Skip to content
← Back to GAMB·8

Last updated: April 2026

Privacy Policy

GAMB·8 takes your privacy seriously and aims to disclose what data we hold about you in plain language. This policy is the canonical reference for what we collect, why, who we share it with, how long we keep it, and the rights you have to access, export, or delete it. If anything here is unclear, email privacy@gamb8.com and we'll explain.

1. Data We Collect

We try to collect as little personal data as the product can function with. The table below lists every category of data we hold about you, what's in it, where it comes from, and where it lives.

Account & identity

  • Email, username, hashed password. Provided when you sign up. Password is hashed (PBKDF2) — we cannot recover it. Used for authentication and account recovery.
  • Display name, avatar, bio, timezone, locale, preferred currency, theme. Optional profile data you set yourself.
  • Subscription tier, XP, streak, achievements. Computed from your account state and product usage.
  • OAuth identity tokens (Google, Discord, X, Kick). Stored encrypted. Used only to keep linked logins working. You can unlink at any time.
  • MFA secret & backup codes. Generated when you enable two-factor auth. Stored encrypted (Fernet). Only used to verify your sign-in challenges.

Behaviour & usage

  • Page history & feature interactions (UserBehavior, ≤50 KB). We store a small JSON record of which pages you've visited, which features you've tapped, and a few aggregates (favourite tools, primary vertical, last-active timestamp). It's synced from your browser to our servers in batches roughly every 30 seconds while you are signed in. It does not contain bet amounts, bet outcomes, or any of your tracker data. You can pause sync or wipe it at any time from Settings → Privacy.
  • Notification preferences. Which alerts (poker, sports, risk, marketing) you have opted in or out of.
  • Linked casinos. If you link a casino account to GAMB·8, we store the operator name, your username on that operator, and the link timestamp. We do not store your casino password and never log into your casino account.
  • Linked integrations (Discord webhook URL, Telegram chat ID). If you opt in to push your own bot/tracker events to a Discord channel or Telegram chat, we store the webhook URL or chat ID, encrypted at rest. These are credential-equivalent secrets for your channels — protect them as you would a password and rotate them if compromised.

Tools & tracker data

  • Bankroll history, bet logs, calculator inputs, tracker sessions. By default these live in your browser's localStorage only and never leave your device. They are uploaded only if you explicitly use a sync, cloud-backup, or export feature.
  • Sports bets, prediction trades, poker sessions, bot sessions. Created by you when you use the relevant features. Retrievable via the data export endpoint.
  • Skill scores (pattern recognition, variance tolerance, risk management, capital allocation). Computed from your tools / tracker activity. See Section 4 for how we use these.

Streamer Truth Engine (if you use it)

  • Streamer correction submissions. If you submit a correction or complaint about a streamer profile, we store your name, email, evidence URL(s), and the submission text so we can review and follow up. Approved corrections are surfaced to the streamer being corrected.
  • Deal reviews and reports. Reviews you publish are tied to your account; reports are private to the moderation team.

Affiliate & partner data

  • Application data. Platform username, average viewers, niche, promotion plan, full legal name.
  • Tax declaration data. Your tax jurisdiction, plus any identifying information you supply when accepting the partner agreement. We may be required to retain this for up to 7 years per applicable tax law.
  • Agreement audit trail. The IP address, browser user agent, and timestamp at the moment you accept the partner agreement.
  • Payout details (USDC / BTC / PayPal). Encrypted at rest. Visible only to you and a small number of payout-operations administrators.

Payments (Stripe)

  • Customer profile, subscription state, invoice history, crypto payment records. We retain the bookkeeping records (invoice number, amount, date, plan, status). The payment instrument itself (card / bank details) is held by Stripe, not by GAMB·8 — we never see or store your card.

Push, error, and device data

  • Push notification tokens (FCM). Created if you enable push on mobile. Used only to deliver notifications you opted into.
  • Device info. Device type, OS version, screen resolution, app version. Used to optimise the experience and triage bug reports.
  • Performance metrics (Core Web Vitals). Anonymous loading, layout, and interactivity timings.

Network & security

  • IP address. Read from request headers on every request. Used for geo-detection (country/region — to apply local legal restrictions and select your default currency) and for fraud / abuse detection. We do not store your full IP long-term; geo lookups happen in real time.
  • Login & session logs. Login attempts, IP, device fingerprint, timestamps, success/failure. Retained for 90 days for security monitoring and incident response.
  • Security alerts. Computed signals like "new login from unfamiliar location" or "OAuth geo-change", used to warn you of suspicious activity.

