1. Who is responsible
1.1 The controller of your data is Governor, referred to here as Governor, or as we and us. The address for privacy enquiries and for all privacy correspondence is privacy@governorpoker.app.
1.2 Our server is hosted in the European Union. Processing personal data on infrastructure in the European Union brings the General Data Protection Regulation into play, and so does offering a service to people in the European Union. We do not treat that as a formality.
2. The short version
We collect three things:
- Who you are — your email address and the account identifier that comes from your Google sign-in, plus your payment record. Not your name, not your country, not your IP address. We never ask you for anything: the only thing you do at sign-up is accept these documents.
- What your computer is — a device identifier and a hardware fingerprint, so that a subscription runs on two devices and not two hundred. The fingerprint is a hash; we do not learn what hardware you have from it.
- What you asked the service about — in order to answer, the client sends us the table as it read it: your two cards, the community cards, the pot and the stacks.
And one thing you should know because it is unusual:
The client keeps a detailed record of every hand on your own computer — every decision, the assessment, how many chips you won or lost, and a moment-by-moment trace of your stack — together with full screenshots of your entire screen. Those files stay on your machine. The screenshots contain whatever else was visible at that moment, including other players' names and avatars.
3. Exactly what is collected
3.1 Account and identity
| data | where it comes from |
|---|---|
| A permanent account identifier issued by Google | your Google sign-in |
| Your email address | your Google sign-in |
| The identifier of a session, never the session token itself | issued when you sign in |
That is the whole of it. We do not have, and do not want, a password: sign-in is delegated to Google. We do not store your name. The display name Google returns was held at one point and has been removed, because it is needed for neither access, nor payment, nor blocking.
We never ask you for anything. There is no profile step, no questionnaire, and no optional fields. Your only action at sign-up is accepting these documents, and that records a fact rather than asking a question.
3.2 Your device
- A random device identifier, generated on first run and kept in the macOS Keychain.
- A hardware fingerprint, derived as a hash from an identifier the Mac exposes.
- The version of the client you last signed in with.
The fingerprint exists for one purpose: to hold a device slot so that the two-device limit means something. It is a hash, not an inventory. Your computer's name and your macOS version were once collected and have been removed from our records entirely.
3.3 Your consent
Every acceptance of a legal document is stored as evidence, and is never modified or deleted. The record consists of exactly four things:
| what it establishes | what is stored |
|---|---|
| who | your account, and the permanent Google account identifier behind it |
| what | the document, its revision, and a fingerprint of the exact published bytes you accepted |
| when | the moment of acceptance |
| from where | which of your devices |
We do not store your IP address, anywhere. It was once part of this record and has been removed, along with your browser's user-agent string. The reasoning, because it is better than saying we minimise data: an IP address proves none of the four things above. It does not establish identity, because virtual private networks, carrier-grade address translation and mobile networks see to that, and it establishes neither the text nor the time. The Google account identifier is strictly stronger. Keeping an address would have meant paying with the promise of an anonymous sign-up for evidence that was already complete without it.
3.4 Payment
- The deposit address assigned to your account, its chain and its asset.
- For each payment: the transaction hash, the block, the amount, the number of confirmations and the state.
A permanent deposit address on a public blockchain has a consequence you should know about. Your payments are permanently and publicly linkable to each other, by anyone, for ever. We cannot undo that, and deleting your account does not undo it.
3.5 What your client sends us when you play
To answer a request for an assessment, the client sends the recognised state of the table — your two cards, the community cards, the pot, the stacks, how many opponents there are and whose turn it is — together with an identifier for the hand, your device identifier and the client version.
We keep a per-day count of how many assessments were given. We do not keep a log of individual requests beyond what is described in section 8.
3.6 What stays on your computer
The client writes, on your own disk and for your own use, a detailed record of each decision point: the cards, the money in play, the assessment and the reasoning behind it, what happened at the end of the hand, how many chips you won or lost, and a moment-by-moment trace of your stack through the hand. Alongside each record it writes a screenshot of your whole screen, not a crop of the table, and a second one when the hand closes.
What this means for you, stated because it is true and not obvious. The client holds a rolling photographic record of your entire screen during play. If your mail client, your bank tab or a private message was visible behind the poker table, it is in those files. They are as private as your Mac is. You may delete them at any time and the service continues to work without them.
Screenshots are not uploaded. Two reasons, and the second matters more than the first: the volume would be enormous, and the frames contain the nicknames and avatars of other players who have no relationship with us.
4. What is never collected
- No nickname of any player is captured — not other players', and not yours. The part of the client that reads the table recognises shapes: cards, seats, the pot, the dealer button, bets and buttons. It has no class for text. The only characters it ever reads off a table are digits, and the blinds line. Players exist in our records as seat numbers only.
- No chat, no messages, no audio.
- No keystrokes and no mouse input, and nothing is ever synthesised. The client contains no input-generating code of any kind, which is also why it cannot act for you.
- No browsing history, and no enumeration of your other applications.
- No location, no advertising identifier, and no third-party analytics or trackers of any kind.
- No card details and no bank details. We never see a payment instrument, only a blockchain transaction.
- No IP address, anywhere.
- No name, no country, no phone number, no questionnaire, no avatar.
5. Why we collect it, and on what basis
| purpose | basis |
|---|---|
| Create and run your account and give you access | performance of the contract |
| Take and confirm payment, and renew the subscription | performance of the contract |
| Enforce the two-device limit | performance of the contract; our legitimate interest in preventing account sharing |
| Prove which revision of which document you accepted, and when | legal obligation; our legitimate interest in holding evidence |
| Improve the analysis, and measure whether its assessments were correct | legitimate interest |
| Suspend an account for non-payment, breach, or a venue request | performance of the contract; legitimate interest |
| Security, abuse and fraud | legitimate interest |
We do not sell your data, we do not share it for advertising, and we do not profile you for anything other than operating and improving the service.
