Privacy

What Acetique keeps, and what it never asks for.

Acetique grades your blackjack decisions against a basic strategy chart and keeps score. This page says exactly what it stores to do that, who else is involved, and how to take your data out or delete it.

Effective 26 September 2026

The short version

There is no sign-up. No email address, no password, no name, no third-party sign-in: the app mints an anonymous account on first launch and that is the whole of your identity here. What we hold is the practice history that account generated — the hands you were dealt, the moves you chose, the points they earned — plus a display name if you set one.

The app is free and ad-supported, which is the one place data leaves us. Ads come from Google AdMob, and only with your permission can they be personalised using your device's advertising identifier. You can say no, at any time, and keep playing.

You can download everything we hold from inside the app, and delete the account outright. One narrow exception to deletion is set out in Consent records, because it would be dishonest to leave it in the small print.

Who we are, and how to reach us

Acetique is made and published by Proseweave LLC, which is the data controller for everything described here. Its registered address is 30 N Gould St, Ste N, Sheridan, WY 82801, United States.

Write to support@acetique.app with any privacy question, including a request to exercise the rights below — replies within two business days, and always within five, and within any shorter deadline the law sets.

What we collect, and why

All of it is tied to the anonymous account, not to you as a named person. We buy no data about you and make no attempt to work out who you are.

WhatWhy
Account. A random anonymous identifier, a session token per device (stored only as a hash, never in the clear), your level, points and streaks, and the time zone your device reports. To keep your progress across launches and devices, and to run streaks and weekly seasons against your local days rather than ours.
Display name — optional, chosen by you, visible to other players. Until you set one, boards show Player and four characters of the account's internal id. To identify you on the leaderboards, in the way you choose.
Practice history. Per decision: the mode, the dealer's upcard, your total and whether it was soft, the move you made, the move the chart called for, whether they matched and how costly the miss was, the points awarded, and when. This is the product. Accuracy, the coverage heat map, level, points, awards and rank are computed from it — on the server, which re-grades every decision rather than trusting a score sent by the app.
Standings. Your points ledger, weekly season ranks, and the awards you have unlocked. To show progress over time, and to rank the boards.
Integrity signals. Flags raised when a batch of decisions looks automated rather than played — an impossible rate, a replayed batch, a device clock far from ours. To keep the leaderboards worth appearing on. Flags are recorded for review; they never change the points you were awarded.
Consent records. Each advertising and tracking choice, when it was made, and where it was made from. To honour the choice, and to be able to show it was yours. See Consent records.
Technical logs. Ordinary server logs — IP address, the request, the time — kept by the API and by our host. The IP address is also what rate limiting counts against. To run the service, diagnose faults and defend it from abuse. They are not used to build a profile of you.
Crash reports. When the app crashes, freezes or hits an error it did not expect, or the API fails a request: the error, where in the code it happened, the app version, the operating system, and device details such as the model, free memory, language and time zone. No IP address, no account id, no display name, nothing about your hands, and no record of what you were doing beforehand. To find and fix what broke. Sent to Sentry, the crash-reporting service we use, and never used to build a profile of you.
Advertising data, handled by Google AdMob — see Advertising and tracking. To fund a free app.

We add no analytics SDK and no tracking pixel of our own, in the app or on this site. We add one SDK that sends anything, Sentry's, and it sends only the crash reports above. The ad SDK is the other exception, and what it collects goes to Google rather than to us — including diagnostics about its own code and an approximate area derived from your IP address. It is listed under Advertising and tracking. The app's ad diagnostics screen exists only on your device and is never uploaded. We do not access your contacts, photos, precise location, microphone or camera, and the app never asks to.

Sign-in and friends. The server can attach a sign-in (Apple, Google or email) to an account so progress and friendships survive a lost device, and adding friends requires one. That path is not enabled in this version, so no email address or provider account is collected today. If it is switched on, this page will say so before it ships, and an email address will be collected only from people who choose to sign in.

Advertising and tracking

Ads are served by Google AdMob. A full-screen ad comes up roughly every eight settled hands, never mid-hand, and rewarded videos are always ones you choose to watch.

Before any ad is requested, the app asks two things. On iOS it asks first for Apple's App Tracking Transparency permission: that prompt comes up on its own, on your first run, whatever you go on to answer next. Then it asks how you want ads handled. Personalisation is used only if you allowed tracking at the first prompt and chose personalised ads at the second, so either answer on its own turns it off.

  • Personalised ads. Google may use your device's advertising identifier (the IDFA on iOS) and information about the ad request — device type, coarse location derived from the IP address, and ads you have interacted with — to choose what to show, under Google's policies.
  • Non-personalised ads. You still see ads, chosen by context rather than by a profile. Google still processes limited data to serve and measure them and to detect fraud.
  • Either way, the ad SDK collects the same short list for Google: a device identifier, the ads you were shown and interacted with, taps and video views inside the ad, an approximate area estimated from your IP address, and crash and performance logs for the SDK's own code. It is Google's published list, and it is what the App Store privacy label on our listing declares.

Changing your mind. Turn off Settings → Privacy → Personalized ads in the app and ads become non-personalised from then on. On iOS you can also withdraw tracking permission for every app at Settings → Privacy & Security → Tracking, which overrides the in-app answer. It changes how relevant the ads are, not how often they appear — we would rather say so than let you find out.

