Privacy · Updated September 23, 2026

Your visit.
Your information.

This page describes how the current Tickertown app handles sign-in information, sessions, and privacy requests.

Why we ask you to sign in

Google sign-in creates your Tickertown account, keeps you signed in, and gives you access to the early 3D world. The public simulation can be observed without an account.

We request Google’s basic identity permissions: openid, email, and profile. The app does not request access to Gmail, Google Drive, contacts, or other Google account content.

What the app stores

Our application database stores your Google account identifier, verified email address, display name, account creation time, and most recent sign-in time. We use these records to identify your account and support access to the world.

The app also stores a hashed session identifier, its account reference, an expiry time, and a security token used to protect sign-out requests. Google tokens are used during authentication but are not saved in the application database. We do not store your Google profile photo.

Cookies and temporary information

Tickertown uses an essential sign-in cookie with a fixed seven-day lifetime. Signing in also creates a temporary security cookie and verification record valid for ten minutes. These help validate Google’s response and prevent reuse of a sign-in attempt.

On HTTPS, these cookies are marked Secure, HttpOnly, and SameSite=Lax. Expired session and sign-in records are cleaned up when the app starts, when a sign-in begins, and during hourly cleanup. The server briefly holds IP addresses and request counts in memory to limit excessive authentication requests.

The services involved

Google processes authentication. Tickertown uses Render for application hosting and Cloudflare for domain services. These providers may process service and network data needed to operate their services.

The current Tickertown app does not send your Google identity information to JEV. The public observatory displays fictional beings and simulation state, not visitor account records; it does not publish your Google identity.

Keeping and removing information

Account records do not currently expire automatically. Signing out removes the current browser’s session and cookie; it does not delete your account or sign out other browsers.

There is no self-service account deletion feature in this release. For a privacy question or an account deletion request, email nova@novalystrix.ai. Include the email address associated with your Tickertown account so we can identify the request. Do not send passwords or Google sign-in codes.

Changes to this page

This notice describes the current app and the hosting arrangement planned for launch. We will update it as the service changes. The date at the top identifies this version.