Privacy Policy
DeNiro Card, operated by NIRO Corp · Last updated August 31, 2026
DeNiro Card is built to be played, not to profile you. A protected DeNiro account lets you recover one coin balance, Online play, Premium benefits, rewards, and durable cosmetics across supported devices. Where native ordinary coin packs are offered, tapping a fixed pack may first create a no-profile device wallet so that purchase has a durable owner; simply opening the Shop or loading prices never creates one. That wallet may use its purchased coins for server-authoritative Solo games on the same device. It must be protected with email, Apple, or Google before Online play, free rewards, Premium, profile features, protected-account export or deletion, or cross-device sync and Restore. We do not use advertising trackers.
What's stored on your device
- Game stats: wins, losses, and streaks per game, saved in your browser's localStorage.
- Settings: sound, haptics, hints, difficulty, and house rules you pick.
- Analytics choice: âAllow analyticsâ or âNo thanks,â stored only on this device. It is not an account, device, install, or session ID.
- Legacy web Premium token: if you previously bought the former web unlock, a proof-of-purchase token may be saved in localStorage so that purchase can be verified on that browser.
- Account or device-wallet session: the website stores a protected Supabase account session in that browser's localStorage. The iPhone and iPad apps store a protected-account or purchase-created device-wallet session in a device-only, non-synchronizing Apple Keychain item; the Android app encrypts it with a key held by Android Keystore and stores only the ciphertext in app-private, backup-excluded storage. After a verified migration, both apps remove any legacy session from embedded-browser storage and fail closed if their secure native store is unavailable. The fully native macOS and Windows clients use macOS Keychain and Windows Credential Locker. A protected session keeps the account ID and last authenticated activity for up to 150 days of inactivity. A purchase-created device-wallet session is not discarded merely because that 150-day period passes, so purchased coins are not silently stranded; before wallet access, including after more than 150 days, the app must revalidate the live canonical anonymous user and device-wallet binding. A missing, mismatched, or definitively rejected binding fails closed without crediting coins or authorizing wallet use. A device wallet contains an opaque User ID and tokens but no email, name, phone number, or profile. Malformed, future-dated, mismatched-account, expired, or definitively rejected sessions are cleared. A temporary offline, timeout, or server error retains the credential so recovery remains possible, but does not authorize wallet use or paid play until authentication succeeds. Signing out or deleting a protected DeNiro account removes its local session and activity record from that client; clearing browser or app data can also remove local access.
- Wallet cache: while a protected-account or device-wallet session is active, the app may cache the last server-confirmed coin balance and an in-progress game reference; a protected account may also cache reward eligibility, level progress, and Premium status. The cache is display state only and cannot grant, spend, or settle coins.
Those items live on your device. Clearing browser or app data removes local copies, including a legacy web Premium token and, on a native app, may permanently remove local access to an unprotected device wallet. Its balance and Solo session can recover only while that same secure device-wallet session remains available. A protected-account balance, eligible virtual items, and active game-session state can recover across supported signed-in devices. Apple App Store, Google Play, and Microsoft Store purchases remain tied to the store account that bought them and are re-checked with that provider, but Restore does not invent a new wallet or copy value to a different User ID. Protecting a device wallet keeps the same User ID and balance. A Stripe website purchase is instead bound to the protected DeNiro account authenticated at checkout.
Your DeNiro account
If you create or protect an account with email on the website or a supported DeNiro Card app, we collect your email address and assign a User ID. Apple or Google protection uses the provider data described below. A protected account is required for Online/social multiplayer, Premium, every welcome, sign-in, daily, hourly, ad, and level reward, profile and cosmetic management, password reset, protected-account export or deletion, and cross-device sync and Restore. On a supported native app, a signed-out player may browse the Shop and may tap one fixed ordinary coin pack; only that tap may create a durable, anonymous device wallet and continue to the store billing sheet. It has a random User ID but no email, name, phone number, or public profile. After server verification, it may read and spend those purchased coins only for stake reservations and settlements in server-authoritative Regular Solo games on that same device. It cannot use Online play, free rewards, Premium, profile/cosmetic management or purchases, password reset, protected-account export or deletion, or cross-device sync and Restore until the player chooses Protect & Sync. Protection links email, Apple, or Google to the same User ID and balance; it never copies or merges coins. Restore never creates a device wallet or a different User ID.
