Privacy Policy
Effective August 13, 2026 · [email protected]
Data controller: Betwatch, Inc., a Delaware corporation
BlackJack Lab knows an enormous amount about how you play, and almost none of that ever leaves your device. This policy says exactly which parts do and which parts do not, because on a training app the difference matters.
The short version: your training data stays on your device. Your account, your subscription, and measurements of which parts of the app you use do not, and since this version, those measurements are linked to your account.
What changed in this version
The previous version of this policy said usage measurements carried no account and that we had no way to connect them to you. That is no longer true, and we would rather lead with it than bury it.
- Usage measurements are now sent from a signed-in app over an authenticated connection, so we know which account they came from.
- The app now sells subscriptions, so there is billing data that did not exist before.
- The upside of the first change: we can now honour a deletion request for your measurements. Under the old design we genuinely could not.
The Terms of Use are being re-presented for acceptance because of this. Nobody is being asked again for a formatting change.
What stays on your device, always
The app stores all of this locally, on your device only. It is never uploaded, and we cannot see it:
- Every hand you have played, every decision you made, and whether it was right
- Your per-decision practice statistics, weak spots, and drill history
- Your count-quiz and chart-quiz results
- Your session results, including every bankroll, stake, and profit figure
- Your trainer settings: table rules, counting system, coaching preferences
- Your app preferences: sound, volume, advanced stats, gestures
- Strategy tables computed by the engine on your device
This is not only a promise in a document. The app's analytics code carries a rule list that blocks cards, decisions, hand histories, money, and free text from being sent, and it drops any measurement that breaks it.
Your device also keeps a local copy of your account profile and the sign-in tokens that save you signing in every time. On phones and tablets, deleting the app deletes all of it. On desktop it does not: the data lives in a folder in your home directory that survives uninstalling, and you can delete that folder yourself at any time.
What survives an uninstall, stated exactly: on iOS and iPadOS, deleting the app removes everything the app stored on the device, including your trial record. We do not hide a marker in the system keychain or anywhere else outside the app’s own storage, and the app contains no code that could. What does outlast a reinstall on every platform is the record on our servers that your account has already used its free trial, because that record is attached to your account rather than to your device.
Your account
BlackJack Lab uses a Betwatch account, and it is required to use the app. When you sign in we hold:
- A Betwatch account identifier
- Your mobile phone number
- Your email address and display name, only if your Betwatch account already has them. An account created from this app has neither
- Which sign-in methods are linked to the account
- The date you signed up, and whether you claimed a founder pass during the beta
You enter your mobile number, we text you a short numeric code, and entering that code signs you in. There is no password and no email step. Standard message rates from your carrier apply. We pass your number to our SMS provider for the sole purpose of delivering that code.
A Betwatch account is not specific to this app. The same account can be used across other Betwatch products, so creating or deleting it affects those too.
Usage measurement
The app can send measurements about how the app is used. Nothing is sent unless two separate things are both true, and either one of them alone stops it: we have switched measurement on by publishing a signed configuration, and you have not refused in Settings. Our switch can only ever subtract. Turning it on never overrides someone who has refused.
These measurements are linked to your account. Read this part. An account is required to use the app, and the app sends measurements over a signed-in, authenticated connection. We therefore know which account each batch came from, and we store it that way on purpose. Assume that anything in the list below is attributable to you.
Two smaller points, because a half-explanation here would be misleading in our favour. The identifier is on the connection, not in the message: the app does not put your account id, phone number or email inside a measurement, and that rule is still enforced in code. But the request carrying it is authenticated, so the linkage happens at our end regardless. Saying "the events contain no identity" would be technically true and practically dishonest, so we are not saying it. The random installation identifier still exists alongside your account; its remaining job is to attribute activity from before you signed in to the right account once you do.
Every measurement is one word from a fixed list, or true/false. There are no free-text fields and no raw numbers: durations and volumes are sent as coarse buckets, never exact figures. What is measured:
- The app being opened and closed, and whether any practice happened
- Which screen you opened and which screen you came from
- How far you got through the first-launch tour
- Practice sessions: which mode, roughly how long, roughly how many hands, and whether you finished. Never how many you got right
- Which optional feature you used, from a fixed list
- Which setting you changed, and whether it now differs from the default. Never the value you set it to
- When the app showed you an error: which subsystem, and whether you recovered. Never the message
- When you switch measurement on or off
- Account actions: whether a sign-in, registration, sign-out or deletion was attempted, and whether it worked
- Trial and subscription state changes, and which step of a purchase was reached. Never a price, a receipt, a transaction id, or a store account
What it never includes, as a rule enforced in code: cards, of any rank or suit. Individual decisions, what was correct, or the count you played at. Any hand history. Money, including the simulated kind. Free text of any kind. How well you play. Device fingerprints, advertising identifiers, device model, OS version, locale, timezone, screen size, or location.
