Privacy Policy
DeNiro Card, operated by NIRO Corp · Last updated August 14, 2026
DeNiro Card is built to be played, not to profile you. A DeNiro account lets you recover one coin balance, Premium benefits, and durable cosmetics across supported devices. Guest training remains available without an email address, but coin-bearing games and purchases require a recoverable account. We do not use advertising trackers.
What's stored on your device
- Game stats — wins, losses, and streaks per game, saved in your browser's localStorage.
- Settings — sound, haptics, hints, difficulty, and house rules you pick.
- Analytics choice — “Allow analytics” or “No thanks,” stored only on this device. It is not an account, device, install, or session ID.
- Legacy web Premium token — if you previously bought the former web unlock, a proof-of-purchase token may be saved in localStorage so that purchase can be verified on that browser.
- Wallet cache — while you are signed in, the app may cache the last server-confirmed coin balance, reward eligibility, level progress, Premium status, and an in-progress game reference so the interface can recover cleanly. The cache is display state only and cannot grant, spend, or settle coins.
Those items live on your device. Clearing browser data removes the local copies, including a legacy web Premium token. A signed-in coin balance, eligible virtual items, and active game-session state are recovered from the server. Apple App Store, Google Play, and Microsoft Store purchases remain tied to the store account that bought them and are re-checked with that provider. A Stripe website purchase is instead bound to the DeNiro account that was authenticated at checkout.
Your DeNiro account
If you create an account on the website or a supported DeNiro Card app, we collect your email address and assign a User ID. Accounts are optional for zero-stake guest training. An account is required before a coin-bearing Practice, Regular, or Online game and before a new coin-pack or Premium order, so every reservation, result, receipt, refund, and Restore is bound to the correct owner. Guests may view the shop, but billing does not begin until sign-in succeeds.
- Email address — used to identify your account, send sign-in codes, verification and recovery messages, and let you sign back in with email/password. It is not sold, rented, or used for marketing.
- Authentication data — a securely hashed password (if you set one), sign-in timestamps, and a session token stored in your browser so you stay signed in.
- Sign in with Google — if you choose it, Google shares your email address and basic profile identifier with us. We never receive your Google password.
- Account-linked data — once signed in, your single coin balance, wallet-event history, reward and level state, Premium entitlement periods, durable cosmetics, active game-session references, stakes, and settlement state can recover across signed-in devices. Local presentation preferences and aggregate solo stats are not account-synced.
Processor. Accounts and their data are hosted for us by Supabase (Supabase, Inc.), acting as our data processor on servers it operates. We use a dedicated DeNiro Card project that is separate from our other apps.
Deleting your account. You can delete your account at any time from the in-app or website account panel — open Sign in → Delete account — or use the public account-deletion page. Before deletion finishes, our server attempts to expire open Stripe website checkouts and cancel any exact Stripe website subscription bound to that DeNiro account; if Stripe cancellation cannot be confirmed, deletion stops so you can retry while still able to sign in. We cannot cancel an Apple, Google, or Microsoft store subscription on your behalf, so cancel store renewal in the store account that billed you. Deletion closes the sign-in account, removes reward streak and level state, refunds unresolved coin reservations, revokes active VIP benefits, and permanently removes or de-identifies non-audit data. It cannot be undone. You can also email us and we will action it after verifying ownership.
Retention. Required payment, receipt-replay, refund, dispute, fraud-prevention, wallet-event, and game-settlement audit records may remain linked to a locked deleted-account tombstone where law, platform rules, or ledger integrity require it; they cannot be used to sign in or resume play. Other account data is kept only until deletion. Guest training creates no DeNiro account record. If usage analytics is active, the limited analytics and security processing described below still occurs.
Usage analytics
DeNiro Card includes a privacy-minimal, first-party usage analytics client. Usage analytics is enabled in this release under the controls described here and disclosed in the store privacy labels.
Usage analytics is on by default and disclosed — there is no separate pop-up asking permission first — except in the EU/UK, where it stays off until you agree. You can turn it off (or back on) any time from the analytics & privacy settings on this device. Global Privacy Control or Do Not Track always turns it off, everywhere.
