Baize privacy policy
Effective date: [EFFECTIVE DATE]
This policy covers the Baize app for iOS and Android and the pages at baize.app. "Baize" is the app. "I" and "me" are the developer named below. "You" is the person using the app.
The controller of your personal data is [CONTROLLER NAME AND POSTAL ADDRESS]. For anything in this policy, write to [email protected].
The short version
- Your poker records live on your phone first. Baize works with no connection.
- By default Baize also backs them up to a Supabase project that I run, under an anonymous account that has no name and no email. One switch in Settings, under Cloud, turns that off.
- An email account is optional. It is what lets you reach your data from another phone.
- There are no ads, no analytics SDK and no tracking. I do not sell your data or share it for advertising.
- Crash reports go to Sentry, without personal data, so I can fix bugs.
- Baize Edge, the optional subscription, is sold by Apple or Google and checked through RevenueCat.
- An AI line check sends the text of one hand to Anthropic through my server. It runs only when you ask for it.
- You can export your data at any time. You can delete your account and your cloud data from inside the app.
What Baize collects and why
| What | Where it comes from | Where it goes | Why |
|---|---|---|---|
| Your poker records | You type them in, or import a CSV | Your phone. With cloud backup on, also my cloud | To give you the app, and to back it up |
| Account data | You, when an account is created | Supabase, my authentication provider | To sign you in and to restore your data |
| Sign-in emails | Sent to the address you give | Resend, which delivers them | To send codes for sign-up and password reset |
| Purchase data | The App Store or Google Play, and RevenueCat | RevenueCat and me | To know whether Baize Edge is active |
| Hand text for line checks | You, when you tap Line check | My server, then Anthropic | To return an AI line check |
| Crash reports | The app, when it crashes or catches a failure | Sentry | To find and fix bugs |
| Update checks | The app, at launch | Expo's update service | To deliver fixes without a new download |
| Server logs | Requests to my authentication and storage services | Supabase | To keep the service secure |
| Your emails to me | You | My mailbox | To answer you |
Your poker records
These are the sessions, buy-ins, cash-outs, expenses, breaks, sold-action percentages and notes you log, with the currency and the exchange rate locked to each session. They also include live session events (rebuys, stack updates and timestamped notes), wallets and their transactions, venues, game types, tags, saved filter views, your bankroll rules and preferences, tournament details, and recorded hands with their cards, positions and actions.
Names and notes are whatever you type. Keep other people's personal details out of them.
All of it is stored in a database on your phone. Nothing leaves the phone unless cloud backup is on, you export a file, or you use a feature described below.
Accounts
- Anonymous account. When cloud backup is on and the phone has a connection, Baize creates an anonymous account on first launch. It is a random ID and nothing else. Only that phone can open it, so a lost or wiped phone loses the way back to it unless you added an email account first.
- Email account. Optional. It holds your email address and a password, which my authentication provider stores as a hash and not as text. A six-digit code sent to the address confirms it. Adding an email to the phone's anonymous account keeps the same account ID, so nothing moves.
- Two-factor sign-in. Optional. It uses an authenticator app. The service stores the authenticator secret, and eight recovery codes are stored only as hashes.
- Sign-in tokens. They are kept in the phone's secure storage (the Keychain on iPhone, the Keystore on Android), not in a plain file.
- Logs. Supabase's authentication service logs the IP address and device type (user agent) of sign-up, sign-in and similar events, for security.
Cloud backup
- Backup files. Each backup is one file holding your records, in a private storage bucket under your account ID. Baize uploads one about thirty seconds after your data last changed. After each upload it keeps the newest ten files plus the newest file of each of the last thirty days, and removes the rest.
- Database copy. My Supabase project also holds database tables shaped like the app's, so records can sync between your phones. Each row is tied to your account ID and a row-level security policy lets only that account read or write it.
- Where. The production project runs in AWS us-east-2, in Ohio, United States.
- Restore. Sign in on another phone and choose Restore from cloud.
- Your control. Settings, then Cloud, has the switch. Off means nothing leaves the phone. You can also back up to a file and restore from one with no account at all.
- Android. Baize opts out of Android's automatic app backup, so Google's backup does not copy the app's data.
Purchases
Baize Edge is bought through the App Store or Google Play. Apple or Google takes the payment and never gives me your card or payment details. RevenueCat, my purchase provider, receives the purchase receipt and your Baize account ID, so it can tell me whether Edge is active on your account. I can see the product, price, dates, status and country of a subscription.
