← Back to Chambers

Privacy Policy

Last updated: [DATE] · Draft — see notice below

This is a draft, not a final legal document. It accurately describes what the app's code actually collects and stores as of this writing, but hasn't been reviewed for compliance with any specific privacy law (GDPR, CCPA, or others) — that review, and any resulting changes, still needs to happen before this should be relied on as your real privacy policy.

This Privacy Policy describes what information Chambers ("we," "us") collects when you use the Service, and how it's used. "Personal data" below means anything that identifies or could reasonably identify you.

1. What we collect

Account information: your email address (if you sign in by email) or your Solana wallet's public address (if you sign in with a wallet), an optional nickname you choose, and your account creation date.

Financial activity: deposit and withdrawal records (amounts, on-chain transaction signatures, timestamps, status), your balance, which chambers you've entered and for how much, and draw outcomes involving your account. Deposits and withdrawals are also permanently recorded on the public Solana blockchain — that record isn't controlled by us and can't be deleted by us or by you.

Responsible-play settings: any self-exclusion period or daily deposit reminder you set.

Technical data: standard web server logs (IP address, browser type, request timestamps) collected by our hosting and database providers as part of normal operation.

Local device storage: your browser stores a few small preferences on your own device (never sent to us as separate data): your light/dark theme choice, whether you've dismissed the welcome banner, when you last used the app (so we can show you wins that happened while you were away), and — only while a deposit is being confirmed — the transaction signature, so a dropped connection doesn't strand a real transfer.

2. What's public by design

Chambers is built to be transparent about how draws work: chamber pools, entry counts, and who entered how many times are visible to anyone using the Service, signed in or not — this is intentional, not a leak, and is core to how the provably-fair system can be independently verified. Your account balance and email address are not part of this — those stay private to your account.

3. How we use this information

To operate your account and process deposits/entries/withdrawals; to run and verify draws; to enforce the responsible-play settings you choose; to detect fraud, abuse, or attempts to circumvent per-account limits; and to comply with legal obligations once a licensing review determines what those are.

4. Who we share it with

We use third-party infrastructure providers to run the Service, who process data on our behalf: Supabase (database, authentication, and backend hosting), a Solana RPC provider (to read and submit blockchain transactions — this provider can see wallet addresses and transaction activity as an inherent part of how blockchains work), and a hosting provider for the website itself [e.g. Vercel]. We do not sell personal data to third parties.

5. Data retention

We retain account and transaction records for as long as your account is active and for a period after closure to meet legal, accounting, and fraud-prevention obligations [SPECIFIC RETENTION PERIOD — TO BE SET DURING LEGAL REVIEW]. On-chain transaction records are permanent and outside our control.

6. Your choices

You can update your nickname and responsible-play settings directly in your account. You can request deletion or export of your account data by contacting us [CONTACT EMAIL] — note that we cannot delete on-chain transaction history (it isn't stored by us), and we may need to retain some records even after a deletion request to meet legal or fraud-prevention obligations.

7. Children

The Service is not directed at, and must not be used by, anyone under [MINIMUM AGE — matches the Terms of Service]. We do not knowingly collect data from anyone under that age.

8. Security

We use reasonable technical measures to protect account data, including restricting all database writes to server-side logic rather than direct client access. No system is perfectly secure, and we can't guarantee absolute security of information transmitted to or stored by the Service.

9. Changes to this policy

We may update this policy from time to time. Material changes will be posted on this page with an updated "Last updated" date.

10. Contact

Questions about this policy or your data: [CONTACT EMAIL — e.g. chambersteam@proton.me]