Privacy Policy
Last updated: April 27, 2026
1. Introduction
Dodo Labs LLC ("we", "us", or "our") operates PokerBuddy (the "Service"). This Privacy Policy explains how we collect, use, store, and protect information about you when you use the Service. By using PokerBuddy, you consent to the practices described in this policy.
2. Information We Collect
Account Information
When you create an account, we collect your email address and a hashed password. We do not store your password in plain text.
Payment Information
Payments are processed by Stripe. We do not store your credit card details on our servers. Stripe collects payment information subject to their own privacy policy. We receive and store confirmation of successful payments, subscription status, and billing metadata (such as plan type and billing period).
Screenshot Data
When you use the Service, the PokerBuddy client application captures screenshots of your poker table window and sends them to our servers to compute your recommendation. These screenshots are processed in memory by AWS Textract (for OCR) and Anthropic Claude (for decision making), then discarded immediately after the response is returned — we do not retain screenshots by default.
If you flag a decisionfor review from the client's History window, the screenshot for that specific decision is re-uploaded to a private, access-controlled AWS S3 bucket along with your comment so our team can investigate. Only flagged-decision screenshots are stored; all other screenshots are never written to disk on our servers. Flagged screenshots may contain the display names of other players at your table; we treat that data as confidential, do not share it, and delete it when your account is deleted.
Usage Data
We store the following data for each decision request for up to 90 days:
- User ID (anonymous identifier) and timestamp
- Table identifier (a non-personal string)
- Credits used and remaining
- Processing latency
- Street (preflop, flop, turn, river) and recommended action
- The game state used to make the decision — your hole cards, the community cards, stack sizes, and the action history — along with the recommendation we returned. If you flag this decision, a pointer to the stored screenshot is also saved
This decision history powers your dashboard, our decision-review tooling, and the feedback loop that improves model quality. It is retained for 90 days and then automatically deleted. Conversational context between decisions is stored only in an encrypted client-side token that we cannot read without the client.
Technical Data
We collect technical information such as your IP address, client application version, and operating system for security, debugging, and service improvement.
Product Usage Analytics
We use PostHog to measure how the Service is used so we can improve it. PostHog records a limited set of behavioral events tied to your account ID (for example, that a signup was completed, a first decision was rendered, a subscription was purchased), plus automatic page views, clicks, and form submissions on the website. We do not record form input values, session replays, or any content of your poker screenshots in PostHog. PostHog sets cookies on the website to associate events with a consistent user identifier across sessions; see the Cookies section below.
Error Reports
We use Sentry to capture unhandled errors and crashes in the PokerBuddy backend and macOS client so we can fix them. Sentry receives error messages, stack traces, and the software version in use. We have PII capture disabled on both Sentry integrations — no IP addresses, request bodies, or user identifiers are sent unless explicitly included in an error message. Sentry does not set cookies in the macOS client and is not used for website analytics.
Ad Performance Data
We use the X (Twitter) Universal Website Tag (the "X Pixel") and the X Ads Conversions API to measure the effectiveness of our paid advertising on X. When you visit pokerbuddy.ai, the X Pixel records the visit. When you complete a signup, initiate a checkout, or complete a purchase, we send the corresponding conversion event to X via the X Pixel and via our server-to-server Conversions API integration.
The events sent to X include: the type of conversion, the conversion value (for purchases), a hashed (SHA-256) version of your email address, the X click identifier (twclid) if you reached our site via an X ad, and — for the X Pixel only — your IP address and user agent. We do not send your password, payment card details, the contents of your poker game state, or any screenshot data to X. We may use audiences built from your website visits to show you ads on X; we do not share this data with other ad networks for retargeting elsewhere.
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Process payments and manage subscriptions
- Analyze screenshots and return poker decision recommendations
- Monitor usage patterns and detect abuse or fraud
- Measure product usage via analytics so we can iterate on features and pricing
- Capture and triage software errors via error-monitoring tools
- Send transactional emails (receipts, password resets, subscription notifications)
- Respond to support requests
- Comply with legal obligations
We do not sell or rent your personal information to third parties. We use a limited set of conversion events (signup, checkout, purchase) to measure the effectiveness of our paid advertising on X (formerly Twitter); see Section 2 ("Ad Performance Data") for the specific data sent.
