Royal Dice Privacy Policy
Effective date: September 7, 2026
Royal Dice is a mobile-first dice board game built with a React/Vite frontend, a Capacitor Android app, Cloudflare Pages, Cloudflare Workers, and Supabase services.
This policy explains what information Royal Dice collects, why it is used, and what choices you have. It is written to reflect the current Royal Dice product and architecture, not a generic template.
If you have questions or want to make a privacy request, contact us at:
[email protected]
Summary
Royal Dice currently uses information to:
- let you sign in;
- save your player profile and progress;
- support online multiplayer;
- run Competitive matchmaking;
- maintain cloud wallet and coin records;
- support Coin Entry matches;
- diagnose game and connection issues;
- keep the game safe and reliable.
Royal Dice does not currently use third-party advertising SDKs, third-party ad networks, or third-party analytics SDKs.
Royal Dice offers optional Android purchases of virtual coin packs through Google Play Billing. Purchases are securely verified before any virtual currency is credited.
Information we collect
Royal Dice collects only the information needed to run the game and related services.
Account and authentication information
If you sign in, Royal Dice uses Supabase Authentication. Depending on the sign-in method, Supabase may process information such as:
- your email address;
- authentication tokens;
- account identifiers;
- sign-in timestamps and security-related metadata.
Royal Dice uses this information to verify your account, keep you signed in, and connect your cloud profile, wallet, and online identity to the right user.
If you play without signing in, Royal Dice may use a local device/browser profile instead of a cloud account. Local guest data may not be recoverable if the app is deleted, browser storage is cleared, or device data is reset.
Display names and player profiles
Royal Dice may store profile information such as:
- display name;
- avatar or player color choices;
- progress;
- match history or recent match summaries;
- settings and preferences;
- collection/unlock/equip choices;
- local or cloud profile metadata.
Display names and basic player identity details may be visible to other players in online rooms or Competitive matches.
Do not use sensitive personal information as your display name.
Online multiplayer data
When you use online multiplayer, Royal Dice may process information needed to create and maintain a match, including:
- room codes;
- player seats and colors;
- display names;
- connection status;
- gameplay messages;
- action requests;
- board state;
- reconnect/resync events;
- timing and version information used to keep players synchronized.
Online multiplayer is handled through Cloudflare Workers and related real-time room infrastructure. Multiplayer data is used to run the match, recover from disconnects, prevent stale state, and diagnose reliability issues.
Competitive matchmaking data
When you enter Competitive matchmaking, Royal Dice may process:
- your authenticated user ID, if signed in;
- matchmaking ticket IDs;
- selected table or entry tier;
- match ID;
- room code;
- player role or seat;
- matchmaking status;
- cancellation, timeout, recovery, or reconnect information.
Competitive matchmaking uses this information to match compatible players, prevent duplicate active queue entries, recover existing reserved matches, and keep the match lifecycle safe.
Coin balances and cloud wallet data
If you activate or use a Cloud Wallet, Royal Dice may store:
- user ID;
- coin balance;
- reserved coin balance;
- wallet status;
- wallet creation and update timestamps;
- economy ledger records.
Wallet records are used to show your balance, support Coin Entry, track rewards or purchases, and reconcile economy activity.
Royal Dice does not store credit card numbers or payment card details in its own database.
Royal Dice coins are closed-loop virtual items with no cash value. They cannot be withdrawn or redeemed for money or real-world prizes.
Coin Entry records
Coin Entry is the Royal Dice flow where coins may be reserved for Competitive matches and later settled, released, or refunded according to trusted server-side records.
Royal Dice may store Coin Entry records such as:
- reservation ID;
- user ID;
- reserved amount;
- reservation status;
- match ID;
- room code;
- player role;
- settlement status;
- winner and loser user IDs when a match is settled;
- final server-authoritative state version;
- ledger entries for reserve, release, refund, win, or loss events.
Coin Entry records are used to prevent duplicate reservations, protect player balances, settle completed matches, refund invalid matches, and support operational review.
Royal Dice does not let the frontend decide Coin Entry payouts. Settlement uses trusted backend and database paths.
Coin Store and Google Play purchases
Royal Dice uses Google Play Billing for optional Android purchases of virtual coin packs. Google Play handles the underlying payment transaction and payment method.
To verify a purchase, prevent duplicate or replayed credits, credit the correct virtual coin pack, and maintain economy integrity and support records, Royal Dice may process purchase-related information such as:
- Google Play product ID;
- purchase token;
- order or purchase evidence, where available;
- purchase state;
- purchase verification outcome;
- associated account or user identifier;
- credited coin pack ID;
- credited coin amount;
- idempotency keys used to prevent duplicate credits;
- purchase ledger and transaction evidence.
Android purchase success does not directly credit coins. Purchase evidence must be verified by a trusted backend path before any wallet credit is applied. Verified consumable purchases may then be consumed through Google Play so they can be purchased again.
Royal Dice does not receive or store payment card numbers or Google account payment credentials.
Royal Dice does not currently process Apple StoreKit purchases.
Optional rewarded ads
Royal Dice has an internal foundation for optional rewarded-ad rewards, but no third-party advertising network is currently live.
Royal Dice does not currently serve third-party ads and does not currently use third-party advertising SDKs.
If optional rewarded ads are added in a future version, this policy should be updated before public use to explain the ad provider, verification flow, and any additional data processed.
Diagnostics and technical information
Royal Dice may process technical information needed to operate and debug the game, such as:
- build target and build label;
- app version or build stamp;
- connection status;
- reconnect and resync counts;
- room authority mode;
- state version;
- protocol path;
- error messages;
- Worker runtime flag summaries;
- device or browser behavior relevant to app stability.
