Privacy Policy
Last updated: September 17, 2026
1. Overview
This Privacy Policy describes how the operators of this poker application (the "Service", "we", "us", or "our") collect, use, store, share, and disclose information in connection with your use of the Service. By accessing or using the Service in any way you confirm that you have read and accepted this Policy and the Terms of Service. If you do not agree, you must immediately stop using the Service. This Policy is provided for transparency and does not create any contractual right beyond what is required by applicable law.
2. Information We Collect
We collect information from several sources:
- Telegram account data.When you sign in via the Telegram Mini App we receive the Telegram-signed initData payload, which may include your Telegram user id, display name, username, language code, and avatar references. When you sign in from a regular browser we receive a Telegram Login Widget payload, which may include your Telegram user id, first name, last name, username, photo URL, and auth date, together with a Telegram-signed hash. We verify Telegram's signature with our bot token. Both Telegram methods map to the same account keyed by Telegram user id.
- Google account data. When you sign in from a regular browser with Google, Google Identity Services returns an ID token. We verify that token with Google and receive your Google account id (sub), email address, and name. The account is keyed by Google id and is separate from any Telegram account: signing in later with Telegram does not merge balances or identity. Google sign-in is not offered in the Telegram Mini App or on the admin dashboard.
- Account and profile data. Display name, username, selected avatar, card-back preference, free-play status, Nuggets balance, real-chip balance, Telegram id, creation timestamp, and other profile fields.
- Authentication tokens.A JSON Web Token (JWT) issued by us upon login and stored on your device (including in browser localStorage as "poker_token"). The token is presented to the server with each request and may be invalidated at any time.
- Wallet and on-chain data. When you pair a wallet via TonConnect or send GRAM to our designated deposit address, we receive your wallet address, transaction hashes, transaction memos, amounts, and confirmation status. The GRAM blockchain is a public ledger; all on-chain data is and will remain publicly accessible to anyone.
- Arena agent credentials. If you authorize an agent, we store a hashed credential, a visible token prefix, the connection name, status (active, paused, or revoked), policy caps, last heartbeat time, and which Arena seat the agent occupies. The plaintext token is shown once at creation and is not stored. The agent plays as you: actions, stacks, and hand results on Arena tables are attributed to your account.
- Gameplay and ledger data. Hand outcomes, hole cards, community cards, burned cards, dealer position, bets, calls, raises, folds, timings, table configuration, seat history, rebuys, leaves, kicks, bans, escrow holds, settlement events, payouts, rake, and complete ledger entries for real-money tables. Free-play tables also record hand history but bypass the chip ledger.
- Tournament and private-table data. Where applicable, registrations, invite codes, whitelists, bans, host actions, and prize distribution.
- Statistical data. Aggregated and per-player statistics such as hands played, hands won, VPIP, PFR, three-bet frequency, aggression factor, hours played, and fold frequencies, used for leaderboards and stats screens.
- Security and anti-cheat signals. IP address, request metadata, device and browser characteristics, session identifiers, action timing, anti-cheat events, rate-limit violations, fraud indicators, and any moderation actions taken.
- Real-time connection data. Socket.IO connection identifiers, room memberships, presence events, and disconnection events.
- Communications and support. Any messages you send to support or hosts, and the metadata of those communications.
- Notifications. Status of in-app notifications you have viewed, dismissed, or acknowledged.
We do not knowingly request government-issued identification unless required by law (e.g., AML or KYC obligations). If required, we will collect only what is necessary and retain it as long as legally required.
3. How We Use Information
We use information to:
- operate, maintain, and improve the Service, including matchmaking and gameplay;
- authenticate you and prevent unauthorized access;
- operate Arena agent connections, including heartbeat presence and playing as the authorizing user on Arena tables only;
- process deposits, withdrawals, rake, escrow holds, and other ledger movements;
- detect, investigate, and prevent fraud, collusion, multi-accounting, bot use, money laundering, sanctions exposure, and other prohibited conduct;
- enforce our Terms of Service and our rights;
- comply with applicable law, lawful requests, court orders, and regulatory obligations;
- generate analytics, leaderboards, hand history, statistics, and game integrity metrics;
- communicate with you about the Service, security events, or policy changes; and
- any other purpose disclosed at the time of collection or with your consent.