When on, it may send only: a one-time random event UUID; a fixed event name and one fixed category; web/iOS/Android surface; the major.minor app release; a coarse device family and OS (e.g. “iPhone”, “ios17”); a coarse country derived by the server from your connection; and, if you buy something, that a purchase completed. The server reads the source network address only to derive that country and enforce abuse limits. It does not store the raw address in an analytics record; it keeps a secret-keyed, non-reversible rate-limit digest for no more than 10 minutes. If the app hits an error it may send a bounded crash report (error type and a truncated, address- and email-stripped message/stack) to help us fix bugs. Aggregated counts are kept about 13 months; crash reports about 90 days.
Usage analytics never contains cards, hands, moves, room or table codes, names, chat, balances, wagers, account/install/session IDs, receipts, payment amounts, page addresses, referrers, precise location, arbitrary properties, or game content. It is not used for advertising and does no cross-app tracking.
Gameplay and multiplayer
Coin-bearing Practice, Regular, and Online games use an authenticated game service. It processes your assigned User ID, chosen display name, game and mode, selected stake and opponent count, legal actions, action sequence numbers, public table state, your private hand, turn and reconnect timing, outcome, forfeit state, and wallet reservation or settlement references. It also processes ordinary network information such as your IP address and service/security logs. A player receives only the private state for that player's seat.
Online public matchmaking pairs compatible real players randomly, without exposing a choice of opponent. Table participants receive the public game state, display names, and post-reservation play-coin stacks needed to present the table; they do not receive another player's private hand, email address, receipt, or payment details. Reconnect state is retained long enough to resume an interrupted table. A confirmed quit or expired reconnect window can forfeit only the stake already reserved for that game; it does not create an additional financial penalty. Do not use a display name to share sensitive personal information.
Local presentation preferences and aggregate solo stats are not uploaded. Authoritative session, action, anti-abuse, and settlement records are retained as needed to reconnect, prevent replay or cheating, resolve disputes, and protect the wallet ledger.
Payments
Where a store-approved paid build offers native coin packs or Premium VIP, Apple App Store, Google Play, or Microsoft Store processes the payment for that platform. Card details go directly to the store — we never see or store card numbers — and localized prices come from the store. A build without approved paid controls does not open a purchase sheet.
Where denirocard.com offers website checkout, Stripe processes that separate USD payment. We send Stripe an app- and User-ID-bound customer record, the selected product, and the minimum checkout metadata needed to attribute the receipt, refund, or subscription to the correct DeNiro account. Stripe receives payment details directly; NIRO does not receive or store the full card number. A browser never supplies the Stripe customer identifier used to open billing management; the server recovers it from the authenticated account and rejects a customer or subscription tagged to another app or owner.
Before a new coin-pack or Extra Spin order, the app or website requires a recoverable account and creates a short-lived, account- and product-bound purchase intent. It sends the provider product ID, transaction identifier, signed receipt or purchase token where applicable, assigned User ID, and that intent identifier to NIRO's receipt-validation service. The service verifies the transaction with the billing provider, prevents replay, and records the account-linked Purchase History and authoritative coin balance. Fixed coin packs grant the displayed amount. An Extra Spin grants only its server-selected wheel prize and has no fixed coin grant. Refund and revocation notifications may adjust that balance or create debt if coins were already used.
Premium VIP is an auto-renewable monthly or yearly subscription where offered. Before a new subscription order, the app or website requires a recoverable account. The server records provider-confirmed entitlement periods so the 2× monthly or 3× yearly daily and level-progress multipliers, monthly stipend eligibility, high-roller access, Premium table and deck, and selected name emoji can be applied exactly once and revoked when the provider reports expiry or refund. The selected emoji preference is stored with the signed-in account, but it is displayed only while the server confirms an active subscription. Manage Stripe website renewal from the authenticated DeNiro account, which opens Stripe's hosted portal. Manage native-store renewal in the store account that made the purchase. Billing eligibility does not automatically transfer among Stripe, Apple, Google, and Microsoft.
Coins always move one way. Free rewards, game results, and verified purchases all enter the same account wallet. Coins may be used only inside DeNiro Card for simulated-game stakes and virtual items. They cannot be sold, gifted for real-world value, redeemed, withdrawn, cashed out, or converted to money, prizes, or outside-app goods or services. Purchased coins do not expire.
What we don't do
- No advertising networks or ad tracking in this release. A future optional rewarded-ad feature will not grant coins unless the ad provider's server verifies completion and the privacy labels are updated first.
- No sale of personal data. Our account, game, hosting, analytics, and store providers process data only to operate the features described above; table participants receive only the shared public game state.
Contact
Questions about privacy or a purchase? Email support@niroaerial.com.