🌹 DeNiro Card
← All games

Privacy Policy

DeNiro Card, operated by NIRO Corp · Last updated August 24, 2026

DeNiro Card is built to be played, not to profile you. A DeNiro account is required to play and lets you recover one coin balance, Premium benefits, and durable cosmetics across supported devices. Purchases also require a recoverable account. We do not use advertising trackers.

What's stored on your device

Those items live on your device. Clearing browser data removes the local copies, including a legacy web Premium token. A signed-in coin balance, eligible virtual items, and active game-session state are recovered from the server. Apple App Store, Google Play, and Microsoft Store purchases remain tied to the store account that bought them and are re-checked with that provider. A Stripe website purchase is instead bound to the DeNiro account that was authenticated at checkout.

Your DeNiro account

If you create an account on the website or a supported DeNiro Card app, we collect your email address and assign a User ID. An account is required before any game and before a new coin-pack or Premium order, so every reservation, result, receipt, refund, and Restore is bound to the correct owner. Signed-out visitors may browse the game catalog and shop, but cannot begin a game or billing flow.

Quick sign-in availability. Google and Apple sign-in are available on the website. Their buttons remain hidden in the iPhone, iPad, Android, Mac, and Windows apps until each exact signed, installed candidate passes provider consent, callback, secure session recovery, relaunch, and sign-out testing. Those apps currently offer email-and-password sign-in. Facebook sign-in is unavailable on every platform.

Processors and sign-in providers. Accounts and their data are hosted for us by Supabase (Supabase, Inc.), acting as our data processor on servers it operates. We use a dedicated DeNiro Card project that is separate from our other apps. If you choose a social sign-in, Google or Apple also processes that sign-in under its own terms and privacy policy.

Deleting your account. You can delete your account at any time from the in-app or website account panel — open Sign in → Delete account — or use the public account-deletion page. Before deletion finishes, our server attempts to expire open Stripe website checkouts and cancel any exact Stripe website subscription bound to that DeNiro account; if Stripe cancellation cannot be confirmed, deletion stops so you can retry while still able to sign in. We cannot cancel an Apple, Google, or Microsoft store subscription on your behalf, so cancel store renewal in the store account that billed you. Deletion closes the sign-in account, removes reward streak and level state, refunds unresolved coin reservations, revokes active VIP benefits, and permanently removes or de-identifies non-audit data. It cannot be undone. If you used Sign in with Apple, deleting the DeNiro account does not currently remove DeNiro Card from your Apple Account's authorized-app list; follow the separate Apple revocation step after deletion. You can also email us and we will action it after verifying ownership.

Retention. Required payment, receipt-replay, refund, dispute, fraud-prevention, wallet-event, and game-settlement audit records may remain linked to a locked deleted-account tombstone where law, platform rules, or ledger integrity require it; they cannot be used to sign in or resume play. Other account data is kept only until deletion. If usage analytics is active, the limited analytics and security processing described below still occurs.

Usage analytics

DeNiro Card includes a privacy-minimal, first-party usage analytics client. Usage analytics is enabled in this release under the controls described here and disclosed in the store privacy labels.

Usage analytics is on by default and disclosed — there is no separate pop-up asking permission first — except in the EU/UK, where it stays off until you agree. You can turn it off (or back on) any time from the analytics & privacy settings on this device. Global Privacy Control or Do Not Track always turns it off, everywhere.

When on, it may send only: a one-time random event UUID; a fixed event name and one fixed category; web/iOS/Android surface; the major.minor app release; a coarse device family and OS (e.g. “iPhone”, “ios17”); a coarse country derived by the server from your connection; and, if you buy something, that a purchase completed. The server reads the source network address only to derive that country and enforce abuse limits. It does not store the raw address in an analytics record; it keeps a secret-keyed, non-reversible rate-limit digest for no more than 10 minutes. If the app hits an error it may send a bounded crash report (error type and a truncated, address- and email-stripped message/stack) to help us fix bugs. Aggregated counts are kept about 13 months; crash reports about 90 days.

Usage analytics never contains cards, hands, moves, room or table codes, names, chat, balances, wagers, account/install/session IDs, receipts, payment amounts, page addresses, referrers, precise location, arbitrary properties, or game content. It is not used for advertising and does no cross-app tracking.

How we use your account records internally

Separately from the anonymous usage analytics above, the account-linked records already described — your game sessions, the games and modes you played, when you played them, session outcomes, and your wallet and purchase history — are also read by us internally to run the business: to see which games are actually played and for how long, how much time an account spends in the app, and what has been purchased. This is a normal part of operating a paid product and it is what tells us which games to keep improving.

