Legal
Privacy Policy
This policy covers this website, the VR StrideS Demo for Meta Quest and the VR StrideS application for PC. They handle data differently, so each is covered separately.
Effective 2 September 2026
Part one
The website
What happens when you read vrstrides.com.
What this website collects
Nothing. This site sets no cookies and runs no analytics.
There is no tracking script, no advertising pixel, no embedded video player and no third-party font request. The typefaces are served from this domain rather than fetched from Google as you browse. Nothing is written to your device: no cookies, no local storage, no session storage. There are no accounts and no forms to fill in.
That is also why you were not asked to dismiss a cookie banner. There is nothing to consent to.
Hosting and server logs
A hosting provider serves these pages and keeps short-lived technical request logs. These typically record the requesting IP address, the page requested, a timestamp and a browser user-agent string. The logs help serve the site and diagnose faults. They are not used to build a profile of you or combined with anything from the application.
Links to other services
This site links to Steam, Discord, YouTube, X, Instagram, Facebook and Google Drive. Each is an independent service with its own privacy policy. Once you follow a link, that service handles your visit. Because nothing here is embedded from those services, none of them learn anything about you until you choose to click.
Part two
The Meta Quest demo
What happens when you install and run VR StrideS Demo on Meta Quest.
How the Quest demo authorises a launch
The Quest demo uses the internet at launch to verify that the app and headset are trusted before it releases the locomotion model key. It does not upload your movement data.
The demo uses headset and Touch controller motion while it is running to calculate movement locally on your headset. It does not transmit that motion, save recordings of it, or use it to identify you.
For each launch, the demo requests a one-time challenge from the VR StrideS service, checks entitlement through Meta, obtains a Meta device-and-application integrity token, and sends that token and the encrypted model’s non-secret salt to the service. The service asks Meta to verify the token and checks the app package, signing certificate, version, store-install status and device-integrity result before returning a model key.
The verified token contains a pseudonymous app-specific device identifier that Meta rotates periodically. The service uses a short hash of it only for an hourly abuse limit. The token, device identifier and model key are not saved to a user profile or cached by the demo. Cloudflare necessarily sees the requesting IP address while carrying the request, but VR StrideS does not write it to application logs.
The demo has no account system, analytics, advertising, movement telemetry or crash-report upload. It does not receive your Meta name, email address, friends list or account ID, and it never sells the launch-verification data.
Data kept on your headset
Any settings or diagnostic files created by the demo remain on your headset. The attestation token and model key are held only for the launch and are not written to local storage. Android removes the demo’s retained app data when you uninstall it.
Meta platform data
Meta independently handles your Meta account, store activity, entitlement and device-integrity service under Meta’s own privacy policy. Meta verifies the integrity token for VR StrideS, but the demo does not receive your Meta account information.
Children
The VR StrideS Demo is not directed at children. It does not request age or account-profile data; the same short-lived launch verification applies to every user.
Part three
The PC application
What happens when you install and run VR StrideS from Steam.
Nothing is collected unless you switch it on
Both data-sharing options ship switched off. Leave them off and the application sends me nothing at all.
On first run VR StrideS asks whether you want to share movement data and whether you want to send crash reports. Both are separate, both are opt-in, and both start off. Your choice is stored locally in your VR StrideS configuration folder and can be changed at any time from Privacy & Data inside the application.
Recording is gated at the point of writing, not at the point of sending. If consent is off, or you withdraw it, no session file is created on your disk in the first place.
What is collected if you opt in
Movement data, and only while you are actually playing:
- Head and controller poses and velocities: position, rotation, linear and angular velocity for the headset and both controllers, sampled around 90 times a second.
- The movement output produced from them, and the Effort setting in force at the time.
- A simplified headset model label, such as “Valve Index” or “Pico 4”. Never a serial number, hardware ID or anything that identifies your specific device.
- Application version, build channel, and the start time of the session.
- A pseudonymous install ID: a random identifier generated on your machine the first time the application runs.
If you enable crash reports, each report also includes a minidump and the last few lines of the application log.
What is never collected
- Audio, video, screenshots or anything about what is on your screen.
- Your Steam ID, account name, real name, email address or friends list.
- File paths, the names of games you play, or anything else about your PC.
- Hardware identifiers of any kind.
- Payment information. Purchases happen entirely on Steam and I never see them.
Your IP address is not stored alongside your data. As with any request over the internet, it is necessarily visible to my hosting provider in transit. I would rather say that plainly than claim an impossibility.
What it is used for
I use this data for one purpose: to improve how VR StrideS detects movement. Seeing the range of real bodies, strides and hardware it has to work with helps me improve motion detection. The data is analysed in aggregate across users and used for nothing else.
It is never sold, never shared with advertisers or data brokers, never used to build a profile of you, and never used to make automated decisions about you.
Why I call this pseudonymous, not anonymous
Before anything leaves your PC, each session is given a random origin offset and a random yaw rotation, and absolute room height is dropped. A recording therefore cannot be tied back to the position, orientation or dimensions of the room you played in.
I still describe the result as pseudonymous rather than anonymous, deliberately. It carries no name and no Steam account, but it is linked to a persistent install ID, and the way a person moves is distinctive. Calling it fully anonymous would overstate what I can guarantee. Treating it as personal data instead means it keeps the full protection of the GDPR, which is the outcome I want for you.
Where it is stored, and for how long
Uploaded data is held in object storage operated by Cloudflare on my behalf, in a bucket pinned to EU jurisdiction. Your data is processed and stored in the European Union.
Movement data is retained for a maximum of 24 months and then deleted. Crash reports are kept only as long as needed to diagnose the fault, and no longer than 24 months.
Your rights, and how to use them
The lawful basis for this processing is your consent (UK and EU GDPR, Article 6(1)(a)). You can withdraw it at any time, and withdrawing is as easy as giving it. There is one toggle in Privacy & Data. Withdrawing stops all future collection immediately; it does not by itself delete what was already sent, which is what the erasure control is for.
Privacy & Data contains a Right to erasure control. It sends a deletion request keyed to your install ID and permanently erases all data tied to that install from my servers. It cannot be undone. The control lives in the application, which stays available in your Steam library even after you uninstall, so reinstalling restores your route to it.
You also have the right to request access to your data, its correction, restriction of processing, portability, and to object to processing. To exercise any of these, or if something here is unclear, email me and quote your install ID if you still have it, since without it I have no way to find data that is deliberately not linked to your identity.
If you believe I have handled your data improperly, you have the right to complain to a supervisory authority. In Poland that is the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych).
Steam and the playtest
VR StrideS is distributed through Steam. Your purchase, your Steam account, your playtest access and any Steam reviews or forum posts are handled by Valve under Valve’s own privacy policy, and Valve is an independent controller for them. I can confirm through Steam whether a licence exists so the application can activate; I do not receive your Steam ID for telemetry, and I never join the two together.
Children
VR StrideS is not directed at children. Consent to this processing should only be given by someone aged 16 or over, in line with Polish implementation of the GDPR. If you believe a child has enabled data sharing, contact me and I will erase the data.
Who is responsible
gnuj industries (Poland) is the data controller for the VR StrideS application and this website, and develops and publishes VR StrideS.
- Controller
- gnuj industries (Poland)
- Contact
- hello@vrstrides.com
Changes to this policy
If this policy changes materially, such as through a new category of data, a different purpose, or a longer retention period, the effective date above is updated and the change is announced in the application and on VR StrideS’s Discord. I will not quietly widen what is collected under consent you gave for something narrower.