Quick sign-in availability. Google and Apple sign-in are available on the website and enabled only in the iPhone, iPad, Android, and macOS test candidates. They are not represented as public native-app features until each exact signed, store-installed build passes provider consent, callback, secure session recovery, relaunch, sign-out, and account-deletion reauthentication testing. Windows quick-sign-in buttons remain hidden until one exact public-candidate package combines them with Microsoft Store buying and passes the same installed-app proof. Email uses one Continue path: a valid existing password signs you in; otherwise the same private emailed-code screen creates or recovers the account without revealing which it was. Code verification stays in memory, and the web or mobile app installs no durable session until the server-confirmed email account has completed password setup. Facebook sign-in is unavailable on every platform.
- Email address: used to identify your account, send sign-in codes, verification and recovery messages, and let you sign back in with email/password. It is not sold, rented, or used for marketing.
- Authentication data: a securely hashed password (if you set one), sign-in timestamps, provider and account identifiers, and the session tokens stored on the device as described above.
- Sign in with Google: if you choose it on an available surface, Google shares your email address, a provider account identifier, and provider profile name with us. That name stays account data and is never used as your public table alias. We never receive your Google password.
- Sign in with Apple: if you choose it on an available surface, Apple shares an account identifier, the email address you authorize (which may be an Apple private-relay address), andâonly on the first authorizationâthe name you authorize. We keep only a sanitized first name for your private account header and your own local seat; opponents still receive a random player alias. Apple may not return the name again for an existing authorization, in which case DeNiro shows the generic Account/You labels. We never receive your Apple Account password.
- Facebook sign-in: not offered in the current release and no Facebook button is shown. If it is enabled in a future release, the active app and store disclosures will be updated first; Facebook may share an app-scoped account identifier, basic profile information you authorize, and an email address only when one is available and you authorize it. We never receive your Facebook password.
- Device-wallet data: before protection, the server keeps the opaque User ID, purchase intent and receipt-verification state, provider reversals, wallet events and balance, and the Solo game stakes, actions, session state, results, settlement, and necessary in-game item debits needed to run and audit same-device Solo play. It does not create free-reward, profile, Premium, Online/social, password-reset, export, deletion-lifecycle, or cross-device synchronization data.
- Protected account-linked data: once protected and signed in, your single coin balance, wallet-event history, reward and level state, Premium entitlement periods, durable cosmetics, active game-session references, stakes, and settlement state can recover across signed-in devices. Local presentation preferences and aggregate solo stats are not account-synced.
Processors and sign-in providers. Accounts and their data are hosted for us by Supabase (Supabase, Inc.), acting as our data processor on servers it operates. We use a dedicated DeNiro Card project that is separate from our other apps. If you choose a social sign-in, Google or Apple also processes that sign-in under its own terms and privacy policy. If Facebook sign-in is offered in a future release, Meta will process that sign-in under its own terms and privacy policy.
Deleting your account. You can delete your protected account at any time from the in-app or website account panel. Open Sign in â Delete account, or use the public account-deletion page. Before deletion finishes, our server attempts to expire open Stripe website checkouts and cancel any exact Stripe website subscription bound to that DeNiro account; if Stripe cancellation cannot be confirmed, deletion stops so you can retry while still able to sign in. If the account used Sign in with Apple, the server also requires a credential bound to that exact Apple identity and asks Apple to revoke it before the DeNiro sign-in identity is removed. A missing, mismatched, or ambiguously failed Apple response stops deletion and asks for a fresh Apple verification or retry; manual cleanup is not treated as completed deletion. This provider step does not cancel an App Store subscription. We cannot cancel an Apple, Google, or Microsoft store subscription on your behalf, so cancel store renewal in the store account that billed you. Deletion closes the sign-in account, removes reward streak and level state, returns unresolved held play coins, revokes active VIP benefits, and permanently removes or de-identifies non-audit data. It cannot be undone. If Facebook sign-in is offered later, removing DeNiro Card through Facebook will send us a cryptographically signed removal request. We will use its app-scoped identifier only to locate and delete the linked DeNiro account; the callback does not need or trust an email address, and its public status page uses only an opaque confirmation code. You can also email us and we will action it after verifying ownership.