Why: to know which parts of the app people use, where the app loses people, where buying breaks, and where the app fails. It is never used for advertising, never sold, and never shared with anyone.
Configuration
The app may fetch a small, cryptographically signed settings file so we can turn a feature off, correct a problem, publish a notice, change a price, or tell you about an update without shipping a new release.
Being straight about what this can do: it is not only cosmetic. We can use it to require a minimum version, which means the app can tell you it will not continue until you update. Any such block is time-limited: it eases after a grace period, and after 30 days it degrades on its own to a notice you can dismiss.
The request asks for nothing but the file: no account, no identifier. The file contains settings, version numbers, numeric limits, prices, links, and short messages only, never program code, which the app structurally cannot accept.
Your subscription, and the licence checks that go with it
BlackJack Lab is sold as a subscription, with a one-time lifetime option.
What we hold about your subscription: one record per account, whichever way you paid. Whether you are trialing, active, past due, cancelled or expired; which plan; which payment route; when the current period ends; whether you have asked it not to renew; when your trial started and ends; and, if an invite code or founder pass granted your access, which one and for how long.
Licence checks: the app verifies your entitlement with our server, normally once per launch when you have a network connection. So we can count how many devices a subscription is used on, the app invents a random identifier for this installation and sends only an irreversible hash of it (SHA-256). This is not a fingerprint of your device: nothing is read from your hardware. No serial number, no MAC address, no advertising identifier, no device characteristic at all. Licence checks fail open: if our server cannot be reached, the app keeps working rather than locking you out.
Your free trial is attached to your account, not to this device. That is the honest trade: your trial follows you to a second device instead of restarting there, and reinstalling does not give you another one.
Paying: there are two routes and they collect different things.
- Apple (in-app purchase on iPhone, iPad and the Mac App Store). Apple is the seller. Apple takes the payment, holds the card, handles the renewal, charges the tax, and issues the refunds. We never see your card details, and we do not learn your Apple Account email or name. Apple sends us a transaction identifier that stays the same across renewals, the product you bought, whether it is sandbox or production, and when it expires.
- Stripe (buying on betwatch.io). Here we are the seller, and Stripe processes the payment for us. Stripe collects your card and billing details directly; they never pass through our servers and we never store them. We receive and keep a Stripe customer and subscription identifier, the plan, the amount, the currency, the invoice identifiers, the last four digits and brand of the card as shown on your receipt, and the country we must charge tax on.
Auto-renewal: monthly and annual plans renew automatically until you cancel; the lifetime purchase does not renew at all. An Apple subscription is managed and cancelled in your Apple account settings, and a Stripe subscription in the customer portal we link from the account screen.
Invite and promotional codes: if you redeem a code, we record which code, your account, the time, the device hash, and the IP address the redemption came from. The IP is there for one reason, because codes get posted publicly and redeemed a thousand times by one person, and it is not used for anything else.
Refunds and chargebacks: if Apple refunds a purchase, or a Stripe payment is charged back, we are told and the entitlement ends. We keep the record of that, because we have to.
What every network request carries anyway
We would rather say this than let you assume otherwise. Every request the app makes carries information the app does not choose to send, because the software making the request adds it: your IP address, which is inherent to any internet connection; a user-agent string, which on desktop names the app and its version, the browser engine, and your operating system and its version; and your language and region setting.
What happens to it: our servers run on Google Cloud, which keeps ordinary request logs, including your IP address, so that we can investigate an outage or an attack. We keep them for 30 days and then they are deleted.
The usage-measurement collector writes no IP address to any record. Your IP reaches it, as it reaches any server, and it is used to rate-limit the request, but it is never written into a measurement, a daily summary, or any other stored document. This is not a promise about intent; it is a property of the code that handles the request, and anyone reading that handler can check it.
Three deliberate exceptions where an IP is stored, all named where they arise rather than hidden here: an invite-code redemption records the IP it came from as an anti-abuse record; claiming a founder pass records the IP it came from, in the same log as administrative actions; and an administrator action on our side is logged with the IP it came from.
What we do not do with any of it: we do not use it to build a profile of you, we do not use it to infer where you live beyond the country we are required to charge tax on, and we do not sell or share it.
An earlier version of this policy said our measurement collector retained no IP addresses at all. That was a specification rather than an observed fact, and the paragraph above replaces it with what the servers actually do.
