Privacy Policy

Effective 2026-08-12

This policy describes how Morat AI, Inc. handles personal data across our services: the morat.ai website, the SABR web application, and the SABR desktop recorder. The short version: your organization's data belongs to your organization, we use it to run and improve our services under the Terms of Service, and we never expose one team's private data to another.

1. Who we are and what this covers

Morat AI, Inc. ("Morat", "we") operates the SABR esports analytics platform. This policy covers our services: the morat.ai website, the SABR web application, and the SABR desktop recorder. It explains how we collect, use, share, and protect personal data. For organizations with a subscription, the Terms of Service (and any signed agreement) also govern how we handle Customer Data (as defined there).

2. Data we collect

  • Account data: name, email address, organization membership, role, and authentication identifiers when you create an account or are invited to a workspace.
  • Organization content: data your organization submits or generates in our services: match and round data, statistics, strategy and playbook materials, notes, bookmarks, prompts and queries to SABR Agent, and their outputs.
  • Capture data (when your organization uses the recorder): gameplay video and in-game match data captured from devices your organization owns or is authorized to use. This can include personal data of players and staff such as names, in-game identifiers, and performance data.
  • Voice communications: where your organization enables audio capture, the recorder captures voice communications during practice sessions. Recordings are stored with the associated session for your organization's review and may be processed by our systems to provide review features. Your organization is responsible for the notices and consents required from every individual it records; if you have been recorded and want to object, contact your organization or contact@morat.ai.
  • Payment data: handled by our payment processor (Stripe). We receive subscription status and billing metadata; we do not store full card numbers.
  • Usage and device data: log data, pages viewed, feature interactions, IP address and user agent (which we may use to infer approximate location), and diagnostics we use to operate, secure, and improve our services.

Public esports data (for example official match results and licensed tournament data) is collected from public or licensed third-party sources; this policy still applies to any personal data it contains.

3. Cookies and similar technologies

We use strictly necessary first-party cookies to operate our services: session cookies that keep you signed in, and preference cookies such as your language selection. We also collect first-party product telemetry (for example page views and feature usage) to operate and improve the product. We do not use third-party advertising cookies, social media pixels, or cross-context behavioral tracking.

4. How we use data

  • to provide, secure, maintain, support, and improve our services;
  • to operate analytics, ratings, search, replay, and AI-assisted features;
  • to develop and improve our models and statistical systems, subject to the model-training terms and opt-out in the Terms of Service, and to produce aggregated or de-identified data that no longer identifies you;
  • to create, use, license, publish, and commercialize aggregated or de-identified data and insights that no longer identify you or your organization (see Section 7 of the Terms of Service);
  • to process subscriptions and payments and to send service and billing notices;
  • to respond to support requests and communicate about our services;
  • to comply with law and enforce our terms.

6. How we share data

We do not sell personal data. Aggregated or de-identified data (which does not identify you or your organization) is not personal data, and we may share, license, or publish it as described in Section 7 of the Terms of Service. We share personal data only with:

  • Service providers (subprocessors): providers bound by contractual data-protection obligations, currently including Google Cloud Platform (hosting, storage, and AI infrastructure, including Vertex AI for AI-assisted features), Stripe (payments), Bunny.net (video storage and delivery for uploaded and recorded gameplay), and Resend (transactional email). Prompts, queries, and related context processed by AI infrastructure providers to power AI-assisted features may also be used by those providers to improve their models and services, subject to their terms. A current subprocessor list is available on request at contact@morat.ai;
  • Your organization: workspace content and activity are visible to your organization's workspace according to its roles and settings;
  • Legal and safety: where required by law, legal process, or to protect the rights, safety, and security of Morat, our customers, or the public;
  • Business transfers: in connection with a merger, acquisition, or sale of assets, subject to this policy.

One organization's private uploads, scrim data, and strategy materials are never disclosed to another customer. Opponent-facing features use only public or licensed third-party data the other customer independently has the right to access.

7. International transfers

We are based in the United States and process data there and in other countries where our service providers operate. Where required, transfers from the EEA, UK, or Switzerland rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses.

8. Retention

We retain personal data for as long as needed to provide our services and for legitimate business or legal purposes. When an organization's subscription terminates and the organization requests deletion, raw Customer Data is deleted or de-identified within 60 days of the request, except aggregated or de-identified data, routine backups (retained for 7 days on a rolling basis), operational logs (retained up to 90 days), and data we are required by law to retain.

The desktop recorder also manages storage on the recording device itself: under your organization's storage settings, older recordings are automatically deleted from the local device. This local cleanup is separate from server-side retention of recordings your organization has uploaded, which remain until deleted by your organization or under the termination rule above.

9. Security

We maintain administrative, physical, and technical safeguards designed to protect personal data, including encryption in transit, access controls, least-privilege credential handling, and logical tenant isolation by organization or workspace, enforced at the application and data-access layer. Credentials that organizations authorize for data access are encrypted at rest, never logged in plaintext, and deleted upon revocation. No system is perfectly secure; report security concerns to contact@morat.ai.

10. Your rights and choices

Depending on your location, you may have rights to access, correct, delete, restrict, or port your personal data, to object to certain processing, and to withdraw consent. You can exercise these rights by emailing contact@morat.ai. If your data was submitted to our services by an organization (for example your team recorded scrims you played in), we may direct your request to that organization, which controls that data.

You may also lodge a complaint with your local data-protection authority. California residents may exercise rights under the CCPA/CPRA through the same contact; we do not sell or share personal data as those terms are defined there.

11. Children and minors

Account holders must be 18 or older, and we do not knowingly collect personal data directly from children under 16. Competition and practice data submitted by an organization may include personal data of younger players on its roster; the organization is responsible for obtaining the consents required for those players (including parental consent where applicable) before recording or submitting their data. If you believe we hold personal data of a child without appropriate consent, contact contact@morat.ai and we will address it.

12. Changes to this policy

We may update this policy from time to time. For material changes we will provide notice (for example by email or an in-product notice) before the changes take effect. The effective date above always reflects the current version.

13. Contact

Morat AI, Inc. Questions about this policy or our data practices: contact@morat.ai.