1. Introduction
#ELSI ("we", "our", "the app") is a poker tracking and coaching application. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the rights you have over it. We follow GDPR (EU), CCPA (California), and Apple/Google Play guidelines.
2. Information We Collect
#Account information
- •Email address (authentication)
- •Username (chosen by you)
- •Profile photo (optional, uploaded from your device)
- •Apple/Google identifier when using Sign in with Apple or Sign in with Google
Poker data
- •Session results (buy-ins, cash-outs, duration)
- •Hand histories (cards, actions, positions)
- •Bankroll calculations derived from your sessions
- •Objectives, daily tasks, mental check-ins
- •Opponent notes you create
Device & technical data
- •Platform (iOS/Android), app version, language
- •Anonymous device identifier (push notifications routing)
- •Crash logs and basic diagnostic events for debugging
- •Push notification token (if you grant the permission)
Permission-gated data
- •Approximate location (foreground only) — used to sort festivals by proximity. Never tracked in background, never shared.
- •Photos library (read access only when you change your avatar or attach a screenshot to a support ticket)
- •Camera (only if you choose to take a photo for your avatar)
Subscription data
- •Purchase status (Free / Premium / Gold) — managed by Apple App Store and Google Play via RevenueCat
- •We never see or store your payment details (card, billing address). Apple/Google handle billing end-to-end.
What we DO NOT collect
- •Real-money gambling transactions — ELSI is a tracker, not a gambling platform
- •Your contact list
- •Your browsing history outside the app
- •Background location
- •Microphone audio
- •Health, biometric or financial account data
3. How We Use Your Data
#- •Core features: tracking your sessions, bankroll, hands, and progress
- •AI Mental Coach: generating personalized insights (server-side proxy to Anthropic Claude)
- •Push notifications: daily reminders and mental check-ins (only if you opt in)
- •Crash & diagnostics: identifying and fixing errors
- •Aggregated, anonymized statistics to improve the product
4. Storage, Security & Hosting
#- •Primary database: Supabase (PostgreSQL) — EU region, encryption at rest
- •Authentication: JWT tokens, sensitive data kept in device secure storage (iOS Keychain / Android Keystore)
- •Row-Level Security (RLS): each user can only read/write their own rows; admins access aggregate views only
- •All transport over HTTPS/TLS
- •No data is stored locally on our servers outside Supabase managed infrastructure
5. AI Processing
#- •Mental coaching uses Anthropic Claude via a secure server-side proxy
- •Only the poker stats relevant to the request are sent — never your raw email, payment data, or contact list
- •Anthropic does not retain conversations beyond processing the request
- •AI features are entirely optional — the app fully works without them
6. Data Sharing & Sub-Processors
#We never sell, rent, or trade your personal data. We share only with the sub-processors strictly required to run the service:
- •Supabase (EU) — database, authentication, storage
- •Anthropic (US) — AI coach, no data retention
- •RevenueCat (US) — subscription receipt validation
- •Apple / Google — Sign in with Apple/Google, push notifications, in-app purchases
- •Vercel (EU/US) — hosting of this website
- •When required by law (court order, valid legal request)
7. International Transfers
#Some sub-processors (Anthropic, RevenueCat, Apple, Google) are based in the United States. We rely on Standard Contractual Clauses (SCCs) and the EU-US Data Privacy Framework where applicable. By using ELSI, you consent to these transfers.
8. Your Rights (GDPR / CCPA)
#- •Access — see all your data in the app and via in-app export
- •Rectification — edit your profile, sessions, hands directly in the app
- •Erasure — delete your account in Settings → Privacy → Delete account (hard delete within 30 days)
- •Portability — export your data as JSON/CSV
- •Restriction & objection — opt out of notifications, AI features, or analytics
- •Lodge a complaint — with your local data protection authority (e.g. CNIL in France)
9. Data Retention
#- •Account data: kept while your account is active
- •Sessions / hands / notes: kept while your account is active
- •Crash & diagnostic logs: 30 days then auto-deleted
- •Account deletion: full data wipe within 30 days, including Supabase backups
10. Children’s Privacy
#ELSI is not intended for users under 18. We do not knowingly collect data from minors. If you believe a minor has registered, contact us via the support page and we will delete the account immediately.
11. Changes to This Policy
#We may update this Privacy Policy as the app evolves or regulations change. We will notify you in-app for any material change and update the "Last updated" date at the top of this page.
12. Contact
#For any privacy question, data request, or to exercise your rights, contact us via the support page at https://elsipoker.com/support — we reply within 48 hours.