This is internal only. It is not sold, rented, shared with advertisers, or used to target advertising, and it is not combined with data from other companies. Access is restricted to NIRO CORP and its data processors. It uses the account records we already keep for the reasons stated in this policy — turning analytics off does not remove your wallet or game-session history, because those records exist to protect the ledger and resolve disputes, not for analytics.

Deleting your account removes or de-identifies this data on the same terms as the rest of your account, subject only to the audit records described under Retention above.

Gameplay and multiplayer

Bot and Online coin games use an authenticated game service. It processes your assigned User ID, chosen display name, game and mode, selected stake and opponent count, legal actions, action sequence numbers, public table state, your private hand, turn and reconnect timing, outcome, forfeit state, and wallet reservation or settlement references. It also processes ordinary network information such as your IP address and service/security logs. A player receives only the private state for that player's seat.

Online public matchmaking pairs compatible real players randomly, without exposing a choice of opponent. Table participants receive the public game state, display names, connection state, consecutive-miss count, server-controlled-seat state, and post-reservation play-coin stacks needed to present the table; they do not receive another player's private hand, email address, receipt, or payment details. The authenticated waiting-table directory contains only game, exact stake, target, and seat counts—never player identity. Reconnect state is retained long enough to resume an interrupted table. After activation, a deliberate confirmed quit, expired reconnect/drop, or third consecutive missed Online turn forfeits the reserved stake and adds a 10% play-coin abandonment surcharge. The first two missed Online turns safely auto-play without surcharge and a valid human action resets the count; Solo turn expiry keeps its stake-only timeout result. An abandoned account receives no later payout or draw refund, and its canonical would-be share is burned rather than redistributed. A play-coin shortfall from the abandonment surcharge may be offset from later coin credits, but it is never a currency charge or store purchase. Do not use a display name to share sensitive personal information.

Local presentation preferences and aggregate solo stats are not uploaded. Authoritative session, action, anti-abuse, and settlement records are retained as needed to reconnect, prevent replay or cheating, resolve disputes, and protect the wallet ledger.

Payments

Where a store-approved paid build offers native coin packs or Premium VIP, Apple App Store, Google Play, or Microsoft Store processes the payment for that platform. Card details go directly to the store — we never see or store card numbers — and localized prices come from the store. A build without approved paid controls does not open a purchase sheet.

Where denirocard.com offers website checkout, Stripe processes that separate USD payment. We send Stripe an app- and User-ID-bound customer record, the selected product, and the minimum checkout metadata needed to attribute the receipt, refund, or subscription to the correct DeNiro account. Stripe receives payment details directly; NIRO does not receive or store the full card number. A browser never supplies the Stripe customer identifier used to open billing management; the server recovers it from the authenticated account and rejects a customer or subscription tagged to another app or owner.

Before a new coin-pack order, the app or website requires a recoverable account and creates a short-lived, account- and product-bound purchase intent. It sends the provider product ID, transaction identifier, signed receipt or purchase token where applicable, assigned User ID, and that intent identifier to NIRO's receipt-validation service. The service verifies the transaction with the billing provider, prevents replay, and records the account-linked Purchase History and authoritative coin balance. Fixed coin packs grant the displayed amount. The historical Extra Spin product is unavailable for new purchase; an eligible older receipt may still be processed for reconciliation. Refund and revocation notifications may adjust that balance or create debt if coins were already used.

Premium VIP is an auto-renewable monthly or yearly subscription where offered. Before a new subscription order, the app or website requires a recoverable account. The server records provider-confirmed entitlement periods so the 2× monthly or 3× yearly daily and level-progress multipliers, monthly stipend eligibility, high-roller access, Premium table and deck, and selected name emoji can be applied exactly once and revoked when the provider reports expiry or refund. The selected emoji preference is stored with the signed-in account, but it is displayed only while the server confirms an active subscription. Manage Stripe website renewal from the authenticated DeNiro account, which opens Stripe's hosted portal. Manage native-store renewal in the store account that made the purchase. Billing eligibility does not automatically transfer among Stripe, Apple, Google, and Microsoft.

Coins always move one way. Free rewards, game results, and verified purchases all enter the same account wallet. Coins may be used only inside DeNiro Card for simulated-game stakes and virtual items. They cannot be sold, gifted for real-world value, redeemed, withdrawn, cashed out, or converted to money, prizes, or outside-app goods or services. Purchased coins do not expire.

What we don't do

Contact

Questions about privacy or a purchase? Email support@denirocard.com.