Privacy Policy

Last updated: September 30, 2026

This Policy explains what personal data STRATKA processes — a free online football manager played in the browser at stratka.app, as a Telegram Mini App with the bot @StratkaGameBot, and as an installable app (PWA) — why, on what legal basis, who we share it with, how long we keep it, and what your rights are. «STRATKA», «we» and «us» mean the service and the team that runs it and decides how and why data is processed.

This Policy is available in eight languages. If the versions differ, the English version prevails.

1. Contacts

2. What data we process

2.1. Account and sign-in

  • Your email and a technical Firebase identifier (UID). You sign in with Google, with email and password, or with Telegram. Google Firebase stores the password; we never receive it;
  • with Google sign-in — the Google profile data Firebase passes on (email, name, avatar);
  • with Telegram sign-in or when you open the Mini App — your Telegram ID, username, first and last name, profile photo link and Telegram interface language.

2.2. Profile

Manager first name and surname, country and city, bio, avatar, signature, name colour, settings (language, theme, privacy, ignore list) and date of birth. We ask for your date of birth before you create a club, to check that you are 16 or older; if you are under 16, the date you entered is not stored.

2.3. Game data

Your club and its identity, squad, tactics, matches and replays, transfers, training, staff, achievements, rankings, in-game money and butcer balance, friends, clan and other in-game activity.

2.4. Messages and public content

Global chat, private messages, clan chat, the forum (including the edit history visible to moderators), wall posts, news comments, likes and mentions.

2.5. Reports and moderation

Reports you file or that are filed about your content (category, comment and a snapshot of the content as evidence), appeals, moderator decisions, warnings, chat restrictions and bans with their reasons, and your trust level.

2.6. Technical and security data

  • IP addresses you use to access your account (with the time first and last seen) — for security, rate limiting, detecting multi-accounting and abuse, and blocking IPs or networks;
  • a shortened IP address (the network) when a club is created — to limit the number of clubs per network;
  • browser and device type (user agent) and technical request logs (time, address, response code) — for diagnostics and security;
  • for actions by moderators and administrators — an audit log with IP address and user agent.

2.7. Notifications

In-game notifications. If you turn on push notifications — your browser's subscription address, its encryption keys and user agent. If you have opened a chat with our bot, we may send you referral programme updates there.

2.8. Referral programme

Whose invite code you used, whom you invited, whether a referral counts (including a check whether both accounts used the same IP address), titles and rewards.

2.9. Marta, the help assistant

Questions you ask the help assistant are processed to find an answer in the help centre. Questions it could not answer are kept for 30 days without a user ID or IP address (emails, links and long numbers are stripped from the text), only to improve the help articles.

2.10. Analytics

Only with your consent — see section 5.

2.11. Correspondence

When you write to us, we receive your address and the content of your message.

We do not sell personal data, do not show ads and do not share data with advertising networks. STRATKA has no real-money purchases.

3. Purposes and legal bases

Providing the game: account, club, matches, communication, in-game notifications
Data2.1–2.4, 2.7
Legal basis (GDPR Art. 6)performance of a contract — the Terms of Use (1)(b)
Security, fair play, fighting multi-accounting, bots and spam, rate limits, IP bans
Data2.5, 2.6, 2.8
Legal basis (GDPR Art. 6)legitimate interests (1)(f)
Moderation, handling reports and illegal content, answering lawful requests from authorities
Data2.4, 2.5
Legal basis (GDPR Art. 6)legitimate interests; legal obligation where one applies (1)(c)
Checking the 16+ age requirement
Datadate of birth
Legal basis (GDPR Art. 6)legitimate interest in protecting children and legal requirements
Referral programme: counting referrals and rewards
Data2.8
Legal basis (GDPR Art. 6)performance of a contract; legitimate interests (abuse checks)
Push notifications
Data2.7
Legal basis (GDPR Art. 6)consent (browser permission), can be withdrawn
Visit statistics, Vercel Analytics and Speed Insights
Datasection 5
Legal basis (GDPR Art. 6)consent (1)(a)
Marketing attribution: referral cookie, UTM tags, first visit
Datasection 6
Legal basis (GDPR Art. 6)consent
Error reports (Sentry), improving the help centre
Datatechnical data, 2.9
Legal basis (GDPR Art. 6)legitimate interests
Support and correspondence
Data2.11
Legal basis (GDPR Art. 6)performance of a contract; legitimate interests

