Privacy policy

Effective date: 2026-09-22

Rules for the HOAOF free public beta. Operator and privacy contact: [email protected].

1. Contact

HOAOF is an individually operated service. For privacy requests, contact [email protected]. This policy describes the current free beta.

2. Account data

We process Google’s account identifier (sub), verified email, internal account ID, username and creation time for authentication and support. We do not receive your Google password. We store session-token hashes and creation/expiry times, plus temporary OAuth state hashes, nonce and PKCE verifier data.

3. Inputs and activity

Hand class, position, player count, opponent stats and actions are used for calculations and bounded temporary caches. New session recording is disabled. Previously, if you started recording, settings, hands, revealed cards, actions, EV, outcomes and actual bonuses are saved in account-owned sessions for review and graphs. Existing records remain stored and can be removed through account deletion or a support deletion request. Recording is opt-in. Administrators see accounts or temporary visitor references active within 60 seconds, the screen category and last heartbeat. IP/request information supports networking, security and rate limits. The activity list does not show IP addresses, passwords or session tokens.

4. Browser storage

We use nlh_session, google_flow and hoaof_presence cookies. Language, table layout and opponent settings use localStorage. Analysis request identifiers use sessionStorage to prevent duplicate charges and are cleared on sign-out. Blocking storage may prevent sign-in or saved settings. HOAOF currently has no advertising-targeting or Google Analytics tracking script.

5. Retention and deletion

Deleting an account removes it from the operating account database with its sessions, Google identity and credit records. Sessions expire after 7 days by default and OAuth flows after 10 minutes; later relevant requests remove expired rows. Presence uses a 60-second window; recent request summaries use 5 minutes. Calculation caches are evicted at capacity or restart. Error logs rotate at 5MiB per file with four files total; fixed-day deletion is not yet implemented. Support notes or manual backups require a separate operator deletion check when requested. Deletion does not instantly physically erase every browser copy or manual backup.

6. External services and international processing

Google processes authentication data during sign-in. Cloudflare processes network/request information to deliver and protect the site. Both are US-based providers with international infrastructure. Support email is processed through Google Gmail. Processing can occur in the US and other countries. Specific locations and retention follow provider policies and settings. You may refrain from using the service or request deletion if you do not wish to use these essential providers. Exact transfer countries, retention terms and the applicable legal basis still require operator confirmation against provider contracts/settings.

7. Sharing and payments

The service does not sell member data to advertisers and currently collects no payment card or bank-account details. Disclosure outside operational purposes is limited to lawful requirements. Do not send passwords, identity numbers or others’ sensitive information in support messages. This notice will change before new payment or advertising processing is introduced.

8. Your rights and security

Use account settings to delete your account or email us for access, correction, deletion or restriction requests. Limited identity checks may be required. We use HTTPS, access controls, hashed session tokens, file isolation and administrator restrictions. Google account controls let you manage account security and revoke the connection. Applicable statutory rights remain unaffected.

9. Updates

Material changes are published here and in service notices, with any legally required notice or consent. Outstanding provider retention and international-transfer details will be updated when verified.

Support conversations

When you submit a ticket, we store your internal account ID, category, subject, messages, replies, status and timestamps for customer support. Subjects and message content are encrypted in a separate database and visible only to you and the operator. Tickets remain available while your account exists and are deleted with your account. Submit and read replies in the Support & suggestions tab.

Google Privacy · Cloudflare Privacy · Cloudflare Cookies