Privacy Policy — Baccarat Stat Master
Effective date: 29 July 2026 | Last updated: 29 July 2026
What changed in this version: we now describe the device identifier and the records our own servers keep (§3.3), the referral programme (§3.4), Claude (Anthropic) as a third optional AI provider (§4, §6), and where those records are actually stored (§7, §13). This policy now covers both the Google Play and Apple App Store editions of the App.
📋 Quick Summary
- Baccarat Stat Master is an educational pattern analysis and statistics study tool for users 18+ only.
- The app does NOT host, facilitate, or enable any real-money gaming, betting, or wagering.
- The app contains NO money management, bankroll tracking, or betting tools.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
- No account, sign-up, email address or password is required. We do, however, identify your device: a hashed device identifier ties together your daily free-prediction count, your referral code and your referral bonus on our servers. See §3.3.
- Your hand-by-hand session history, statistics and learned patterns stay on your device — we never receive them. The one exception is the optional "External AI" mode, where they go to the AI provider you choose and pay for. See §6.
1. Who We Are
Baccarat Stat Master ("the App", "we", "us", "our") is published by Manav Arora, an individual developer based in Delhi, India, and is distributed on both the Google Play Store and the Apple App Store. We are the data controller (and, for users in India, the Data Fiduciary) for the limited data described in this policy. The best way to reach us is the email address in §15; our full registered postal address is available on request to that address, and is also shown on our App Store listing. The App is a pure educational, statistical, and pattern-analysis study tool for baccarat outcome data. It is intended only for users aged 18 years and older in jurisdictions where such educational software is permitted.
Compliance Notice: This App is intended only for users aged 18+ in jurisdictions where educational statistical study tools are permitted. Users are responsible for ensuring their use complies with all applicable local laws.
2. What This App Is — and Is Not
This App IS:
- A statistical and pattern-analysis tool that performs all of its analysis offline, on your device. It contacts our servers only to check your subscription, your daily free-prediction allowance and your referral bonus — including each time the App starts and each time it returns to the foreground. See §3.3.
- An educational study application for baccarat outcome data
- A purely analytical software product with subscription-based premium features
This App IS NOT:
- A gambling app
- A real-money gaming service
- A betting, wagering, or staking platform
- A money management or bankroll tracking tool
- An "online money game" or "online money gaming service" as defined under any applicable law, including but not limited to India's Promotion and Regulation of Online Gaming Act, 2025
The App does not accept deposits, hold balances, place bets, or facilitate financial transactions of any kind beyond the standard in-app subscription processed by Google Play or the Apple App Store.
Where the statistics screens show a figure labelled "profit" or "units", this is simply the count of correct predictions minus incorrect ones. The App has no concept of currency, stakes, balances or bankrolls.
3. Information We Collect
3.1 Information stored locally on your device (not sent to us)
- Hand-by-hand session data (Banker / Player / Tie outcomes you enter)
- Saved pattern rules and strategies you create
- App preferences (theme, language, mode selection)
- Walkthrough completion state
This data is stored only in the App's own storage on your device. We never receive it — none of it is sent to our servers, and none of it appears in analytics or crash reports. It leaves your device in only two situations:
- When you export it yourself (Data → Import/Export → Export). The export is a JSON file named
baccarat_ultra_advanced_<timestamp>.json, handed to whichever app you pick in your device's share sheet. It contains every saved session — the full ordered hand history, the exact local start and end time of each session, win/loss statistics, and per-prediction-mode results — plus the complete pattern database the App has learned from your play. It contains no device identifier, advertising identifier or account identifier, but it is a detailed, timestamped record of how and when you played, so treat it accordingly. Once you share it, its security is governed by wherever you send it.
- If you turn on the optional "External AI" mode, in which case your recent hand history is sent to the AI provider you selected and paid for. See §6 for exactly what is sent.
Separately, if you use Pattern Rules → Export → "Save to file" on Android, the App writes a JSON file of your custom rules to your Downloads folder, which is outside the App's private storage. That file is not deleted automatically.
3.2 Information collected by third-party services
The App uses the following services. They are not optional and start when the App starts.
- Firebase Analytics (Google LLC) — pseudonymous, not anonymous: every event carries an identifier for your app installation. It collects automatic events generated by the SDK (first open, session start and end, app update, OS update, app removal, app errors, and an automatic in-app-purchase event carrying the product, price and currency), plus device model, OS version, app version, device language, and an approximate country derived by Google from your IP address. In addition, the App itself logs exactly three events of its own, all relating to the referral programme:
referral_shared, referral_redeemed and referral_rewarded (with the number of bonus days and whether the plan is monthly or yearly). No baccarat hands, session results, predictions or statistics are ever sent to Analytics.
- Firebase Crashlytics (Google LLC) — a per-installation identifier assigned by Crashlytics, full stack traces and exception message text, device model, OS version, app version and build, device orientation, free memory and storage. We report not only crashes but every uncaught framework and asynchronous error, including non-fatal ones. Exception messages are transmitted as written and may incidentally contain file paths from your device. We attach no identifier, custom key or user ID of our own.
