đŸŒč DeNiro Card
← All games

Privacy Policy

DeNiro Card, operated by NIRO Corp · Last updated August 31, 2026

DeNiro Card is built to be played, not to profile you. A protected DeNiro account lets you recover one coin balance, Online play, Premium benefits, rewards, and durable cosmetics across supported devices. Where native ordinary coin packs are offered, tapping a fixed pack may first create a no-profile device wallet so that purchase has a durable owner; simply opening the Shop or loading prices never creates one. That wallet may use its purchased coins for server-authoritative Solo games on the same device. It must be protected with email, Apple, or Google before Online play, free rewards, Premium, profile features, protected-account export or deletion, or cross-device sync and Restore. We do not use advertising trackers.

What's stored on your device

Those items live on your device. Clearing browser or app data removes local copies, including a legacy web Premium token and, on a native app, may permanently remove local access to an unprotected device wallet. Its balance and Solo session can recover only while that same secure device-wallet session remains available. A protected-account balance, eligible virtual items, and active game-session state can recover across supported signed-in devices. Apple App Store, Google Play, and Microsoft Store purchases remain tied to the store account that bought them and are re-checked with that provider, but Restore does not invent a new wallet or copy value to a different User ID. Protecting a device wallet keeps the same User ID and balance. A Stripe website purchase is instead bound to the protected DeNiro account authenticated at checkout.

Your DeNiro account

If you create or protect an account with email on the website or a supported DeNiro Card app, we collect your email address and assign a User ID. Apple or Google protection uses the provider data described below. A protected account is required for Online/social multiplayer, Premium, every welcome, sign-in, daily, hourly, ad, and level reward, profile and cosmetic management, password reset, protected-account export or deletion, and cross-device sync and Restore. On a supported native app, a signed-out player may browse the Shop and may tap one fixed ordinary coin pack; only that tap may create a durable, anonymous device wallet and continue to the store billing sheet. It has a random User ID but no email, name, phone number, or public profile. After server verification, it may read and spend those purchased coins only for stake reservations and settlements in server-authoritative Regular Solo games on that same device. It cannot use Online play, free rewards, Premium, profile/cosmetic management or purchases, password reset, protected-account export or deletion, or cross-device sync and Restore until the player chooses Protect & Sync. Protection links email, Apple, or Google to the same User ID and balance; it never copies or merges coins. Restore never creates a device wallet or a different User ID.

Quick sign-in availability. Google and Apple sign-in are available on the website and enabled only in the iPhone, iPad, Android, and macOS test candidates. They are not represented as public native-app features until each exact signed, store-installed build passes provider consent, callback, secure session recovery, relaunch, sign-out, and account-deletion reauthentication testing. Windows quick-sign-in buttons remain hidden until one exact public-candidate package combines them with Microsoft Store buying and passes the same installed-app proof. Email uses one Continue path: a valid existing password signs you in; otherwise the same private emailed-code screen creates or recovers the account without revealing which it was. Code verification stays in memory, and the web or mobile app installs no durable session until the server-confirmed email account has completed password setup. Facebook sign-in is unavailable on every platform.

Processors and sign-in providers. Accounts and their data are hosted for us by Supabase (Supabase, Inc.), acting as our data processor on servers it operates. We use a dedicated DeNiro Card project that is separate from our other apps. If you choose a social sign-in, Google or Apple also processes that sign-in under its own terms and privacy policy. If Facebook sign-in is offered in a future release, Meta will process that sign-in under its own terms and privacy policy.

Deleting your account. You can delete your protected account at any time from the in-app or website account panel. Open Sign in → Delete account, or use the public account-deletion page. Before deletion finishes, our server attempts to expire open Stripe website checkouts and cancel any exact Stripe website subscription bound to that DeNiro account; if Stripe cancellation cannot be confirmed, deletion stops so you can retry while still able to sign in. If the account used Sign in with Apple, the server also requires a credential bound to that exact Apple identity and asks Apple to revoke it before the DeNiro sign-in identity is removed. A missing, mismatched, or ambiguously failed Apple response stops deletion and asks for a fresh Apple verification or retry; manual cleanup is not treated as completed deletion. This provider step does not cancel an App Store subscription. We cannot cancel an Apple, Google, or Microsoft store subscription on your behalf, so cancel store renewal in the store account that billed you. Deletion closes the sign-in account, removes reward streak and level state, returns unresolved held play coins, revokes active VIP benefits, and permanently removes or de-identifies non-audit data. It cannot be undone. If Facebook sign-in is offered later, removing DeNiro Card through Facebook will send us a cryptographically signed removal request. We will use its app-scoped identifier only to locate and delete the linked DeNiro account; the callback does not need or trust an email address, and its public status page uses only an opaque confirmation code. You can also email us and we will action it after verifying ownership.

