Downcard is operated by Nightjar Labs LLC, based in New York, USA, which is the controller of the personal data described here. Downcard collects the minimum it needs to run multiplayer poker between friends, sync your progress across devices, and fix bugs. No ads, no ad tracking, and nothing is sold or shared for marketing. This page lays out exactly what we store, where it lives, and what we don't touch.
What we store on our server
When you set up your profile during onboarding, an anonymous account is created for you in the background, with no email or password required. Opening the app on its own doesn't create an account. It lives on this device. It won't move to a new phone on its own, and uninstalling the app loses it for good. To keep your chips, items, and progress across a reinstall or a new device, claim the account by linking an email or signing in with Apple or Google. That's the only way to carry it over.
Tied to that account, our server stores:
- Profile: the display name and avatar emoji you pick.
- Install identifier: a random id for your app install, stored on your profile so we can tie your anonymous account to this device and clean up ones that were clearly abandoned.
- Wallet: your virtual chip balance and a ledger of chip movements.
- Inventory and equipment: which cosmetics you own (felts, card backs, emote packs, titles) and which you have equipped.
- Progression and play stats: XP, level, unlocked achievements, and lifetime table stats like hands played and hands won.
- Multiplayer rooms: while you're in a multiplayer game, the server tracks your seat at the table so the other players can see your moves. When the room ends, the live game state is dropped. If you play a real-chip table, we keep a settlement record (the room code, buy-in, and timing) with your wallet ledger for as long as your account exists, so your chip history stays accurate.
If you choose to claim your account (link an email or sign in with Apple / Google), we also store the identifier the auth provider gives us: an email address or a stable provider id. We don't store your password; that lives with the auth provider.
What's stored on your device
Downcard keeps a local copy of the data above so the app feels instant. Your chip balance, items, and recent rooms render off the local store, then reconcile against the server in the background. If you delete the app, the local copy goes with it.
Crash reports and diagnostics
This is the one place we collect more than gameplay data, so here's the full picture.
- Crash and error reports go to Sentry. A report includes a stack trace, your device model, OS version, app version, and, once you're signed in, your account id and display name (plus email on a claimed account). It also carries diagnostic tags like the screen you were on, random session and install ids, and, in a multiplayer game, the room code and the account ids of the other players at your table, so we can reconstruct the shared game state around a bug. We attach your identity on purpose: when you tell us "the app ate my chips," it's how we find your session and fix it.
- Bug reports you send from the app include a log of that session's activity and, if you're in a multiplayer game, a snapshot of the current table state (which includes the other players at your table), plus any screenshots you attach and your email if you enter one, so we can retrace what happened.
- Usage and reliability telemetry goes to Grafana Cloud: events like "app opened," "room joined," or "purchase completed," plus warning-level logs when something misbehaves. These are tagged with random session and install identifiers so we can follow one broken session end to end.
All of this exists to keep the app working. None of it is used for advertising, sold, or shared with anyone for their own purposes.
Where your data lives
We don't run our own data centers. Your account data is stored and authenticated through Supabase, our game server runs on Fly.io, and diagnostics live with Sentry and Grafana Cloud. Your account data (Supabase) and our game server (Fly.io) run in the United States; the diagnostics providers handle their data on their own infrastructure. These providers process data on our behalf under their own security and privacy commitments; we don't hand them your data for their own purposes. If you're in the EU or UK, using Downcard means your data is transferred to and processed in the United States. For those transfers we rely on the standard safeguards our providers offer, such as the EU Standard Contractual Clauses, which Supabase, Fly.io, Sentry, and Grafana Cloud each publish.
In-app purchases
Chip packs are sold via the Apple App Store or Google Play. The transaction itself happens between you and Apple / Google. Downcard receives a receipt confirming the purchase succeeded, then grants the chips to your account. We don't see or store your payment method.
What we don't collect
Downcard does not:
- Show ads, or integrate any advertising SDK.
- Use marketing or ad-tech analytics (no Google Analytics, no Mixpanel, no Amplitude, no Facebook SDK).
- Track your location.
- Read your contacts or photos.
- Sell, rent, or share your data with third parties for marketing.
Permissions the app asks for
- Notifications (opt-in, if you grant it): used only for game moments worth knowing about. Never time-of-day pings, never "come back" prompts.
- Internet access: required for multiplayer, syncing your wallet and items, and downloading the catalog. The app works offline against bots; multiplayer doesn't.
How long we keep it
We keep your account data for as long as your account exists. An anonymous account that's clearly been abandoned (never claimed, no purchases, and no real progress) may be cleaned up automatically. The live state of a multiplayer room is dropped when it ends. For real-chip tables, a chip-settlement record stays with your wallet ledger for as long as your account exists. Crash reports and telemetry age out on the providers' retention schedules, typically weeks to a few months. When you delete your account, the data tied to it is removed (see below).
How we protect your data
Traffic between the app and our server is encrypted in transit (HTTPS/TLS), and data at rest sits with reputable infrastructure providers. No system is perfectly secure, but we collect little enough that there isn't much to lose: no payment details, no location, no contacts.
Your privacy rights
Wherever you live, you can ask us to:
- See what we hold about you.
- Correct it, though most of it (display name, avatar) you can edit yourself in the app.
- Delete it, either yourself from Profile → Account → Delete account, or by emailing us.
- Export a copy.
- Object to how we process it.
Email contact@downcard.app to exercise any of these. We have never sold or shared your personal information for anyone else's purposes, and we never will. If you're in the EU or UK, you can also complain to your local data-protection authority. If you're in a US state with its own privacy law, you can raise concerns with your state Attorney General, and where your state's law allows it, appeal a request we've denied.
Our legal basis (EU and UK)
If you're in the EU or UK, data-protection law asks us to name a legal basis for using your data. Ours are: our legitimate interest in running the game, keeping it working, and stopping abuse; performing our contract with you, which is how we deliver the chips and cosmetics you buy; and meeting legal obligations like keeping records of purchases. We don't run advertising or tracking that would need separate consent.
Deleting your data
You can delete your account from the app: Profile → Account → Delete account. That removes your profile, wallet, inventory, and progression from our server. There's no soft-delete grace period; once it's gone, it's gone. Crash reports and telemetry already sent age out on their own retention schedules.
Children
Downcard is intended for adults. It is not directed at anyone under 18, and we don't knowingly collect data from anyone under 18. If you think someone under 18 has created an account, email us and we'll delete it.
Changes to this policy
If this policy ever changes, the new version will be posted here and the "Last updated" date at the top will be revised. Material changes will also be flagged in the app the next time you open it.
Contact
Questions? Reach out at contact@downcard.app.