Privacy
Last updated: 22 September 2026
The short version: the editor sends us nothing about your maps, and apart from counting visits, nothing at all unless you press something that says it will. We keep what an account needs and what a bill needs, and not the contents of your maps or what you typed. The only things counted are visits to our websites and downloads of the game graphics, without cookies (section 1). There is no advertising and nothing that follows you between sites.
1. If you only use the editor
Opening maps, editing them and saving them happens entirely in your browser or on your own machine. Your map files are not uploaded, and we have no way to see them. You can use scmJS forever without us learning who you are.
The pages on this site make two requests to GitHub on your behalf — the release version beside the download buttons, and the plugin list on the plugins page. Those go to GitHub, not to us, and GitHub sees your IP address as it would for any page on their site.
This site, the documentation, and the editor at editor.scmjs.dev and nightly.editor.scmjs.dev count visits with Cloudflare Web Analytics. It records the page, where you came from, your country, browser and device type, and how fast the page loaded. It sets no cookies, keeps no identifier for you, and learns nothing about your maps. The desktop app and copies of the editor hosted by other people do not send it. When the editor downloads the StarCraft graphics through our forwarder, we count that download too, with your country and which of our sites asked for it, and nothing else.
The editor at editor.scmjs.dev is served through Cloudflare, which sees your IP address and the page you asked for, as any web host does. When someone pastes a link to a stored map or a shared map somewhere that shows previews (Discord, Slack, a forum), the card shows that map's name, who shared it, its size and players, and its picture, to anyone who can see the link. Making the card stores nothing and does not count as opening the map.
When the editor saves a map to scmjs.dev, it also sends a picture of the map, which is kept with that revision and counts toward your storage. It is what the map's card is drawn with. If you embed a card somewhere (a forum post, a README, a website), anyone who sees it sees the same things a link's card shows. The card's own address opens nothing; only the link you put around it does.
2. What is kept in your browser
Under Preferences ▸ Browser storage in the editor, listed under the scmjs.dev plugin:
- your sign-in session, if you have signed in;
- a random device identifier, which is what the one free trial per browser is counted against — it is not linked to you and is not an advertising identifier;
- your AI options and the on/off ticks.
Clearing your browser storage removes all of it. The account page on this site also sets one cookie, described in section 6.
3. What we store on the server
Only once you have started a trial or signed in.
- Your account. The identifier your sign-in provider uses for you, your display name there, and your email address where the provider says it is verified (Discord and Google do; Battle.net sends none). We use the email only to tell two sign-ins apart as the same person, and to reach you about your account. We do not email you otherwise.
- A ledger. One row per charge and per top-up: when, how much, and which feature it was for. This is what the activity list on your account page shows you, and it is what a bill is made of.
- Per-request diagnostics. For each AI request: the feature, the model, how long it took, how many tokens it used, what it cost, and whether it failed. Not the content — not your prompt, not your map, not the answer.
- Your IP address, recorded against a trial when one starts and against a sign-in when one happens. This is the only thing that stops the free credit being collected over and over from one machine, and it is used for nothing else.
- Maps you chose to upload, with their revisions, notes and thumbnails, if you use map storage. Maps are stored in Google Cloud Storage in a private bucket. They are served back only to you, unless you make a link to one: anyone who has a map's link can download that map, without signing in, until you remove the link or the map. The server counts how many times each link is opened. Uploading and making a link are always something you press a button to do.
- Maps you share, while they are shared. Sharing a map for others to edit sends a copy of it to the server, and every change anyone in it makes goes through the server to the others. The copy, the changes, the names people type to join and the messages they write in the map's chat are held in the server's memory only. They are never written to storage, and they are gone when sharing ends: when the person who shared the map stops, half an hour after the last person leaves, or when the server restarts. People who join from a link need no account. The server's log notes that your account opened a shared map, and when.
- Maps you keep open. If you choose to keep a shared map open (for a day, a week, a month, or until you end it), it is stored as one of your maps: the file, the changes made to it since its last saved copy, the name of whoever made the last change, and the names of the people who changed it since its last revision, which go into that revision's note. If the server restarts while people are in the map, the names they typed to join are stored until the map is opened again, so their editors can reconnect. The chat is still held in memory only and is gone once everyone has left. When sharing ends, the changes and names go; the map and its revisions stay with your other maps.
4. What we send to the model provider
An AI request is answered by Anthropic, through their API. To answer it we send what the request needs: what you typed, and the parts of the open map that are relevant — which for something like a review or the assistant may be most of the map's contents, and may include a screenshot of the map if you ticked the picture box.
Anthropic processes this under their commercial API terms: API inputs and outputs are not used to train their models. Part of the request — the fixed instructions and reference tables, which are the same for everybody — is held in their prompt cache for up to an hour so that repeat requests cost less; the part of the request that is your map is what makes a request unique and is not shared with anyone.
Our own server does not keep the content of requests. It can be told to keep them for one named account, which we do only when someone asks us to help debug their own requests, and only for as long as that takes.
5. Payment
Credit purchases go through Stripe on Stripe's own page. Your card details are never sent to us and we could not store them if we wanted to. We keep the reference Stripe gives us for the purchase, so a payment can be matched to a top-up, and Stripe keeps whatever their own privacy policy says they do.
6. Cookies
One, on the account page on this site: it holds your sign-in session.
It is HttpOnly, SameSite=Lax and
Secure, lasts 60 days without use, and exists only so
that the page knows who you are. There are no analytics or advertising
cookies (the visit counting above uses none), so there is nothing to
consent to and no banner.
7. How long it is kept
- Your account and ledger — until you delete the account. Some ledger rows may be kept after that, with the account no longer identifiable, where tax or accounting rules require a record of a payment.
- Per-request diagnostics — kept while the account exists; they carry no content.
- Trial and sign-up IP records — kept for the period the anti-abuse rules look back over, and cleared after.
- Maps — until you delete them or the account.
- Shared maps — only while they are shared; nothing of them is kept afterwards.
- Maps kept open — the map and its revisions like any of your maps; the changes and names that go with keeping it open until sharing ends.
8. Deleting everything
The account page has a delete button. It removes your account, your identities, your balance, your ledger and every map you stored. It is immediate and it is not reversible — including any credit you have left, so spend or ask for a refund of that first.
You can also ask us for a copy of what we hold, or ask us to correct it, at support@scmjs.dev. We will answer within 30 days. These are rights you have under Canada's PIPEDA and Alberta's Personal Information Protection Act, and under the GDPR if you are in the UK or the EU.
9. Children
The service is not intended for children under 13, and the sign-in providers have their own minimum ages. We do not knowingly keep an account for a child under 13; tell us and we will delete it.
10. Who to ask
scmjs.dev is run by Rebecca Sterling in Alberta, Canada, who is the person accountable for the personal information described here. Anything about your data goes to support@scmjs.dev, and a postal address is available on request.
If this policy changes, the date at the top changes with it. A change that affects what we do with data we already hold will be said plainly here rather than folded in quietly.