Privacy Policy
Privacy at a glance
River is a play-money Texas Hold’em game. We collect only what River needs to run your account and your games with friends: how you sign in, your profile, your chips and the hands you play online. There are no ads, no analytics and no third-party trackers, and we never sell your data. Games against the AI stay on your iPhone, and only a short summary is uploaded to keep your chips and stats in sync. You can delete your account in the app at any time, and that erases your personal data from our database.
Who we are
River is made by GitSwift LLC, a company based in Sheridan, Wyoming, USA (“GitSwift”, “we”, “us”). We decide how the personal data described here is used, so we are its “controller” under laws such as the GDPR. This policy covers the River app for iPhone, the River online service at river.melbournemasters.org, and these web pages.
What we collect
Your account
- Email and password, if you sign up with email. We store your password only as a salted one-way hash (argon2id), so we can’t read it.
- Sign in with Apple, if you use it: the identifier Apple issues to River for your Apple Account, and the email address Apple shares with us. That is either your real address or a private relay address, or none if Apple doesn’t provide one. If Apple shares your name the first time you sign in, River ignores it and doesn’t store it. When you sign in, the app also sends us a one-time code from Apple, which we exchange with Apple for a token tied to your Apple sign-in. We store that token encrypted and use it only to revoke River’s access to your Apple Account when you delete your account.
Your profile and settings
- Your username, avatar color, friend code, the experience level you choose during setup, and your app settings (for example notification and leaderboard preferences, or who can invite you).
- The language for our emails (English or Simplified Chinese), taken from your device’s language when you sign in.
Your chips and games
- Your chip balance and a history of chip changes: buy-ins, rebuys and cash-outs at tables, solo session results, free chips and redeemed codes.
- Multiplayer rooms: rooms you create or join, your seats, and a record of every hand played on our server (cards dealt, actions, pots and results). From these we calculate statistics such as hands played, win rate and results by position and starting hand.
- Solo games against the AI: when you’re online, the app uploads a summary of each finished session. The summary holds the start and end time, AI level, table size, blinds, chips bought in and cashed out, your best hand, and totals such as hands played, how often you raised, and results by position and starting hand. Individual solo hands are never uploaded.
Friends and Inbox
- Your friends, the friend requests you send and receive, room invitations, and the items in your Inbox.
- Whether you’re online, in a lobby or in a game while the app is connected, and when you were last seen.
Blocks and reports
- The players you block, and when.
- Reports you file about another player: the player, the reason you chose, your note if you write one, the room or hand you reported from, and the time. Reports other players file about you, in the same form.
Technical information
- Server logs. Each request to our server, including visits to these pages, is logged with your IP address, the time, the address requested (without query parameters), the result and, when you’re signed in, your account ID. Some events, such as an email being sent, a code being redeemed or a report being filed, are also logged with account IDs. Logs never contain passwords, sign-in tokens, codes, email addresses or email contents.
- Abuse protection. To limit repeated sign-up, sign-in and password-reset attempts, we briefly hold your IP address, and the email address you entered, in our server’s memory. Neither is stored for this purpose, and IP addresses are never stored in our database.
- Sign-in sessions. We keep records of your sign-in sessions, password-reset requests and email-change requests (including the new address until it is confirmed). Session tokens and codes are stored only as hashes.
We don’t collect your location, the contacts on your phone, photos, advertising identifiers or payment details. River has no purchases.
What stays on your iPhone
Your solo hand history, a cache of your settings and stats, and your sign-in tokens (kept in the iOS Keychain) are stored on your device. Solo play works fully offline, and nothing about it leaves your device until a session summary is uploaded as described above. Deleting the app removes its local data. iOS may keep Keychain items after an app is deleted, but the tokens stop working when you log out, change your password, delete your account or leave River unused for 60 days.
How we use it
- To create and secure your account, sign you in, help you reset your password or change your email (we email you a 6-digit code), and tell you when your password or email changes.
- To run multiplayer games: dealing, turn timers, settling chips, and letting you replay hands you played.
- To show your chips, stats, hand history, friends, Inbox and leaderboards.
- To keep River fair and working: stopping automated sign-ups and code guessing, looking into cheating, and fixing bugs.
- To keep players safe: enforcing your blocks, screening usernames and room names for offensive words, and reviewing reports.
We use your email address only for account messages: a welcome email when you sign up, codes for password resets and email changes, notices when your password or email address changes (the notice about a new address goes to your old one), and a confirmation when you delete your account. We don’t send marketing email.
Where laws such as the GDPR apply, we rely on these legal bases: providing the service you asked for (performance of a contract); our legitimate interest in keeping River secure and fair; and complying with the law.
What we don’t do
- No advertising, and no ad networks.
- No analytics, crash-reporting or tracking software in the app or on these pages.
- No cookies on these pages.
- We don’t sell or rent personal data, and we don’t share it for targeted advertising.
- We don’t track you across other companies’ apps or websites.
What other players can see
- Any signed-in player can find you by username or friend code. They can see your username, initials and avatar color, when you joined, your total hands and win rate, whether you’re online, in a lobby or in a game (with the room’s name), and when you were last online. Only friends also see the room code.
- Players you’ve shared a table with see a head-to-head summary of the hands you both played.
