Skip to the main content
jocuriclasice.ro
ENEnglish
  • RORomână
  • ENEnglish

The fine print, in plain words

Privacy

Last updated: 27 August 2026

This policy explains what personal data jocuriclasice collects, why, how long it is kept, and what you can do about it. It is written to be read, not to be skimmed past — if anything here is unclear, write to us and ask.

Who is responsible

jocuriclasice is a free app for traditional card and board games, built and operated by Darius Chira, an individual developer based in Romania. Under the EU General Data Protection Regulation (GDPR) he is the data controller for the personal data described below.

Contact for any privacy question or request: chira.mircea.darius@gmail.com. The same address handles access, correction and deletion requests. There is no data protection officer: the service is too small to require one.

What we collect

  • Guest device key hash. Playing without an account still needs a stable identity for your seat. The app generates a random key on your device and the server only ever stores its hash — enough to recognise the same guest, not enough to identify you.
  • Display name. Whatever you type in. It is shown to your opponents, so do not put personal information in it.
  • Match data. Game, variant, seats, scores, results, timestamps and the actions of an online match — needed to run the match, to resolve disconnects and to detect cheating.
  • Progression. Your level and experience in each game, the achievements you have unlocked, your seed balance and the ledger that explains it, your daily-hand results, the Arena seats you have taken, and the tournaments you entered together with your standings and pairings in them.
  • Groups (mese). Which standing tables you belong to and since when, plus the invitations into one that you sent or received — who asked whom, and what became of each.
  • Clubs. Which club you are a member of, your role in it and since when, the club's name, tag and crest, plus the invitations into a club that you sent or received — who asked whom, and what became of each. A club's seeds total is added up from its members' balances when somebody looks, and is not stored.
  • Club chat. The lines you write to your club, plus who wrote each and when, and the tables you share into it. Every member of the club can read them.
  • Account housekeeping. The games you starred, when you changed your display name — the timestamps only, never the name you gave up — and which notifications you dismissed from your inbox.
  • Direct messages. The content of the messages you send, plus who sent them and when. This includes the "Team" thread — the messages our team sends you about your account and anything you write back. Our team answers as one sender; which member of staff wrote a particular message is recorded internally for accountability and is never shown to you.
  • Table chat, which is relayed and not kept. At an online table you can type a short message to the other people in the room, at most 200 characters, from the moment you sit down until the final score. Our server checks it against a word list, masks what that list finds, sends the result to everyone at the table including you, and keeps no copy: no history, no identifier, no row, nothing in a log. The same is true of the emoji reactions. Nothing about either reaches our database.
  • Profile picture. If you upload one, our server re-encodes it to a fixed size and format before storing it — which strips whatever EXIF or GPS data your camera attached to the original — and shows it to other players exactly like your display name.
  • Friends, blocks and mutes. Your friend requests and friendships, the accounts you block and the players you mute. These are your own choices about who may reach you or appear to you; nobody is told that you blocked or muted them.
  • Reports. If you report another player, we keep the reason you picked, anything else you wrote, and a short quoted excerpt of what you are reporting. If another player reports you, we keep the same record naming you as the subject, including how it was resolved.
  • Room invitations. The invites you send to and receive from other players — which game, which table, and whether each one was accepted, declined or left to expire.
  • Sign-in sessions. Once you have an account, the IP address and browser or device identifier (user agent) of each session that is signed in, plus when it started and when it expires — so you can see and revoke the devices signed in to your account.
