Privacy Policy

Last updated: 2026-10-05

Controller

Julius Kaiser
Blattjiweg 9
3940 Steg VS
Switzerland
Email: hello@gonutsev.com

Scope

This is the single privacy policy for both the GoNutsEV app and gonutsev.com. It is the policy linked from the app stores and from the app's Settings screen. There is no separate app-only policy and no other version hosted elsewhere. The app part comes first because that is where nearly all processing happens; the website itself collects almost nothing.

The app: what stays on your device

GoNutsEV has no user account, no login and no cloud backup. The following data is stored only on your device and is never uploaded or synced to a server:

  • Your hand histories, including the original voice transcript, your notes and the AI-generated title.
  • Your bankroll sessions: buy-ins, cash-outs, costs, staking terms, and the venue and notes you type in.
  • Your staking entries, including the names you give to the players whose action you bought.
  • Player notes: the names of people you play with or stake, the labels you give them and the reads you write about them. This is your private notebook about other people: it never leaves your device except inside a backup you export yourself, and it is never part of a shared hand.
  • All app settings.

Data leaves the device only when you choose to send it: the Export and Backup features hand a file to the system share sheet, and only the app or person you pick receives it.

On Android, the operating system's own backup (if you have it switched on) includes the app's database, its settings and the anonymous device identity described below, so they move to a new phone when you restore it. This backup is handled by Android and Google in your Google account, not by us; the device identity is only included when the backup is end-to-end encrypted (a screen lock is set) or when you transfer directly from your old phone.

The app: voice input and AI processing

When you record a hand by voice, the recording (up to 3 minutes) is saved temporarily on your device and sent to our server for processing. Our server forwards the audio to OpenAI for speech-to-text and the resulting text (up to 4,000 characters) to Anthropic, whose AI model structures it into a hand history. Typing a hand instead of speaking it skips the speech-to-text step. The optional AI title feature sends a copy of the finished hand to Anthropic with the transcript, notes, existing title and all identifiers removed first.

Our server does not store the recording, the transcript, the prompt or the AI response. Its logs contain only record sizes, status codes, latency, token counts and your anonymous device ID, and are deleted after 14 days. Neither OpenAI nor Anthropic receives your device ID. OpenAI does not retain audio sent to its transcription endpoint. Anthropic retains the text it processes for up to 30 days under the retention setting of our account. Neither provider uses API data to train its models.

The app: anonymous device identity and credits

On first use the app generates a random device ID and a random password, stores them on the device (on Android in an app-private file that travels with the Android backup described above, on iOS in the Keychain) and registers them with our authentication service (AWS Cognito, Frankfurt). This identity carries no name, email address, phone number or other personal identifier. It exists so that the AI features can be billed in credits: our ledger (AWS DynamoDB, Frankfurt) keeps the credit balance and a history of credit grants, debits and refunds per device ID, plus weekly usage statistics that are pure totals without any device reference. The same device ID identifies you to our purchase provider (see below). You can copy your device ID at any time by long-pressing the version line at the bottom of Settings.

The app: purchases

Subscriptions and credit packs are sold through Google Play or the Apple App Store and processed by RevenueCat. We receive purchase metadata only: the product, the billing period, a transaction reference and status events such as renewal, cancellation or refund. We never see your payment details.

The app: feedback

Sending feedback from the app is voluntary. Your message is emailed to our inbox (via AWS SES) together with the app version, your operating system version and your device ID, so that we can answer questions about credits or purchases. You can optionally add an email address so that we can reply to you. It is used only for that reply: it travels with the mail as its reply address and is neither stored in a database nor on your device. The message text and the email address are never written to our server logs. Feedback mails are kept for as long as needed to handle them, and deleted on request.