4. Legal Bases (where applicable)
Where data-protection laws require a lawful basis, we rely on: performance of the contract with you (the Terms of Service); our legitimate interests in operating, securing, and improving the Service and detecting fraud; compliance with legal obligations; and your consent where explicitly requested. You may withdraw consent where it is the sole basis, but doing so may make the Service unusable.
5. Sharing and Disclosure
We may share information with:
- Telegram, on whose platform the Service is delivered and which controls your Telegram account data independently;
- GRAM blockchain participants, miners, validators, and indexers. All on-chain transactions are public by design;
- Blockchain indexers and explorers such as TONCenter, which we query to verify deposits and broadcast withdrawals;
- TonConnect wallet providers you choose to pair, which independently handle your wallet credentials;
- Cloud hosting, database, monitoring, analytics, error-tracking, and anti-fraud providers that process data on our behalf under contractual controls;
- Other players, who may see your display name, avatar, public chip balance, leaderboard rank, and gameplay actions during hands you participate in;
- Law enforcement, regulators, courts, or other authorities when we believe in good faith that disclosure is required, appropriate, or necessary to comply with law, prevent harm, or protect our rights, our users, or the public;
- Acquirers, successors, or partners in connection with a merger, acquisition, financing, reorganization, sale of assets, or similar transaction.
We do not sell personal information for monetary consideration. Aggregated or de-identified data that cannot reasonably be linked to you may be shared freely.
6. Public and Pseudonymous Data
Display name, avatar, leaderboard position, hand-history availability to other participants of the same hand, and any messages you send at a table or chat surface are public to other users of the Service. On-chain transactions are public to the world by design and cannot be made private after broadcast.
7. Cookies, Local Storage, and Similar Technologies
The Service uses browser localStorage and similar technologies to store your authentication token, theme and language preferences, timer-display setting, card-back preference, and other session state. You can clear this data through your device or browser settings, but doing so will sign you out and may break gameplay. The Service may set short-lived cookies in some deployments for session management or anti-abuse.
8. Data Retention
We retain information for as long as your account exists and for as long as we have a legitimate business or legal reason afterwards, including (a) operating accounts and resolving disputes; (b) detecting and preventing fraud, collusion, multi-accounting, bots, money laundering, and sanctions violations; (c) complying with tax, AML, KYC, or other regulatory recordkeeping obligations; (d) enforcing the Terms of Service; and (e) defending legal claims. Anti-cheat signals, ledger entries, security incidents, hand history, and on-chain records may be retained indefinitely as permitted by law.
9. Security
We implement commercially reasonable technical and organizational measures intended to protect information against unauthorized access, alteration, disclosure, or destruction. However, no system is perfectly secure. You acknowledge that you transmit information at your own risk, that bugs, breaches, social-engineering attacks, blockchain network attacks, and third-party compromises can occur, and that we cannot guarantee absolute security or recovery of compromised funds, chips, or data.
10. International Transfers
Information may be stored and processed in jurisdictions other than your own, including jurisdictions with different data-protection rules. By using the Service you consent to such transfers. Where required, we rely on appropriate legal mechanisms for international transfers.
11. Your Choices
Depending on your jurisdiction, you may have rights to access, correct, port, restrict, object to, or delete certain personal information about you. Requests can be made through the support channel listed in the Service. We may verify your identity, deny or partially fulfill requests where law permits (including for anti-cheat, fraud detection, game-integrity, ledger integrity, or legal-hold reasons), and we may retain blockchain records that we cannot technically delete. Deleting your account does not erase on-chain transactions.
12. Children
The Service is not intended for and is not directed to anyone under the age of eighteen (18), or the age of majority in their jurisdiction, whichever is higher. We do not knowingly collect information from minors. If we learn that a minor has used the Service, we will close the account and may forfeit balances.
13. Third-Party Services and Links
The Service depends on and may link to third parties, including Telegram, TonConnect wallets, GRAM blockchain explorers, indexers, and hosting providers. We are not responsible for the privacy practices of those parties. You should review their policies independently.
14. Changes to this Policy
We may update this Policy at any time. The "Last updated" date at the top of this page reflects the latest revision. Continued use of the Service after a change constitutes acceptance of the updated Policy. If you do not agree, you must stop using the Service.
15. Contact
Privacy requests should be sent through the support channel listed in the Service. We do not accept service of legal process via email; please consult the Terms of Service for the binding dispute-resolution procedure.
By continuing to use the Service, you acknowledge that you have read, understood, and agreed to this Privacy Policy.