- Firebase Installations (Google LLC) — a per-installation identifier that Analytics, Crashlytics and session reporting all depend on. The App never touches this service directly, but it is what links Analytics and Crashlytics data for the same installation.
- Firebase Sessions (Google LLC) — app session identifiers and foreground/background timing, used to produce crash-free-user metrics.
- Firebase App Check (Google LLC) — device-integrity attestation used to block requests from modified or repackaged copies of the App. On Android this uses the Google Play Integrity API; on iOS it uses Apple App Attest, with Apple DeviceCheck as a fallback, which means Apple Inc. receives a per-device token scoped to us as a developer.
The App does not use Firebase Authentication, Firestore, Cloud Storage, Remote Config, Performance Monitoring or push messaging, and it has no client connection to any database.
There is currently no in-App switch to turn analytics or crash reporting off. Please see §10 before you decide whether to use the App.
3.3 Information our own servers collect
We operate our own backend: Firebase Cloud Functions in Google Cloud us-central1 and a Firebase Realtime Database in asia-southeast1 (Singapore), under the Firebase project ai-baccarat-predictor. This is the only data we ourselves hold about you.
- A device identifier. The App obtains an identifier from your device's operating system — on Android the Android ID (SSAID), on iOS Apple's
identifierForVendor (Vendor ID) — and caches it in the App's own preferences. It is sent to our servers in the request body, without an account or name attached. Our server does not store it in raw form: it stores a one-way SHA-256 hash of it, salted with our Firebase App ID, and uses that hash as the record key. The same hash is used for the free-prediction allowance and for the referral programme, so those records sit under a single, stable pseudonym for your device.
- Please note this identifier is deliberately durable. On Android it is provided by the operating system and survives uninstalling the App and clearing app data — that is the point, so that the free daily allowance cannot be reset by reinstalling. Reinstalling will re-associate you with the same server-side record. On iOS the Vendor ID resets once you delete every app from this developer from the device.
- Your free-prediction allowance record. To enforce the limit of 25 free predictions per day, our server stores against your hashed device identifier: how many free predictions you have used today, the reset date, timestamps of your most recent request and most recent denial, and your device's UTC offset in minutes (a coarse time-zone signal, so the allowance resets at your local midnight). The first UTC offset we receive is retained and is not updated afterwards.
- When we contact our servers. Each time the App starts, each time it returns to the foreground, each time you use a free prediction, and when a purchase is verified or restored — not only when you buy something.
Your hand-by-hand results, statistics, strategies and pattern database are never sent to our servers.
3.4 Referral programme
- Our server mints a six-character referral code against your hashed device identifier and stores it, together with the date it was created and last updated. The App fetches this code automatically each time it starts and each time it returns to the foreground, whether or not you have ever opened the Invite Friends screen.
- If you enter a friend's code, we store a permanent link between your device record and your friend's device record — in effect, "who referred whom". Both sides of that link are hashed device identifiers.
- If you then take out a paid subscription, the App sends your store purchase token together with your device identifier to our referral service so the bonus Premium can be granted to both of you. We keep an audit record consisting of a one-way hash of that purchase token, both parties' hashed device identifiers, the plan name, the number of bonus days and the date.
- The events
referral_shared, referral_redeemed and referral_rewarded are sent to Firebase Analytics (see §3.2).
- Participation is voluntary. The bonus Premium (7 days on a monthly plan, 90 days on a yearly plan, for both parties) is the only benefit offered, and its value to you is the pro-rata subscription price of those bonus days. We place no other monetary value on the device identifier involved, and you can simply not use the feature — the App works identically without it. This paragraph also serves as our notice of financial incentive for California residents.
3.5 Subscription data
If you purchase a premium subscription:
- Google Play / Apple App Store handles all payment processing. We never receive your card numbers, banking details, or other payment information.
- The store gives the App a purchase token (Android) or a store receipt (iOS). Our server forwards it to Google or Apple to confirm the subscription is valid, and does not store it. The token contains no name, email address or payment details, and we never receive any of those — but it is an identifier that Google or Apple can resolve to your store account, so we do not describe it as containing no personal information.
- If you took part in the referral programme, the same token is also sent to our referral service together with your device identifier so the bonus can be paid out, and we permanently retain a one-way hash of it in the grant record described in §3.4. This is the only place where a purchase is tied to a device on our systems.
4. Permissions and Platform Capabilities
- Internet — required for: (a) verifying premium purchases with Google Play or the Apple App Store, (b) our own free-allowance and referral checks (§3.3), (c) the optional "External AI" mode if you connect your own ChatGPT (OpenAI), Gemini (Google) or Claude (Anthropic) API key, (d) Firebase services.
- Purchases — premium subscriptions are processed by Google Play Billing on Android and by Apple In-App Purchase (StoreKit) on iOS. On Android this is a manifest permission; on iOS no permission is involved.
On iOS the App requests no runtime permissions at all, and shows no App Tracking Transparency prompt because it does not track you across other companies' apps or websites.
