Skip to content
VR StrideS

Privacy Policy

This policy covers this website, the VR StrideS Demo for Meta Quest and the VR StrideS application for PC. They handle data differently, so each is covered separately.

Effective 2 September 2026

The website

What happens when you read vrstrides.com.

What this website collects

Nothing. This site sets no cookies and runs no analytics.

There is no tracking script, no advertising pixel, no embedded video player and no third-party font request. The typefaces are served from this domain rather than fetched from Google as you browse. Nothing is written to your device: no cookies, no local storage, no session storage. There are no accounts and no forms to fill in.

That is also why you were not asked to dismiss a cookie banner. There is nothing to consent to.

Hosting and server logs

A hosting provider serves these pages and keeps short-lived technical request logs. These typically record the requesting IP address, the page requested, a timestamp and a browser user-agent string. The logs help serve the site and diagnose faults. They are not used to build a profile of you or combined with anything from the application.

The Meta Quest demo

What happens when you install and run VR StrideS Demo on Meta Quest.

How the Quest demo authorises a launch

The Quest demo uses the internet at launch to verify that the app and headset are trusted before it releases the locomotion model key. It does not upload your movement data.

The demo uses headset and Touch controller motion while it is running to calculate movement locally on your headset. It does not transmit that motion, save recordings of it, or use it to identify you.

For each launch, the demo requests a one-time challenge from the VR StrideS service, checks entitlement through Meta, obtains a Meta device-and-application integrity token, and sends that token and the encrypted model’s non-secret salt to the service. The service asks Meta to verify the token and checks the app package, signing certificate, version, store-install status and device-integrity result before returning a model key.

The verified token contains a pseudonymous app-specific device identifier that Meta rotates periodically. The service uses a short hash of it only for an hourly abuse limit. The token, device identifier and model key are not saved to a user profile or cached by the demo. Cloudflare necessarily sees the requesting IP address while carrying the request, but VR StrideS does not write it to application logs.

The demo has no account system, analytics, advertising, movement telemetry or crash-report upload. It does not receive your Meta name, email address, friends list or account ID, and it never sells the launch-verification data.

Data kept on your headset

Any settings or diagnostic files created by the demo remain on your headset. The attestation token and model key are held only for the launch and are not written to local storage. Android removes the demo’s retained app data when you uninstall it.

Meta platform data

Meta independently handles your Meta account, store activity, entitlement and device-integrity service under Meta’s own privacy policy. Meta verifies the integrity token for VR StrideS, but the demo does not receive your Meta account information.

Children

The VR StrideS Demo is not directed at children. It does not request age or account-profile data; the same short-lived launch verification applies to every user.

The PC application

What happens when you install and run VR StrideS from Steam.

What is collected if you opt in

Movement data, and only while you are actually playing:

  • Head and controller poses and velocities: position, rotation, linear and angular velocity for the headset and both controllers, sampled around 90 times a second.
  • The movement output produced from them, and the Effort setting in force at the time.
  • A simplified headset model label, such as “Valve Index” or “Pico 4”. Never a serial number, hardware ID or anything that identifies your specific device.
  • Application version, build channel, and the start time of the session.
  • A pseudonymous install ID: a random identifier generated on your machine the first time the application runs.

If you enable crash reports, each report also includes a minidump and the last few lines of the application log.

What is never collected

  • Audio, video, screenshots or anything about what is on your screen.
  • Your Steam ID, account name, real name, email address or friends list.
  • File paths, the names of games you play, or anything else about your PC.
  • Hardware identifiers of any kind.
  • Payment information. Purchases happen entirely on Steam and I never see them.

Your IP address is not stored alongside your data. As with any request over the internet, it is necessarily visible to my hosting provider in transit. I would rather say that plainly than claim an impossibility.

What it is used for

I use this data for one purpose: to improve how VR StrideS detects movement. Seeing the range of real bodies, strides and hardware it has to work with helps me improve motion detection. The data is analysed in aggregate across users and used for nothing else.

It is never sold, never shared with advertisers or data brokers, never used to build a profile of you, and never used to make automated decisions about you.

Why I call this pseudonymous, not anonymous

Before anything leaves your PC, each session is given a random origin offset and a random yaw rotation, and absolute room height is dropped. A recording therefore cannot be tied back to the position, orientation or dimensions of the room you played in.

I still describe the result as pseudonymous rather than anonymous, deliberately. It carries no name and no Steam account, but it is linked to a persistent install ID, and the way a person moves is distinctive. Calling it fully anonymous would overstate what I can guarantee. Treating it as personal data instead means it keeps the full protection of the GDPR, which is the outcome I want for you.

Where it is stored, and for how long

Uploaded data is held in object storage operated by Cloudflare on my behalf, in a bucket pinned to EU jurisdiction. Your data is processed and stored in the European Union.

Movement data is retained for a maximum of 24 months and then deleted. Crash reports are kept only as long as needed to diagnose the fault, and no longer than 24 months.

Your rights, and how to use them

The lawful basis for this processing is your consent (UK and EU GDPR, Article 6(1)(a)). You can withdraw it at any time, and withdrawing is as easy as giving it. There is one toggle in Privacy & Data. Withdrawing stops all future collection immediately; it does not by itself delete what was already sent, which is what the erasure control is for.

Privacy & Data contains a Right to erasure control. It sends a deletion request keyed to your install ID and permanently erases all data tied to that install from my servers. It cannot be undone. The control lives in the application, which stays available in your Steam library even after you uninstall, so reinstalling restores your route to it.

You also have the right to request access to your data, its correction, restriction of processing, portability, and to object to processing. To exercise any of these, or if something here is unclear, email me and quote your install ID if you still have it, since without it I have no way to find data that is deliberately not linked to your identity.

If you believe I have handled your data improperly, you have the right to complain to a supervisory authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).

Steam and the playtest

VR StrideS is distributed through Steam. Your purchase, your Steam account, your playtest access and any Steam reviews or forum posts are handled by Valve under Valve’s own privacy policy, and Valve is an independent controller for them. I can confirm through Steam whether a licence exists so the application can activate; I do not receive your Steam ID for telemetry, and I never join the two together.

Children

VR StrideS is not directed at children. Consent to this processing should only be given by someone aged 16 or over, in line with Polish implementation of the GDPR. If you believe a child has enabled data sharing, contact me and I will erase the data.

Who is responsible

gnuj industries (Poland) is the data controller for the VR StrideS application and this website, and develops and publishes VR StrideS.

Controller
gnuj industries (Poland)
Contact
hello@vrstrides.com

Changes to this policy

If this policy changes materially, such as through a new category of data, a different purpose, or a longer retention period, the effective date above is updated and the change is announced in the application and on VR StrideS’s Discord. I will not quietly widen what is collected under consent you gave for something narrower.