  • Presence. The last time you were seen active on the service, so other players can tell whether you are online right now.
  • Support requests. The email address you give us, the subject and the body of your message, plus your browser identifier (user agent) and a salted hash of your IP address — the two we keep so the form cannot be used to send mail in bulk. The IP address itself is never stored, only the hash.
  • Server logs. Our web server writes one line for every request it receives: a shortened version of your address (the last part is dropped, so the line points at a network and not at you), the page or file asked for, your browser identifier (user agent), the time, and how the server answered. Sign-in cookies, authorisation headers and the one-time links behind data exports, deletion status and room invitations are never written to it.
  • Error diagnostics. When something crashes, our error monitoring service (Sentry) receives the error message and stack trace, the app version and release, the browser or device type and OS version, and a timestamp. The report also carries what the browser's error reporting attaches on its own: the address of the page you were on and the page you came from, your browser identifier (user agent), and a trail of what happened just before the crash — the screens you moved through, the requests the app made and anything it wrote to the browser console. Before a report leaves your device we strip the secret out of the few addresses that carry one — data exports, deletion receipts and room invitations — but the rest of that trail is sent as it stands. No IP address is attached to the report: the setting that would send one is switched off. Sentry's servers still see the address your device connects from, the way any server does, but it is not recorded in the report.
  • Product analytics, and only if you consent. Eight events: the app opening, a game starting, a match finishing, analytics being switched on, an invite link being shared, an invite link being opened, an online room being joined, and an ad being watched through to its 2x XP reward. Each one carries at most the game, its variant, the number of seats, how long the match lasted, whether it was played online or offline, and one short word for how it went — whether you won, whether the share sheet took the link, whether a code was well formed, or which of the four ways you entered a room. Never the room code itself: no message content, no display names, no other player's identifier, and not the address of the page you were on. If you are signed in, the events are linked to your account identifier and to nothing else. Beyond that allowlist, our analytics provider's own software development kit still attaches its usual technical properties to every event — your browser and operating system, a session identifier, and an approximate location derived from your IP address. Decline, and none of this, allowlisted or technical, is collected or even requested.
  • Where you play from, if you choose to tell us. This is optional, it is off until you turn it on, and it is one of two things: a Romanian county, or a country. Never an address, never a street, and never a coordinate — we have nowhere to put one. You can set it by hand from a list, or press a button that asks your own device. If you press it, your device works out which county it is in by itself, using the map of Romania the app already carries; the county is the only thing that is sent to us, your coordinates never leave your device, and nothing is looked up by anyone else. Outside Romania your device simply says "abroad" and you may name the country yourself if you want it named. You can change it or remove it whenever you like, from your profile.
  • A record of where you played from in each past month, kept while your account lives. When you tell us where you play from, we note it against the month you told us, so a ranking of a month that has already ended keeps showing the places people played from at the time instead of quietly rearranging itself every time somebody moves. It holds the same county or country as above, one entry per month, and nothing else. Your all-time seed ranking works the other way and always shows where you are now.
  • Settings stored only on your device. Language, theme, display name, chosen interface options, the reconnect ticket for an online room and your consent choices live in your browser's local storage and are never sent to us. They are listed one by one in the cookie policy.