AI line checks
A line check runs only when you tap Line check on a hand. The app sends the text of that one hand to my server, signed in as your account so the server can check that Edge is active and that you are inside your usage allowance. The text is built from the hand itself: cards, positions and bet sizes. My server passes only that text to Anthropic's API, with no name, email or account ID, and returns the answer to you.
Anthropic does not use API inputs to train its models. It deletes inputs and outputs within 30 days, and may keep them longer only where its own terms allow, for example to enforce its usage policy or to meet a legal duty. My server keeps a count of the checks each account has used and does not keep the text.
Crash reports
When the app crashes or catches an unexpected failure, and the build carries a Sentry key, it sends Sentry the error and its stack, the app version, the platform, the OS version and the device model. It also sends anonymous session counts, so I can see how many sessions end in a crash. They carry a random install ID that the crash reporter generates, which changes if you reinstall the app. Baize does not link them to your account.
Baize sets the crash reporter not to collect personal data: no IP address inference, no tracing and no session replay. It also drops the console and network breadcrumbs, because those could carry balances or venue names. Error messages describe what failed rather than what you entered. If one ever carried a fragment of a record, it would reach Sentry with the report.
Update checks
At launch the app asks Expo's update service whether a newer version of its code is available. The request carries the app version, the platform, the update channel, a random install ID and your IP address, as every internet request does. It carries none of your records.
What Baize does not collect
- Your location, contacts, photos, camera, microphone or calendar.
- The advertising ID or any other hardware identifier.
- Health data.
- Card numbers or other payment details.
The app has no advertising or analytics SDK and does no cross-app tracking. On Android it asks only for network access and the state of the network, and for purchases the Google Play billing permission. On iPhone it does not ask for any permission. The privacy policy and terms pages set no cookies and load nothing from other sites.
The legal bases I rely on
This table is for people covered by the GDPR, the UK GDPR or similar laws.
| Purpose | Basis |
|---|---|
| Running the app, accounts, sign-in, backup and restore, and sign-in emails | Contract: it is the service you installed Baize to get (Article 6(1)(b)) |
| Selling Baize Edge and checking that it is active | Contract (Article 6(1)(b)). Tax and accounting records are kept under a legal obligation (Article 6(1)(c)) |
| AI line checks | Contract: you ask for each one (Article 6(1)(b)) |
| Crash reports, update checks, and security and abuse prevention | Legitimate interests in keeping the app working and secure, using as little data as possible (Article 6(1)(f)) |
| Answering your emails | Contract, or legitimate interests where you are not a user yet (Article 6(1)(b) and (f)) |
I do not rely on consent for any of this. Cloud backup is on by default because it is part of the service, and you can switch it off. You can object to anything I do under legitimate interests by writing to [email protected].
Who receives your data
I use these providers to run Baize. Each acts on my instructions, as a processor, and only for the purpose in the table.
| Provider | What it does for Baize | Where |
|---|---|---|
| Supabase | Hosting, database, storage, authentication and server functions | AWS us-east-2, Ohio, United States |
| Resend | Delivering sign-in emails from [email protected] | United States |
| Sentry | Receiving crash reports | United States |
| Expo | Delivering app updates | United States |
| RevenueCat | Checking subscription status | United States |
| Anthropic | Producing AI line checks | United States |
Apple and Google run the stores and the payments. They are independent controllers of the data they hold, under their own policies.
I do not sell personal information. I do not share it for advertising or give it to data brokers. I may disclose data where the law requires it, to protect people's safety or rights, or to a buyer if the business is sold, and in that case you would be told first.
Transfers outside your country
Every provider above is in the United States. If you are in the European Economic Area, the United Kingdom or Switzerland, your data leaves that area. These transfers rely on the Standard Contractual Clauses in each provider's data processing agreement, and on the EU-US Data Privacy Framework where the provider is certified. Write to [email protected] for a description of the safeguards.
How long I keep data
| Data | Kept for |
|---|---|
| Records on your phone | Until you delete them or the app. Baize never deletes them on its own. |
| Anonymous accounts, with their backups | While the phone keeps using them. A job that runs daily removes an anonymous account, its backups and its records once it is more than 60 days old, with no sign-in activity and no backup in the last 60 days. |
| Email accounts | Until you delete the account. |
| Backup files | The newest ten plus the newest of each of the last thirty days, while the account exists. |
| After you delete your account | Removed at once from my database and storage. Supabase's own infrastructure backups can hold a copy for up to 30 days before they expire. |
| Authentication logs | A few days to a few weeks, as Supabase keeps them. The copy that would otherwise sit in my own database is switched off. |
| Crash reports | 90 days at Sentry. |
| Hand text sent to Anthropic | Up to 30 days at Anthropic, under its terms. |
| Purchase and tax records | As long as tax and accounting law requires me to keep them. |
| Emails you send me | Up to two years after the conversation ends. |
Delete your data
In the app:
- Open Settings, then Cloud.