- If you block a player, they can no longer find you in search, see whether you’re online or when you were last seen, send you friend requests or invitations, or sit at or watch a table you’re hosting or playing at, and you stop being friends. They aren’t told that you blocked them. A player you report isn’t told who reported them.
- Players at your table see your actions and any cards you show at showdown. Cards you fold or muck stay hidden, including in replays.
- Your friends see your rank, chips won and hands played on their friends leaderboard. The global leaderboard shows your username, chips won and hands played to every player, unless you turn off Show me on global ranks in Settings. Leaderboards only count multiplayer rooms, not solo games.
Service providers
We use a small number of providers that process data only on our behalf and under our instructions:
- Oracle Cloud Infrastructure hosts our server and database in Melbourne, Australia.
- Our email delivery provider sends the account emails described above, and delivers reports to our support mailbox. It receives the recipient’s email address and the message.
If you use Sign in with Apple, Apple confirms your identity under its own privacy policy, we contact Apple to exchange and, when you delete your account, revoke the sign-in token described above, and any email we send to a private relay address is forwarded by Apple. Apple also distributes the app through the App Store.
We may disclose information if the law requires it, to protect the rights and safety of our players or others, or as part of a merger or acquisition. In that case this policy keeps applying to your data.
Where your data is stored
Our server and database are in Australia, and GitSwift LLC is in the United States. Your information is therefore processed in those countries, whose data-protection laws may differ from where you live. We protect it as this policy describes wherever it is processed.
How long we keep it
- Account, profile, chips, games, friends and Inbox: for as long as your account exists. Game invitations disappear when their room closes.
- Sign-in sessions and codes: sessions expire after 60 days without use, and password-reset and email-change codes after 15 minutes. Expired sessions are deleted automatically within an hour, and signed-out sessions and code records (including an unconfirmed new email address) about a day later. Everything left is erased when you delete your account.
- Blocks: until you unblock the player or either of you deletes your account.
- Reports: up to one year, then deleted automatically. If you delete your account, reports you filed are kept without your name or account ID, and reports about you are deleted. The copy emailed to our support mailbox is deleted when we close the report, and within one year at most.
- Sign in with Apple token: until you delete your account. We then ask Apple to revoke it, retrying for up to 7 days if Apple can’t be reached, and delete our encrypted copy once Apple confirms or the 7 days pass.
- Server logs, including IP addresses: up to 30 days.
- Database backups: up to 30 days. After that, deleted data is gone from backups too.
Deleting your account
You can delete your account at any time in the app under Settings → Delete account. Deletion is immediate and can’t be undone. If you’re seated at a table, your chips are cashed out first. Then we erase your email address, password hash, Apple identifier, profile, settings, chips and chip history, redeemed codes, friends and friend requests, blocks, Inbox, sessions, reports about you and your statistics, and we sign you out on every device. We send a confirmation to your email address, if your account has one.
Records of multiplayer hands you played remain in the history of the other players at that table, so their replays keep working. In those records you appear as “deleted”: they keep only your seat, cards, actions and chip results, under your former account ID, which no longer leads to a name, email address or profile. The names of rooms you created may also remain in other players’ history. Logs and backups expire as described above.
If you used Sign in with Apple, we also ask Apple to revoke River’s access to your Apple Account, so River no longer appears among the apps using Sign in with Apple. You can also remove it yourself in your Apple Account settings (Sign in with Apple).
If you can’t use the app, email us from the address on your account and we’ll help.
Security
All traffic between the app and our server is encrypted with TLS. Passwords are hashed with argon2id, and the Sign in with Apple token is encrypted (AES-256-GCM). Access tokens expire after 15 minutes, refresh tokens are replaced each time they are used, and both are stored in the iOS Keychain. Access to our servers is restricted. No system is perfectly secure, so if a breach ever affects your data, we will tell you as the law requires.
Children
River is only for adults aged 18 and over and is not directed at children. We don’t knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us and we’ll delete it.
Your rights
River is available worldwide, and we give every player the same core rights, wherever they live:
- See and correct your data. Most of it is shown in the app, where you can change your username, avatar, email, password and settings.
- Delete your account and personal data, in the app under Settings → Delete account.
- Get a copy of the data we hold about you, in a portable format.
- Object to or restrict some processing, such as processing based on our legitimate interests.
To make a request, email support@gitswift.com from the address on your account. We’ll reply within 30 days, and we may ask you to confirm that the account is yours. We won’t treat you differently for using your rights.
EU, EEA and UK. The GDPR and UK GDPR give you the rights above, and you can complain to your local data-protection authority.
California and other US states. Laws such as the California Consumer Privacy Act (CCPA, as amended by the CPRA) give you the right to know what we collect and why, and to access, correct and delete it. You may use an authorized agent. We don’t sell or share personal data for targeted advertising, and we don’t use sensitive data to infer things about you, so there is nothing to opt out of.
Australia. You can ask to access or correct your information under the Australian Privacy Principles. If you aren’t satisfied with our answer, you can complain to the Office of the Australian Information Commissioner (OAIC).
Changes to this policy
If we change this policy, we’ll update the effective date at the top of this page. We’ll make significant changes clear in the app or on this page before they take effect.
Contact
GitSwift LLC30 North Gould Street, Suite R
Sheridan, WY 82801
United States
support@gitswift.com