If you create an account, we additionally store your email address, whether it has been verified, which sign-in providers you linked — Google, Apple or Facebook — and, if you enable two-factor authentication, the secret and hashed backup codes needed to check it.

Linking a provider stores two more things. The first is the set of tokens that provider hands us to prove the link — an access token, a refresh token, an identity token, when each stops being valid, and the scope you agreed to; they are what keep the link working without sending you back to the provider, and they are deleted when you unlink it or delete your account. The second is the picture the provider prefills your profile with, which we keep as a web address pointing at the provider's own servers rather than as an image of ours; it is a fallback shown only until you set an avatar yourself, and you can clear it from your profile at any time. Neither of these came from you directly — they came from the provider you chose to sign in with.

We do not collect payment details, precise location, contacts, biometric data or identity documents. Where you play from is a county or a country and is never more than that: if you ask your device to fill it in, the reading your device takes stays on your device and only the name of the place reaches us. We do not sell personal data, we do not use it for profiling, and no decision with a legal effect on you is made automatically.

You are not obliged to give us any of this. The app deals a hand offline with nothing stored on our side, so playing costs you no data at all. A display name and a device key are what an online seat needs, and an email address is what an account needs — without them that part of the service cannot work, and nothing else follows from declining.

Why we use it, and on what legal basis

  • Running the game, your account and online matches — performance of a contract with you, Article 6(1)(b) GDPR.
  • Keeping the service usable and safe: anti-cheat, rate limits, server logs, abuse reports, bans — our legitimate interests, Article 6(1)(f).
  • Diagnosing crashes and fixing bugs — our legitimate interests, Article 6(1)(f).
  • Publishing leaderboards, so that a standing is public, comparable and worth playing for — our legitimate interests, Article 6(1)(f).
  • Answering your support requests — Article 6(1)(b) and 6(1)(f).
  • Optional storage, analytics and personalised advertising — your consent, Article 6(1)(a), which you may withdraw at any time.
  • Showing where you play from on the rankings — your consent, Article 6(1)(a). It is off until you turn it on, and clearing it in your profile withdraws that consent with immediate effect.
  • Keeping records we are legally required to keep, and answering lawful requests from authorities — legal obligation, Article 6(1)(c).

Who else sees it

Other players see your display name, your avatar, the moves you make in a shared match and any message you choose to send.

Some things go further than that and are readable by anyone on the internet, with no account and no sign-in. Leaderboards are public: a board carries your display name, your position on it, and your wins and points for that game. If you have told us where you play from, that county or country is public in the same way: it is drawn on the map beside the rankings and it names the card you appear on. It is the reason for turning it on, and clearing it in your profile takes you off the map at once — including off the rankings of months that have already closed. The seed board and the daily-hand board are public in the same way, and so are three lists that carry a display name: the championships anybody may enter, each of which names whoever created it; a championship's standings; and the tables waiting for players, each of which is titled with its host's display name. Profile pictures are served publicly too, so anything that already knows which account a picture belongs to can fetch it. Nothing in any of them identifies you further — no row carries an account identifier, so none can be turned into a friend request, a report or a block. If you would rather not appear, you can change your display name, play offline, or object to us at the address above and we will act on it.

Beyond that, data is handled only by service providers acting on our instructions under Article 28 data-processing agreements: our hosting provider, Sentry for error monitoring, PostHog for product analytics (its European region, and only if you consent), an email delivery provider for support replies, and — only if you consent to advertising — Google for the ads: AdMob on mobile, Google Ad Manager on the web, both non-personalised, and both serving only Google's own test inventory until real inventory is configured. Some of them may process data outside the European Economic Area; where they do, the transfer relies on an adequacy decision or on the European Commission's standard contractual clauses. Write to the address at the top of this policy and we will tell you which of the two a given provider relies on and send you a copy of the clauses, with the commercial terms removed.

If you sign in with Google, Apple or Facebook, that step is handled by the provider itself. Each one is an independent controller for what it hands us to complete the sign-in — typically your name, email address and whether the provider has verified it — under its own privacy policy, which we do not control.

How long we keep it

This is the retention schedule the service operates, enforced by a scheduled job:

