Privacy
Privacy Policy
This policy explains how Jensen Tang (“we”, “us” or “our”) handles information when you use DoubleDeck.
1. Who controls your information
Jensen Tang is responsible for DoubleDeck. Our contact location is Melbourne, Victoria, Australia. Privacy questions and requests can be sent to [email protected].
2. Information stored only on your device
DoubleDeck can be played locally without creating an account. The app may store the following on your device:
- gameplay state, fictional Credits, completed hands and local progression;
- mastery, streak, achievement and Daily Puzzle progress;
- sound, haptic, onboarding, analytics-consent, accessibility-related and appearance preferences;
- a locally generated guest name or identifier;
- locally queued analytics events while product analytics is enabled; and
- development-only StoreKit Configuration data in non-production builds.
This local information generally remains until you delete the app, reset the relevant in-app data, or the operating system removes it. Disabling product analytics clears analytics that is still waiting for delivery.
3. Account and authentication information
Account creation is optional for basic local gameplay. Accounts support synced Gold, cosmetic ownership and eligible purchase restoration. Depending on the sign-in method you choose, we may handle:
- the DoubleDeck account UUID created by our account provider;
- your email address when you choose email authentication;
- Apple’s stable provider identifier when you choose Sign in with Apple;
- your name if Apple supplies it and you choose to share it, or the display name you provide;
- authentication session and refresh tokens stored securely in the iOS Keychain;
- for Sign in with Apple, a server-side Apple refresh token used only to maintain the Apple authorization lifecycle and revoke DoubleDeck’s authorization when you delete your account;
- your server Gold balance and immutable Gold ledger entries;
- cosmetics you own and the cosmetic selected for each category; and
- account creation, update and deletion timestamps.
Passwords are handled through our authentication provider. We do not receive your Apple ID password. Apple authorization credentials are not exposed to other DoubleDeck users.
4. Multiplayer and server gameplay information
When you use Private Tables, DoubleDeck stores the information needed to create, join and run that table. This can include a table identifier, member identifiers, seat and presence state, a generated player alias, the selected virtual-currency mode, gameplay snapshots and other state needed to keep participants synchronised. Signed-out multiplayer uses a device-bound anonymous authenticated identity rather than requiring an email address or Apple sign-in identity.
Private Table aliases are generated from a controlled word set rather than exposing free-form account display names to other table participants. Private Table data is used only to provide the multiplayer session, protect access to the table and resolve the game consistently for its members.
If a participant deletes their permanent DoubleDeck account while they belong to an active Private Table, that ephemeral table is closed and its member/state/snapshot records are removed so the deleted identity is not left in multiplayer state.
5. Purchase and App Store transaction information
Apple processes payments. DoubleDeck receives and verifies Apple-signed transaction data needed to deliver and restore purchases. This may include:
- transaction and original transaction identifiers;
- the purchased product identifier;
- Sandbox or Production environment;
- purchase, verification, refund and revocation dates;
- the signed
appAccountTokenthat binds a purchase to a DoubleDeck identity; - the stable Apple provider identity needed to protect eligible restoration after account recreation;
- the Gold amount granted by our server product contract;
- cosmetics granted by a bundle; and
- refund clawback and shortfall information where purchased Gold has already been used.
The iOS app cannot choose its own Gold grant. Our server verifies Apple’s signed transaction and derives the grant from an allowlisted product contract.
6. Product analytics
Product analytics is enabled by default. You can disable Share product analytics from the first-hand screen or later in Settings, and can re-enable it at any time.
When enabled, the app may send a closed, non-free-text set of product interaction events together with:
- a randomly generated app-instance UUID and session UUID;
- event name, event identifier and event time;
- app version and build number;
- device family and major operating-system version;
- a local day index used for retention analysis; and
- strictly allowlisted event properties such as game mode, action, outcome, cosmetic or product identifier, purchase-attempt identifier, table identifier and seat count where relevant.
The analytics payload does not include your name, email address, Apple provider identifier, authentication token, table join code or free-text messages. The ingestion service hashes the app-instance and session UUIDs with SHA-256 before durable database storage and does not retain the raw UUIDs in the analytics table.
Analytics is used to understand activation, reliability, retention, multiplayer success and the purchase funnel. It is not used for advertising or cross-app tracking. Analytics events are retained for up to 90 days, after which they are deleted by the analytics retention process. Disabling analytics stops new collection and clears events still queued on the device for delivery.