Diagnostics are used to troubleshoot gameplay, online reliability, build targeting, and economy safety. Royal Dice does not intentionally log authentication tokens, wallet secrets, keystore secrets, or payment credentials.
How we use information
Royal Dice uses information to:
- provide the game;
- authenticate players;
- save progress and preferences;
- support cloud wallet features;
- run online rooms and Competitive matchmaking;
- process Coin Entry reservations, settlements, releases, and refunds;
- prevent duplicate queue, reservation, purchase, or reward events;
- recover matches after refresh, reconnect, or app resume;
- keep the service secure;
- investigate bugs, abuse, or economy reconciliation issues;
- comply with legal or platform requirements.
What we do not currently collect or use
Royal Dice does not currently:
- use third-party analytics SDKs;
- use third-party advertising SDKs;
- show forced ads;
- sell personal information;
- store payment card numbers;
- use frontend-only purchase success to credit coins;
- allow Royal Dice coins to be withdrawn or redeemed for money or real-world prizes.
Platform and infrastructure providers may process technical logs needed to deliver and secure the service.
Third-party services
Royal Dice currently relies on these service providers:
Supabase
Supabase is used for authentication and database-backed features such as profiles, wallets, economy ledger records, Coin Entry records, purchase foundations, and related account data.
Cloudflare
Cloudflare Pages and Cloudflare Workers are used to host the frontend, run backend APIs, support online rooms, and operate matchmaking and real-time gameplay infrastructure.
Google Play
Royal Dice uses Google Play Billing for optional Android purchases of virtual coin packs. Google processes the payment transaction and payment method according to Google's own policies. Royal Dice receives purchase evidence, verifies it through a trusted backend path, and credits coins only after successful verification.
Data sharing
Royal Dice shares information only as needed to operate the game and its infrastructure.
Examples:
- basic display name and seat information may be visible to other players in the same online room;
- gameplay state is shared with players in the same match;
- Supabase processes account, database, and authentication data;
- Cloudflare processes requests, hosting, and Worker traffic;
- Google Play processes payment and purchase information for Android coin-pack purchases.
Royal Dice does not sell personal information.
Data retention
Royal Dice keeps information for as long as it is needed to provide the game, maintain economy safety, resolve disputes, prevent duplicate credits or payouts, and comply with legal or platform obligations.
Different kinds of data may be kept for different periods:
- local guest data may remain on your device until you clear app/browser storage or uninstall the app;
- account and profile data may remain while your account exists;
- wallet, ledger, Coin Entry, purchase, reward, and settlement records may be retained longer because they are needed for financial-style reconciliation, fraud prevention, and audit safety;
- temporary matchmaking or room data may expire or be cleaned up when no longer needed;
- operational logs may be retained for a limited time based on the settings of the infrastructure providers.
Account deletion
You may request account deletion by contacting:
[email protected]
If you request deletion, Royal Dice will take reasonable steps to delete or de-identify account data that is no longer needed.
Some records may need to be retained where required for:
- security;
- fraud prevention;
- economy reconciliation;
- legal compliance;
- dispute resolution;
- prevention of duplicate purchase, reward, or settlement credits.
If your account is deleted, you may lose access to cloud progress, cloud wallet records, Competitive history, and cloud-saved profile data.
Local device storage
Royal Dice may store some data locally in the browser or Android WebView, such as:
- guest profile data;
- settings;
- local progress;
- session or auth state;
- cached app data needed for normal operation.
You can remove local data by clearing browser/app storage or uninstalling the app. Removing local data may reset guest progress or require signing in again.
Some locally stored information is used to improve gameplay continuity, including reconnecting to active matches after an interruption.
Security
Royal Dice uses technical and organizational measures intended to protect data, including:
- Supabase authentication;
- server-side wallet and economy operations;
- service-role-only trusted database paths for sensitive economy changes;
- idempotency keys for rewards, purchases, reservations, and settlement flows;
- server-side verification designed to protect wallet and economy operations
- Cloudflare-hosted backend APIs and infrastructure protections.
No system can be guaranteed perfectly secure. If you believe you have found a security issue, contact us at:
[email protected]
Please do not publicly disclose security issues before we have had a reasonable chance to investigate.
Children's privacy
Royal Dice is intended for a general audience and is not directed toward children under 13.
We do not knowingly collect personal information from children under 13. If you believe a child has provided personal information to Royal Dice, contact us at:
[email protected]
We will take reasonable steps to delete the information if appropriate.
If a different minimum age applies in your region, you should only use Royal Dice if you meet that requirement or have appropriate parental or guardian consent.
Your choices
Depending on how you use Royal Dice, you may be able to:
- play locally without signing in;
- choose or change your display name;
- clear local app/browser data;
- request account deletion;
- choose whether to participate in Competitive or Coin Entry modes;
- avoid optional future rewarded ads or purchases.
Some features, such as cloud wallet, Competitive identity, Coin Entry, and account recovery, may require signing in.
International processing
Royal Dice uses cloud infrastructure providers. Your information may be processed in locations where those providers operate. By using Royal Dice, you understand that data may be processed outside your state, province, or country.
Policy updates
Royal Dice may update this Privacy Policy as the product changes.
If we make material changes, we will update the effective date and provide notice where appropriate. Future updates may be needed before enabling third-party rewarded ads, additional platforms, or new account/economy features.
Contact
For privacy questions, account deletion requests, or security reports, contact:
[email protected]