Privacy

Last updated: 22 September 2026

The short version: the editor sends us nothing about your maps, and apart from counting visits, nothing at all unless you press something that says it will. We keep what an account needs and what a bill needs, and not the contents of your maps or what you typed. The only things counted are visits to our websites and downloads of the game graphics, without cookies (section 1). There is no advertising and nothing that follows you between sites.

1. If you only use the editor

Opening maps, editing them and saving them happens entirely in your browser or on your own machine. Your map files are not uploaded, and we have no way to see them. You can use scmJS forever without us learning who you are.

The pages on this site make two requests to GitHub on your behalf — the release version beside the download buttons, and the plugin list on the plugins page. Those go to GitHub, not to us, and GitHub sees your IP address as it would for any page on their site.

This site, the documentation, and the editor at editor.scmjs.dev and nightly.editor.scmjs.dev count visits with Cloudflare Web Analytics. It records the page, where you came from, your country, browser and device type, and how fast the page loaded. It sets no cookies, keeps no identifier for you, and learns nothing about your maps. The desktop app and copies of the editor hosted by other people do not send it. When the editor downloads the StarCraft graphics through our forwarder, we count that download too, with your country and which of our sites asked for it, and nothing else.

The editor at editor.scmjs.dev is served through Cloudflare, which sees your IP address and the page you asked for, as any web host does. When someone pastes a link to a stored map or a shared map somewhere that shows previews (Discord, Slack, a forum), the card shows that map's name, who shared it, its size and players, and its picture, to anyone who can see the link. Making the card stores nothing and does not count as opening the map.

When the editor saves a map to scmjs.dev, it also sends a picture of the map, which is kept with that revision and counts toward your storage. It is what the map's card is drawn with. If you embed a card somewhere (a forum post, a README, a website), anyone who sees it sees the same things a link's card shows. The card's own address opens nothing; only the link you put around it does.

2. What is kept in your browser

Under Preferences ▸ Browser storage in the editor, listed under the scmjs.dev plugin:

Clearing your browser storage removes all of it. The account page on this site also sets one cookie, described in section 6.

3. What we store on the server

Only once you have started a trial or signed in.

4. What we send to the model provider

An AI request is answered by Anthropic, through their API. To answer it we send what the request needs: what you typed, and the parts of the open map that are relevant — which for something like a review or the assistant may be most of the map's contents, and may include a screenshot of the map if you ticked the picture box.

Anthropic processes this under their commercial API terms: API inputs and outputs are not used to train their models. Part of the request — the fixed instructions and reference tables, which are the same for everybody — is held in their prompt cache for up to an hour so that repeat requests cost less; the part of the request that is your map is what makes a request unique and is not shared with anyone.

Our own server does not keep the content of requests. It can be told to keep them for one named account, which we do only when someone asks us to help debug their own requests, and only for as long as that takes.

5. Payment

Credit purchases go through Stripe on Stripe's own page. Your card details are never sent to us and we could not store them if we wanted to. We keep the reference Stripe gives us for the purchase, so a payment can be matched to a top-up, and Stripe keeps whatever their own privacy policy says they do.

6. Cookies

One, on the account page on this site: it holds your sign-in session. It is HttpOnly, SameSite=Lax and Secure, lasts 60 days without use, and exists only so that the page knows who you are. There are no analytics or advertising cookies (the visit counting above uses none), so there is nothing to consent to and no banner.

7. How long it is kept

8. Deleting everything

The account page has a delete button. It removes your account, your identities, your balance, your ledger and every map you stored. It is immediate and it is not reversible — including any credit you have left, so spend or ask for a refund of that first.

You can also ask us for a copy of what we hold, or ask us to correct it, at support@scmjs.dev. We will answer within 30 days. These are rights you have under Canada's PIPEDA and Alberta's Personal Information Protection Act, and under the GDPR if you are in the UK or the EU.

9. Children

The service is not intended for children under 13, and the sign-in providers have their own minimum ages. We do not knowingly keep an account for a child under 13; tell us and we will delete it.

10. Who to ask

scmjs.dev is run by Rebecca Sterling in Alberta, Canada, who is the person accountable for the personal information described here. Anything about your data goes to support@scmjs.dev, and a postal address is available on request.

If this policy changes, the date at the top changes with it. A change that affects what we do with data we already hold will be said plainly here rather than folded in quietly.