1. Who is responsible
Pokerista is responsible for the personal data it processes to run Pokerista Academy. This notice explains that processing and how to contact us about your information. Payment and identity providers may also process information for their own purposes under their own notices.
2. Information used by the service
We receive information you provide, information generated when you use the Academy, and limited information from the sign-in and payment providers you use. The information processed depends on the features you use; technical and security data can also be generated when you browse.
- Account and profile: name, email, account identifier, profile choices and authentication records. Password-based accounts store a password hash, not the readable password. Where ChatGPT sign-in is offered, the identity service provides sign-in identity information instead.
- Learning activity: course and scenario attempts, answers, scores, XP, progress, practice preferences, saved hands, simulator and tournament state, and preparation plans.
- AI Coach: prompts, conversation messages, submitted hand histories, selected learning context, generated answers, thread metadata, usage records and selected earlier messages and answer excerpts used for conversation continuity.
- Billing: customer and subscription identifiers, plan, status, dates, transaction references and payment-related records received from our payment provider. Checkout collects payment details directly; the Academy’s own billing records do not contain your full card number or security code.
- Technical and support information: session identifiers, security events, request/device information processed by the hosting and payment services, browser preferences, and information you include when contacting support.
- Issue reports: your verified account email and the category, summary, description and optional page path you submit. Reports are sent through our email provider to our support inbox so we can investigate and respond; screenshots, cookies and activity logs are not automatically attached.
3. Purposes and legal bases
Where EU or UK data-protection law applies, we rely on contract necessity to create and authenticate your account, provide requested learning and AI features, save your progress, administer a membership and answer service requests. Account details are needed for account-based features; refusing them prevents us from providing those features.
We rely on legitimate interests in securing the service, preventing abuse, diagnosing faults and resolving disputes, subject to balancing those interests against your rights. We rely on legal obligations for required accounting, tax records and valid legal requests.
If we introduce an optional use requiring consent, such as non-essential tracking, we will explain it and ask first. You can withdraw consent for future processing without affecting its earlier lawfulness. Creating an account or accepting necessary cookies is not permission for unrelated marketing.
4. AI processing and learning personalization
AI Coach uses an external AI service from OpenAI when enabled. Your request, relevant conversation history, selected hands or scenarios, and relevant learning context may be sent to that service to generate a response. Records stored on our servers and, where enabled, a search index of earlier messages and answer excerpts support history, search and continuity.
Do not put sensitive information, payment details or identifying information about other players into prompts or hand histories. AI responses may be inaccurate. Learning scores and suggested study topics are automated educational feedback; they are not decisions about credit, employment or other similarly significant matters.
Deleting a Coach conversation removes it from the conversation interface and its associated search entries. Separate AI request, response, usage and accounting records may remain; conversation deletion is not a promise that every copy of a prompt or answer has been erased. Use the privacy-request process for a broader erasure request.
6. Processing locations
Information may be processed outside your country, including by providers in the United States. The processing locations depend on the services you use and the providers involved.
Contact us for information about the processing locations and international-transfer safeguards applicable to your information.
7. How long information is kept
Retention depends on why a record is needed: account and learning records support your continuing account; conversations and related AI records support requested history, continuity and usage accounting; payment and security records may be needed for legal obligations, dispute handling and abuse prevention.
There is no single automatic deletion deadline that applies to all account data. Deleting a conversation, signing out or clearing browser storage does not delete all server records. Deletion requests can cover account, learning, AI, billing, search, log and backup records, subject to any lawful retention requirements.
Browser-storage durations are listed in the Cookie Policy. Contact us for more information about the retention criteria and applicable periods for your records, or to request deletion.
8. Your rights and requests
Depending on your location and the applicable law, you may have rights to access and receive a copy of your personal data, correct it, request erasure, restrict processing, obtain portable data, object to processing based on legitimate interests, and withdraw consent. These rights are subject to legal conditions and exceptions.
Use the privacy contact on the Contact page to make a request. Describe what you need and use the account email where possible. We may need proportionate identity verification. Do not send passwords or card details. Account-wide download and deletion are not currently available as self-service buttons.
Where EU or UK GDPR applies, requests are generally answered within one month; lawful extensions and reasons will be communicated where applicable. You can complain to your local data-protection authority, including the ICO in the UK or the relevant EEA authority, without first having to resolve a complaint with us.
9. Age, security and updates
The Academy is intended for adults aged 18 and over and is not directed to children. If you believe a child has supplied personal data, contact us so the situation can be reviewed and appropriate action taken.
The service uses access controls, password hashing for password accounts and session protections. No system can guarantee absolute security. Protect your credentials and avoid submitting information that is unnecessary for learning.
The date on this notice identifies its version. Material new processing will be explained before it begins, with a separate consent request where required.