Legitimate interests. Our interest is a game that works, is fair and safe for players, and keeps accounts protected. We collect as little as we can, encrypt the most sensitive data, limit how long we keep it, and people — not algorithms — decide on sanctions. You can object to this processing by writing to privacy@stratka.app; we will look at your particular situation.

4. Who sees your data

Other players see your public profile, club, results and public posts. Private messages are visible only to the people in the conversation; moderators may see a message that has been reported (a snapshot is kept with the report). Team access to data is limited by role.

5. Analytics and error reports

  • Our own visit statistics — only with your «Analytics» consent. We receive the page address, the site you came from, device type, screen width, language and country (as detected by our hosting). We do not store your IP address or user agent for statistics: together with a random daily «salt» that is deleted the next day they produce a hash, so a visitor cannot be followed from one day to the next. If you are signed in, the pageview is linked to your account. Detailed records are deleted after 90 days; only daily totals remain.
  • Vercel Web Analytics and Speed Insights — only with your «Analytics» consent: anonymised visit and page-performance statistics.
  • Sentry — error reports from the website (technical crash data; emails, phone numbers and tokens are masked before sending, session recording is off).

We honour Global Privacy Control and Do Not Track signals: optional categories stay off.

6. Cookies and browser storage

Necessary items are always on. Analytics and marketing are switched on only with your consent. You can change your choice at any time via the «Cookie settings» link at the bottom of every page or in Settings → Privacy. When you withdraw consent, the related entries are deleted.

stratka.theme, stratka.palette, stratka.locale, stratka.nav (cookies)
Categorynecessary
Purposetheme, palette, language, menu state
Duration1 year
stratka.session (cookie)
Categorynecessary
Purposehint that you are signed in (no token)
Duration30 days
Firebase (IndexedDB / localStorage)
Categorynecessary
Purposesign-in session
Durationuntil you sign out
localStorage, IndexedDB, app cache
Categorynecessary
Purposematch replays, tips, drafts, PWA offline cache
Durationuntil cleared
stratka.ref.session (sessionStorage)
Categorynecessary
Purposeinvite code for the sign-up you are completing
Durationuntil the tab closes
stratka.consent (cookie)
Categorynecessary
Purposeyour cookie choice
Duration12 months
stratka.visit (sessionStorage), Vercel Analytics, Speed Insights
Categoryanalytics
Purposecounting visits and performance
Durationtab session
stratka.ref (cookie; localStorage in Telegram)
Categorymarketing
Purposethe referral link you arrived with
Duration30 days
stratka.ft (localStorage), UTM tags and ad-click type
Categorymarketing
Purposewhere you first came from
Duration90 days

If you accepted marketing and then signed up, the source of your first visit (campaign, referring site, landing page, device, country, language) is stored with your account.

7. Service providers

We use providers that process data on our behalf and only to provide their services:

Google Firebase
Purposeauthentication
LocationUSA / global
Fly.io
Purposegame server, database, background jobs
LocationFrankfurt (EU)
Upstash Redis (via Fly.io)
Purposecache, rate limits, real-time event delivery
LocationEU
Tigris (via Fly.io)
Purposeavatars and logos, replay archives, encrypted backups
LocationUSA / global
Vercel
Purposewebsite hosting and CDN; Vercel Analytics and Speed Insights (with consent)
LocationUSA / global
Cloudflare
PurposeDNS, forwarding of @stratka.app email, proxy and protection for the game API
LocationUSA / global
Sentry
Purposewebsite error reports
LocationUSA
Browser push services: Google FCM, Mozilla, Apple, Microsoft
Purposedelivering push notifications
LocationUSA / global

Telegram and Google (when you sign in with them) also process data as independent controllers under their own terms — see section 15.