Who else is involved

  • Google AdMob — advertising, as above. Google's privacy policy.
  • Render — our host. The API, the database and the cache run on Render's infrastructure in the United States, and Render processes the data only to host it for us. Render's privacy policy.
  • Sentry — crash reporting. It receives the crash reports described in What we collect, stores them in the United States, and processes them only to show them to us. Sentry's privacy policy.
  • Apple — distributes the app and, if a paid option ever exists, takes the payment. Apple's privacy policy.

Purchases. This version sells nothing — there are no in-app purchases. If a paid option is added, the store takes the payment and we receive only its confirmation that the purchase is genuine, recorded against your account so the thing you bought stays bought. We never see your card details.

We share your data with nobody else. It leaves the parties above only where the law requires it, or to establish or defend a legal claim.

Where your data is kept, and how

In a managed Postgres database and cache hosted by Render in the United States. Traffic between the app and the API is encrypted in transit, and session tokens are stored only as salted hashes — a copy of the database yields nothing that could be used to sign in as you. Crash reports are held separately by Sentry, also in the United States, and are sent encrypted.

If you are in the EEA, the UK or Switzerland, that means a transfer to the United States. Where the transfer needs a safeguard it rests on the European Commission's Standard Contractual Clauses, with the UK Addendum where the UK GDPR applies.

Your rights: access, export and deletion

Both of the big ones are in the app, and neither needs to go through us:

  1. Export. Settings → Privacy → Export my data produces a single JSON document with everything tied to your account: the profile, every decision, the points ledger, your season ranks and your consent history. Portable as well as readable.
  2. Deletion. Settings → Privacy → Delete account erases the account immediately. Your decisions, points ledger and season ranks go with it, and the account disappears from every leaderboard; the device's token stops working the moment it is done. There is no undo and no copy we can restore — export first if you want one. Deleting your account sets the whole thing out on a page of its own.

You also have the right to ask what we hold and have it corrected, to object to or restrict processing, to withdraw a consent (which does not affect what was done before you withdrew it), and to complain to your data protection authority. Write to support@acetique.app for anything the app does not already do for you. None of it costs anything, and asking changes nothing about how you are treated.

Because accounts are anonymous, the app is the proof that an account is yours: a request made from it is authenticated, an email is not. If you write to us from outside the app about a specific account, we may be unable to identify it — a consequence of collecting so little, not an attempt to be unhelpful. Tell us roughly when you played and the display name you used.

How long we keep things

  • Account, practice history, standings: until you delete the account. Nothing expires — an account you come back to in a year still has its history.
  • Consent records: kept after deletion, detached from the account, as above.
  • Technical logs: retained briefly by the host on a rolling window, then discarded.
  • Crash reports: kept by Sentry for at most 90 days, then deleted. They are not tied to your account, so deleting the account does not find them, and they expire on their own.
  • Advertising and ad-SDK diagnostic data held by Google is subject to Google's retention, not ours.

Children

Acetique is not directed to children. It deals simulated blackjack hands, and although the chips staked on them have no cash value and nothing cashes out, that is content for adults: you must be 18 or older to use it, and the App Store listing is rated 18+ accordingly.

We do not knowingly collect data from anyone under that age. If you believe a child has used the app, write to support@acetique.app and we will delete the account — though the in-app delete does the same thing without us.

If you are in the EEA or the UK

These are the lawful bases we rely on under the GDPR and UK GDPR:

ProcessingLawful basis
Running the account, saving your practice history, scoring, ranking and showing you on leaderboards Performance of a contract — this is the service you asked for
Personalised advertising, and tracking on iOS Consent, which you may withdraw at any time
Non-personalised advertising, integrity checks, rate limiting, security, fault diagnosis and crash reports Legitimate interests — keeping a free service running, honest and available, weighed against the little it takes to do it
Keeping consent records after deletion Legal obligation, and our legitimate interest in being able to demonstrate that consent was properly obtained

You may complain to your supervisory authority — in the UK, the Information Commissioner's Office.

If you are in California

In the past twelve months we have collected the categories listed in What we collect: identifiers (an anonymous account id, a device advertising identifier), internet or other electronic network activity (your practice history and ad interactions), approximate location inferred from an IP address, the ad SDK's diagnostics about its own performance, and crash reports about ours. We collect no sensitive personal information, and use and disclose personal information for no purpose other than those set out here.

We do not sell your personal information, and have not in the past twelve months. Allowing personalised ads counts as sharing for cross-context behavioural advertising under the CPRA; turning off Settings → Privacy → Personalized ads is our "Do Not Sell or Share My Personal Information" control, and it takes effect for every ad after it. We do not knowingly sell or share the personal information of anyone under 16.

Your rights to know, delete, correct and opt out are the ones in Your rights, exercised by the same in-app controls. You may use an authorised agent; we will still need to tie the request to an account. We will not discriminate against you for exercising any of them.

Changes to this policy

If this changes in a way that affects you, the effective date at the top moves and the app says so before the change takes effect. A change that would widen what we collect, or what it is used for, is put to you as a fresh choice rather than assumed. Ask us for the previous wording if you need it.

Questions, at any time: support@acetique.app.