Privacy Policy — Shuffle Up and Deal!
Effective date: 13 July 2026 App version: 1.0.0 Publisher: AceRiver Studios ("we", "us") Contact: hello@aceriverstudios.com
This policy explains what Shuffle Up and Deal! (the "App") does with your data — including the data the in-app TURNER assistant handles. We have written it to be specific and verifiable rather than legally exhaustive: the claims about what TURNER and the optional App Usage telemetry send are each backed by an automated build-time test (the "privacy fence") that fails the build if those claims drift.
If you only read one paragraph: the App requires a free account and keeps your data synced to our secure cloud so it is available on all your devices and is not lost if a device is. Your data is private to your account — it is encrypted in transit, stored on managed infrastructure that encrypts it at rest, and isolated so that you, and only you, can read or change it. We never sell, rent or share your data, and you can ask us at any time for a copy of what we hold or to erase it completely.
Your data is stored in an on-device database and syncs to the cloud automatically whenever you are connected. An internet connection is recommended while you use the App so your changes are saved and kept up to date across your devices.
1. Your account and sign-in
The App requires you to sign in. There is no anonymous or guest mode. Sign-in and account management are handled for us by Clerk, a specialist identity provider acting as our processor. Depending on how you choose to sign in, Clerk holds:
- Your email address (your primary identifier).
- Your display name (first / last name), if you provide one.
- A password, if you create an email-and-password account. Clerk stores this securely on our behalf in hashed form — we never see or store your password.
- If you use Sign in with Apple or Sign in with Google, the identifier those providers return to Clerk to authenticate you. We receive your email and name, not your Apple or Google password.
- Device details attached to your account so you can recognise your active devices: a device label, platform (iOS / Android), OS name and version, device model and brand, and the App version and build. This is used for account/session management only.
We use your account to authenticate you, to keep your data private to you, and to sync your data across your devices.
2. What syncs to the cloud, and where it is stored
When you are signed in and connected, the App syncs your tournament data to a database in our cloud so it is available on every device you sign in on. The synced data is the working content of the App, including:
- Your tournaments and everything attached to them — players in each event, tables, clocks, presets, results, result snapshots, seat assignments, action logs, and the payout / financial ledgers.
- Your players, including their names, nicknames, any contact details you choose to enter (phone, email), notes, lifetime statistics, and photo avatars (see §3).
- Your venues and their table layouts.
- Your leagues, including seasons, points, qualification lines, accolade settings, adjustments and adjustment logs, and pinned league dashboards.
- Your blind structures, blind levels, payout structures and payout-structure lines.
- Your settings (currency, fonts, voice and sound preferences, and similar in-app options).
- A small per-device sync audit log that records sync activity so you can see and troubleshoot what has synced.
Two specialist processors handle the sync on our behalf:
- PowerSync — the sync engine that moves changes between your device's local database and our cloud database over an encrypted connection.
- Neon — the managed PostgreSQL database service that hosts the synced data.
Your local TURNER chat transcripts are not synced by this system — they stay on the device that created them. (A separate, anonymised server-side log of TURNER activity is described in §9; it does not contain your transcripts in readable form.)
3. Player photos (avatars)
Player photo avatars do leave your device. When you add a player photo it is uploaded to our cloud object storage and the player record stores a reference to it. The image therefore syncs to your other devices along with the rest of that player's record.
Avatar images are private to your account: reading an avatar requires a valid signed-in session, and our server verifies that the avatar you are requesting belongs to your account before it returns the image. When you delete a player photo, or delete your account, the corresponding image is deleted from object storage.
Because photos are personal data of the people in them, only add photos of players who are happy for you to store their image (see §6 and the Terms of Use).
4. How your data is kept private and secure
Keeping your data private to you is a core design goal, enforced in code rather than by policy alone:
- You can only ever access your own data. Every sync request is authenticated with a verified Clerk session token. On the download path, the cloud only ever sends your device rows that belong to your account. On the upload path, our server stamps every write with your verified account identifier and restricts each write to your own rows — so it is not possible to read or modify another account's data, even by a malformed request.
- Encryption in transit. All communication between the App and our servers, sync engine and object storage uses HTTPS / TLS.
- Encryption at rest. Synced data and avatars are stored on managed infrastructure (Neon PostgreSQL and our object storage provider) that encrypts data at rest.
