The fine print, in plain words
Cookies
Last updated: 27 August 2026
The short version
jocuriclasice sets no advertising cookies and no tracking cookies. It does set a few strictly necessary ones, listed below, to keep you signed in. Most of what the app remembers is not a cookie at all but your browser's local storage — the same kind of technology, covered by the same rules — which holds your settings between sessions. On Android and iOS the app stores the same values inside its own webview.
What is stored on your device
Strictly necessary — always active, because the app cannot work without them:
Cookies, set by our server:
- Session (better-auth.session_token, or __Secure-better-auth.session_token over https). What keeps you signed in once you have signed in. It lasts seven days, extended while you keep playing, and signing out deletes it. Your browser sends it back only to us, and scripts on the page cannot read it.
- Two-factor challenge (better-auth.two_factor). Written only if you use two-factor authentication, in the gap between your password and your code, to remember which sign-in the code belongs to. It lives ten minutes and is deleted as soon as the code has been checked.
- Sign-in round trip (better-auth.state). Written only while you are signing in with Google, Apple or Facebook, so that the answer coming back can be matched to the request that started it. It lives five minutes and lapses on its own once the round trip is over.
Those three are the only cookies our own screens cause to be set. The sign-in library behind them can write one more — better-auth.dont_remember — if a sign-in asks not to be remembered; nothing in this app ever asks for that, so in normal use it is never written, and it is named here because a list of cookies should name what is possible rather than only what is likely. None of them measures anything, none of them advertises, and none of them follows you to another site, which is why they need no consent — not the same thing as needing no mention, and this list is the mention.
Account and sign-in:
- Guest device key (jocuriclasice.deviceKey). The credential that lets a guest profile sign back in on this device. The server only ever sees its hash.
- Account link hint (jocuriclasice.signedIn). Remembers that this device has signed in for real, so a returning player is not handed a fresh guest profile before their own loads.
- Signed-in session (jocuriclasice.session). In the Android, iOS and desktop apps only, the key that keeps you signed in after you close the app, so you do not sign in again every time you open it. It is kept in the device's own secure store — the Keychain on iOS, the Android Keystore on Android — never in ordinary app storage, never in a backup and never on another device. It is deleted when you sign out. On the website nothing like it is stored: there, the sign-in cookie above already does this.
- Account id cache (jocuriclasice:accountId). The account you are signed in as, cached so your avatar and starred games can load before the network answers.
- Sign-in verifier (jocuriclasice.oauthVerifier). A one-time secret that outlives the app while you finish signing in with Google, Apple or Facebook in the system browser. Deleted the moment sign-in succeeds or fails.
- Online session ticket (jocuriclasice.onlineSession). Lets you rejoin the room you were disconnected from. Cleared when the match ends.
Settings:
- Language (jocuriclasice.language). Remembers whether you chose English or Romanian. Kept until you clear the app's storage.
- Theme (jocuriclasice.theme). Remembers the table style you picked.
- Table set (jocuriclasice.tableSet). The felt, the piece rack and the card back you picked, and which of them you have earned by playing. It is worked out on this device and never sent anywhere.
- Text size (jocuriclasice.textScale). Remembers the text size you picked.
- Card face (jocuriclasice.cardFace). Remembers whether you asked for the whole printed card or just the rank and the suit.
- Orientation tip (jocuriclasice.orientationTip). Remembers the day the hint that a remi table plays better with the phone sideways was last shown to you, so it is offered at most once a day.
- Ajutor (jocuriclasice.ajutor). Remembers whether you asked the table to explain the rules while you practise on your own. It changes nothing except what the table says to you, and it is never sent anywhere.
- Display name (jocuriclasice:playerName), guest name (jocuriclasice:guestName) and avatar look (jocuriclasice:avatarSeed). Remember the name and the smiley you play under so you do not set them again. The guest name is the one you did not pick: it is made up for you — by this device, or by our server the first time you play online — and looks like "SwiftFox42", so that a seat without an account still has something to be called. A name you type in yourself is kept apart from it, and is the one that is used.
- Quick reacts (jocuriclasice:reactIds). The set of in-match reacts you chose.
- Your standing at each game (jocuriclasice.standings). The level and the ring your account last held at each game, so a table you play with no connection can still show them. It is only ever written from an answer our server already gave you, it is replaced if a different account signs in on this device, and it decides nothing — your real level and ring live on our server.
- Sound (jocuriclasice.audio). Whether music and sound effects are on.