The app: reporting a misparsed hand

When the AI gets a hand wrong you can report it, and after correcting such a hand in the editor you can share the correction. Both are optional: nothing is sent until you tap Send, the form lists what the report contains and lets you read your transcript before sending, and the offer itself can be switched off in the onboarding tour or in Settings. A report contains the transcript or text you entered, the AI's raw answer, the hand as the app displayed it, your corrected hand if you made one, your sizing settings (the numbers the parser uses as defaults) and your comment. It is emailed to our inbox together with the feedback metadata above; the transcript and hand content are never written to our server logs. We use reports to improve the recognition. A copy with the device ID removed and any names or places in the transcript removed may be kept as a test case in our source code for as long as it is useful. Send us your device ID to have the mail deleted.

The app: error log

The app keeps a small log of its own recent errors on your device: up to 20 entries with the time, the type of error, a short error message (cut to 200 characters), the place in the app's code where it happened and how often it repeated. It contains no hands, sessions or other entries of yours, but an error message can occasionally quote a piece of input. The log stays on your device unless you send feedback with the "attach error log" checkbox switched on; the checkbox appears only when the log has entries, and you can switch it off before sending. After an error the home screen may offer to send the log, at most once a week; that offer only opens the feedback form, nothing is sent until you tap Send, and the offer can be switched off in Settings. A sent log reaches our inbox with the feedback mail, is never written to our server logs (only the number of entries is) and is removed from your device after a successful send.

The app: exchange rates

If you use the bankroll feature with a session currency other than your base currency, the app can fetch the daily reference exchange rate (Pro feature). Only the currency pair and the date are sent to our server, which retrieves the rate from frankfurter.dev. No device ID or other data reaches that provider.

The website

gonutsev.com sets no cookies and uses no analytics or tracking of any kind. It has no contact form; the only contact channel is the email address on this page. Fonts are bundled with the site at build time, so your browser never requests them from a third party. Our hosting provider (AWS Amplify, hosted in the EU) keeps standard server access logs.

When you open a shared hand or range, the website loads it from the short-term store described in the app section to display it. Opening it records nothing about you beyond the hosting provider's access logs.

Disclosure to third parties

We use the following processors to provide the service described above: OpenAI (speech-to-text), Anthropic (AI hand parsing and titles), Google Play, Apple and RevenueCat (purchases, in-app review prompts), AWS (authentication, backend, credit ledger, email and website hosting) and frankfurter.dev (exchange rates, receives no personal data). We do not sell data and we do not share data for advertising purposes.

International data transfers

We are based in Switzerland and process data in accordance with the Swiss Federal Act on Data Protection (FADP/DSG). OpenAI, Anthropic, Google, Apple and RevenueCat are based outside Switzerland and the EU, so using the app and its AI and purchase features means data leaves Switzerland to reach them. The AWS infrastructure under our own control is hosted in the EU (Frankfurt), and frankfurter.dev is hosted in the EU.

Your rights

Under the Swiss FADP you have the right to request access to, correction of, or deletion of your data, and to object to its processing. Everything stored on your device is deleted by uninstalling the app. To have the server-side data tied to your device ID deleted (credit ledger entries and feedback mails; shared hands and ranges are not tied to it and expire on their own), email us at hello@gonutsev.com and include the device ID copied from Settings; we cannot identify you any other way. Note that deleting the ledger entry also deletes any remaining credit balance.

Retention period

  • Voice recordings, transcripts and AI responses: not retained on our servers. Provider retention is described in the voice section above.
  • Server request logs (sizes, status, latency, device ID): 14 days.
  • Credit ledger (balance and credit history per device ID): for as long as the balance is in use, or until you request deletion.
  • Feedback mails (including hand reports and error logs): for as long as needed to handle them, or until you request deletion. Pseudonymised hand reports kept as test cases: for as long as they are useful.
  • Shared hands and ranges: available for 7 days after sharing, then deleted automatically. Daily share counter per device ID: 2 days.
  • Purchase records at Google, Apple and RevenueCat: per their own policies.
  • Website server logs: the standard period applied by our hosting provider.

Changes to this policy

We may update this policy as the app or website changes. The date at the top of this page marks the last revision.