BankrollHQ

Privacy Policy

Last updated 14 September 2026

This is a draft, not reviewed legal advice. It describes what this application actually stores and where, in plain language — it is not a substitute for a lawyer's review before you rely on it, particularly the GDPR sections below.

What is collected

An email address (or a GitHub account identifier, if you sign in that way), and the poker results you enter or import — cash session and tournament figures, timestamps, and which poker room they're from. BankrollHQ never records another player's identity, cards, or actions: only your own results, ever.

What is never collected

No payment card details — a future paid plan would be billed through Stripe, which handles and stores card data directly; this application never sees or stores it. No raw poker hand histories: files you import are parsed on your own device or on our server at the moment of import, and only the resulting figures (buy-in, result, timestamp) are kept — the file's own contents, including any opponent data in it, are discarded, not retained anywhere.

Where it's stored

In a PostgreSQL database, isolated per account with row-level security so one account's data is unreachable by another even in the event of an application bug. Hosted alongside the application itself with no direct public access to the database.

Who else sees it

Nobody, by default. A short list of infrastructure providers process data on our behalf strictly to run the service:

  • A hosting provider, for the application and its database.
  • An email delivery provider, to send sign-in codes — it sees the email address and the code, nothing else.
  • GitHub, only if you choose to sign in with a GitHub account.
  • Stripe, only once a paid plan is active — it would handle payment details directly and never passes card data to us.

None of them are permitted to use your data for their own purposes, and none of it is sold or shared for advertising.

Your rights (GDPR and equivalent)

You can, at any time, from the Account page:

  • Export a complete copy of your data as a downloadable file.
  • Delete your account permanently — this removes every session, entry and imported-file record immediately and without a recovery window.

If you'd rather ask a person to do either of these for you, or have another question about your data, email support@bankrollhq.xyz.

Cookies

One cookie, to keep you signed in. It is strictly necessary for the service to function and is not used for tracking or advertising, so there is nothing to opt into or out of beyond signing in and out.

Retention

Your data is kept for as long as your account exists. Deleting your account deletes it immediately, cascading through every table that references it — there is no separate backup copy kept around afterward for this application to restore from.

Changes

This page may change as the product does. Material changes will be reflected here with an updated date.

Contact

Questions about this policy, or a data request: support@bankrollhq.xyz.

See also the Terms of Service.