7. How we use information
We use information only as reasonably necessary to:
- authenticate your account and maintain your session;
- operate DoubleDeck, Private Tables and local or synced settings;
- deliver consumable Gold and non-consumable bundle items;
- sync Gold, ownership and equipped cosmetics between devices;
- restore eligible non-consumable purchases;
- prevent duplicate grants, transaction replay, fraud and unauthorised account transfer;
- apply verified refunds and revocations;
- delete your active account and revoke DoubleDeck’s Sign in with Apple authorization when applicable;
- measure product performance while product analytics is enabled;
- diagnose failures, secure the service and provide support; and
- comply with applicable legal, accounting and App Store obligations.
8. Service providers
- Apple
- Provides Sign in with Apple, StoreKit, App Store payment processing, signed transaction data and refund or revocation notifications. Apple handles information under its own terms and privacy policy.
- Supabase
- Provides authentication, database, Realtime and Edge Function infrastructure for DoubleDeck accounts, commerce, Private Tables and first-party analytics. The configured project region is Northeast Asia (Seoul).
We do not sell personal information. We do not share information with advertising networks or data brokers.
9. International processing
Apple and Supabase may process information in the countries where they or their service providers operate. We select and configure services for the purposes described in this policy and take reasonable steps to protect information in accordance with applicable law.
10. Retention
Active account, wallet and cosmetic information is retained while your DoubleDeck account exists and as needed to operate the service. Private Table state is retained only as needed to operate and support multiplayer sessions.
Analytics events are retained for up to 90 days. Disabling analytics also removes analytics still queued locally for future delivery.
When you delete your account, we delete the active profile, Gold wallet, Gold ledger, ownership, equipment and local authentication session. Any server-side Sign in with Apple revocation credential associated with the deleted DoubleDeck account is removed as part of account deletion after the authorization lifecycle has been handled. We retain a detached App Store transaction tombstone for as long as reasonably necessary for duplicate-grant prevention, refund or revocation handling, and eligible non-consumable restoration or longer where required by applicable law, accounting obligations, dispute handling or App Store refund processes.
A transaction tombstone is not linked to an active DoubleDeck profile. It may retain transaction identifiers, product and environment, purchase or revocation dates, the original signed account token and stable Apple provider identifier. These records are used only to prevent duplicate grants, match later refunds or revocations, and restore an eligible non-consumable to the same Apple identity. Consumable Gold is not restored after account deletion.
11. Account deletion
You can initiate account deletion in DoubleDeck under Progress → Settings → Manage Account → Delete Account. Deletion removes the active account and synced Shop state as described above. Any active Private Table that includes the deleting permanent account is closed so that the deleted identity is not retained in multiplayer state. Eligible non-consumable cosmetics may later be restored only after a verified App Store transaction is matched to the same Apple identity; deleted Gold is not replayed.
If you used Sign in with Apple, DoubleDeck attempts to revoke its Apple authorization as part of deletion before removing the DoubleDeck account. Accounts created before this revocation flow was available may require you to remove DoubleDeck manually from your Apple Account’s Sign in with Apple settings. Deleting your DoubleDeck account does not delete your Apple Account or alter Apple’s own App Store transaction records.
12. Security
DoubleDeck uses HTTPS, iOS Keychain storage, server-side Apple signature verification, restricted server-side Sign in with Apple revocation credentials, row-level database security, restricted server functions, idempotent transaction processing and internal ledger controls. Analytics identifiers are hashed before durable analytics storage. No system can guarantee absolute security. Contact us promptly if you believe your account or purchase information has been compromised.
13. Your choices and rights
Depending on where you live, you may have rights to request access to, correction of, deletion of, or information about personal information we hold. Send a request to [email protected]. We may need to verify your identity before acting.
You can play basic local blackjack without signing in. Product analytics is enabled by default and can be disabled at first launch or at any time in Settings. You can stop account-related collection by signing out, deleting your DoubleDeck account and removing the app, subject to the limited transaction retention described above.
14. Children and age rating
DoubleDeck is a simulated card game and does not offer real-money gambling or prizes. The app’s availability to younger users is governed by its App Store age rating, family settings and applicable law. If you believe a child has provided personal information contrary to applicable requirements, contact us.
15. Changes to this policy
We may update this policy when DoubleDeck, our providers or legal requirements change. We will publish the revised policy at https://playdoubledeck.app/privacy.html with a new effective date and provide additional notice where required.
16. Contact and complaints
Email privacy questions or complaints to [email protected]. We will review and respond within a reasonable period. You may also have the right to contact the privacy regulator in your jurisdiction.