Removing a device wallet. An unprotected purchase-created wallet has its own two-step Remove this device wallet action; it does not use the protected-account deletion page. The confirmation warns that removal is permanent and any coins left in the wallet cannot be recovered. The server safely returns or cancels an active Solo reservation first, then hard-deletes the anonymous authentication user and operational wallet identity, whether the wallet is empty or still has purchased coins. Only the minimum pseudonymous receipt-replay, provider refund or reversal, fraud, accounting, settlement, and deletion tombstones needed to reject a reused receipt and process later provider events remain. The app clears its local wallet credential and activity record only after the server confirms that exact deletion. If a network, timeout, or ambiguous response prevents confirmation, those local recovery records remain and the app retries the same removal-request UUID instead of starting a second deletion; wallet use still requires live server revalidation.
Retention. Required payment, receipt-replay, provider reversal, dispute, fraud-prevention, wallet-event, game-settlement, and deletion audit records may remain linked to a locked protected-account or removed-device-wallet tombstone where law, platform rules, accounting, security, or ledger integrity requires it; they cannot be used to sign in, recreate the wallet, or resume play. Other account and device-wallet data is kept only until deletion or removal. If usage analytics is active, the limited analytics and security processing described below still occurs.
Usage analytics
DeNiro Card includes a privacy-minimal, first-party usage analytics client. Usage analytics is enabled in this release under the controls described here and disclosed in the store privacy labels.
Usage analytics is on by default and disclosed. There is no separate pop-up asking permission first. In the EU/UK, it stays off until you agree. You can turn it off (or back on) any time from the analytics & privacy settings on this device. Global Privacy Control or Do Not Track always turns it off, everywhere.
When on, it may send only: a one-time random event UUID; a fixed event name and one fixed category; web/iOS/Android surface; the major.minor app release; a coarse device family and OS (e.g. âiPhoneâ, âios17â); a coarse country derived by the server from your connection; and, if you buy something, that a purchase completed. The server reads the source network address only to derive that country and enforce abuse limits. It does not store the raw address in an analytics record; it keeps a secret-keyed, non-reversible rate-limit digest for no more than 10 minutes. If the app hits an error it may send a bounded crash report (error type and a truncated, address- and email-stripped message/stack) to help us fix bugs. Aggregated counts are kept about 13 months; crash reports about 90 days.
Usage analytics never contains cards, hands, moves, room or table codes, names, chat, balances, wagers, account/install/session IDs, receipts, payment amounts, page addresses, referrers, precise location, arbitrary properties, or game content. It is not used for advertising and does no cross-app tracking.
How we use your account records internally
Separately from the anonymous usage analytics above, we also read the account-linked records already described to run the business. These include your game sessions, the games and modes you played, when you played them, session outcomes, and your wallet and purchase history. They show which games are actually played and for how long, how much time an account spends in the app, and what has been purchased. This is a normal part of operating a paid product and it tells us which games to keep improving.
This is internal only. It is not sold, rented, shared with advertisers, or used to target advertising, and it is not combined with data from other companies. Access is restricted to NIRO CORP and its data processors. It uses the account records we already keep for the reasons stated in this policy. Turning analytics off does not remove your wallet or game-session history, because those records exist to protect the ledger and resolve disputes, not for analytics.
Deleting your account removes or de-identifies this data on the same terms as the rest of your account, subject only to the audit records described under Retention above.
Gameplay and multiplayer
Bot and Online coin games use an authenticated game service. A same-device device wallet may use this service only for Solo/bot games bought with its purchased coins; Online play requires a protected account. The service processes your assigned User ID, a random non-editable Player-XXXXXX alias, game and mode, selected stake and opponent count, legal actions, action sequence numbers, public table state, your private hand, turn and reconnect timing, outcome, forfeit state, and wallet reservation or settlement references. Players cannot enter a name, biography, status, chat message, or other free-form public text. It also processes ordinary network information such as your IP address and service/security logs. A player receives only the private state for that player's seat.
