Privacy policy
Private study data deserves narrow access.
Effective August 27, 2026. This deployment-ready policy must be reviewed with the final operator identity, contact details, providers, jurisdiction, and retention settings before launch.
Data we process
Account identifiers, secure session records, subscription status, product preferences, saved studies and drills, user-supplied hand histories, solver job metadata, learning progress, operational logs, and audit events. PokerLab does not store card-payment data.
Why we process it
To authenticate users, authorize paid features, operate study workflows, prevent abuse, debug failures, honor exports/deletions, and meet security obligations. Product analytics are optional and disabled by default.
Storage and retention
Relational metadata is designed for D1 and private artifacts for R2. User-configurable retention applies to uploaded histories; backups follow the documented recovery schedule. Deletion revokes access and removes or schedules owned records and objects subject to limited legal/security retention.
Sharing and transfers
Configured infrastructure, email, authentication, billing, monitoring, and solver providers process only the data required for their function under the operator’s agreements. PokerLab does not sell personal information.
Your controls
Users can manage sessions, request an export, delete their account, set retention preferences, and contact the configured privacy address. Applicable rights vary by jurisdiction.