Privacy Policy
Felted: Texas Hold'em Poker
Last Updated: 12 August 2026
GTO Solutions AS is the data controller for Felted: Texas Hold'em Poker ("Felted" or "the App"). This policy explains what data Felted processes, why it is processed, when it leaves your device, and the choices available to you.
Felted is an adult, play-money poker game. It contains no advertising and does not use data to track you across apps or websites owned by other companies. Purchased chips have no cash value and cannot be transferred or cashed out.
1. Data We Process
1.1 Local gameplay and profile data
Offline modes run on your device. Felted stores information such as your display name and avatar, chip balance, campaign and training progress, hand history, poker statistics, achievements, settings, and purchase-grant records in local app storage.
If you use only offline play and do not enable cloud features, most gameplay data remains on your device. Some diagnostics, analytics, purchase, and support information may still be sent as described below.
1.2 Accounts and cloud backup
You may play offline as a guest. If you sign in with Apple or Google, or use an online feature that creates an anonymous Firebase identity, we process a Firebase user identifier and authentication-provider information. Depending on your sign-in method, this may include your name or email address.
Signed-in players can use cloud backup. A backup can include profile information, chip balance, campaign and training progress, aggregate poker statistics, achievements, selected cosmetics, daily progression, and purchase-grant records so supported progress can be restored on another device. Individual hand histories are stored locally and are not included in the cloud backup.
1.3 Play with Friends
Private online tables require an internet connection. We process invite codes, player identifiers, display names, avatars, seats, table settings, chip stacks, actions, and hand state to operate the game. Hole cards and server deck state are stored separately with access controls so other players cannot read them during play.
1.4 Purchases and virtual currency
Apple or Google processes payment details. We do not receive your full card number. We receive purchase and entitlement information such as product, transaction identifier, store, price, country, and purchase or refund status. Felted and RevenueCat use this information to grant chips, prevent duplicate grants, restore eligible purchase history, provide support, detect fraud, and reconcile refunds.
Before opening the chip store, Felted sends a request to our Cloud Function. The request IP address is used to resolve country and state or region for legal availability checks, including the Washington State restriction. The decision is cached on your device for a limited period. We do not add the resolved region to your RevenueCat customer profile.
1.5 Analytics, diagnostics, and device context
We use Firebase Analytics and Firebase Crashlytics to understand app usage, diagnose failures, and improve reliability. Data may include app version, device model, operating-system version, screen or feature interactions, approximate timestamps, crash traces, diagnostic logs, and a Firebase user identifier when available.
We also send first-party customer attributes to RevenueCat, such as app version, device model, anonymous or signed-in status, campaign progress, gameplay statistics, chip balance, and purchase-related progression. These attributes support customer service, product analysis, and Felted's own in-app messaging or offers. Felted does not request App Tracking Transparency permission, collect IDFA or Google Advertising ID for advertising, or enable third-party ad-network integrations.
1.6 Support and bug reports
If you submit a report in the App, we process the description, optional reproduction steps, optional contact email, app and device context, and up to three screenshots. Authentication and app-verification tokens are used to prevent abuse. Contact details and screenshots are kept in a restricted support record. A sanitized issue containing the report description and non-sensitive device context may be created in our development issue tracker, so please do not include passwords, payment details, or other sensitive information in the description.
1.7 AI coach (Dex)
Felted includes an optional in-app poker coach. When you ask the coach a question, the question text and the limited game context that accompanies it — your aggregate poker statistics and, if you attach one, a summary of one of your own hands — are sent to our Cloud Function and passed to our large-language-model API provider (currently Google's Gemini API) to generate the answer. Recent turns of your current conversation are included with each request so follow-up questions make sense, but the conversation thread and the coach's answers are not stored on our servers.
We do store each question you ask, together with when you asked it and technical metadata (for example whether statistics or a hand were attached, and whether an answer was produced), in your account's server records. We use these stored questions to understand what players want from the coach and to improve the App. They are deleted when you delete your account. Please do not include passwords, payment details, or other sensitive information in coach questions.
2. Why We Use Data
We process data to:
- provide offline gameplay, online private tables, cloud backup, account access, and customer support;
- complete purchases, grant virtual chips, restore eligible transactions, and handle refunds;
- protect accounts, tables, purchases, and support systems from abuse or fraud;
- measure performance, diagnose crashes, and improve the App; and
- comply with legal, tax, accounting, platform, and regional-availability obligations.
Where applicable under EEA law, these activities rely on performance of our contract with you, our legitimate interests in operating and securing Felted, compliance with legal obligations, or your consent when consent is specifically requested.
3. Service Providers and Disclosures
We do not sell personal data. We do not share personal data for cross-app advertising. We use service providers that process data on our behalf, including:
- Google Firebase and Google Cloud: authentication, database, online game functions, cloud backup, remote configuration, analytics, crash reporting, storage, and abuse prevention;
- RevenueCat: purchase validation, transaction history, customer attributes, and purchase support;
- Large-language-model API provider (currently Google's Gemini API): generating AI-coach answers from the question and context described in section 1.7, processing on our behalf under commercial API terms;
- Apple and Google: app distribution, in-app payments, and optional sign-in;
- GitHub: development issue tracking for sanitized support reports; and
- professional advisers, authorities, or counterparties when required by law or necessary to protect users, the App, or our legal rights.
These providers may process data outside Norway or the EEA. Where required, transfers use recognized safeguards such as adequacy decisions or standard contractual clauses.
4. Retention
- Local data: remains until you reset the App, delete it, or uninstall it, subject to device backups controlled by you or your platform provider.
- Account and cloud data: remains while your account is active and is removed or anonymized when account deletion completes, except where retention is legally required.
- Online tables: are retained only as needed to operate, secure, and clean up private games.
- Support records: remain as long as reasonably needed to resolve the report, prevent repeated abuse, and document the resolution.
- AI-coach questions: remain in your account's server records while your account is active and are deleted when account deletion completes. Our model provider may retain request data for a limited period for abuse monitoring under its own terms.
- Analytics and diagnostics: follow the retention settings of our Firebase services and may be kept in aggregated or de-identified form.
- Purchase, fraud, tax, and security records: may be retained as required by law, platform rules, or legitimate fraud-prevention needs.
5. Security
We use access controls, authenticated requests, App Check attestation, encrypted transport, private per-player game records, rate limits, and least-privilege database rules. No system is completely secure, but we review these controls and limit data access to people and services that need it.
6. Your Choices and Rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data. You may also withdraw consent where processing relies on consent and complain to your local data-protection authority. In Norway, the supervisory authority is Datatilsynet.
- Delete a Firebase account from Settings → Delete Account in the App.
- Remove purely local guest data by deleting the App and its device data. On platforms that expose it, clearing the App's storage has the same effect.
- Choose not to enable cloud backup or online play.
- Contact us for an access, correction, portability, or deletion request.
Deleting a Felted account does not delete transaction records held independently by Apple or Google. Limited records may also be retained where required for legal compliance, dispute handling, security, or fraud prevention.
7. Children's Privacy
Felted is intended only for people aged 18 or older. We do not knowingly collect personal information from children. If you believe a child has provided personal data, contact us so we can investigate and delete it where appropriate.
8. Changes to This Policy
We may update this policy when the App, our providers, or legal requirements change. The date above identifies the current version. Material changes will be communicated through the App or another appropriate channel when required.
9. Contact
For privacy questions or requests, contact:
- Email: info@gtogecko.com
- Controller: GTO Solutions AS
- Address: Fredrik Meltzers gate 13b, Bergen, Norway