What we never do
No advertising. No advertising identifiers. No third-party analytics, attribution, or crash-reporting SDKs. No data brokers. We do not sell your personal information, and we do not share it for cross-context behavioural advertising (the CCPA/CPRA terms). We have never done this and this policy would have to change first.
Artificial intelligence: we do not use any
We are stating this because the honest answer is unusual and worth having in writing, and because "AI" has become a word people assume rather than check.
No part of BlackJack Lab uses artificial intelligence or machine learning. Not the strategy engine, not the grading, not the drills, not the simulations, not anything on our servers.
What the app actually does is older and more boring than AI, and better suited to the job: it solves the game exactly. Its recommendations come from expectimax dynamic programming over the exact composition of the remaining shoe, and from Monte Carlo simulation where enumeration is too slow. Those are deterministic algorithms. Given the same rules and the same cards they produce the same answer every time, and that answer is the mathematically correct one rather than a plausible-looking one.
The consequences for you, which are the reason this section exists:
- Nothing you do in this app is sent to any AI service. Not to OpenAI, not to Anthropic, not to Google, not to any hosted model, and not to a model running on your own device. There is no such code in the app and no such dependency in it.
- Nothing you do trains any model, ours or anyone else’s. We do not have a model. Your hands, decisions, counts and results never leave your device at all, so there is nothing to train on even if we wanted to.
- No decision about you is made by an automated model. Whether you are subscribed is a database record, not a prediction.
If this ever changes, this section changes before the version that changes it ships, and we will tell you in the app.
Third parties
The companies below process data on our behalf, or receive it because there is no other way to do the job. None of them is permitted to use it for their own purposes, and none of them receives your training data, because we do not have it.
- Google Cloud and Firebase (Google LLC): our servers, our database, and the service that issues your sign-in session.
- Prelude, which delivers the sign-in code. It receives your phone number, for that purpose only.
- Stripe, Inc., if you buy on the web. It collects and holds your card and billing details directly; we never receive them.
- Apple Inc., if you buy through in-app purchase. Apple is the seller and holds the payment method.
- Sign in with Apple and Google Sign-In, used in one place only: claiming an optional founder pass in Settings during the beta. They are not how you sign in to your Betwatch account.
- The app stores (Apple, Google), for distribution of the app itself.
There is no third-party software inside the app that collects or transmits anything else. No analytics SDK, no attribution SDK, no crash reporter, no advertising library.
Founder passes: while the app is in beta, Settings offers a founder pass, a record that your account was here early. Claiming one uses Sign in with Apple or Google, the only two places in the app that do. From that sign-in we receive an account identifier, and your name and email address only if you choose to share them, plus the date and platform you claimed on.
Messages we send you
Messages about your subscription, which you cannot turn off, because they are the record of a transaction between us and in several places the law requires us to send them:
- A confirmation when you buy, setting out what you bought, the price, how often it renews and how to cancel.
- A reminder 30 to 45 days before an annual subscription renews, saying what it will cost and how to cancel. You get this whether you bought on the web or through Apple. Apple sends its own receipts and notices for its own purchases; ours is in addition, not instead.
- A yearly check-in confirming you still want the subscription.
- A notice if a payment fails (web purchases; Apple handles its own).
- A notice before any price change, in time for you to cancel (web purchases; Apple runs its own consent process).
- A confirmation when you cancel.
Monthly subscriptions get no pre-renewal reminder. A monthly term does not require one, and a monthly message about a monthly charge is noise.
How we reach you, and why it is not simply "email". Your account is a phone number. An email address is optional and many accounts do not have one. So these notices reach you in the app, by push notification if you have allowed it, and by email where we have an address for you. If you would rather have them by email, you can add an address in Settings. We are saying this rather than promising "we will email you", because for a lot of accounts that would be a promise we could not keep.
Messages about the app: occasional news about releases and features. These are optional, we will ask before we start, and every one carries a working way to stop them. Turning them off never affects the messages above.
Administration on our side
A small number of people at Betwatch can look up an account to answer a support question, issue a free or discounted licence, revoke one, or publish a notice into the app. Every one of those actions is written to an audit log recording who did it, what changed, when, and the IP address they did it from. The log exists so that access to your record is accountable rather than invisible.
One thing you do yourself is written to the same log, and we would rather say so than let you find it. Claiming a founder pass (whether it succeeds or is refused) is recorded there too, with your own IP address, because a grant of free access has to be as auditable as an administrator handing one out. So this log is not exclusively a record of what staff did; that one user action appears in it as well.
It is kept for 7 years, which is a long time for an IP address, and it is the longest retention in this policy. The reason is that the point of an audit log is to outlast the dispute it exists to settle. Nothing in it is used for analytics, advertising, or profiling, and it is never joined to your usage data.
