river.

Privacy Policy

Effective

Privacy at a glance

River is a play-money Texas Hold’em game. We collect only what River needs to run your account and your games with friends and other players: how you sign in, your profile, your chips and the hands you play online. There are no ads, no analytics and no third-party trackers, and we never sell your data. Games against the AI stay on your device (your iPhone, or your browser in the web app), and only a short summary is uploaded to keep your chips and stats in sync. To keep online play fair, our server briefly uses the IP address you connect from to keep accounts on the same network apart; it never stores that address for this. You can delete your account in the app or the web app at any time, and that erases your personal data from our database.

Who we are

River is made by GitSwift LLC, a company based in Sheridan, Wyoming, USA (“GitSwift”, “we”, “us”). We decide how the personal data described here is used, so we are its “controller” under laws such as the GDPR. This policy covers the River app for iPhone and iPad, the River web app at river.gitswift.com/play, the River online service at river.gitswift.com, and these web pages.

What we collect

Your account

Your profile and settings

Your chips and games

Friends and Inbox

Blocks and reports

Technical information

We don’t collect your location, the contacts on your phone, photos (other than a profile photo you choose to add), advertising identifiers or payment details. River has no purchases.

What stays on your device

Your solo hand history, a cache of your settings and stats, and your sign-in tokens (kept in the iOS Keychain) are stored on your device. Solo play works fully offline, and nothing about it leaves your device until a session summary is uploaded as described above. Deleting the app removes its local data. iOS may keep Keychain items after an app is deleted, but the tokens stop working when you log out, change your password, delete your account or leave River unused for 60 days.

The web app works the same way in your browser. It keeps your sign-in tokens, your settings, copies of your profile and lists so it can start quickly, your solo game in progress, your solo hand history and session summaries, and anything still waiting to reach our server (solo session summaries, redeem codes entered offline) in your browser’s storage for river.gitswift.com (local storage, IndexedDB and session storage), separately for each account that signs in on that browser. The web app’s files (including the game engine that runs solo play in your browser) are saved by your browser’s offline cache so it starts quickly and works offline; nothing from your account is put in that cache. The web app uses no cookies.

Logging out removes the sign-in tokens and the copies of your profile and lists. If you’re offline at that moment, the web app keeps the old sign-in token only until it can tell our server to cancel it, or until it expires. Your solo games, solo hand history and anything waiting to be uploaded stay in the browser under your account, so nothing is lost when you sign in again. Deleting your account in the web app also erases your solo games, solo hand history and the copies that browser kept for your account, and clearing this site’s data in your browser removes everything the web app stored. The tokens stop working in the same cases as in the app.

How we use it

We use your email address only for account messages: a welcome email when you sign up, codes for password resets and email changes, notices when your password or email address changes (the notice about a new address goes to your old one), a confirmation when you delete your account, and, if we act on a report about you, a message from us explaining what we did, such as a warning. We don’t send marketing email.

Where laws such as the GDPR apply, we rely on these legal bases: providing the service you asked for (performance of a contract); our legitimate interest in keeping River secure and fair; and complying with the law.

What we don’t do

What other players can see

Service providers

We use a small number of providers that process data only on our behalf and under our instructions:

If you use Sign in with Apple, Apple confirms your identity under its own privacy policy, we contact Apple to exchange and, when you delete your account, revoke the sign-in token described above, and any email we send to a private relay address is forwarded by Apple. Apple also distributes the app through the App Store.

We may disclose information if the law requires it, to protect the rights and safety of our players or others, or as part of a merger or acquisition. In that case this policy keeps applying to your data.

Where your data is stored

Our server and database are in Australia, and GitSwift LLC is in the United States. Cloudflare passes requests through its network, which may handle them in data centres outside Australia, usually the one closest to you. Your information is therefore processed in those countries, whose data-protection laws may differ from where you live. We protect it as this policy describes wherever it is processed.

How long we keep it

Deleting your account

You can delete your account at any time in the app or the web app under Settings → Delete account. Deletion is immediate and can’t be undone. If you’re seated at a table, your chips are cashed out first. Then we erase your email address, password hash, Apple identifier, profile, profile photo, settings, chips and chip history, redeemed codes, friends and friend requests, blocks, Inbox, sessions, online table searches, fair-play records that include you, reports about you and your statistics, and we sign you out on every device. We send a confirmation to your email address, if your account has one.

Records of multiplayer hands you played remain in the history of the other players at that table, so their replays keep working. In those records you appear as “deleted”: they keep only your seat, cards, actions and chip results, under your former account ID, which no longer leads to a name, email address or profile. The names of rooms you created may also remain in other players’ history. Logs and backups expire as described above.

If you used Sign in with Apple, we also ask Apple to revoke River’s access to your Apple Account, so River no longer appears among the apps using Sign in with Apple. You can also remove it yourself in your Apple Account settings (Sign in with Apple).

If you can’t use the app, email us from the address on your account and we’ll help.

Security

All traffic between the app or your browser and our server is encrypted: with TLS up to Cloudflare, and through an encrypted tunnel from Cloudflare to our server. Passwords are hashed with argon2id, and the Sign in with Apple token is encrypted (AES-256-GCM). Access tokens expire after 15 minutes, refresh tokens are replaced each time they are used, and both are stored in the iOS Keychain in the app, or in your browser’s local storage in the web app. Access to our servers is restricted. No system is perfectly secure, so if a breach ever affects your data, we will tell you as the law requires.

Children

River is only for adults aged 18 and over and is not directed at children. We don’t knowingly collect personal data from anyone under 18. If you believe a minor has created an account, contact us and we’ll delete it.

Your rights

River is available worldwide, and we give every player the same core rights, wherever they live:

To make a request, email river@gitswift.com from the address on your account. We’ll reply within 30 days, and we may ask you to confirm that the account is yours. We won’t treat you differently for using your rights.

EU, EEA and UK. The GDPR and UK GDPR give you the rights above, and you can complain to your local data-protection authority.

California and other US states. Laws such as the California Consumer Privacy Act (CCPA, as amended by the CPRA) give you the right to know what we collect and why, and to access, correct and delete it. You may use an authorized agent. We don’t sell or share personal data for targeted advertising, and we don’t use sensitive data to infer things about you, so there is nothing to opt out of.

Australia. You can ask to access or correct your information under the Australian Privacy Principles. If you aren’t satisfied with our answer, you can complain to the Office of the Australian Information Commissioner (OAIC).

Changes to this policy

If we change this policy, we’ll update the effective date at the top of this page. We’ll make significant changes clear in the app or on this page before they take effect.

Contact

GitSwift LLC
30 North Gould Street, Suite R
Sheridan, WY 82801
United States
river@gitswift.com