POKER CHIPS

Privacy Policy

Last updated 15 September 2026

Poker Chips has no accounts, no analytics, no advertising and no tracking. It has no verified identity: a player name can be a nickname, and the app does not ask for an account, email address or legal name.

Remote play and content reports send data to a server. This policy explains what is sent and how long it is kept.

Two ways to play

Everyone in the same room

Devices find each other on your own Wi-Fi and game traffic travels directly between them (Bonjour and TCP). No game server is involved. If you explicitly send a content report, that report is sent to our reporting service as described below. Opening an invite or support page also makes a normal HTTPS request to that website.

Playing remotely

When you choose to play remotely, the table runs on a server we operate in Stockholm, Sweden (AWS eu-north-1). The server acts as the dealer: it keeps the table, deals the cards and decides whose turn it is.

What the server receives and keeps

The state of the table — the player names and optional unit label you typed, chip counts, buy-ins and cash-outs, settlement values, and the sequence of actions taken during the evening
On disk, so an interrupted evening survives a reconnection or a server restart. The service stops restoring it 24 hours after the last table activity. The expired file is removed when that record is accessed, when the server starts, or by a sweep that runs every five minutes while the service is online.
The table code used to join
The same 24-hour expiry and deletion schedule as the table record
An installation identifier — a random number generated once by the app, used to give you your own seat back if your connection drops
Stored with the table record: the founder’s identifier and the links between installations and player seats. This connects the identifier to player names and gameplay. The same 24-hour expiry and deletion schedule applies as for the table record.
Your own cards
During the hand, private cards are sent to their owner and the private deal is held in server memory. Public board and hand reveals are saved in the game log. At showdown the log also saves a verification seed that can reconstruct the original deal, including folded hands. These records have the same expiry as the table. A voluntary winner-only reveal does not publish this seed.

The player names and unit label are whatever you type. Names can be nicknames — the app does not require or check real names, and it asks for no account or contact details.

IP addresses

Like every internet service, the server necessarily receives your device's IP address in order to send data back to it. The Poker Chips application does not put the address in the table record and does not configure its own access log. We audited the production configuration on 16 August 2026: CloudFront standard logging, S3 access logging, VPC Flow Logs and CloudWatch log groups are disabled, Caddy has no access-log directive, and the relay journal holds service lifecycle messages rather than client addresses or table data. AWS still processes the connection metadata needed to deliver and secure its infrastructure under its own service terms.

Service provider and other players

Amazon Web Services processes the remote table and website connections on our behalf. Other invited players receive the table information needed to play — such as player names, chip counts, public actions and revealed cards. The showdown verification seed also makes the original deal reconstructable after betting has ended. We do not sell data or share it for advertising or tracking.

Invite links

An invite is the table code, and the app can share it as a link of the form pokerchipsapp.com/j/<code>. That address is a static page: it shows the code and nothing else. Opening it makes a normal HTTPS request to our AWS CloudFront website, which necessarily receives the connection's IP address to return the page. The page has no analytics, no cookies and no scripts beyond reading the code out of the address itself, and we do not add an application access log for it.

The result card

The settlement can be shared as an image. It is drawn on your device and handed to the system share sheet — where it goes from there is your choice, and we never see it.

What the app stores on your device

The evening in progress
One file, so an interrupted evening can be resumed. Deleted when the evening ends.
Display preferences
Whether you keep your cards face up, and whether the peek hint has been shown.
Muted seats
Which seats' reactions you muted. Local to your phone and never shared.
Hosted evenings
One number and one date: how many evenings this device has hosted and when the last one was.
Evenings you explicitly save
Date, game variant, number of hands, unit and conversion rate, player names, bought-in and net chip values, and the evening's awards. Android archives also include the public game snapshot, action log and any hand reviews you opened. Private card messages are excluded. Saved evenings can be deleted individually.

This local data stays on your device. The operating system may include it in your own cloud backup or device-to-device transfer. Deleting the app removes its local copy; a platform backup can retain a restorable copy according to your backup settings.

Reporting and hiding content

When you choose Send report, the app sends the selected player name or unit label, your selected reason, a random report ID, your installation ID and, for a player-name report, the reported seat ID. Reports do not include the table invite, a full game log, or private cards. Reports are used to investigate abuse and apply moderation measures; they are not used for advertising.

Reports are retained for 30 days from receipt and removed by a periodic cleanup within five minutes after expiry. Only the publisher's designated moderators have access. A moderation decision may restrict the reported seat or text for a further 30 days from that decision. These private restrictions expire automatically; they do not erase the game's accounting. A failed submission stays as a local draft and is sent again only when you choose to retry. Hiding content stores a local preference and changes displayed names and social reactions, not chip totals or the game's accounting. The app also stores the version of the content terms you accepted.

What we never do

The app does not accept, transmit or hold money, and it offers no payment method, wallet or link for cashing out to money.

Your rights

The data controller is Kare Oja (contact below). Data is processed to provide the game you asked for — under the GDPR, on the basis of performing that service at your request.

There is no account or verified-identity index. A player name may still identify a person if somebody types a real name. We can locate a remote table only from its table code. The service stops restoring table state after 24 hours and deletes the expired record on access, at startup or in its five-minute sweep. Send the table code to the address below if you request earlier deletion. You may also contact your national data protection authority.

Children

The app is not directed at children. It asks for no account, contact details or verified identity; a player name or unit label may nevertheless contain information that a user chooses to type.

Changes

If this policy changes in a way that affects what is sent or kept, the date at the top changes with it.

Contact

Questions about this policy: kare.oja@outlook.com