Privacy Policy

Private by default. Shared only for the table you join.

DeckKit does not require an account and does not include advertising, third-party analytics, or cross-app tracking. Most information stays on your device. Nearby gameplay is exchanged directly with the players at your table, and feedback is sent to the developer only when you choose Send Feedback.

Effective date: 4 August 2026 · Version 1.0

What this policy covers

This policy describes information handled by the DeckKit iPhone and iPad app, its nearby multiplayer features, the first-party feedback service, and this DeckKit support website. “DeckKit,” “we,” and “us” refer to the developer operating these services. It does not replace the privacy policies of Apple, Cloudflare, Google, or another service you choose to use.

Information stored on your device

DeckKit stores information locally so the app works as expected:

  • Your chosen nickname.
  • Appearance, theme, soundtrack, sound, haptic, and card-layout preferences.
  • Quick Start completion and other app preferences.
  • Games played, results, times, moves, scores, and personal leaderboards.
  • Current room and game state while a session is active.

DeckKit does not send local preferences or personal statistics to the developer. Persisted data remains until you change or reset it, delete the app, or manage a device backup through Apple. Apple may handle app downloads and device backups under its own terms and settings.

Information shared with players at your table

Multiplayer rooms use Apple Multipeer Connectivity to communicate directly with nearby devices. DeckKit requires encrypted sessions and does not use a DeckKit-operated remote game server or internet matchmaking for gameplay.

Depending on the game and room state, nearby players may receive:

  • Your nickname, ready status, host or player role, and connection state.
  • Room configuration, game choice, player count, and room code.
  • Game actions, turns, scores, results, and public table state.
  • Private card or game data addressed to your device when required to render your own hand or board.

Other people at your table can see information the game presents to them, including your nickname and public actions. Nearby session data is used to run the current room and is not written to the developer’s feedback database. The host device may process the complete authoritative game state needed to validate and distribute a round, even when DeckKit’s interface reveals private cards only to their intended player.

QR scanning and shared links

Camera access is optional and requested only when you choose to scan a room invitation. DeckKit uses the camera view to recognize the invitation and does not upload or store a photo or video. You may enter the room code instead. If you share an invitation through another app or service, that provider handles the shared content under its own privacy terms.

Information submitted when you choose Send Feedback

Sending feedback is optional and requires an internet connection. A submission may contain:

  • Your feedback message.
  • An optional feedback category.
  • An optional reply email address.
  • DeckKit’s app identifier, app name, version, build number, and platform.
  • A randomly generated submission identifier plus client and server timestamps.
  • An internal review status used to organize product planning.

Do not include passwords, financial information, health information, details about children, or other sensitive personal data in feedback.

Cloudflare processing

The feedback API and this website use Cloudflare. When a request reaches Cloudflare, Cloudflare may process IP address, request headers, timestamps, security signals, and other network metadata to deliver and protect the service. The feedback Worker uses the request IP as a temporary rate-limit key, but the Worker code does not write the IP address into the feedback database.

Cloudflare may process and retain request metadata according to the account configuration, its service terms, and its Privacy Policy. This website has no analytics scripts, advertising cookies, forms, or third-party fonts.

Why information is used

  • Save your choices and personal game history on your device.
  • Discover, connect, operate, and recover nearby game rooms.
  • Receive, review, categorize, and prioritize product feedback.
  • Understand which DeckKit version produced a feedback submission.
  • Prevent accidental duplicates and abuse.
  • Reply when you provide an email address and a response is useful.
  • Maintain, secure, troubleshoot, and improve DeckKit.
  • Comply with applicable legal obligations.

DeckKit does not use information for targeted advertising, cross-app tracking, or sale to data brokers.

Nearby players, providers, and disclosures

Information may be processed by or shared with:

  • Nearby players, as needed to operate the room and display the game state described above.
  • Apple, which supplies app distribution, device services, camera frameworks, local networking, and optional backups.
  • Cloudflare, which hosts the support site, feedback API, rate limiter, and feedback database.
  • Google, when you contact the public Gmail support address or receive a reply, under Google’s Privacy Policy.

We may also disclose information when reasonably necessary to comply with law, enforce rights, protect users or the service, investigate abuse, or complete a business transfer with appropriate safeguards. We do not sell personal information.

How long information is kept

There is currently no fixed automatic deletion schedule for feedback submissions. Feedback and related app context are retained for as long as reasonably necessary to evaluate product ideas, respond when appropriate, maintain operational records, resolve disputes, protect the service, and meet legal obligations. Information no longer reasonably required may be deleted or de-identified.

Support emails are retained for as long as reasonably necessary to address the request and maintain appropriate support records. You may request earlier deletion, subject to verification and any information we must keep for legitimate security or legal reasons.

Control, access, correction, and deletion

You can change your local preferences in DeckKit Settings, decline camera access and enter room codes manually, play without submitting feedback, and delete the app to remove its local data subject to device backups.

To request access, correction, or deletion of feedback or support records, email flowstatecoders@gmail.com with the subject “DeckKit Privacy Request.” We may ask you to verify a request. If you included a reply email, contact us from that address where possible. Otherwise provide the approximate submission date, category, app version, and enough of the message to locate it. We may be unable to identify an anonymous submission when the supplied details are insufficient or match multiple records.

How information is protected

DeckKit requires encryption for nearby sessions, uses HTTPS for feedback, validates submitted fields, limits request rates, and exposes no public route for reading the feedback database. Access to stored submissions requires authorized Cloudflare credentials. No method of storage or transmission is completely secure, so absolute security cannot be guaranteed.

Cloudflare and Google may process information in countries other than your own, subject to their contractual and legal safeguards.

Family and group use

DeckKit is a general-audience card-game app and is not designed to collect personal information from children. Children should not submit personal information through Send Feedback or support email. An adult supervising family or group use should contact support on their behalf.

Policy updates

This policy may be updated when DeckKit’s features, service providers, or legal obligations change. The effective date and version at the top of this page will be revised. Material changes will be communicated through an appropriate channel when required.

Questions or requests

flowstatecoders@gmail.com