Removing a device wallet. An unprotected purchase-created wallet has its own two-step Remove this device wallet action; it does not use the protected-account deletion page. The confirmation warns that removal is permanent and any coins left in the wallet cannot be recovered. The server safely returns or cancels an active Solo reservation first, then hard-deletes the anonymous authentication user and operational wallet identity, whether the wallet is empty or still has purchased coins. Only the minimum pseudonymous receipt-replay, provider refund or reversal, fraud, accounting, settlement, and deletion tombstones needed to reject a reused receipt and process later provider events remain. The app clears its local wallet credential and activity record only after the server confirms that exact deletion. If a network, timeout, or ambiguous response prevents confirmation, those local recovery records remain and the app retries the same removal-request UUID instead of starting a second deletion; wallet use still requires live server revalidation.

Retention. Required payment, receipt-replay, provider reversal, dispute, fraud-prevention, wallet-event, game-settlement, and deletion audit records may remain linked to a locked protected-account or removed-device-wallet tombstone where law, platform rules, accounting, security, or ledger integrity requires it; they cannot be used to sign in, recreate the wallet, or resume play. Other account and device-wallet data is kept only until deletion or removal. If usage analytics is active, the limited analytics and security processing described below still occurs.

Usage analytics

DeNiro Card includes a privacy-minimal, first-party usage analytics client. Usage analytics is enabled in this release under the controls described here and disclosed in the store privacy labels.

Usage analytics is on by default and disclosed. There is no separate pop-up asking permission first. In the EU/UK, it stays off until you agree. You can turn it off (or back on) any time from the analytics & privacy settings on this device. Global Privacy Control or Do Not Track always turns it off, everywhere.

When on, it may send only: a one-time random event UUID; a fixed event name and one fixed category; web/iOS/Android surface; the major.minor app release; a coarse device family and OS (e.g. “iPhone”, “ios17”); a coarse country derived by the server from your connection; and, if you buy something, that a purchase completed. The server reads the source network address only to derive that country and enforce abuse limits. It does not store the raw address in an analytics record; it keeps a secret-keyed, non-reversible rate-limit digest for no more than 10 minutes. If the app hits an error it may send a bounded crash report (error type and a truncated, address- and email-stripped message/stack) to help us fix bugs. Aggregated counts are kept about 13 months; crash reports about 90 days.

Usage analytics never contains cards, hands, moves, room or table codes, names, chat, balances, wagers, account/install/session IDs, receipts, payment amounts, page addresses, referrers, precise location, arbitrary properties, or game content. It is not used for advertising and does no cross-app tracking.

How we use your account records internally

Separately from the anonymous usage analytics above, we also read the account-linked records already described to run the business. These include your game sessions, the games and modes you played, when you played them, session outcomes, and your wallet and purchase history. They show which games are actually played and for how long, how much time an account spends in the app, and what has been purchased. This is a normal part of operating a paid product and it tells us which games to keep improving.

This is internal only. It is not sold, rented, shared with advertisers, or used to target advertising, and it is not combined with data from other companies. Access is restricted to NIRO CORP and its data processors. It uses the account records we already keep for the reasons stated in this policy. Turning analytics off does not remove your wallet or game-session history, because those records exist to protect the ledger and resolve disputes, not for analytics.

Deleting your account removes or de-identifies this data on the same terms as the rest of your account, subject only to the audit records described under Retention above.