Online public matchmaking pairs compatible real players randomly, without exposing a choice of opponent. Table participants receive the public game state, assigned aliases, connection state, consecutive-miss count, server-controlled-seat state, and post-reservation play-coin stacks needed to present the table; they do not receive another player's private hand, email address, receipt, or payment details. The authenticated waiting-table directory contains only game, exact stake, target, and seat counts, never player identity. Reconnect state is retained long enough to resume an interrupted table. Leaving or disconnecting during the server-owned pre-deal countdown dissolves the pending table and returns every held stake in full with no surcharge. After activation, a deliberate confirmed quit, expired reconnect/drop, or third consecutive missed Online turn forfeits the reserved stake and adds a 10% play-coin abandonment surcharge. The first two missed Online turns safely auto-play without surcharge and a valid human action resets the count; an ordinary Solo turn expiry keeps its stake-only timeout result. An abandoned account receives no later payout or returned stake on a draw, and its canonical would-be share is burned rather than redistributed. A play-coin shortfall from the abandonment surcharge may be offset from later coin credits, but it is never a currency charge or store purchase.
Local presentation preferences and aggregate solo stats are not uploaded. Authoritative session, action, anti-abuse, and settlement records are retained as needed to reconnect, prevent replay or cheating, resolve disputes, and protect the wallet ledger.
Payments
Where a store-approved paid build offers native coin packs or Premium VIP, Apple App Store, Google Play, or Microsoft Store processes the payment for that platform. Card details go directly to the store. We never see or store card numbers. Localized prices come from the store. A build without approved paid controls does not open a purchase sheet.
Where denirocard.com offers website checkout, Stripe processes that separate USD payment. We send Stripe an app- and User-ID-bound customer record, the selected product, and the minimum checkout metadata needed to attribute the receipt, provider reversal, or subscription to the correct DeNiro account. Stripe receives payment details directly; NIRO does not receive or store the full card number. A browser never supplies the Stripe customer identifier used to open billing management; the server recovers it from the authenticated account and rejects a customer or subscription tagged to another app or owner.
Before a new coin-pack order, the app or website uses the billing and account flow offered on that platform and creates a short-lived purchase intent bound to the applicable store or DeNiro account and product. It sends the provider product ID, transaction identifier, signed receipt or purchase token where applicable, the applicable owner identifier, and that intent identifier to NIRO's receipt-validation service. The service verifies the transaction with the billing provider, prevents replay, and records the associated Purchase History and authoritative coin balance. Fixed coin packs grant the displayed amount. The historical Extra Spin product is unavailable for new purchase; an eligible older receipt may still be processed for reconciliation. Provider refund, revocation, reversal, or chargeback notifications may adjust that balance or create debt if coins were already used.
Premium VIP is an auto-renewable monthly or yearly subscription where offered. A new subscription uses the billing and account flow offered on that platform. The server records provider-confirmed entitlement periods so the 2Ă monthly or 3Ă yearly daily and level-progress multipliers, monthly stipend eligibility, high-roller access, Premium table and deck, and selected name emoji can be applied exactly once and revoked when the provider reports expiry, refund, or revocation. The selected emoji preference is stored with the signed-in account, but it is displayed only while the server confirms an active subscription. Manage Stripe website renewal from the authenticated DeNiro account, which opens Stripe's hosted portal. Manage native-store renewal in the store account that made the purchase. Billing eligibility does not automatically transfer among Stripe, Apple, Google, and Microsoft.
Coins always move one way. Verified purchases and game results enter the applicable device or protected-account wallet; free rewards enter protected-account wallets only. Coins may be used only inside DeNiro Card for simulated-game stakes and permitted virtual items. They cannot be sold, gifted for real-world value, redeemed, withdrawn, cashed out, or converted to money, prizes, or outside-app goods or services. Purchased coins do not expire.
What we don't do
- No advertising networks or ad tracking in this release. A future optional rewarded-ad feature will not grant coins unless the ad provider's server verifies completion and the privacy labels are updated first.
- No sale of personal data. Our account, game, hosting, analytics, and store providers process data only to operate the features described above; table participants receive only the shared public game state.
Contact
Questions about privacy or a purchase? Email support@denirocard.com.