- Turn and tournament reminders (jocuriclasice.turnNotifications, jocuriclasice.tournamentReminders). Whether you asked for a local alert when it is your turn, or before a tournament slot you joined starts.
- Consent and age-gate record (jocuriclasice.consent). Remembers the choices you made in the consent banner so you are not asked again, and the version of the notice you saw.
Game-local data:
- Starred games (jocuriclasice.gameFavorites). The games you starred, merged with your account's copy once you sign in.
- Played games (jocuriclasice.gameStats, jocuriclasice.playedGames, jocuriclasice.playedGames.offline). A local mirror of your played-games list, plus the offline matches that never leave this device.
- Last table played (jocuriclasice.lastTable). The game and the table you last sat at, so the front door can offer it again. It stays on this device.
- Match in progress (jocuriclasice.parkedMatch). One unfinished practice match — the hand itself, the table it was dealt at and the names of the bots you were playing — so that leaving it is not the same as losing it. There is only ever one: starting another game replaces it, and abandoning it deletes it. It stays on this device.
- Preferred table (jocuriclasice.variants). For each game, the last variant you chose — Remi 51 rather than Remi 45 — so every picker opens on it and shows it first. It stays on this device.
- Daily hand (jocuriclasice.dailyHand). For each game, the date of the last Mâna zilei you finished, what it scored, your best score and how many days in a row you have played. This record never leaves the device: it is what lets the app show your streak with no network. Playing the hand while signed in is separate, and that run does reach us and does appear on the day's public board under your display name.
- Seat plates (jocuriclasice.showRank, jocuriclasice.showClub). Whether the other players' place in the ranking and their club are shown beside their names at the table.
- Muted players (jocuriclasice.mutes). Which opponents you have muted at the table — enforced on this device only; nobody is told.
- Tournament list filter (jocuriclasice.championships.joinedByMe). Whether the tournaments screen is filtered to the ones you joined. Cleared when the browser tab closes.
- Offline cache. A service worker stores the app itself — code, images, sounds and the texts in your language — so it starts and plays against bots with no network. It holds no personal data.
Analytics — written only if you switch the category on:
- Product analytics (keys beginning with ph\_ or \_\_ph\_). Only after you accept analytics in the consent banner, our analytics provider PostHog stores a random identifier and a session id, so that repeat visits are counted once rather than twice. Nothing is written before you accept, and every key under those prefixes is deleted the moment you switch analytics back off.
Preferences and advertising storage: nothing is written for these categories today. If that ever changes, the categories appear in the consent banner first and stay switched off until you turn them on.
Third parties
The web app loads Google's advertising tag (Google Ad Manager) only after you switch Advertising on in the consent banner, and never before: with it off, or unanswered, no request is made to Google at all. With it on, Google may set its own cookies on its own domains (doubleclick.net, googlesyndication.com) to serve and count the ads; every ad is requested non-personalised, and the only inventory configured today is Google's test inventory, which shows sample creatives and pays nobody. Switch Advertising off again and the tag is not loaded on your next visit. Product analytics is handled by PostHog, on its European servers: what we send is limited to eight events — the app opening, a game starting, a match finishing, analytics being switched on, an invite link being shared, an invite link being opened, an online room being joined, and an ad being watched through to its 2x XP reward — carrying no free text, no room code and nothing that identifies another player. PostHog's code is downloaded only after you accept analytics, so if you decline, or have not answered yet, no request is made to it at all. Crash diagnostics are sent to Sentry, our error-monitoring provider, but Sentry stores nothing on your device.
The Android and iOS apps are built with Google AdMob wired in, gated by Google's User Messaging Platform consent form (plus Apple's App Tracking Transparency prompt on iOS) so that no ad request can be made without your consent. A build that is not configured with an ad unit requests no ad and shows none; the only inventory configured in any build today is Google's test inventory, which shows sample creatives and pays nobody. The Google Mobile Ads library is bundled into those two apps and starts with them; with no ad unit configured it asks for nothing, and the advertising identifier those apps would otherwise be able to read is switched off in the build. See the privacy policy for what happens once real inventory replaces the test one.
How you stay in control
- On the web the consent banner appears on first run; on Android and iOS the app asks your age and leaves the optional categories switched off, and advertising is asked through Google's own consent form. Whatever you choose, the game stays fully playable. Declining the optional categories costs you nothing.
- You can change your choices at any time from the app's settings.
- Your browser can block or clear storage for this site, and the mobile app can be cleared from your device settings. Doing so resets your language, theme and name to their defaults.
Contact
Questions about this policy: chira.mircea.darius@gmail.com.