This Privacy Policy (this "Policy") describes how Nightjar Labs LLC ("Nightjar Labs," "we," "us," or "our"), based in New York, USA, collects, uses, stores, and shares your personal information when you use the Downcard mobile application and any related services (collectively, the "Services"). Nightjar Labs LLC is the controller of the personal information described in this Policy. We collect the minimum information necessary to operate multiplayer poker, synchronize your progress across devices, and diagnose and correct defects. The Services contain no advertising and no advertising trackers, and we do not sell personal information or share it for marketing purposes. If you do not agree with this Policy, please discontinue use of the Services.
Table of Contents
- 1. What Information Do We Collect?
- 2. How Do We Process Your Information?
- 3. What Legal Bases Do We Rely On to Process Your Information? (EU and UK)
- 4. When and With Whom Do We Share Your Personal Information?
- 5. What Information Do We Not Collect?
- 6. How Are Payments Handled?
- 7. Is Your Information Transferred Internationally?
- 8. How Long Do We Keep Your Information?
- 9. How Do We Keep Your Information Safe?
- 10. Do We Collect Information From Minors?
- 11. What Are Your Privacy Rights?
- 12. Controls for Do-Not-Track Features
- 13. Do United States Residents Have Specific Privacy Rights?
- 14. How Can You Review, Update, or Delete the Data We Collect?
- 15. Do We Make Updates to This Policy?
- 16. How Can You Contact Us About This Policy?
1. What Information Do We Collect?
Information you provide to us. When you set up a profile during onboarding, an anonymous account is created for you; no email address or password is required, and simply opening the App does not create an account. We store the display name and avatar you select. If you choose to claim your account by linking an email address or signing in with Apple or Google, we also store the identifier the authentication provider issues to us: an email address or a stable provider identifier. We do not store passwords; those are held by the authentication provider. If you submit a bug report from within the App, we collect the contents of that report, including any screenshots you attach and your email address if you provide one.
Information collected automatically. In connection with your account, our server stores:
- Install identifier: a randomly generated identifier for your App installation, associated with your profile so that we can tie an anonymous account to its device and identify accounts that have been abandoned.
- Wallet: your virtual chip balance and a ledger of chip movements.
- Inventory and equipment: the virtual cosmetic items you own (felts, card backs, emote packs, titles) and those you have equipped.
- Progression and play statistics: experience points, level, unlocked achievements, and lifetime table statistics such as hands played and hands won.
- Multiplayer room data: while you participate in a multiplayer game, the server tracks your seat and in-game actions so that they can be displayed to the other players in the room. When a room ends, its live game state is discarded. For real-chip tables, we retain a settlement record (the room code, buy-in, and timing) with your wallet ledger for as long as your account exists, in order to maintain an accurate chip history.
The App also maintains a local copy of the data described above on your device so that content renders immediately and reconciles against the server in the background. Deleting the App deletes this local copy.
Crash reports and diagnostics. This is the one area in which we collect information beyond gameplay data:
- Crash and error reports are transmitted to Sentry. A report includes a stack trace; your device model, operating system version, and App version; and, once you are signed in, your account identifier and display name (plus your email address on a claimed account). Reports also carry diagnostic context such as the screen you were on, randomly generated session and install identifiers, and, in a multiplayer game, the room code and the account identifiers of the other players seated at your table, which allows us to reconstruct the shared game state surrounding a defect. We associate reports with your account identity deliberately: it is how we locate your session and remediate account-specific issues.
- Bug reports you submit from the App include a log of that session's activity and, if you are in a multiplayer game, a snapshot of the current table state (which includes the other players at your table).
- Usage and reliability telemetry is transmitted to Grafana Cloud: discrete events such as "app opened," "room joined," or "purchase completed," together with warning-level logs when the App misbehaves, tagged with randomly generated session and install identifiers so that a single defective session can be traced end to end.
All diagnostic information is collected for the sole purpose of keeping the Services functioning. None of it is used for advertising, sold, or shared with any party for that party's own purposes.
Application permissions. The App requests the following device permissions:
- Notifications (opt-in): used solely for gameplay-related events. We do not send marketing or re-engagement notifications.
- Internet access: required for multiplayer play, wallet and inventory synchronization, and catalog downloads. Single-player play against bots functions offline; multiplayer does not.
2. How Do We Process Your Information?
We process your information to:
- Provide, operate, and maintain the Services, including facilitating multiplayer games between users;
- Synchronize your account, wallet, inventory, and progression across devices;
- Deliver the chips and virtual items you purchase;
- Maintain the security and integrity of the Services, including preventing cheating, fraud, and abuse;
- Diagnose, reproduce, and correct crashes and defects; and
- Comply with applicable legal obligations, including maintaining records of purchases.
We do not process your information for advertising or marketing purposes.
3. What Legal Bases Do We Rely On to Process Your Information? (EU and UK)
If you are located in the European Union or the United Kingdom, applicable data-protection law requires us to identify a legal basis for processing your personal information. We rely on the following bases: (1) performance of a contract, to deliver the Services and the chips and virtual items you purchase; (2) legitimate interests, namely operating the game, keeping it functioning, and preventing abuse; and (3) legal obligations, such as maintaining records of purchases. We do not conduct advertising or tracking that would require separate consent.