- Choose Delete account if you have an email account, or Delete cloud data if the phone only has an anonymous account.
- Confirm twice.
That removes your account, your database rows and your backups from my servers. Records on your phone stay, and delete when you delete the app or its data. Baize creates a fresh anonymous account afterwards only if cloud backup is still on.
If you cannot open the app, write to [email protected] from the address on the account with the subject "Delete my Baize account". I will delete the account and confirm within 30 days. An anonymous account has no name or email, so I cannot tell which one is yours from the outside. Use the in-app option, or leave it: it is deleted by itself after 60 days without use.
What can remain after a deletion: purchase and tax records that the law requires me to keep, copies in Supabase's own infrastructure backups until they expire, and crash reports at Sentry until they expire. None of them is tied to your name or email.
Other choices you have:
- Switch off cloud backup in Settings, then Cloud. The card then reads "Off. Nothing leaves this phone."
- Export your sessions as CSV, or back up to a file, from Settings. Import and export are always free.
- Turn on two-factor sign-in in Settings, then Security.
Your rights
If you are in the EEA, the UK or Switzerland you can ask me to give you access to your data, correct it, delete it, restrict how I use it, or hand it to you in a portable form. You can object to processing based on legitimate interests. You can complain to your data protection authority. Write to [email protected]. I answer within one month. I may ask you to prove the account is yours by writing from its email address. Most of this you can already do in the app, since the data is yours to export and delete. Baize makes no decisions about you by automated means. The statistics it shows are calculated from your own records, for you to read.
People in other countries with a privacy law, such as Brazil or Canada, can use the same address for the same requests.
California residents
This section is for residents of California under the CCPA as amended by the CPRA. In the last twelve months Baize has collected the following.
| Category | Examples | Source | Disclosed to |
|---|---|---|---|
| Identifiers | Account ID, email address, random install IDs, IP address in server logs | You and your device | Supabase, Resend, Sentry, Expo, RevenueCat |
| Commercial information | That you subscribed to Baize Edge, and when | The stores and RevenueCat | RevenueCat |
| Financial information you enter | Buy-ins, cash-outs, results, expenses and wallet balances in your records | You | Supabase |
| Internet or network activity | Crash reports, session counts, app version and device model | Your device | Sentry |
| Sensitive personal information: account log-in and password | Your email and password, and the authenticator secret | You | Supabase |
Baize does not collect geolocation, biometrics, audio or visual recordings, or employment or education information, and makes no inferences about you. I use the sensitive information only to sign you in and keep your account secure, so the right to limit its use does not apply.
I have not sold or shared personal information in the last twelve months, and I do not knowingly sell or share information about anyone under 18. Because of that there is no "Do Not Sell or Share" link.
You can ask me to tell you what I hold, delete it, or correct it, and I will not treat you worse for asking. Write to [email protected], or use Delete your data above. I answer within 45 days, and I may take another 45 if I tell you why. An authorized agent can write on your behalf, and I will ask for proof of the authorization and of the account.
Security
- Every connection to my servers and to the providers above uses TLS.
- Supabase encrypts stored data. Row-level security means one account cannot read another's rows, and the backup bucket is private, one folder per account.
- Passwords are stored as hashes. The check against leaked passwords is switched on.
- Two-factor sign-in is available, and the database refuses to serve an account that has it unless the session passed it.
- Recovery codes are stored only as hashes.
- Sign-in tokens sit in the phone's secure storage.
- The server key that bypasses row-level security lives only in my server functions. It is never in the app.
No system is perfectly secure. If a breach affects you, I will tell you as the law requires.
Children
Baize is for people who are 18 or older, or of legal age to play poker where they live if that is higher. It is not directed at children, and I do not knowingly collect their data. If you think a child has an account, write to me and I will delete it.
Changes to this policy
When this policy changes I post the new version at this address and change the effective date. For a material change I will also tell account holders in the app or by email. Earlier versions are available on request.
Contact
[CONTROLLER NAME AND POSTAL ADDRESS]