PRIVACY
プライバシーポリシー
改定日: 2026年8月24日
取得する情報
Sign in with Apple、Googleログイン、またはメールアドレスとパスワードを利用したFirebase Authenticationによる認証処理では、アカウント識別子、メールアドレス、表示名、プロフィール画像、認証状態・認証情報、IPアドレスおよびユーザーエージェントが処理される場合があります。Apple AccountまたはGoogleアカウントのパスワードを本サービスへ入力することはありません。メールアドレスとパスワードによる認証で入力した平文のパスワードはFirebase Authenticationへ直接送信され、当社のアプリケーションサーバーは取得または保存しません。
対戦、コロシアム、設定、所持品、称号、購入状態、端末・ブラウザ情報、エラー、通信状況および不正利用防止に必要な操作履歴を取得します。
対戦の詳細履歴(手札、公開カード、アクションおよび結果)は各ユーザーについて最新100件まで、自己完結した記録として保存します。元の対戦詳細の複製は双方の参加者の最新100件から参照される間だけ保持し、片方の100件から押し出された時点で削除しますが、もう片方の自己完結した履歴は残ります。履歴に記録しない中断対戦は回復のため最大24時間保持した後に削除します。HUD等に必要なハンド数、勝敗、ベット・レイズ傾向等の累積値は、詳細履歴とは分離して利用期間中の全体集計として保存します。
本人用プロフィールには、認証元、表示名確認日時、ベット/レイズのプリセット等を保存する場合があります。ユーザーが任意にアップロードしたプロフィール画像は、サイズと形式を検証したデータURLとして本人用プロフィール内に保存する場合があります。この画像は挑戦状、ゲームまたは公開対戦プロフィールには複製されず、対戦相手には表示されません。対戦相手へ渡すプロフィールは、公開表示名、公開プレイヤーID、対戦参加者を区別する内部アカウント識別子、キャラクター、称号等の対戦表示と認可に必要な項目に限定します。プロフィール画像として対戦相手に表示される可能性があるのは、対象条件を満たす信頼済みのGoogleプロフィール画像URLに限ります。
App Store課金またはGoogle Play課金を利用する場合、商品ID、購入トークン、購入・取消・返金状態および照合に必要な情報を取得します。クレジットカード番号などの決済手段そのものは取得しません。
通報の対象・理由・詳細、ブロック関係、同意状態およびモデレーション判断に必要な証拠を取得します。
利用目的
本人確認、対戦機能、招待、プロフィール、所持品、購入の反映、アカウント削除、問い合わせ対応およびサービス改善のために利用します。
不正利用、嫌がらせ、権利侵害その他の規約違反を検知・調査し、ユーザー生成コンテンツの安全性を確保するために利用します。
外部サービス
本サービスはApple、App Store、Google Play、FirebaseまたはGoogle Cloud、Vercel等を利用します。認証、保存、配信、課金および障害調査に必要な範囲で情報が各サービスへ送信される場合があります。
保存期間と削除
利用中のデータはサービス提供に必要な期間保持します。退会時にはプロフィール、対戦データ、所持品、ブロック関係および現在のモデレーション状態は削除または匿名化します。
通報内容、サーバーが取得した証拠および運営判断の履歴は、安全管理用の仮名へ置き換え、異議申立て、再発防止および法的義務に必要な期間保持します。
購入・返金の証跡は、ユーザーIDや表示名から切り離した会計用の仮名識別子へ置き換え、退会完了から7年間保持します。
未使用の有償挑戦状と購入済みの非消耗型権利は、氏名、表示名、生のFirebase UIDまたは認証元識別子を含まないストア取引単位の保留台帳へ移します。台帳では、ランダムな会計主体IDと、旧内部アカウントおよびストア取引・ストアアカウント証明から作った一方向の仮名ハッシュを使います。退会前に当社が所有者へ発行した単回リカバリー証明、または対応ストアが検証可能な購入者証明を提示し、ストア上の最新購入状態をサーバーで再検証できた場合に復元し、復元またはストアによる返金・取消が確認されるまで保持します。
退会完了後、AppleまたはGoogle等の認証元識別子が利用できる場合、同一の認証元から再登録された際の初期無料特典の不正な再取得を防ぐため、認証元識別子をHMAC等の鍵付きハッシュで仮名化した認証元マーカーを、退会完了から180日間保持する場合があります。元の識別子はこの記録に保存せず、このマーカーは安全対策および不正利用防止以外の目的には使用しません。
過度なアクセスや不正操作を制限するため、IPアドレスまたはアカウント識別子から作成した仮名ハッシュとアクセス回数を保存します。この記録には利用制限期間の終了から24時間後の自動削除期限を設定します。
端末には、表示言語、操作設定、処理中の招待・購入・退会の再開情報、公開項目だけに限定した募集中の対戦情報、実績イベント送信の短期再試行情報(セッション中、最大20件・24時間)、Firebaseの認証・同期情報および静的キャッシュが保存される場合があります。実績イベントの再試行情報は現在のアカウント分だけを保持します。設定の「ログアウト」で、サーバー上のアカウントを残したまま対象端末のログインを終了できます。
iOSアプリを削除すると、そのアプリ内に保存された端末データは削除されますが、サーバー上のアカウントや購入記録は削除されません。Androidアプリをアンインストールしただけでは、Chromeが同じWebサイト用に保持するデータやサーバー上のアカウントが削除されない場合があります。Android版またはブラウザ版でブラウザが保持する端末データは、Chromeその他のブラウザのサイト設定から別途消去してください。サーバー上のデータを削除する場合は、アプリ内の「退会・アカウント削除」を実行してください。
ユーザーの権利
登録情報の確認、訂正、削除、利用停止およびアカウント削除に関する請求は、お問い合わせ窓口で受け付けます。本人確認ができない場合または法令上対応できない場合は、その理由を説明します。
お問い合わせ窓口
本プライバシーポリシーに関する問い合わせは、合同会社DCFトレーディング(info@dcftrading.com)で受け付けます。
PRIVACY
Privacy Policy
Last updated: August 24, 2026
Information we collect
When authentication is performed through Sign in with Apple, Google Sign-In, or Firebase Authentication with an email address and password, your account identifier, email address, display name, profile image, authentication status and authentication information, IP address, and user agent may be processed. You do not enter your Apple Account or Google Account password into this service. A plaintext password entered for email/password authentication is sent directly to Firebase Authentication; our application server does not receive or store it.
