Baize

Baize privacy policy

Effective date: [EFFECTIVE DATE]

This policy covers the Baize app for iOS and Android and the pages at baize.app. "Baize" is the app. "I" and "me" are the developer named below. "You" is the person using the app.

The controller of your personal data is [CONTROLLER NAME AND POSTAL ADDRESS]. For anything in this policy, write to hello@baize.app.

The short version

What Baize collects and why

What Where it comes from Where it goes Why
Your poker records You type them in, or import a CSV Your phone. With cloud backup on, also my cloud To give you the app, and to back it up
Account data You, when an account is created Supabase, my authentication provider To sign you in and to restore your data
Sign-in emails Sent to the address you give Resend, which delivers them To send codes for sign-up and password reset
Purchase data The App Store or Google Play, and RevenueCat RevenueCat and me To know whether Baize Edge is active
Hand text for line checks You, when you tap Line check My server, then Anthropic To return an AI line check
Crash reports The app, when it crashes or catches a failure Sentry To find and fix bugs
Update checks The app, at launch Expo's update service To deliver fixes without a new download
Server logs Requests to my authentication and storage services Supabase To keep the service secure
Your emails to me You My mailbox To answer you

Your poker records

These are the sessions, buy-ins, cash-outs, expenses, breaks, sold-action percentages and notes you log, with the currency and the exchange rate locked to each session. They also include live session events (rebuys, stack updates and timestamped notes), wallets and their transactions, venues, game types, tags, saved filter views, your bankroll rules and preferences, tournament details, and recorded hands with their cards, positions and actions.

Names and notes are whatever you type. Keep other people's personal details out of them.

All of it is stored in a database on your phone. Nothing leaves the phone unless cloud backup is on, you export a file, or you use a feature described below.

Accounts

Cloud backup

Purchases

Baize Edge is bought through the App Store or Google Play. Apple or Google takes the payment and never gives me your card or payment details. RevenueCat, my purchase provider, receives the purchase receipt and your Baize account ID, so it can tell me whether Edge is active on your account. I can see the product, price, dates, status and country of a subscription.

AI line checks

A line check runs only when you tap Line check on a hand. The app sends the text of that one hand to my server, signed in as your account so the server can check that Edge is active and that you are inside your usage allowance. The text is built from the hand itself: cards, positions and bet sizes. My server passes only that text to Anthropic's API, with no name, email or account ID, and returns the answer to you.

Anthropic does not use API inputs to train its models. It deletes inputs and outputs within 30 days, and may keep them longer only where its own terms allow, for example to enforce its usage policy or to meet a legal duty. My server keeps a count of the checks each account has used and does not keep the text.

Crash reports

When the app crashes or catches an unexpected failure, and the build carries a Sentry key, it sends Sentry the error and its stack, the app version, the platform, the OS version and the device model. It also sends anonymous session counts, so I can see how many sessions end in a crash. They carry a random install ID that the crash reporter generates, which changes if you reinstall the app. Baize does not link them to your account.

Baize sets the crash reporter not to collect personal data: no IP address inference, no tracing and no session replay. It also drops the console and network breadcrumbs, because those could carry balances or venue names. Error messages describe what failed rather than what you entered. If one ever carried a fragment of a record, it would reach Sentry with the report.

Update checks

At launch the app asks Expo's update service whether a newer version of its code is available. The request carries the app version, the platform, the update channel, a random install ID and your IP address, as every internet request does. It carries none of your records.

What Baize does not collect

The app has no advertising or analytics SDK and does no cross-app tracking. On Android it asks only for network access and the state of the network, and for purchases the Google Play billing permission. On iPhone it does not ask for any permission. The privacy policy and terms pages set no cookies and load nothing from other sites.

This table is for people covered by the GDPR, the UK GDPR or similar laws.

Purpose Basis
Running the app, accounts, sign-in, backup and restore, and sign-in emails Contract: it is the service you installed Baize to get (Article 6(1)(b))
Selling Baize Edge and checking that it is active Contract (Article 6(1)(b)). Tax and accounting records are kept under a legal obligation (Article 6(1)(c))
AI line checks Contract: you ask for each one (Article 6(1)(b))
Crash reports, update checks, and security and abuse prevention Legitimate interests in keeping the app working and secure, using as little data as possible (Article 6(1)(f))
Answering your emails Contract, or legitimate interests where you are not a user yet (Article 6(1)(b) and (f))

I do not rely on consent for any of this. Cloud backup is on by default because it is part of the service, and you can switch it off. You can object to anything I do under legitimate interests by writing to hello@baize.app.

Who receives your data

I use these providers to run Baize. Each acts on my instructions, as a processor, and only for the purpose in the table.