4. Third-Party Services
We rely on the following third-party services to operate PokerBuddy. Each has its own privacy policy governing their handling of your data:
- Amazon Web Services (AWS) — infrastructure, authentication (Cognito), database (DynamoDB), OCR (Textract), email (SES)
- Anthropic (Claude API) — AI-powered decision analysis. Screenshots and game state are sent to Anthropic for inference. Anthropic does not train on customer data from API requests.
- Stripe — payment processing and subscription management. See stripe.com/privacy.
- Resend — transactional email delivery. Email addresses and message contents pass through Resend when we send receipts, password-reset codes, and subscription notifications.
- PostHog— product analytics. Behavioral events and page views are sent to PostHog's US infrastructure. No screenshots or poker hand contents are sent. See posthog.com/privacy.
- Sentry — error monitoring for backend and macOS client. Receives stack traces and error messages only; personally identifying data (IP addresses, request bodies) is disabled. See sentry.io/privacy.
- X (Twitter) — we use the X Pixel (browser script) and the X Ads Conversions API (server-side) to measure the effectiveness of our X ad campaigns. X receives page visits and conversion events tagged with hashed email, X click identifiers (twclid), and conversion values where applicable. See x.com/en/privacy.
5. Cookies and Similar Technologies
The PokerBuddy website (pokerbuddy.ai) uses cookies and similar technologies for essential functionality and for measuring the effectiveness of our paid advertising on X (Twitter).
- Session cookies — used to keep you signed in across page loads of the dashboard and checkout flows. These expire when you log out or after a period of inactivity.
- Authentication tokens — stored in browser local storage to maintain your login session. These are not cookies but serve a similar purpose.
- Stripe checkout cookies— set by Stripe during payment and subscription management. Governed by Stripe's own privacy policy.
- PostHog analytics cookies — used to recognize a returning visitor and tie events together into a single user journey. These include a unique identifier cookie (typically stored under a name beginning with
ph_) and associated session cookies. No advertising, no cross-site tracking, and no session replay. - X (Twitter) Pixel cookies— set by the X Universal Website Tag on visits to pokerbuddy.ai. Used by X to associate your page visits and conversion events with the X ad you may have clicked. We also store the X click identifier (twclid) in browser localStorage for up to 35 days so we can forward it to X's server-side Conversions API on signup, checkout, and purchase.
Aside from X-Pixel measurement of our own ads on X, we do not share cookie data with other ad networks and we do not run retargeting campaigns on websites other than X. You can disable cookies in your browser settings; the dashboard and checkout may not function correctly without session cookies, but analytics, ad-attribution, and error-monitoring functions gracefully degrade. The PokerBuddy macOS client application does not use cookies.
6. Data Retention
We retain your account information for as long as your account is active. Decision history (game state, action, and reasoning) is retained for up to 90 days for operational purposes. Screenshots are not retained by default — they are processed in memory and discarded after each decision. Only screenshots for decisions you explicitly flag are stored, and those are deleted when your account is deleted. Billing records are retained as required by applicable tax and accounting laws. You may request deletion of your account at any time by contacting support@pokerbuddy.ai. Upon deletion, your personal information is removed from our systems, though anonymized usage statistics may be retained.
7. Data Security
We implement industry-standard security measures to protect your data, including TLS encryption for data in transit, encrypted storage for sensitive data, secure password hashing, and role-based access controls on our infrastructure. However, no security measure is perfect, and we cannot guarantee absolute security.
8. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access — request a copy of the personal information we hold about you
- Correction — request correction of inaccurate information
- Deletion — request deletion of your account and associated data
- Portability — request a machine-readable export of your data
- Withdrawal of consent — at any time, without affecting the lawfulness of prior processing
To exercise any of these rights, contact us at support@pokerbuddy.ai.
9. Children's Privacy
The Service is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
10. International Users
PokerBuddy is operated from the United States. If you access the Service from outside the US, your information will be transferred to, stored, and processed in the US. By using the Service, you consent to this transfer.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the Service. The "Last updated" date at the top of this page reflects the date of the most recent changes.
12. Contact
Questions about this Privacy Policy? Contact us at support@pokerbuddy.ai.
Dodo Labs LLC
30 N Gould St Ste R
Sheridan, WY 82801