Gameplay and multiplayer

Bot and Online coin games use an authenticated game service. A same-device device wallet may use this service only for Solo/bot games bought with its purchased coins; Online play requires a protected account. The service processes your assigned User ID, a random non-editable Player-XXXXXX alias, game and mode, selected stake and opponent count, legal actions, action sequence numbers, public table state, your private hand, turn and reconnect timing, outcome, forfeit state, and wallet reservation or settlement references. Players cannot enter a name, biography, status, chat message, or other free-form public text. It also processes ordinary network information such as your IP address and service/security logs. A player receives only the private state for that player's seat.

Online public matchmaking pairs compatible real players randomly, without exposing a choice of opponent. Table participants receive the public game state, assigned aliases, connection state, consecutive-miss count, server-controlled-seat state, and post-reservation play-coin stacks needed to present the table; they do not receive another player's private hand, email address, receipt, or payment details. The authenticated waiting-table directory contains only game, exact stake, target, and seat counts, never player identity. Reconnect state is retained long enough to resume an interrupted table. Leaving or disconnecting during the server-owned pre-deal countdown dissolves the pending table and returns every held stake in full with no surcharge. After activation, a deliberate confirmed quit, expired reconnect/drop, or third consecutive missed Online turn forfeits the reserved stake and adds a 10% play-coin abandonment surcharge. The first two missed Online turns safely auto-play without surcharge and a valid human action resets the count; an ordinary Solo turn expiry keeps its stake-only timeout result. An abandoned account receives no later payout or returned stake on a draw, and its canonical would-be share is burned rather than redistributed. A play-coin shortfall from the abandonment surcharge may be offset from later coin credits, but it is never a currency charge or store purchase.

Local presentation preferences and aggregate solo stats are not uploaded. Authoritative session, action, anti-abuse, and settlement records are retained as needed to reconnect, prevent replay or cheating, resolve disputes, and protect the wallet ledger.

Payments

Where a store-approved paid build offers native coin packs or Premium VIP, Apple App Store, Google Play, or Microsoft Store processes the payment for that platform. Card details go directly to the store. We never see or store card numbers. Localized prices come from the store. A build without approved paid controls does not open a purchase sheet.

Where denirocard.com offers website checkout, Stripe processes that separate USD payment. We send Stripe an app- and User-ID-bound customer record, the selected product, and the minimum checkout metadata needed to attribute the receipt, provider reversal, or subscription to the correct DeNiro account. Stripe receives payment details directly; NIRO does not receive or store the full card number. A browser never supplies the Stripe customer identifier used to open billing management; the server recovers it from the authenticated account and rejects a customer or subscription tagged to another app or owner.

Before a new coin-pack order, the app or website uses the billing and account flow offered on that platform and creates a short-lived purchase intent bound to the applicable store or DeNiro account and product. It sends the provider product ID, transaction identifier, signed receipt or purchase token where applicable, the applicable owner identifier, and that intent identifier to NIRO's receipt-validation service. The service verifies the transaction with the billing provider, prevents replay, and records the associated Purchase History and authoritative coin balance. Fixed coin packs grant the displayed amount. The historical Extra Spin product is unavailable for new purchase; an eligible older receipt may still be processed for reconciliation. Provider refund, revocation, reversal, or chargeback notifications may adjust that balance or create debt if coins were already used.

Premium VIP is an auto-renewable monthly or yearly subscription where offered. A new subscription uses the billing and account flow offered on that platform. The server records provider-confirmed entitlement periods so the 2× monthly or 3× yearly daily and level-progress multipliers, monthly stipend eligibility, high-roller access, Premium table and deck, and selected name emoji can be applied exactly once and revoked when the provider reports expiry, refund, or revocation. The selected emoji preference is stored with the signed-in account, but it is displayed only while the server confirms an active subscription. Manage Stripe website renewal from the authenticated DeNiro account, which opens Stripe's hosted portal. Manage native-store renewal in the store account that made the purchase. Billing eligibility does not automatically transfer among Stripe, Apple, Google, and Microsoft.

Coins always move one way. Verified purchases and game results enter the applicable device or protected-account wallet; free rewards enter protected-account wallets only. Coins may be used only inside DeNiro Card for simulated-game stakes and permitted virtual items. They cannot be sold, gifted for real-world value, redeemed, withdrawn, cashed out, or converted to money, prizes, or outside-app goods or services. Purchased coins do not expire.

What we don't do

Contact

Questions about privacy or a purchase? Email support@denirocard.com.