How long we keep things
- Account records: while your account exists, and up to 30 days after you delete it.
- Usage measurements, raw: deleted 90 days after they arrive.
- Usage measurements, daily summaries: one row per account per day, kept while your account exists and deleted when you delete your account.
- Usage statistics, aggregate: totals that name nobody are kept indefinitely. Deleting your account does not retract your contribution to a total, and no honest policy can promise it does.
- Subscription, licence and payment records: while the subscription is live, and after that for as long as tax and accounting law requires (typically up to 7 years).
- Invite-code redemptions, including the IP address: 12 months.
- Server request logs, including IP addresses: 30 days.
- Founder-pass claims, including the IP address: 7 years, in the audit log below. This is the longest we keep an IP and it is called out separately because it is the one entry there that records something you did.
- Administrative audit log: 7 years.
- Training data: we never have it. It lives on your device until you delete it.
Your rights
Depending on where you live, you have rights over the personal information we hold. We honour these for everyone, not only where they are legally required: see it, correct it, delete it, take it with you, object or restrict, and complain to your data protection authority.
Deleting your account: Settings, then Account, then Delete account removes your account and its records permanently, on our servers and not merely on your device. It needs a network connection, and if it cannot reach us it tells you the account has not been deleted rather than pretending. Because it is a Betwatch account, deleting it also ends your access to other Betwatch products that use it.
What deleting removes: your account record, your device list, your subscription status, your invite redemptions, your founder pass, your daily usage summaries, and any raw measurements still held. Two exceptions, stated because you should hear them from us rather than discover them. Records of a sale: if you have paid us, tax and accounting law requires us to keep a record of the transaction for up to 7 years. Aggregate statistics: totals that name nobody are not unpicked.
Deleting your account does not delete your training data, because we never had it. It is on your device. The optional "also erase local data" tickbox clears your bankroll, ratings and beta records, but it does not clear your session history, weakness statistics, or cached strategy charts. Those live in the engine’s own profile, and the way to remove them is Settings, clear cache, or deleting the app.
The measurement limit in the previous version of this policy is gone, and this is the good news in the change. That version said measurements carried no account, so if you asked us to delete "your" measurements we could not find them. Now that they are tied to your account we can, and we do.
Email [email protected] to exercise any of these. We will not charge you, discriminate against you, or degrade the app because you did.
If you are in the EU or UK
Our lawful bases are: contract, for your account, subscription, licence checks and payments; legal obligation, for keeping records of sales and tax; legitimate interests, for security, fraud and abuse prevention, and usage measurement; and consent, for the founder-pass sign-in.
On usage measurement specifically, and why we are flagging our own weak point: when these measurements were unlinkable, the legitimate-interests argument was easy. Now that they are tied to your account it is genuinely weaker, and we would rather say so than assert a balancing test we have not done. Our position is that the interest is real and narrow, the data is deliberately coarse and contains nothing about how you play, it is never used to advertise to you, profile you, or make any decision about you, and you can refuse it at any time in Settings, which is the objection right, available without asking us. If you object, that is the end of it; we do not require a reason.
If you are in California
The categories of personal information we collect, in the CCPA/CPRA’s own terms: identifiers (account id, phone number, email if your account has one, the random installation and device identifiers, IP address); commercial information (what you bought, your subscription status, your payment history); internet or network activity (the usage measurements above); financial information limited to what the subscription section lists, since the card itself is held by Stripe or Apple and never by us; and inferences, of which we draw none.
We do not sell your personal information and we do not share it for cross-context behavioural advertising. We have never done either. There is consequently no "Do Not Sell or Share My Personal Information" link to offer you, because there is nothing for it to switch off. You have the rights to know, delete, correct, and to be free from retaliation for asking.
International transfers
Betwatch, Inc. is in the United States and our servers are in the United States. If you are outside the US, using the app means your account, subscription and usage data are transferred there and processed there.
For people in the EEA, the UK and Switzerland, those transfers rely on the European Commission’s standard contractual clauses (and the UK addendum), which is also the basis on which our processors handle the data they receive. Apple’s handling of an in-app purchase is governed by Apple’s own terms with you, not by ours. If you would like the details of these safeguards, email us and we will send them.
Children
The app is rated for adults (18+) because of its simulated-gambling training theme. It is not directed at children and we do not knowingly collect anything from anyone under 18. If you believe a child has given us information, email us and we will delete it.
Changes
If a future version collects something not described here, this policy will be updated before that version ships, and the app-store data disclosures will be updated to match. If the change is material we will tell you in the app and, if the law requires it, ask you again.
Questions about this policy: [email protected]
← Back to BlackJack Lab