Privacy

Privacy Policy

How TableRival handles data in the app, first-party API, public website, purchases and support.

Last updated:

1. Controller and contact

The data controller is Mariusz Twaróg, Łososina Górna 47, 34-600 Limanowa, Poland (the “Operator”). Privacy contact: tablerival@gmail.com. This policy applies to the TableRival app with package identifier app.tablerival.poker, the first-party API used for explicitly enabled features and the public website. There is no TableRival login account.

2. Key principles

  • No TableRival account is required.
  • Training history, hands, opponent aliases, notes, settings and diagnostics remain on the device by default.
  • TableRival does not accept poker deposits, pay prizes, display ads or sell data.
  • Feature analytics requires separate voluntary consent.
  • Payment-card details remain with Google or Apple.

3. Data that may be processed

3a. Public website analytics

Only with your consent, we use Google Analytics 4, provided by Google Ireland Limited. Its purpose is to understand traffic sources and website usefulness; the legal basis is your voluntary consent, which you can withdraw. Google receives pseudonymous cookie identifiers, public pages visited, referral source, language, time and basic browser and device information. We also measure guide-answer openings and beta-access clicks. Google processes the network data needed to connect to its service.

We do not send message contents, email addresses, training data or arbitrary URL parameters. Page addresses are sent without query strings or fragments; traffic sources use only the referring domain or predefined campaign labels. Google Signals, ad personalisation, granular location and device data collection and automatic form measurement are disabled. Learn how Google uses data on partner sites.

GA4 user and event data retention is set to 2 months, without resetting the period on new activity. This setting does not limit retention of standard aggregated reports. You can change consent in “Analytics settings” in the footer; declining stops further measurement but does not automatically erase previously collected data. See the Cookies Policy for cookie lifetimes and storage of your choice. Website analytics is separate from app analytics.

4. Recipients

Depending on the platform and enabled features, data may be processed by Google Play or Apple App Store (distribution and payments), RevenueCat (purchase and Pro-entitlement verification), the app/API/database hosting provider, the email provider and authorities or advisers where legally required. Providers act only to the extent needed to deliver their services under their own terms or data-processing agreements. The Operator does not disclose data to advertisers or data brokers.

5. Transfers outside the EEA

Some providers may process data outside the European Economic Area. Required safeguards include an applicable European Commission adequacy decision, Standard Contractual Clauses or another GDPR-approved mechanism.

6. Retention

  • Local data: until you delete it, reset the app or uninstall.
  • Optional app analytics: the service checks for records older than 12 months when a new analytics request is processed.
  • Recommendation reports: the service checks for records older than 24 months when a new report request is processed.
  • Those checks are not a continuously scheduled deletion guarantee. You may request deletion at any time, and the Operator reviews whether data should be deleted or anonymised when a stated period is not enforced automatically.
  • Support correspondence, security records, purchase and entitlement data: only for as long as needed for the stated purpose, disputes, security or an applicable tax, accounting, consumer or limitation obligation.
  • Anonymous aggregate statistics that cannot identify a person may be kept longer.

The Operator must approve the final retention schedule and verify it operationally. This policy does not claim automatic deletion where no automated schedule has been verified.

7. Security

TableRival uses data minimisation, encrypted HTTPS transport, pseudonymous identifiers, narrow API contracts, access controls and signed store releases. See the Security Policy for details and vulnerability reporting.

8. Your rights and choices

Where the GDPR applies, you may request access, correction, erasure, restriction or portability, object to processing and withdraw consent without affecting prior lawful processing. Email tablerival@gmail.com. You may also complain to the Polish supervisory authority (UODO) or your local authority.

Local reset and remote deletion instructions are on the Data deletion page.

9. Automated decisions and children

Poker recommendations are educational information and do not produce legal or similarly significant effects. The service is for adults aged 18 or over and is not directed to children.

10. Changes

This policy will be updated before a new material data-collection practice is enabled. The current date will remain visible here; material changes may also be announced in the app or store.