We built PokerPay to be simple and trustworthy. Here's exactly what data we collect, why, and how we protect it.
We only collect data that is necessary to make the app work. Below is a complete list of every category of data we hold.
| Data | Where it's stored | Why we need it |
|---|---|---|
| @handle & display name | Supabase (cloud) | Your public identity inside the app |
| Email address | Supabase (cloud) | Account recovery & optional notifications |
| Password (hashed) | Supabase Auth | Authentication — never stored in plain text |
| Venmo / Cash App / Zelle handle | Supabase (cloud) | Generate settlement payment links for your crew |
| Game creation timestamps | Supabase (cloud) | Anonymous usage analytics (no game content) |
| IP address (temporary) | Supabase (server log) | Rate limiting sign-in and sign-up attempts |
| Subscription status | Apple App Store + Supabase | Enforce free / Pro plan features |
| Waitlist submission (name, email, handle) | Supabase (cloud) | Notify you when escrow payouts launch |
Your actual game data — player names, buy-in amounts, stack sizes, and settlement results — is stored only on your device using iOS secure storage (Keychain and UserDefaults). This data never leaves your phone and is never sent to our servers.
Your account credentials (session token) are stored in the iOS Keychain — the most secure storage available on iPhone, protected by your device passcode and Face ID / Touch ID.
We do not use your data for advertising, profiling, or any automated decision-making that affects you in a meaningful way.
PokerPay does not process payments. We do not hold funds, operate a money-transmission service, or store credit card or bank account numbers.
Settlement works by generating a deep link (e.g. venmo://paycharge?...) that opens your existing Venmo, Cash App, or Zelle app. All payment processing happens entirely within those third-party apps under their own terms and privacy policies.
Pro plan subscriptions are billed and managed entirely by Apple through the App Store. PokerPay never sees your payment card details.
We share your data with the following service providers only, and only to the extent needed to operate the app:
| Provider | Purpose | Data shared |
|---|---|---|
| Supabase | Database, auth, and serverless functions | Account & profile data, rate-limit logs |
| Apple App Store | In-app subscription billing | Purchase receipt (handled by Apple) |
| Google Fonts | Website typography | Your IP (standard CDN request) |
We do not sell your data. We do not share your data with advertisers, data brokers, or analytics platforms. We will share data with law enforcement only if required by a valid legal order.
We take security seriously and have implemented the following protections:
We retain your account data for as long as your account is active. Specific retention periods:
You can permanently delete your account at any time from Account → Delete Account inside the app. Deletion removes your profile row, auth record, and all associated server-side data immediately and irreversibly. Device-local game data is removed when you uninstall the app.
Regardless of where you are located, you have the following rights regarding your data:
To exercise any of these rights, email privacy@pokerpay.app. We will respond within 30 days.
PokerPay is intended for users aged 17 and older (matching Apple's App Store rating). We do not knowingly collect personal data from anyone under the age of 13. If we become aware that a child under 13 has provided personal data, we will delete it immediately. If you believe a child has created an account, please contact us at privacy@pokerpay.app.
Apple requires apps to disclose their data practices in a standardized format on the App Store product page. Below is PokerPay's complete disclosure, mapped to Apple's categories.
Data linked to you
| Apple Category | Specific data | Purpose |
|---|---|---|
| Name | Display name | App Functionality, Product Personalization |
| Email Address | Email address | App Functionality (account recovery) |
| User ID | @handle, internal account ID | App Functionality |
| Other User Contact Info | Venmo / Cash App / Zelle handles | App Functionality (settlement payment links) |
| Purchase History | Pro subscription status | App Functionality (plan enforcement) |
| Product Interaction | Game creation timestamps (no game content) | Analytics (usage measurement) |
| Other Diagnostic Data | IP address (rate-limit logs, retained max 30 days) | App Functionality (fraud & abuse prevention) |
Data NOT collected
| Apple Category | Status |
|---|---|
| Precise or Coarse Location | Not collected |
| Health & Fitness | Not collected |
| Payment Info (card/bank) | Not collected — Apple handles billing |
| Sensitive Info | Not collected |
| Contacts | Not collected |
| Photos, Videos, Audio | Not collected |
| Browsing or Search History | Not collected |
| Device ID (IDFA/IDFV) | Not collected |
| Advertising Data | Not collected — no ads |
Game data (player names, buy-in amounts, stack sizes, settlement results) is processed entirely on your device and never transmitted to our servers. It is not collected under Apple's definition.
If you have any questions about this policy or how we handle your data, reach out:
privacy@pokerpay.app — general privacy questions and data requests.
security@pokerpay.app — vulnerability reports and security concerns.
This policy may be updated from time to time. If we make material changes, we will update the effective date at the top of this page. Continued use of the app after changes constitutes acceptance of the revised policy.