  • Table chat and emoji reactions: there is nothing to keep. The room relays each line to the table and forgets it, so a match produces no chat data at all and this job has nothing to delete.
  • Direct messages, including the "Team" thread: 180 days.
  • Club chat: 180 days from when each line was written.
  • Support tickets: 12 months.
  • Sign-in sessions: deleted once the session expires. A session lasts seven days, extended while you keep using it; signing out ends it there and then.
  • Room invitations: 7 days after the invitation expires.
  • Group (masă) invitations: 7 days after the invitation expires. A group itself is kept while it still has a member and is deleted outright when the last one leaves.
  • Club invitations: 7 days after the invitation expires. A club itself is kept while it still has a member and is deleted outright, chat included, when the last one leaves.
  • Matches and results: kept indefinitely, and anonymised when the account that played them is deleted.
  • Progression, achievements and your seed balance: kept while the account lives and deleted with it, never on a timer. The ledger that explains a seed balance and your daily-hand results are kept 400 days; an Arena entry, 90 days.
  • Notifications you dismissed: 12 months.
  • Rate-limit ledgers and internal queues: 30 days or less, and most of them a day or two. They hold an account and a clock, never what was sent.
  • Anything that carries an expiry of its own — a data-export download, a sign-in or verification token, a rewarded XP boost: deleted as soon as that expiry has passed.
  • Error reports in Sentry: 90 days (the provider's default retention).
  • Analytics events in PostHog, if you consented to them: 12 months.
  • Server logs: rotated by the web server itself rather than by that job. A log file is kept at most 7 days after the server closes it and starts a new one, and every update we deploy erases all of them. On a quiet server the file still being written to can hold older lines, so the deploy is what bounds those.
  • Our application server's own request log: bounded by size rather than by a clock. It writes one line per request — the same shortened address, the path asked for, and how it answered, with cookies and authorisation headers left out entirely — and only the most recent 50 MB per service is kept. Every update we deploy erases those too.
  • Profile pictures, the friend graph, the accounts you block and the players you mute, and the championships you entered: kept while the account lives and deleted with it, never on a timer.
  • Where you play from, and the record of where you played from in each past month: kept while the account lives and deleted with it, never on a timer. Clearing it in your profile deletes both the current answer and every past month's entry immediately, without waiting for anything.
  • The record of a moderation or account action taken by our team: kept indefinitely, as our record that the platform acted. It names the account acted on, and it survives that account's deletion for the same reason a report does.
  • Reports: the report itself, the decision and the reasons for it are kept indefinitely as our record that the platform acted, the same reason support tickets and data-subject requests are logged. Unlike the messages a report can quote, the quoted excerpt has no fixed time limit of its own — it is removed only when the account that wrote it is deleted, not on the 180-day schedule above. We treat this as a deliberate, narrow exception for moderation evidence rather than an oversight.

Data stored locally on your device stays there until you clear the app's storage or uninstall the app.

Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, erase it, restrict or object to how we use it (including processing based on our legitimate interests), and receive it in a portable, machine-readable form. Where processing is based on consent, you can withdraw that consent at any time — withdrawing it does not affect what was done before.

Two of these are self-service in the app, under your profile:

  • Request my data — an export is assembled automatically, then checked and released by us, and reaches you as a download link that expires after seven days and works only while you are signed in to the account it belongs to. The account needs a verified email address for you to ask. We never email raw data files. The export opens with a manifest listing everything we hold about you, including the few things it withholds and why — a message somebody else sent you is their words as much as yours, so the export describes those rather than reproducing them.
  • Delete my account — a transactional cascade removes your personal data, purges your sessions, linked sign-in identities and message bodies, and replaces your display name with a "[DELETED]" placeholder so past matches and leaderboard rows stay consistent without naming you. A few things outlive it on purpose and none of them names you: the empty shell of the account, so a past match still has a seat to point at; the fact that a report or a support ticket existed and how it was decided; and our record of any action our team took.

We answer requests within one month of receiving them. If a request is complex we may extend that by two further months and will tell you why.

If you think we are handling your data unlawfully, you can complain to the Romanian supervisory authority, ANSPDCP (dataprotection.ro), or to the authority of the country where you live or work.

Children

The app is not directed at young children. It asks about your age the first time it runs — only an age band is stored, never a birthdate. 16 is the age of digital consent in Romania: a player who says they are under that age can still play, online and offline, but analytics and advertising stay switched off for that profile and cannot be turned on. If you believe a child has given us personal data, write to us and we will delete it.

How we protect it

Traffic is encrypted in transit. Passwords, guest device keys and backup codes are stored hashed, never in the clear. The game server is authoritative and sends each player only their own view of a match, so no opponent — and no modified client — can read your hand. No system is perfectly secure, and we do not claim otherwise.

Changes to this policy

When this policy changes, the date at the top changes with it. Material changes are announced in the app before they take effect.

The other documents

  • Cookies
  • Terms
  • Disclaimer
Back to the front page

jocuriclasice.ro

romanian card games

PrivacyCookiesTermsDisclaimer

Play and earn seeds

© jocuriclasice.ro 202616+