Privacy Policy
Last updated: August 2026
StackXo ("we", "our") is a session tracking app for poker players. This policy explains what data we collect and how we use it.
Data we collect
- Account info: email address and display name, provided when you sign up with email, Apple, or Google.
- Session data you enter: poker session records (dates, buy-ins, results, locations, game types, notes).
- Feedback messages: messages you send us through the in-app feedback channel, along with your device platform and app version.
- Photos you scan: when you scan a tournament clock or blind structure, the photo is sent to our server and on to Google’s Gemini API, which reads the text in the image and returns it. We don’t store the photo - only a record that a scan happened, so we can count it against your monthly allowance.
- Location (optional): if you grant location access, the app may use your device location while you’re using it to suggest the room you’re playing at. You can decline, and you can change this at any time in your device settings.
Analytics
We use PostHog (PostHog, Inc., United States) to understand how the app is used - which screens people open, and whether features such as importing sessions actually work. PostHog processes this data on our behalf.
- What we send: the screens you open, a small set of named product events (for example, that a session was started or saved), your app version, device type and operating system, and an account identifier (a random ID assigned by our database).
- What we never send: your email address, your session notes, and any monetary amounts. Buy-ins, results, and bankroll figures never leave the app for analytics.
- Session replay: we may record replays of app sessions to diagnose problems and improve the app.
- We don’t use advertising identifiers (such as Apple’s IDFA or Android’s advertising ID), and we don’t track you across other apps or websites.
- Analytics data is stored in the United States and retained for up to 12 months.
To opt out of analytics, contact us at [email protected].
Crash reports and diagnostics
We use Firebase Crashlytics and Firebase (Google LLC, United States) to find out when the app crashes or misbehaves, so we can fix it.
- What we send: crash reports and error logs, the app version, your device model and operating system version, and a randomly generated installation identifier. Crash reports include technical details about what the app was doing when it failed.
- What we never send: your session notes and any monetary amounts. Buy-ins, results, and bankroll figures are never included in crash reports or diagnostics.
- Google processes this data on our behalf.
How you found us
We use AppsFlyer (AppsFlyer Ltd.) to measure which channel led you to install the app - for example, whether you came from a search, a link we posted, or an ad. This tells us where to spend our effort; it is not used to build a profile of you.
- What we send: the fact that an install or app open happened, your device model and operating system version, your IP address, your rough country, and a randomly generated identifier for the installation.
- We don’t use advertising identifiers for this. Apple’s IDFA is not requested, so the app never shows a tracking permission prompt, and on Android we block the advertising ID permission outright. We don’t track you across other apps or websites.
- AppsFlyer processes this data on our behalf.
How we use it
- To provide the app: store and sync your session data across devices.
- To authenticate you and secure your account.
- We do not sell your data or share it with third parties for advertising.
- We may share limited information when the law requires it, or when we need to report or investigate fraud, abuse, or a violation of our terms. This includes reporting review or rating manipulation to the app store that hosts us.
Where it’s stored
Your data is stored with Supabase (our backend provider) on secure cloud infrastructure. Authentication is handled by Supabase Auth with Apple and Google sign-in options.
Service providers we use: Supabase (database, authentication), PostHog (analytics), Firebase and Firebase Crashlytics (crash reporting and diagnostics), AppsFlyer (measuring which channel led you to install the app), RevenueCat (subscription management), and Google Gemini (reading text from photos you scan). They process data on our behalf and aren’t permitted to use it for their own purposes.
Your rights
- You can delete your account and all associated data at any time from within the app (Settings → Delete Account). See how to delete your account.
- You can request a copy or deletion of your data by contacting us.
Contact
Questions about this policy: [email protected]