We collect information about matches, Coliseum, settings, inventory, titles, purchase status, devices and browsers, errors, connection status, and activity history necessary to prevent misuse.
For each user, we retain self-contained detailed records for only the latest 100 hands, including hole cards, visible cards, actions, and results. A duplicate of the original game detail is retained only while both participants' latest-100 rings still reference it. It is deleted when either ring evicts it, while the other participant's self-contained history record remains available. Interrupted games that are not recorded in history may be kept for recovery for up to 24 hours and are then deleted. Lifetime counters needed for HUD and statistics, such as hands, results, and betting or raising tendencies, are stored separately as aggregate values while the account is active.
A private account profile may include the authentication source, display-name confirmation time, and bet or raise presets. A profile image voluntarily uploaded by the user may be stored as a data URL after its size and format have been validated. The uploaded image is stored only in the private account profile, is not copied into Challenge Letters, games, or public match profiles, and is not shown to opponents. Profiles shared with an opponent are limited to fields needed for table display and authorization, such as the resolved public display name, public Player ID, an internal account identifier that distinguishes match participants, character, and title. The only profile image that may be shown to an opponent is a trusted Google profile image URL that meets the applicable conditions.
When you use In-App Purchase or Google Play Billing, we collect the product ID, purchase token, purchase, cancellation, and refund status, and information necessary for verification. We do not collect payment methods themselves, such as credit card numbers.
We collect the subject, reason, and details of reports, block relationships, consent status, and evidence necessary for moderation decisions.
Purposes of use
We use this information for identity verification, match features, invitations, profiles, inventory, applying purchases, account deletion, responding to inquiries, and improving the service.
We also use it to detect and investigate misuse, harassment, infringement of rights, and other violations of these Terms, and to protect the safety of user-generated content.
External services
This service uses Apple, the App Store, Google Play, Firebase or Google Cloud, Vercel, and other services. Information may be sent to these services to the extent necessary for authentication, storage, delivery, billing, and incident investigation.
Retention and deletion
We retain data while you use the service for as long as necessary to provide it. When you close your account, we delete or anonymize your profile, match data, inventory, block relationships, and current moderation status.
We replace report content, evidence collected by the server, and the history of operational decisions with pseudonyms used for safety management, and retain them for as long as necessary for appeals, preventing recurrence, and meeting legal obligations.
We replace purchase and refund records with accounting pseudonymous identifiers that are separated from user IDs and display names, and retain them for seven years after account closure is completed.
Unused paid Challenge Tickets and purchased non-consumable entitlements are moved to a store-transaction escrow record that contains no name, display name, raw Firebase UID, or authentication-provider identifier. The record uses a random accounting-subject ID and one-way pseudonymous hashes derived from the former internal account and store transaction/account evidence. Restoration requires either a one-time recovery proof that we issued to the owner before deletion or claimant evidence that the applicable store can verify, together with server-side revalidation of the latest store purchase state. We retain this evidence until restoration or a store-confirmed refund or revocation.
Where an authentication-provider identifier is available, such as through Apple or Google sign-in, we may retain for 180 days after account closure a pseudonymous authentication-source marker created by applying an HMAC or another keyed hash to the provider identifier. We use this marker to prevent fraudulent re-acquisition of initial free benefits when registering again through the same provider. We do not store the original provider identifier in this record and do not use the marker for any purpose other than security and misuse prevention.
To limit excessive access and abusive actions, we store a pseudonymous hash derived from an IP address or account identifier together with an access count. This record is assigned an automatic deletion deadline 24 hours after the applicable rate-limit window ends.
The device may store display language, interaction settings, recovery information for pending invitations, purchases, or account deletion, open-match information limited to public fields, short-lived achievement-event delivery retry data (session-only, up to 20 entries for 24 hours), Firebase authentication and synchronization data, and static caches. Achievement retry data is kept only for the currently authenticated account. “Log out” ends the sign-in on that device without deleting the server account.
Deleting the iOS app removes data stored by that app on the device, but it does not delete your server-side account or purchase records. Uninstalling the Android app alone may not remove data that Chrome keeps for the same website and does not delete the server-side account. Device data retained by a browser for the Android or browser edition can be cleared through Chrome or another browser's site settings. To delete server-side data, use Account Closure and Deletion in the app.
Your rights
Requests to access, correct, or delete registered information, suspend its use, or delete an account are accepted through our contact channel. If we cannot verify your identity or cannot fulfill a request under applicable law, we will explain the reason.
Contact
Inquiries about this Privacy Policy are accepted by 合同会社DCFトレーディング (info@dcftrading.com).