expose Home Assistant on the public Internet.
- Server access is key-only with fail2ban throttling repeated attempts.
- Daily backups of the database and TLS state, retained 30 days on the server, plus an encrypted off-site copy of each backup at Scaleway (Paris), retained one year.
Your rights
Under the GDPR, you have the right to:
- Access the data we hold about you
- Correct inaccurate data
- Request erasure ("right to be forgotten")
- Restrict processing
- Receive your data in a portable format - your home is downloadable as one JSON file at any time, from Account settings > Your data > Export as JSON (floors, rooms, walls, devices and their bindings, watering networks, device library; no credentials, no other member's details)
- Object to processing based on legitimate interest
- Withdraw your consent where processing relies on it (your answer to why you deleted your account), without affecting what was done before
- Lodge a complaint with the French data protection authority (CNIL) at cnil.fr/en/plaintes
To exercise any of these rights, email contact@stratorama.app. We aim to respond within 30 days.
Cookies and local storage
Stratorama does not use tracking cookies, advertising cookies, or third-party analytics. The only data your browser stores locally is:
- An authentication session cookie (httpOnly, first-party) - required to keep you signed in.
- An anonymous boolean display hint (
strat-authedinlocalStorage) that avoids a visual flash while the app boots. It contains no personal data. - Your language, in a first-party cookie readable by the page (
strat-locale, holding nothing butenorfr, renewed at each visit and kept one year after the last). It is written by the language switch and, while you are signed in, by your account's language. The app starts in that language, and a sign-up with Google, GitHub or Discord gives it to the new account. Our server also reads it to send you from an English public page to its French version when it says French, and never when it says English. Without it, the language your browser prefers decides, read from what it sends with each visit. - On a wall tablet only, two first-party cookies, neither of which identifies a person:
__Host-strato_panel(httpOnly), the credential that keeps the tablet paired to its home, and__Host-strato_mode, readable by the page, which only says this browser is a wall tablet so the app starts in the right mode. Both last 400 days and are renewed while the tablet is in use. - A few functional markers, none of which identifies you: a flag that a home's welcome message has been shown once (
stratorama.welcomed.<home id>), the Household price you picked on the landing before your account existed (stratorama.billing-intent, kept one hour at most and removed once used), a one-shot guard that lets the app reload itself once after an update (strat-chunk-reload, session only), and a mark that your sign-up has been counted once in our audience figures (strat-signup-tracked:<account id>). - For a moment after you leave a home, decline one or lose access to one, a one-shot note that lets the next page say so, carrying that home's name (
strat-notice, in this tab only, removed as soon as it is shown and ignored after two minutes). - Right after you delete your account, a one-time code that lets that tab send us why, if you choose to (
strat-deletion-feedback, in this tab only, removed when you send an answer or skip and ignored after one hour). The code itself contains nothing about you. - If you open a payment link for somebody's home while signed out, that link is kept in your browser (
stratorama.payment-offer) for 24 hours at most, for one reason: so that creating an account brings you back to the page you arrived at instead of losing it. It is removed as soon as you are signed in, as soon as the link is used, and if you never come back it expires by itself. It never leaves your browser - it is the same link you were sent.
All of these are strictly necessary or purely functional and don't require a consent banner under French and EU rules (CNIL, ePrivacy).
Audience measurement
We measure how the site is used with Umami, an open-source tool running on our own server in France (stats.stratorama.app). It sets no cookie and stores no identifier in your browser; your IP address is never stored - visits are grouped by a short-lived hash of connection data that rotates and cannot be turned back into an address. With each page view it records the address and title of the page (never the secret part of a link, such as a password-reset or payment-link token), the site that linked to it, and a few coarse facts about the visit: browser, operating system, type of device, screen size, the language your browser prefers, and the country, region and city estimated from your IP address at that moment. Besides page views, we count a handful of product steps (a button clicked on the landing, a sign-up sent, Home Assistant paired, a checkout started) with the shape of the step - which plan, which sign-in provider, and which language the site was shown in - and never who did it. Once you are in the editor, we also count that a room was drawn, a device was placed, a device was linked to a Home Assistant entity and a device was operated from the plan, together with the steps of the first-run checklist - carrying only the kind of device or the kind of action and the language the site was shown in, never its name, its entity id or which home it belongs to. Nothing leaves our server, nobody else has access, and the figures are not linked to your account.
Children
Stratorama is not designed for children under 16. We do not knowingly collect data from minors. If you are a parent or guardian and believe a minor has signed up, contact us and we'll delete the account.
Automated decision-making
We do not perform automated decision-making that produces legal effects on you, including profiling.
Changes to this policy
When this policy changes, we update the "Last updated" date at the top. For material changes that affect your rights, we'll also notify active users by email.
Contact
For any question about your personal data:
- Email: contact@stratorama.app
- Postal: JULIEN GUEDON CONSEIL, 24 rue René Viviani, 44200 Nantes, France