1. Service and responsible parties
Stelah is published under the Stelah and Katzulabs names. The public website at stelah.katzulabs.com provides the browser interface. Each Stelah Windows host is operated by the person or organization controlling that PC (the “Host Operator”). The Host Operator controls who may have an account, the available games, Sparkly balances, developer access, session history, retention, and the physical host computer.
Katzulabs is responsible for this public website and the Stelah software. The Host Operator is responsible for information stored in their private host database. Privacy questions may be sent to support@katzulabs.com; questions about a particular private account should also be directed to its Host Operator.
2. Information Stelah collects
Account and login
- Email address, account status, creation time, and last-login time.
- A one-way password hash for a password account; the original password is not stored.
- For Google, Microsoft, or Facebook login: provider name, provider-specific account identifier, and email address.
Gameplay and library
- Selected game, session times, playtime, frame-rate choice, Sparkly use, favorites, preferences, key bindings, mobile layouts, and crash/end reasons.
- Public game metadata such as title, description, artwork, tags, rating, IGDB ID, and Steam App ID.
Streaming and device
- Live game video and audio, keyboard, mouse, controller, and touch input.
- Microphone audio only after the user grants browser permission and enables forwarding.
- IP address, browser/device information, connection diagnostics, and ordinary security logs processed by the Host Operator or Cloudflare.
3. Google and other identity-provider data
Stelah offers optional Google, Microsoft, and Facebook sign-in. The provider authenticates the user and returns an authorization code to the Stelah host. The host exchanges it server-to-server and verifies the signed identity response.
Google data requested
- openid: supplies a stable Google account identifier so the correct Stelah account can be recognized.
- email: supplies the user’s verified Google email address for account matching and display.
- profile: permits basic profile claims during authentication. Stelah uses the response for sign-in and persists only the provider name, provider-specific identifier, and email needed to link the account.
Stelah does not request or access Gmail, Google Drive, Google Photos, contacts, calendars, location history, payment information, or the user’s Google password. It does not post to a provider account.
How identity data is used
- Authenticate the user and prevent impersonation.
- Match the identity to an existing host account or, only when the Host Operator allows it, create a private host account for that email.
- Remember the provider-to-account link for future sign-ins and protect the host from unauthorized access.
Authorization codes, identity tokens, provider access tokens, state values, and nonces are processed only to complete sign-in. They are not used for advertising, sold, or retained as long-term account data. Stelah does not request offline access or store provider refresh tokens.
4. How all information is used
- Authenticate authorized users and secure the private Windows host.
- Display the host’s game library and account information.
- Launch and stream a selected game, transmit user input, and forward optional microphone audio.
- Calculate server-side Sparkly consumption and retain account preferences and session history.
- Diagnose crashes, connection failures, abuse, and security incidents.
- Maintain, troubleshoot, and improve Stelah’s reliability and compatibility.
Depending on applicable law, processing is necessary to provide the requested service, based on consent for optional permissions such as microphone access, and based on legitimate interests in operating and protecting the private service.
5. Live streaming and recordings
Game video and audio are transmitted from the host PC to the signed-in browser. Input and optional microphone audio travel from the browser to the host. Stelah processes this information for the active session and does not intentionally create recordings of game video, game audio, or microphone audio. A game, launcher, voice-chat service, operating system, or other host software may separately record or log activity under its own settings and policies.
6. Storage, cookies, and browser data
Account records, provider links, balances, preferences, and session history are stored in the Host Operator’s local Stelah database. Provider application secrets are protected for the Windows user on that host. The website stores a temporary Stelah access token in browser session storage and limited player preferences in local browser storage. Session storage normally clears when the browser session ends; users may also clear site data through browser settings.
Stelah itself does not use cross-site advertising cookies. Google, Microsoft, Facebook, Cloudflare, and other third parties may use cookies when their services are visited, according to their own policies.
7. Sharing and service providers
Stelah shares information only as needed to operate requested features:
- Host Operator: administers accounts, games, balances, permissions, sessions, and the local database.
- Cloudflare: may deliver the static website, route encrypted API traffic, prevent abuse, and process network/security metadata.
- Google, Microsoft, and Meta: process information when the corresponding optional sign-in method is selected.
- IGDB/Twitch and Steam-related services: may receive game identifiers or metadata requests initiated by the host.
- Game and communication services: may process gameplay or voice information when their software is used during a session.
Stelah does not sell or rent personal information, does not share provider data for behavioral advertising, and does not allow humans to read provider data except when necessary for security, support requested by the user, compliance with law, or operation of the service.
8. Retention and deletion
- OAuth state and nonce records expire after approximately ten minutes.
- Authorization codes and provider tokens are used transiently to finish sign-in and are not kept as long-term account records.
- The provider name, provider-specific identifier, and email link remain until the Host Operator deletes the account or associated records.
- Account, balance, preference, and session-history records remain on the host until changed or deleted by the Host Operator, subject to legitimate security or legal retention needs.
- Ordinary infrastructure logs are kept according to the Host Operator’s and Cloudflare’s operational retention settings.
To request access, correction, account unlinking, or deletion, contact the Host Operator and email support@katzulabs.com with the Stelah account email and the request. Do not send a password or access token. The requester may be asked to verify account ownership. Stelah/Katzulabs will address website-controlled data requests; the Host Operator must address data held only on their PC.
A user may also revoke Stelah’s Google access through Google Account third-party connections. Revoking provider access prevents future provider authorization but does not by itself delete the Stelah host account; request deletion from the Host Operator as described above.
9. User choices and privacy rights
Users may sign out, decline microphone permission, disable microphone forwarding, clear browser site data, revoke provider access, or ask for account records to be reviewed, corrected, disabled, unlinked, exported where applicable, or deleted. Depending on location, users may have additional rights to access, correction, deletion, restriction, objection, portability, or appeal. Stelah cannot directly fulfill a request for data that exists only on another person’s private host PC without that Host Operator’s involvement.
10. Security
Stelah uses short-lived signed access tokens, encrypted provider secrets on Windows, provider state and nonce checks, signed identity-token verification, server-side account and Sparkly authority, and game-window isolation. Traffic to the public domains is intended to use HTTPS. No Internet transmission, software, or computer can be guaranteed completely secure, so users should protect their accounts and Host Operators should keep Windows and Stelah updated.
11. Children
Stelah is not offered as a public service directed to children under 13. A parent, guardian, or family Host Operator who gives a minor access is responsible for supervising that access and complying with applicable child-privacy requirements. Contact the Host Operator and support@katzulabs.com if information is believed to have been provided without required consent.
12. International processing and legal disclosures
Internet traffic may pass through infrastructure in countries different from the user’s location. Information may be disclosed when reasonably necessary to comply with law, respond to valid legal process, protect users or the host, investigate abuse, or preserve the security and integrity of Stelah.
13. Policy changes and contact
This policy may be updated when Stelah’s features, providers, or legal requirements change. The effective date at the top will be revised for material updates. Questions, complaints, and website-controlled privacy requests may be sent to support@katzulabs.com. For records belonging to a particular private Windows host, contact that Host Operator as well.