6. Who else sees it
| recipient | what, and why |
|---|---|
| your sign-in. Google learns that you signed in to this service, because you chose Google sign-in. | |
| Our hosting provider | hosts the server in the European Union and therefore technically holds everything that reaches it. |
| The public blockchain | your deposit address and every transaction to it — permanently, irreversibly, visible to anyone. |
| A poker operator | only as described in section 7. |
| Law enforcement or a court | if legally required. |
We have no advertising partners, no analytics vendors and no data brokers.
7. Requests from a poker operator
7.1 We publish a page for poker operators describing how to contact us about a user of the service.
7.2 If we receive such a request and act on it, we may confirm to the requesting operator that access has been terminated. We do not undertake to disclose your identity, your email address, or your gameplay records to them, and we will not do so without a legal basis.
7.3 How a request is matched to an account. We hold no table nicknames, so we cannot connect a name at a poker table to an account of ours. A platform that wants a user of ours blocked sends us an email address — the step from nickname to email happens on their side, from their own registration records — and we act on that. We do not ask our customers for their screen names and we hold no such field.
7.4 Confirming to a third party that access has been terminated is itself a disclosure about you, and we treat it as one. It is deliberately the narrowest thing we are prepared to say.
8. How long we keep it
| data | retention |
|---|---|
| Records of your play that reach our server | 90 days in full detail. After 90 days only aggregates remain, as described below. |
| Your account record | while the account exists, then 90 days |
| Consent records | while the account exists, and after deletion. Not subject to the 90 days. |
| Payment records | as required by tax and accounting law. Years, not days. Not subject to the 90 days. |
| Screenshots and session records on your own computer | until you delete them. We do not delete them for you, and the 90 days does not apply to them: it governs our server, not your disk. |
8.1 The 90 days applies to records of your play and to nothing else. It is the answer to how long we keep a record of how you played. It is not a general deletion period: consent evidence and payment records deliberately outlive it, for the reasons below.
8.2 What survives after 90 days. After 90 days we keep only aggregates, and the distinction is deliberate: everything that makes the record behavioural is destroyed.
Deleted at 90 days, irreversibly: the moment-by-moment trace of your stack; your hole cards and the board; any cards revealed at showdown; the per-decision detail of actions, equities and reasoning; and timestamps finer than a calendar day.
Retained beyond 90 days: counts per calendar day, such as hands played and assessments given, broken down by type of action; aggregate quality statistics used to measure whether the assessments were any good; and the fingerprints of which build of the analysis served you.
What remains cannot reconstruct a hand, cannot show what you held, and cannot show what you did at any particular moment. It can show that on a given day you played, and roughly how much.
8.3 Consent records are not subject to the 90 days, on purpose. The record that you accepted a particular revision is kept for as long as the account exists, and after deletion. It is the evidence that the agreement was made, and evidence that expires before the obligation it evidences is not evidence. It is a very small record: a document identifier, a revision, a fingerprint, a timestamp and a device identifier.
8.4 A request pauses the clock. If you ask us for a copy of your data, or raise a complaint or a dispute, we suspend the 90-day deletion for the records in scope until it is resolved. Without that hold, a request arriving near the end of the window would be answered with data that had been deleted while the request was being handled.
8.5 Deleting local data yourself. Delete the session folder the client writes to, in Finder, like any other folder on your Mac. Revoke screen recording in macOS System Settings to stop new captures. The 90 days is about our server; these files are on your disk and stay until you remove them.
8.6 What cannot be deleted. Blockchain transactions to your deposit address are permanent and public. We cannot remove them, and no request to us can.
9. Your rights
9.1 If the General Data Protection Regulation applies to you, you have the right to access, rectify, erase, restrict, port and object; and to complain to your national supervisory authority. Write to privacy@governorpoker.app. We aim to answer within one month.
9.2 If you ask for a copy of your data, or for it to be deleted, the hold described in section 8.4 is applied first, so that the answer is not eaten by the retention clock while it is being prepared.
10. Security
10.1 Sign-in is delegated to Google and we hold no passwords. Session tokens are stored in the macOS Keychain on your machine, and the token itself is not stored on our server, only its identifier. Transport is encrypted.
10.2 The honest statement is that this is a small service operated by one person. We are not going to write industry-standard security or bank-grade encryption on this page. Those are claims, they are checkable, and overstating them would be a separate wrong from any breach.
10.3 If a breach occurs that is likely to risk your rights, we will notify you and the relevant authority as required.
11. Children
The service is not for anyone under 18. We do not knowingly collect data from minors, and we will delete it if we learn that we have.
12. International transfers
Data sits on infrastructure in the European Union; Governor may be outside it; customers are worldwide. Access to data held in the European Union from outside it is itself a transfer and needs a mechanism. We rely on the Standard Contractual Clauses adopted by the European Commission.
13. Changes, and contact
13.1 New revisions carry an identifier, for example privacy/v2, a date, and a fingerprint of the exact published text. Material changes are put to you for acceptance, and superseded revisions remain available on request.
13.2 If what leaves your computer ever changes — in particular if the per-hand records described in section 3.6 ever start being sent to us — this policy is re-issued as a new revision on the day that happens, and not afterwards.
13.3 Write to privacy@governorpoker.app.