- Credentials stay on the server. The database connection string and other server secrets are held only on our server and are never shipped inside the App.
- Passwords are never handled by us. Authentication and password storage are handled by Clerk; we never receive your raw password.
No system can be guaranteed perfectly secure, and we do not claim otherwise (see the Terms of Use). But access to your data is scoped to your authenticated account at every layer.
5. We do not sell or share your data
We do not sell, rent, trade or share your personal data with anyone for their own purposes. We have no advertising, no "share with partners" mode, and no data brokers.
The only parties that ever handle your data are the processors we use to run the App, each acting only on our instructions and only to provide their part of the service:
- Clerk — sign-in and account management.
- PowerSync — the cloud sync engine.
- Neon — the database that hosts your synced data.
- Our object storage provider — hosting player avatar images.
- Our AI provider (Google, for TURNER replies) — see §8 and §9.
- RevenueCat for subscription and entitlement management (see §14).
- Apple and Google for processing subscription payments made through the App Store and Google Play (see §14).
We may also disclose data if we are legally required to (for example a valid court order), or to protect our rights, safety, or the integrity of the service against abuse.
6. Lawful basis and your players' data
Under UK GDPR we rely on the following lawful bases:
- Performance of a contract — to create your account and provide the core App and sync features you ask for.
- Legitimate interests — to keep the service secure, prevent abuse, debug incidents, and improve the App. We balance these against your rights.
- Consent — for the optional App Usage telemetry in §8, which is on by default and which you can switch off at any time.
About the people in your roster: when you record players' names, contact details or photos, you are deciding to process other people's personal data using our App. For that data you are the controller and we act as your processor. You are responsible for having a lawful basis (for most clubs, the consent of the players) to record and upload their details — see the Terms of Use.
7. Where your data is stored, and international transfers
We are based in the United Kingdom and your data is protected under UK GDPR. We configure our service providers to store and process your data in UK and European data centres where available:
- Your synced tournament data — the database content described in §2, including your players and their contact details — is stored in a UK data centre (our database provider, Neon).
- Your account and sign-in data (Clerk) and the sync engine (PowerSync) are likewise configured to use UK / EU data centres for customers in our region.
- Subscription management (RevenueCat) and the app stores (Apple and Google) are based outside the UK / EU and process limited subscription and payment information internationally under the safeguards described below.
Some service providers are headquartered outside the UK / EU and may process limited information internationally. Where any data is transferred or processed outside the UK / EEA, we rely on appropriate legal safeguards — such as the UK International Data Transfer Agreement (IDTA) or Standard Contractual Clauses — so that it keeps an equivalent level of protection. You can ask us for details of the safeguards that apply using the contact address in §16.
8. What the TURNER assistant sends, and to whom
TURNER ("Tournament Utility for Rules, Neutral Evaluation & Resolution") is an AI chat feature. When you send a message, the following payload leaves your device over HTTPS and is sent to our TURNER API server:
- The text of your message and the recent history of the current conversation (capped to a short rolling window).
- An optional short label describing the screen you opened TURNER from (for example "League Dashboard"). Free-form labels are not allowed — only an internally allow-listed set of screen names can be sent.
- Optional opaque entity tokens describing what you were viewing — for
example
tournament:t1,league:l1,venue:v1,player:p1. These are random local identifiers from your device's storage. They carry no name, no contact details, no photo, no statistics. - Any house rules you have authored that apply to the current screen. These leave the device verbatim because you wrote them; treat them as if they will be read by a third party.
- A per-install random identifier (
X-Install-Id) used for rate limiting and for the anonymised server-side logging described in §9.
TURNER is keyed to a random per-install identifier, not to your
account. Names, photos, contact details, money amounts attributable to
a specific person, and full rosters never enter the request body. The
on-device anonymiser converts unambiguous mentions of real names you
have typed into kind:id tokens before the request leaves the
device. Ambiguous names (for example two players both called "Liam")
are converted to non-identifying placeholders such as
player:ambiguous:liam. You can long-press the "Show last anonymised
request" row in Settings → TURNER to inspect the exact bytes that left
your device on TURNER's most recent request.
The codebase enforces this contract automatically. A test called the "privacy fence" walks every screen that registers context with TURNER and refuses to compile the App if a screen tries to send a free-text label, a real name, or any field outside the allow-list.