Provider What it does for Baize Where
Supabase Hosting, database, storage, authentication and server functions AWS us-east-2, Ohio, United States
Resend Delivering sign-in emails from hello@baize.app United States
Sentry Receiving crash reports United States
Expo Delivering app updates United States
RevenueCat Checking subscription status United States
Anthropic Producing AI line checks United States

Apple and Google run the stores and the payments. They are independent controllers of the data they hold, under their own policies.

I do not sell personal information. I do not share it for advertising or give it to data brokers. I may disclose data where the law requires it, to protect people's safety or rights, or to a buyer if the business is sold, and in that case you would be told first.

Transfers outside your country

Every provider above is in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data leaves that area. These transfers rely on the Standard Contractual Clauses in each provider's data processing agreement, and on the EU-US Data Privacy Framework where the provider is certified. Write to hello@baize.app for a description of the safeguards.

How long I keep data

Data Kept for
Records on your phone Until you delete them or the app. Baize never deletes them on its own.
Anonymous accounts, with their backups While the phone keeps using them. A job that runs daily removes an anonymous account, its backups and its records once it is more than 60 days old, with no sign-in activity and no backup in the last 60 days.
Email accounts Until you delete the account.
Backup files The newest ten plus the newest of each of the last thirty days, while the account exists.
After you delete your account Removed at once from my database and storage. Supabase's own infrastructure backups can hold a copy for up to 30 days before they expire.
Authentication logs A few days to a few weeks, as Supabase keeps them. The copy that would otherwise sit in my own database is switched off.
Crash reports 90 days at Sentry.
Hand text sent to Anthropic Up to 30 days at Anthropic, under its terms.
Purchase and tax records As long as tax and accounting law requires me to keep them.
Emails you send me Up to two years after the conversation ends.

Delete your data

In the app:

  1. Open Settings, then Cloud.
  2. Choose Delete account if you have an email account, or Delete cloud data if the phone only has an anonymous account.
  3. Confirm twice.

That removes your account, your database rows and your backups from my servers. Records on your phone stay, and delete when you delete the app or its data. Baize creates a fresh anonymous account afterwards only if cloud backup is still on.

If you cannot open the app, write to hello@baize.app from the address on the account with the subject "Delete my Baize account". I will delete the account and confirm within 30 days. An anonymous account has no name or email, so I cannot tell which one is yours from the outside. Use the in-app option, or leave it: it is deleted by itself after 60 days without use.

What can remain after a deletion: purchase and tax records that the law requires me to keep, copies in Supabase's own infrastructure backups until they expire, and crash reports at Sentry until they expire. None of them is tied to your name or email.

Other choices you have:

Your rights

If you are in the EEA, the UK or Switzerland you can ask me to give you access to your data, correct it, delete it, restrict how I use it, or hand it to you in a portable form. You can object to processing based on legitimate interests. You can complain to your data protection authority. Write to hello@baize.app. I answer within one month. I may ask you to prove the account is yours by writing from its email address. Most of this you can already do in the app, since the data is yours to export and delete. Baize makes no decisions about you by automated means. The statistics it shows are calculated from your own records, for you to read.

People in other countries with a privacy law, such as Brazil or Canada, can use the same address for the same requests.

California residents

This section is for residents of California under the CCPA as amended by the CPRA. In the last twelve months Baize has collected the following.

Category Examples Source Disclosed to
Identifiers Account ID, email address, random install IDs, IP address in server logs You and your device Supabase, Resend, Sentry, Expo, RevenueCat
Commercial information That you subscribed to Baize Edge, and when The stores and RevenueCat RevenueCat
Financial information you enter Buy-ins, cash-outs, results, expenses and wallet balances in your records You Supabase
Internet or network activity Crash reports, session counts, app version and device model Your device Sentry
Sensitive personal information: account log-in and password Your email and password, and the authenticator secret You Supabase

Baize does not collect geolocation, biometrics, audio or visual recordings, or employment or education information, and makes no inferences about you. I use the sensitive information only to sign you in and keep your account secure, so the right to limit its use does not apply.

I have not sold or shared personal information in the last twelve months, and I do not knowingly sell or share information about anyone under 18. Because of that there is no "Do Not Sell or Share" link.

You can ask me to tell you what I hold, delete it, or correct it, and I will not treat you worse for asking. Write to hello@baize.app, or use Delete your data above. I answer within 45 days, and I may take another 45 if I tell you why. An authorized agent can write on your behalf, and I will ask for proof of the authorization and of the account.

Security

No system is perfectly secure. If a breach affects you, I will tell you as the law requires.

Children

Baize is for people who are 18 or older, or of legal age to play poker where they live if that is higher. It is not directed at children, and I do not knowingly collect their data. If you think a child has an account, write to me and I will delete it.

Changes to this policy

When this policy changes I post the new version at this address and change the effective date. For a material change I will also tell account holders in the app or by email. Earlier versions are available on request.

Contact

hello@baize.app

[CONTROLLER NAME AND POSTAL ADDRESS]