PRIVACY POLICY

Your cards are private.
So is your data.

Effective September 10, 2026. This policy covers The Long Bluff website and the Android and iOS apps.

Who is responsible

Gigamiga Solutions Ltd., Harkomim 26, Holon, Israel, is the controller of the information described here. For privacy questions or requests, email support@thelongbluff.com.

Information we handle

Account and sign-in

You sign in with Google or Apple. We retain the provider account identifier needed to bind that sign-in to an internal player account, your chosen display name, internal player ID, protected session records, login-security records, and the version and time of your Community Rules acceptance. Provider credentials may transiently contain an email address, name, or profile-photo URL, but The Long Bluff does not retain those profile fields. Apple credentials needed to revoke Sign in with Apple access are encrypted.

Game and social activity

We handle tables, seats, spectators, invitations, friend connections, poker hands and actions, turn timing, chat messages, reactions, blocks, abuse reports, and queued notifications. Timing is part of gameplay, so other players may see how long an action took.

Virtual chips and store purchases

We keep an append-only, double-entry ledger of virtual-chip movements so every chip's origin and use can be audited. If purchases are enabled, Apple or Google processes the payment. We do not receive or store card or bank details. RevenueCat helps validate and deliver store purchases using your internal player identifier, purchase history, transaction and product identifiers, store environment, and purchase or refund state. RevenueCat also provides purchase analytics. We use these records to deliver or reverse digital goods and prevent fraud. See RevenueCat's privacy policy.

Device and technical data

If you enable notifications, we may handle an Apple Push Notification service or Firebase Cloud Messaging token and its platform. Authentication rate limits use a short-lived, one-way protected network bucket rather than retaining a raw IP address in our application database. Hosting, authentication, app-update, and platform providers may process technical request data such as an IP address, device or browser type, timestamps, and diagnostics in their operational logs.

We do not collect a date of birth, exact age, your device address book, precise location, microphone recordings, camera content, or payment-card details.

Rewarded advertising

In native app builds with rewarded advertising enabled, Google AdMob supplies optional videos. The reward is shown before you choose to watch. We load the ad integration only after sign-in and onboarding and complete applicable consent steps before requesting ads. Declining tracking or personalisation does not change the reward; ads are requested only when Google's consent system permits them. Where required, you can revisit Ad privacy choices in Chips or Profile.

Google's advertising SDK may process your IP address (including an approximate location inferred from it), device/app identifiers, ad interactions and diagnostic information to deliver and measure advertising and prevent fraud. Android advertising-ID access is blocked; iOS tracking access depends on your permission. See Google's privacy policy. We send an internal player identifier and a one-use reward ticket to Google for signed completion verification. We keep the verified reward in our chip ledger and a one-way device-derived value in reward tickets to scope reward requests and apply any configured reward limits. The current offer has no daily video limit. The public website does not load this SDK.

Optional analytics and attribution

After sign-in and onboarding, you may choose to enable Singular measurement. When enabled, Singular may process an opaque internal player identifier, app sessions, device/app and network information, campaign attribution, link metadata, and a small allowlist of conversion events such as accepting an invitation or submitting a turn. We do not send cards, table or friend identifiers, messages, display names, chip balances, contact details, or invite URLs as event properties. iOS activation also requires the platform tracking permission.

You can turn measurement off in Profile without losing any game feature. This stops further Singular collection on that device and clears the account alias. Singular may also receive the signed routing token contained in a Singular invite link in order to preserve that invitation across installation. See Singular's privacy policy.

The website and invitation links

The public website uses no analytics, advertising SDKs, contact forms, or tracking cookies. A signed invitation link acts like a key to a private table. Do not publish or forward it outside the people you intend to invite.

Why we use information

Depending on where you live, these uses are based on performing our agreement with you, our legitimate interests in operating and securing the service, compliance with legal obligations, or consent where required.

Who receives information

We do not sell personal information. We disclose information only as needed to run the service, comply with law, protect people and the service, or complete a transaction you request.

These providers may process information outside Israel or your country. We require providers handling information for us to protect it consistently with this policy and applicable law.

Players at your private table receive the display name, gameplay, messages, reactions, and timing information needed for the shared game. Live hole cards are sent only to their owner; spectators receive a redacted view until the game rules permit disclosure.

We may disclose information when reasonably necessary to comply with law, respond to valid legal process, investigate fraud or abuse, protect safety or rights, or complete a corporate transaction subject to appropriate safeguards.

How long we keep it

We keep information only as long as needed to operate and secure the service, preserve shared game integrity, handle disputes and refunds, prevent fraud, and meet legal obligations. Short-lived sign-in attempts and delivery handles expire within minutes. Sessions remain until expiry, logout, revocation, or deletion. Notification tokens remain until the related session is revoked or the account is deleted. Chat, reactions, account, and social records remain while the account exists unless removed earlier. Encrypted Apple revocation material remains only until revocation succeeds. Hosting logs and database backups are retained for limited operational periods and then deleted or overwritten according to provider and backup schedules.

After deletion, narrowly de-identified or pseudonymous records may remain: the chip ledger; shared hand actions and timing; store transaction records needed for later refunds; tables still used by other players; abuse-report snapshots; and one-way values used to prevent repeated welcome grants, bankroll-recovery abuse, or reward farming. They remain for game integrity, security, fraud prevention, dispute handling, and store accounting, and cannot be used to sign in or restore the deleted account.

Your choices and account deletion

Delete your account in the app through Profile → Delete my account. If you no longer have the app, follow the web deletion instructions or email support@thelongbluff.com.

Deletion removes provider identity bindings, your display name, sessions, notification tokens, chat and reactions, invitations, cosmetics, blocks, and other account-linked operational records. Your chips are closed into the auditable game ledger. Only the narrowly retained records described above remain for their stated purposes.

You may disable notifications in your device settings. Where an optional feature relies on consent, you may withdraw it through the relevant app or device control. Depending on where you live, you may also request access, correction, deletion, restriction, objection, or portability, withdraw consent, or complain to a data-protection authority. We may need to verify that a request belongs to you.

Security

We use measures designed to protect information, including encrypted transport, hashed credentials, encrypted Apple revocation credentials, access controls, server-authoritative game actions, and redaction of live hole cards. No system is completely secure, so we cannot guarantee absolute security.

Adults only

The Long Bluff is intended only for people aged 18 and over. We do not knowingly offer the service to children or collect dates of birth. If you believe a child has provided information to us, email support@thelongbluff.com.

Changes

We may update this policy when the service, providers, or legal requirements change. We will publish the updated policy with a new effective date and provide additional notice when required.

For amusement purposes only.

The Long Bluff does not offer real-money gambling or an opportunity to win real money or prizes. Virtual chips have no cash value and cannot be cashed out or redeemed.