App Usage (anonymous telemetry)
Settings → App Usage lets your device send a small anonymous summary of how the App is used so we can prioritise improvements. It's on by default and you can switch it off at any time. When it's on, your device sends — once per day, in the background when you next open the App, over HTTPS — the following:
- Per-tournament counts: entries, rebuys, re-entries, add-ons, duration in minutes, paid finishing positions, non-cash prize count, buy-in / fee / prize pool totals in your tournament's native currency. Our server converts money to GBP for reporting using a daily exchange-rate cache; the original currency is also recorded.
- Per-league counts: number of seasons, tournaments, distinct players, manual adjustments, plus the point-system kind (field-size based or fixed-per-position).
- Per-structure counts: number of rows in your saved blind / payout structures, and how often they've been applied.
- Your in-app settings keys from a hardcoded allow-list (theme, default currency, default players-per-table, balancing mode, sound / voice preferences, animation toggles). Values are primitive only — booleans, small integers, short enum strings.
- Device shape: platform (iOS / Android), app version, OS version, short locale tag, time zone.
- The same opaque per-install
X-Install-Idtoken used by TURNER.
Everything that could identify you, your players, or your venue is permanently excluded and a build-time test fails if anything on this list ever drifts onto the wire:
- Tournament titles and notes.
- Player names, contact details, photos, statistics.
- Venue names and league names.
- Blind-structure and payout-structure names.
- Action logs, chat transcripts, free-text fields of any kind.
Where references to a tournament's venue or league are needed, they
travel as opaque per-install tokens (venue:abc123, league:def456)
that carry no underlying name.
Settings → App Usage also includes a "Delete my usage data" button. Tapping it tells the server to wipe everything it holds for your install ID, and resets the local "last synced" timestamps on this device so you start clean.
9. Third-party AI provider, and what we store for TURNER
TURNER's replies are generated by Google's Gemini 2.5 Flash model, accessed through our AI gateway. Google therefore sees the exact request payload described in §8 (anonymised text plus opaque tokens) and returns a streamed reply. Google's processing of this content is governed by Google's API terms; our gateway forwards the request without storing the content. We do not send your device identifier or any account identifier to Google.
We do not train any model on your data and we do not authorise our provider to do so.
We keep an anonymised log of TURNER chat activity so we can monitor usage, prevent abuse, debug incidents, improve the assistant, and satisfy our rate-limit obligations. The only server-side storage tied to your use of TURNER is:
Rate-limit counters. A row keyed by your random per-install identifier holding integer counters (per-minute, per-day, per-month) and the timestamps at which each counter resets. We use this to stop one device from flooding the model. We never store message bodies, conversation history, citations, screen context, screen labels or names in this table. Buckets are pruned automatically when their reset time has passed.
Anonymised chat logs. For every TURNER chat send we record one row capturing the request outcome (success, cancelled, error, rate-limited, tool-iteration-cap), the model name, the active ruleset, server-side latency, token-count totals, citation and tool-call counts, and the same anonymised payload your device sent (the message text after the on-device anonymiser has rewritten any real names into
kind:idtokens, plus anykind:identity tokens and house-rule snippets). Each row is keyed by your random per-install identifier (X-Install-Id) and a salted one-way hash of your source IP address; the salt is held only on our server and is never returned in any response. Raw rows are retained for 180 days and then deleted. Aggregated counts derived from the rows (daily totals per install, per ruleset, per outcome) are retained indefinitely for trend analysis but contain no message content."Report this reply" submissions. When you tap the "Report" button on an assistant reply, we store: your random per-install identifier; an opaque local identifier for the message you reported (we cannot use that identifier to retrieve the message text — we do not have it); the moderation category you picked (for example "Inaccurate" or "Inappropriate"); the optional free-text reason you typed; and the list of rule references the reply linked to. Message bodies, citation bodies, attached context, conversation history, names and IP addresses are never persisted in this table.
We use these logs only for the operational purposes listed above. We do not sell, rent or share them with anyone outside AceRiver Studios.
10. What we do not collect
The App has no analytics SDK, no crash reporter, no advertising identifier and no third-party trackers beyond the named processors in this policy. The TURNER API server logs include standard HTTP-level metadata (timestamp, status code, path, anonymised IP) for operational purposes only.
11. Your rights and how to exercise them
Under UK GDPR you have the right to:
- Access — ask for a copy of the personal data we hold about you.
- Rectification — correct data that is wrong. Most of your data you can edit directly in the App; for account data, contact us.
