VIDEO POKER PALEV TRAINER

Privacy Policy

EFFECTIVE 2026-07-14 · VIDEOPOKERPAL.COM
Video Poker Pal is built to need as little of your data as possible. This policy explains what we collect, why, and what we never do with it. Short version: no ads, no data sales, no cross-site tracking, and you can use almost everything without signing in at all.

1. What We Collect

  • Account data (only if you sign in with Google): your name, email address, and profile picture, as provided by Google, plus the Terms/Privacy version and time you accepted before sign-in. Used to identify your account, record consent, and sync your data. We never see your Google password.
  • Training data: the practice hands you got wrong (“mistakes”), so you can review and drill them. Stored on our server only when you are signed in (capped at 10,000 per account); otherwise kept in your browser’s local storage.
  • Personal report progress: your count of completed practice hands and bounded EV-loss summaries used to build the personal report. This version is stored in your browser, separately from resettable session statistics. Replays and analyzer use do not count.
  • Feedback (only if you submit it while signed in): the category and message you enter, the app release identifier, and—only when you explicitly enable the checkbox—the five dealt cards, selected and recommended holds, paytable, and EV values shown in the preview. Feedback is available only to authorized administrators. We do not copy your account email into the feedback record.
  • Anonymous usage events: counters like page views, hands played, and hint usage, keyed to random browser and tab identifiers. Event properties are strictly allowlisted and contain no name, no email, no card hands, no query strings, and no free-text error details — they tell us the app is used, not who you are.
  • Server logs: standard technical logs (request paths, timing, status codes) kept briefly for reliability and abuse prevention.
  • Waitlist and price-interest data (only if you submit it): your email is used to announce the Pro launch. If you choose the $29/year interest option, we also store the fixed offer identifier, server-defined price and period, entry point, and submission time so we can measure submitted price interest. When the submitted email matches your signed-in account, we record that match; anonymous submissions do not prove email ownership or an independent user. No payment is taken. This data is never shared and is removable any time by emailing us.
  • Aggregate traffic statistics via Google Analytics: page views and approximate geography, with IP anonymization on and all advertising/personalization signals disabled. Google’s privacy policy applies to this processing.

2. What We Never Do

  • No advertising and no ad networks today. If we ever introduce ads, this policy will be updated first and the change will be visible on this page.
  • No selling, renting, or sharing of personal information.
  • No tracking across other websites, and no advertising or personalization signals in our analytics.
  • No collection of payment data — the Service is free and handles no money.

3. Cookies & Local Storage

We use one strictly necessary session cookie to keep you signed in (via Google OAuth). Your browser’s local storage holds preferences (language, theme, game selection) and, when signed out, your saved mistakes (capped at 20), plus personal-report progress and a marker recording whether the one-time Double Bonus Pro offer was shown. A feedback draft may remain in this tab’s session storage for up to 15 minutes so it can survive the Google sign-in round trip. Clearing site data in your browser removes all of it.

4. Data Retention & Deletion

  • In-app: once the Mistakes page confirms “Clear all,” your saved mistakes and report evidence have been deleted locally and, when signed in, from the live server. If a deletion cannot be confirmed, the app keeps the evidence visible and shows a retry state.
  • Feedback: submitted feedback and administrator review notes are deleted from the live database automatically after 180 days. Encrypted disaster-recovery snapshots age out under a rolling schedule of up to six monthly backups; a restored database runs the same 180-day purge before it is put into service.
  • Account deletion: email us from your account address and we will delete your account and all associated data within 30 days.
  • Anonymous events are kept for product statistics and contain nothing that identifies you.

5. Sharing & Third Parties

Sign-in is provided by Google (their privacy policy applies to the sign-in step itself), and the site is delivered through Cloudflare’s network, which processes IP addresses as a network service provider. Beyond that, your data stays on our servers. We disclose data only if required by law.

6. Security

All traffic is encrypted with TLS. Server data lives in access-restricted storage, and account sync endpoints require authentication. No system is perfectly secure, but the Service also holds very little worth stealing by design.

7. Children

The Service is intended for adults 18+ and is not directed to children. We do not knowingly collect personal information from anyone under 18; if you believe we have, contact us and we will delete it.

8. Changes & Contact

We may update this policy; the effective date above reflects the latest revision. Questions or deletion requests: [email protected].