Affiliate attribution & referral cookies

  • If you arrived via a partner referral link, a small attribution cookie (gamb8_ref / gamb8_referral) is set in your browser for 60 days so the partner gets credit if you sign up. The cookie holds an opaque code only — no personal data — and is cleared once you create an account. See the Cookie Policy.

2. Why We Process Your Data

For users in the EU and UK, GDPR Article 6 requires us to identify a lawful basis for each processing activity. Our bases are:

  • Performance of a contract (Art. 6(1)(b)) — account creation, authentication, payment processing, delivering the features you signed up for.
  • Legitimate interests (Art. 6(1)(f)) — security monitoring, fraud detection, anonymous performance metrics, error reporting, and improving the product.
  • Consent (Art. 6(1)(a)) — analytics in GDPR regions (PostHog), marketing emails, push notifications, opt-in pool data sharing for poker stats. You can withdraw consent at any time without affecting the lawfulness of processing prior to withdrawal.
  • Legal obligation (Art. 6(1)(c)) — tax records for affiliate payouts, response to lawful regulator or court orders.
  • Vital interests (Art. 6(1)(d)) — used only when responsible-gambling safeguards trigger an alert that we believe is necessary to prevent immediate harm.

3. Third-Party Services We Share Data With

We use the third parties below to operate GAMB·8. Each has its own privacy policy and handles your data under its own legal terms. We have data-processing agreements in place where required. For the up-to-date canonical list — including any vendor swaps between policy revisions — see Sub-processors.

PostHog — Product analytics

Anonymised event data only (page views, feature taps). Session recording is disabled. No PII, no financial data, no bet outcomes are sent. In GDPR regions (EU/UK), PostHog is initialised only after you consent on the cookie banner.

Provider: PostHog Inc. · Region: US & EU · Retention: 90 days · Policy: posthog.com/privacy

Sentry — Error tracking

Stack traces, browser version, and device type are sent when something crashes. Sentry is configured to strip sensitive fields (passwords, tokens, full request bodies) from error payloads.

Provider: Functional Software Inc. · Region: US · Retention: 30 days · Policy: sentry.io/privacy

Stripe — Payments

Card and payment-method data is collected and processed by Stripe directly inside Stripe's hosted checkout. GAMB·8 receives only the bookkeeping fields (customer ID, subscription state, invoice references) and never sees your card details. Stripe is PCI-DSS compliant.

Provider: Stripe, Inc. · Region: US/EU · Retention: per Stripe terms · Policy: stripe.com/privacy

Firebase Cloud Messaging — Push notifications

If you enable push, we send notification payloads through Firebase Cloud Messaging, operated by Google. Used only to deliver notifications you opted into. No advertising use.

Provider: Google LLC · Region: US · Retention: until you unregister · Policy: policies.google.com/privacy

OAuth providers (Google, Discord, X, Kick)

Used only when you actively choose to link a third-party login. The provider sees our app name and the scopes you grant. We receive (and store, encrypted) only what we need to keep that link working — usually a stable user identifier and a refresh token.

Providers: Google LLC, Discord Inc., X Corp., Kick Streaming B.V. · Region: per provider · Retention: until you unlink

Cloudflare — Edge network & geo-IP

All requests pass through Cloudflare for DDoS protection, caching, and geo-IP enrichment. Cloudflare sees your IP and approximate location for the duration of each request.

Provider: Cloudflare, Inc. · Region: global · Policy: cloudflare.com/privacypolicy

We do not sell your personal data to anyone, and we do not run any third-party advertising network. No data is shared with advertising platforms.

4. Automated Decision-Making (GDPR Art. 22)

GAMB·8 runs a small number of automated systems that compute scores about you from your gameplay and tool usage. We disclose them here so you can decide whether you are comfortable with that processing.

  • Skill scores — pattern recognition, variance tolerance, risk management, capital allocation. Computed daily from your activity in tracker, poker, sports, and prediction tools.
  • Churn risk score — a model output indicating how likely you are to cancel your subscription. Used to prioritise product improvements and outreach.
  • Tilt detection — a behavioural rule engine supplemented by a lightweight ML classifier that flags potentially harmful gameplay patterns and surfaces non-blocking warnings. Output is advisory; we never take an automated account action based on it. See the AI Act Compliance page for the full registry of AI systems and their oversight controls.

None of these scores are used to deny you access to a feature, change your price, or restrict your account automatically. They are used only to personalise the product (e.g., suggest a tool you might find useful) and to improve internal product decisions.