- Erasure — have your data deleted (see below).
- Restriction / objection — ask us to limit or stop certain processing, including the legitimate-interests processing in §6.
- Portability — receive your data in a portable form.
- Withdraw consent — turn off App Usage telemetry at any time in Settings → App Usage.
To exercise any of these, email hello@aceriverstudios.com. We will respond within one month, as UK GDPR requires.
Deleting your account and all of its data
The App provides an in-app Delete Account option. When you confirm it, we permanently and irreversibly:
- delete your sign-in identity from Clerk;
- hard-delete all of your synced data from our cloud database (every table listed in §2);
- delete all of your player avatar images from object storage;
- delete your TURNER chat logs, reports and device records from our systems.
This cannot be undone, and we will not retain a copy. (Anonymised aggregate TURNER counts that contain no message content and cannot be linked back to you may remain, as described in §9.)
Deleting just your TURNER logs
If you want to remove your server-side TURNER logs without deleting your account, email turner@aceriverstudios.com quoting your install UUID (Settings → TURNER → "Show install UUID"). Within seven working days we will wipe every chat-log, chat-message, retrieval-log, tool-call-log, dispute-wizard and report row keyed to that UUID, and reply to confirm the counts deleted. Two caveats:
- Deletion does NOT reset your rate-limit counters — that is deliberate, so a deletion request cannot be used to bypass our daily / monthly message caps. The rate-limit row expires on its own schedule.
- Deletion does not affect anonymised aggregate counts, which contain no message content.
Complaints
If you are unhappy with how we handle your data you can complain to the UK Information Commissioner's Office (ICO) at ico.org.uk. We would appreciate the chance to put things right first — please contact us.
12. Data retention
- Account and synced data — kept while your account is active, and deleted when you delete your account.
- Player avatars — kept until you delete the photo or your account.
- Anonymised TURNER raw logs — 180 days, then deleted.
- Anonymised aggregate counts — retained indefinitely (no message content, no names).
- App Usage telemetry — until you delete it or switch the feature off and request deletion.
- Subscription status: held by RevenueCat and our server while your account is active, under RevenueCat's own retention policy.
13. Children
The App is rated 17+ on the App Store because tournament-management software is gambling-adjacent and because TURNER is a generative AI feature with user-generated content surfaces (see "Age rating" in docs/legal/age-rating.md). It is not designed for, marketed to or intended for children under 17, and you must not create an account if you are under 17.
14. Subscriptions and payments
Shuffle Up and Deal! offers optional paid subscriptions. There is a permanent free tier, so no payment is required to use the core App.
Payments are processed by Apple and Google, never by us. When you buy a subscription or start a free trial, the transaction is handled entirely by the App Store (Apple) or Google Play (Google) using the payment method on your store account. We never see or store your card number, billing address, or any payment credential.
To unlock the right plan on all of your devices we use RevenueCat, a specialist subscription-management processor acting on our behalf. RevenueCat receives, and lets our server read:
- A subscriber identifier. We set this to your existing account identity (§1) so your plan follows you across your devices. It is not a new piece of personal data.
- The purchase and receipt details the store returns: which product you bought (for example a monthly or annual plan), the store it was bought on, and its current status (active, in free trial, in a billing-retry grace period, expired, or refunded), including renewal and expiry dates.
- Basic device and platform information (for example iOS or Android and the App version) that the store and RevenueCat attach to a purchase.
RevenueCat does not receive your tournaments, your players, your photos, or your TURNER content. We use your subscription status only to unlock the features and capacity of your plan, including your plan's TURNER allowance on our server. Your current plan is cached on your device so it keeps working while you are offline.
The price you see, and any introductory free-trial offer, come live from the App Store or Google Play in your local currency. To change or cancel a subscription, use the subscription settings in your Apple or Google store account. Refunds are handled by Apple or Google under their store policies. Deleting your account (§11) removes your synced data, avatars and TURNER logs as described there, but it does not cancel a store subscription: cancel that through your store account to stop future charges.
15. Changes to this policy
If we change this policy in a way that materially affects what we do with your data, we will require you to re-accept the Terms of Use on next launch. Minor edits (typos, clarifications) will be published in the App without re-prompting.
16. Contact
Questions, concerns or data requests: hello@aceriverstudios.com TURNER log deletion: turner@aceriverstudios.com