5. What Information Do We Not Collect?
The Services do not:
- Display advertising or integrate any advertising SDK;
- Use marketing or advertising-technology analytics (no Google Analytics, Mixpanel, Amplitude, or Facebook SDK);
- Collect your location;
- Access your contacts or photos (other than screenshots you voluntarily attach to a bug report); or
- Sell, rent, or share your personal information with third parties for marketing purposes.
6. How Are Payments Handled?
Chip packs are sold through the Apple App Store or Google Play. The payment transaction occurs between you and Apple or Google, respectively, under that platform's terms and privacy policy. We receive a receipt confirming that a purchase succeeded, which we use to credit chips to your account. We do not receive, see, or store your payment method information.
7. Is Your Information Transferred Internationally?
We do not operate our own data centers. Your account data (Supabase) and our game server (Fly.io) are hosted in the United States; Sentry and Grafana Cloud process diagnostic data on their own infrastructure. If you are located in the European Union or the United Kingdom, your use of the Services entails the transfer of your personal information to, and its processing in, the United States. For those transfers we rely on the safeguards our providers make available, including the European Commission's Standard Contractual Clauses, which Supabase, Fly.io, Sentry, and Grafana Cloud each publish.
8. How Long Do We Keep Your Information?
We retain your account data for as long as your account exists. An anonymous account that has clearly been abandoned (never claimed, with no purchases and no material progress) may be deleted automatically. The live state of a multiplayer room is discarded when the room ends; for real-chip tables, a settlement record is retained with your wallet ledger for as long as your account exists. Crash reports and telemetry expire on our providers' retention schedules, typically several weeks to a few months. When you delete your account, the data associated with it is removed as described in Section 14 (How Can You Review, Update, or Delete the Data We Collect?).
9. How Do We Keep Your Information Safe?
We have implemented appropriate technical and organizational measures designed to protect your personal information. Traffic between the App and our servers is encrypted in transit using HTTPS/TLS, and data at rest is held by established infrastructure providers under their own security commitments. However, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure. We mitigate this risk through data minimization: we do not hold payment details, location data, or contacts.
10. Do We Collect Information From Minors?
The Services are intended for adults. They are not directed at anyone under 18 years of age, and we do not knowingly collect personal information from anyone under 18. If we learn that personal information from a user under 18 has been collected, we will deactivate the account and delete the associated data. If you become aware that anyone under 18 has created an account, please contact us at contact@downcard.app.
11. What Are Your Privacy Rights?
Depending on where you live, you may have the right to:
- Access the personal information we hold about you;
- Correct it (your display name and avatar can be edited directly in the App);
- Delete it, either yourself from within the App (Profile → Account → Delete account) or by contacting us;
- Export a copy of it in a portable format;
- Restrict or object to our processing of it; and
- Withdraw consent, where processing is based on consent, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, contact us at contact@downcard.app. We will respond in accordance with applicable law. If you are located in the European Union or the United Kingdom and believe we are unlawfully processing your personal information, you also have the right to lodge a complaint with your local data-protection supervisory authority.
12. Controls for Do-Not-Track Features
Most web browsers and some mobile operating systems include a Do-Not-Track ("DNT") feature or setting. No uniform technology standard for recognizing and implementing DNT signals has been finalized, and we do not currently respond to DNT signals. If a standard for online tracking is adopted that we must follow in the future, we will inform you about that practice in a revised version of this Policy.
13. Do United States Residents Have Specific Privacy Rights?
If you reside in a US state with a comprehensive privacy law (such as California, Colorado, Connecticut, Texas, Utah, or Virginia), you may have additional rights with respect to your personal information. In the preceding twelve (12) months, we have collected the following categories of personal information: identifiers (account identifier, display name, email address on claimed accounts, and install and session identifiers); commercial information (records of chip-pack purchases and virtual-item transactions); and internet or other similar network activity (in-app interaction events and diagnostic logs). We do not collect protected classifications, biometric information, precise geolocation, audio or visual information, professional or employment information, education information, inferences, or sensitive personal information.
We have not sold or shared any personal information to or with third parties for a business or commercial purpose, including for cross-context behavioral advertising, and we do not use or disclose sensitive personal information.
Depending on your state, you may have the right to know what personal information we hold about you, to correct or delete it, to obtain a portable copy, and not to be discriminated against for exercising these rights. To exercise them, contact us at contact@downcard.app or use the in-App deletion path described in Section 14. Where your state's law provides for it, you may appeal a decision we make on your request by replying to our response, and you may also raise concerns with your state Attorney General.
14. How Can You Review, Update, or Delete the Data We Collect?
You may delete your account directly from within the App: Profile → Account → Delete account. Doing so removes your profile, wallet, inventory, and progression from our servers. There is no soft-delete grace period; deletion is immediate and permanent. Crash reports and telemetry already transmitted expire on our providers' retention schedules as described in Section 8. To request review, correction, export, or deletion of your personal information by other means, contact us at contact@downcard.app.
15. Do We Make Updates to This Policy?
We may update this Policy from time to time. The updated version will be posted on this page and indicated by a revised "Last updated" date above. Material changes will also be surfaced within the App upon your next launch. We encourage you to review this Policy periodically to stay informed about how we protect your information.
16. How Can You Contact Us About This Policy?
If you have questions or comments about this Policy, or wish to exercise any of the rights described in it, you may contact us at:
Nightjar Labs LLC
New York, NY, USA
contact@downcard.app