Under GDPR Article 22 you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. Because our scores do not have those effects today, this right does not currently restrict anything you can do — but if that ever changes (for example, if we introduced a feature that priced based on a score), we would offer an explicit opt-out and a path to human review before doing so. You can opt out of behavioural scoring entirely from Settings → Privacy; opting out switches Tilt Monitor and Edge Radar to fully rule-based operation and stops skill / churn model updates for your account.

5. Storage & Security

Server-side data lives in a PostgreSQL database hosted by Railway, encrypted at rest (AES-256) and in transit (TLS 1.3). Sensitive fields (OAuth tokens, MFA secrets, payout addresses, integration webhook URLs) are additionally encrypted at the application layer using Fernet. Most of your tool inputs and tracker history live in your browser's localStorage and never leave your device unless you use a sync, export, or backup feature.

We use rate limiting, throttles, JWT refresh-token rotation, MFA lockout on repeated failures, OAuth CSRF protection, security alerting on geo-anomalies, and a documented incident-response process. None of this is a guarantee against every possible breach — the only data we cannot lose is data we never collect, which is why we keep collection minimal.

6. Cookies

Strictly necessary cookies are used for authentication sessions and CSRF protection. Analytics cookies (PostHog) are set only after consent in GDPR regions. Affiliate attribution cookies are set when you arrive via a referral link and expire after 60 days. We do not use advertising cookies and we honour the Do Not Track header.

See the dedicated Cookie Policy for the full breakdown and management instructions.

7. Your Rights

Depending on where you live, you have some or all of the following rights:

  • Access — request a copy of all personal data we hold about you.
  • Export (portability) — download your data in a structured JSON format from Settings → Account. Exports are rate-limited to one per 24 hours.
  • Correction — request correction of inaccurate personal data.
  • Deletion (right to be forgotten) — delete your account and associated server-side data from Settings → Account, or by emailing privacy@gamb8.com. Account deletion requires your password (or TOTP) plus typing the literal word DELETE as confirmation. Backups are purged within a further 30 days (worst-case total retention 60 days). Local device data can be cleared from your browser's site-data settings.
  • Restriction & objection — ask us to stop or limit specific processing. You can disable analytics and behavioural scoring at any time from Settings → Privacy.
  • Withdraw consent — withdraw any consent you previously gave (analytics, marketing emails, push notifications, pool data sharing). Withdrawal does not affect the lawfulness of processing before withdrawal.
  • Lodge a complaint — if you are in the EU or UK and unhappy with how we have handled your data, you may complain to your local supervisory authority (e.g., the ICO in the UK).

To exercise any of these rights, email privacy@gamb8.com. We respond within 30 days for routine requests and within 72 hours for urgent matters. We will never charge a fee for a reasonable request.

8. Data Retention

  • Account data — for as long as your account is active. Deleted within 30 days of an account-deletion request.
  • UserBehavior page history — server-side TTL of 30 days for individual events; aggregates retained while your account is active.
  • Login & session logs — 90 days.
  • PostHog analytics events — 90 days (PostHog-side).
  • Sentry error reports — 30 days.
  • Push notification tokens — until you unregister or delete the account.
  • Affiliate tax / partner agreement records — up to 7 years per applicable tax law, then deleted.
  • Stripe invoice records — retained for the duration required by tax and accounting regulation in our jurisdiction (typically 7 years).
  • Streamer correction submissions — until the correction is resolved, then retained for 12 months as part of the editorial audit trail.
  • Backups — encrypted backups are retained for 30 days; data deleted on the live system rolls out of backups within that window.

9. Children's Privacy

GAMB·8 is intended for users aged 18 and older (or the legal gambling age in your jurisdiction, whichever is higher). We do not knowingly collect data from minors. If you believe a minor has created an account, contact us immediately at privacy@gamb8.com and we will delete the account and all associated data.

10. Changes to This Policy

We may update this policy when we add new features, change service providers, or update our processing activities. Material changes are notified by in-app banner or email at least 14 days before they take effect. The "Last updated" date at the top of this page reflects the most recent revision.

11. Contact

For privacy-related questions, data requests, or to report a concern:

GAMB·8 OÜ — Privacy Team
Operating entity: GAMB·8 OÜ, registered in the Republic of Estonia
privacy@gamb8.com

For all other legal questions: legal@gamb8.com. For the operating entity, data-controller details, DMCA agent, and other formal identifiers, see the Company Information page.