8. Transfers outside the EU

Some providers process data in the USA or other countries outside the EEA. These transfers rely on the EU–US Data Privacy Framework (for certified providers) and/or the European Commission's Standard Contractual Clauses included in those providers' data processing terms.

9. How we protect data

  • connections to the website and the API use TLS (HTTPS) only;
  • private messages and chats, emails, Telegram profile data, push subscription keys, report texts, moderator notes, and IP addresses and user agents in the audit log are stored encrypted in the database (AES-256-GCM); the keys are kept separately from the database;
  • database backups are encrypted before they reach storage;
  • the admin panel requires two-factor authentication, and roles get only the access they need;
  • rate limits and protection against automated attacks.

No protection is absolute. This is not end-to-end encryption: the game server can access the data in order to show it to you.

10. Retention

Account, profile, game data, messages, referral data
Retentionwhile the account exists
After you request account deletion
Retention30 days to change your mind, then deletion or anonymisation; public content and match history may remain as «deleted manager»
Database backups
Retentionup to 21 days; infrastructure snapshots — 5 days
Reports and evidence snapshots
Retention90 days after review (longer only if authorities need it in an illegal-content case)
Unanswered questions to Marta
Retention30 days
Detailed analytics records
Retention90 days; the daily salt — 1 day
Network IP at club creation
Retention7 days
Notifications
Retentionread — 30 days, unread — 180 days
IP and security logs, audit log
RetentionIP log — 12 months after the last sign-in from an address; IP and user agent in the audit log — 12 months, audit entries themselves — 24 months. The account's IP log is deleted with the account
Push subscription
Retentionuntil you turn notifications off or the subscription becomes invalid
Correspondence
Retentionas long as needed to handle your request

11. Your rights

You have the right to access your data, have it corrected or erased, restrict or object to its processing, receive it in a portable format, and withdraw consent at any time (this does not affect processing before the withdrawal).

How: in Settings → Privacy (data export, account deletion, cookie choice) or by writing to privacy@stratka.app from your account's email address. We reply within one month; for complex requests this may be extended by two more months, and we will tell you if so.

You can also complain to a supervisory authority: in the EU, the data protection authority of your country (list); in the UK, the ICO (ico.org.uk); in Ukraine, the Ukrainian Parliament Commissioner for Human Rights (ombudsman.gov.ua).

12. Children

STRATKA is for people aged 16 and over. We do not knowingly collect data from younger children. If we learn that an account belongs to someone under 16, access is suspended and the account is closed. If the date was entered by mistake, write to support@stratka.app.

13. Automated checks

We make no decisions that have legal or similarly significant effects on you based solely on automated processing (GDPR Art. 22). Automation only assists:

  • multi-account signals — shared IP addresses and other indicators add up to a score with an explanation for every point; they never block anyone on their own, a person decides;
  • trust levels — new accounts (younger than 3 days or with fewer than 5 official matches) post on the forum after moderator review, without links and with a pause between posts; the level rises automatically with account age and activity;
  • word filter — names, club names, signatures and other profile fields with offensive or reserved words (such as «admin») are not accepted;
  • activity limits and link filter — automatic limits on sending private messages and wall posts (including an on-site activity budget) and on suspicious links in messages, to hold back spam and scams.

14. Data breaches

If a breach puts you at risk, we will notify the supervisory authority and, where the law requires, you — within the time limits set by law.

15. Signing in with Google and Telegram

With Google sign-in we receive a verified email, name and avatar from Firebase — never your password. With Telegram sign-in or in the Mini App we receive the data listed in 2.1, signed by Telegram, and we verify that signature. Their own processing is governed by the Google Privacy Policy and the Telegram Privacy Policy.

16. Changes to this Policy

We may update this Policy. We will announce material changes in the game in advance. The date at the top shows the current version. See also the Terms of Use and the Community Rules.

Privacy Policy · STRATKA