Privacy Policy
Last Updated: May 20, 2026
In 30 Seconds
Not legal advice. If you need help with your rights, talk to a lawyer in your country.
• Roll is a poker tracker plus a small social feed.
• Anything you post, share, or put on your profile is public.
• We use Supabase to store your data. We don't sell it.
• You can delete your account anytime. Everything (photos too) is gone within 30 days.
• Need anything? Email roll@rollpoker.xyz.
What We Collect
Stuff you give us:
• Email or phone (so you can sign in)
• Username, avatar, bio
• Your posts, photos, comments, sessions, tags, shared links
Stuff we pick up automatically:
• Who you follow, block, or report
• Device type, OS, app version
• Crash logs
Stuff we don't collect:
• Payment info (Roll has no in-app purchases)
• GPS location
• Your contacts
• Health or biometric data
• Anything from other apps
What's Public
Roll is social. Treat anything you post as something anyone could see.
• Your profile (username, avatar, bio, follower counts) — visible to every Roll user.
• Posts and comments — visible per the privacy setting you pick: public, followers, or private.
• Shared session pages (rollpoker.xyz/s/…) — visible to anyone with the link.
How We Keep Things Clean
We auto-screen post captions, comments, bios, usernames, and shared text. Bad words get blocked with a notice. You can edit and try again.
You can also:
• Report any post, comment, or user from the "⋯" menu.
• Block anyone. Neither of you sees the other after that.
• Manage blocks in Settings → Blocked users.
If we remove your content, we'll tell you why. Push back by emailing roll@rollpoker.xyz.
How We Use Your Data
• Run the app (your feed, stats, sessions)
• Keep your account secure
• Send sign-in codes and account notices
• Catch spam, abuse, and rule-breakers
• Fix bugs
• Comply with the law
For EU/UK users, our GDPR legal bases are: running your account (contract), keeping things secure and useful (legitimate interest), consent (when we ask), and the law (when it tells us we have to).
What You Can Do
Without asking us:
• See your data → open the app
• Export sessions → Settings → Export Data (CSV)
• Delete your account → Settings → Delete Account (gone within 30 days, photos included)
• Edit profile or posts → in the app
• Block users → Settings → Blocked users
• Report content → "⋯" menu
For everything else, email roll@rollpoker.xyz.
EU, UK, or Switzerland (GDPR):
You can ask us to: show, fix, move, limit, or delete your data. You can also object to processing or take back your consent. We respond within 30 days. You can also complain to your country's data protection authority.
California (CCPA / CPRA):
You can: see what we collect, delete it, correct it, or opt out of "sale/sharing." Roll doesn't sell or share for ads anyway. Email us to use any of these.
Other US states (TX, VA, CO, CT, UT, and others):
Your state probably gives you similar rights. Email us.
How We Keep Your Data Safe
• TLS in transit
• Encrypted at rest in Supabase
• Every database table has row-level access controls
• We update dependencies and review security regularly
No system is bulletproof. If we get breached, we'll tell you — and any regulator we have to notify — within 72 hours.
Where Your Data Lives
Roll runs in the United States. If you use Roll from elsewhere, your data crosses borders to reach us.
For EU/UK/Swiss users, we use Standard Contractual Clauses with our service providers. Email us for a copy.
How Long We Keep Things
• Active account — as long as you keep using Roll
• Deleted account — gone within 30 days (photos too)
• Records we must keep by law (fraud, tax, abuse) — as long as the law says
• Backups — Supabase's standard 7–30 day rotation
You can't undo account deletion.
Kids
You need to be 13 or older to use Roll.
If you're a parent and your under-13 kid signed up, email roll@rollpoker.xyz and we'll delete the account.
In some EU countries, users between 13 and 16 may need a parent's permission.
Copyright (DMCA)
If someone's posting your copyrighted work on Roll without permission:
• Email: roll@rollpoker.xyz · subject: DMCA notice
• Agent ID: DMCA-1073038
Your notice needs the six items in 17 USC §512(c)(3). The full template lives at rollpoker.xyz/legal/dmca.
We take down content fast. Users who get multiple valid complaints lose their accounts.
Illegal Content (EU Users — DSA)
If you're in the EU and you see content that breaks your country's law: use the in-app Report button, or email roll@rollpoker.xyz.
We'll confirm we got it, review it, and tell you what we decided and why. You can push back by replying to the same email.
Changes
We update this policy when things change. The "Last updated" date at the top moves. For big changes, we'll tell you in the app or by email.
Using Roll after a change means you accept it.
Contact
• Email: roll@rollpoker.xyz
• Web: https://rollpoker.xyz/support
Use the same email for privacy questions, data requests, DMCA notices, or anything else.