The App does not request or use precise or approximate device location, contacts, camera, microphone, phone, SMS, or accounts permissions, and it has no account system. Two clarifications so that statement is not misread:
- We do send your device's UTC offset in minutes to our server, so the daily free-prediction allowance resets at your local midnight, and it is stored with that record (§3.3). Firebase Analytics separately derives an approximate country from your IP address (§3.2). Neither is a location permission, but both are coarse geographic signals.
- On Android, choosing "Save to file" when exporting your pattern rules writes a JSON file to your Downloads folder, which is outside the App's private storage. Nothing else the App stores leaves its own sandbox.
5. How We Use Information
- To operate, maintain, and improve App functionality
- To verify premium subscriptions and prevent fraud
- To enforce the limit of 25 free predictions per day, including across reinstalls
- To operate the referral programme and grant bonus Premium to both parties
- To diagnose crashes and technical issues
- To measure the referral funnel and aggregate usage patterns
- To comply with legal obligations
Where the EU/UK GDPR applies, our legal bases are:
- Performance of a contract (Art. 6(1)(b)) — verifying your subscription and granting referral bonuses.
- Legitimate interests (Art. 6(1)(f)) — identifying your device to enforce the free daily allowance and prevent it being reset by reinstalling the App, and diagnosing crashes and errors. We have weighed these against your interests; the data involved is a hashed device identifier and a usage counter, and no profile is built from it.
- Consent (Art. 6(1)(a)) — the optional External AI mode, which you activate by supplying your own API key and selecting the mode.
- Legal obligation (Art. 6(1)(c)) — retention required by tax and accounting law.
We do not build advertising profiles, run behavioural targeting, or use your data for any marketing purpose, and no advertising is shown in the App. We do not combine your data with data from other sources.
6. Data Sharing
We do not sell, rent, lease, or share your personal data with third parties for marketing purposes.
Limited data is shared only with:
- Ourselves — our own Firebase Cloud Functions and Firebase Realtime Database receive and store the records described in §3.3 and §3.4.
- Google LLC (USA) — Firebase Analytics, Crashlytics, Installations, Sessions and App Check, the Google Play Integrity API, and the Google Play Developer API used to verify Android subscriptions. Firebase processes data under Firebase's privacy terms.
- Apple Inc. — App Attest / DeviceCheck device attestation on iOS, and App Store receipt verification.
- Google Play / Apple App Store — for subscription processing, governed by their respective privacy policies.
- An External AI provider of your choosing — only if you voluntarily enter your own API key in External AI mode: OpenAI, L.L.C. (
api.openai.com), Google LLC (generativelanguage.googleapis.com), or Anthropic PBC (api.anthropic.com). Communications go directly between your device and that provider; they do not pass through our servers, and we do not intercept, log or store them.
What External AI mode sends, in full. Once you have saved an API key and selected the mode, the App sends the following to your chosen provider automatically after every hand you record — not once per session and not on a per-request tap: your total hand count; Banker / Player / Tie counts and percentages for the whole session; a shoe-style classification; your current streak; a road-pattern description; the last 10 hands and the last 50 hands written out; a five-hand momentum summary; a consecutive-loss counter; the App's own local prediction; and a feedback block replaying the last 8 predictions against their actual outcomes with a short written note on recent losses. If you enable "majority voting", the same payload is sent three times per hand. No device identifier, installation identifier, account or timestamp is attached — the request is authenticated only with your own API key, so the provider attributes the content to your own account with them and retains it under their policy, not ours. You can turn the mode off or clear your key at any time.
7. Data Storage and Location
Your session history, statistics and pattern database stay on your device. Data sent to Firebase's own services is processed on Google Cloud servers in the United States and other regions Google operates.
Our own backend is split across two regions, and this matters for where your records live:
- Our Cloud Functions run in Google Cloud us-central1 (Iowa, United States). This is where subscription verification, free-allowance and referral requests are handled.
- The records those functions create — your free-prediction allowance record and your referral records (§3.3, §3.4) — are stored in a Firebase Realtime Database located in asia-southeast1 (Singapore).
Our servers are contacted when the App starts, when it returns to the foreground, when you use a free prediction, and when a purchase is verified or restored.
8. Data Security
- All network communication uses HTTPS/TLS encryption.
- Firebase App Check verifies that requests from current versions of the App come from a genuine, signed installation, using Google Play Integrity on Android and Apple App Attest / DeviceCheck on iOS.
- Server-side purchase verification ensures only legitimate subscriptions unlock premium features.
- We do not store passwords, because we do not require accounts.
- If you use External AI mode, your provider API key is held in your device's secure, hardware-backed store (Android Keystore / iOS Keychain). It is sent only to the AI provider you chose, as the request credential, and is never transmitted to our servers or included in any export or crash report. Please note that the "copy key" button in the External AI settings places the key on your device clipboard in plain text, where other apps — and, on Apple devices with Handoff, your other devices — may be able to read it.
No system is 100% secure, but we apply industry-standard safeguards.
9. Data Retention
- Local on-device data: retained until you uninstall the App or clear app data. Two exceptions: if a data file is ever found to be damaged, the App keeps up to three quarantined backup copies of your session history in its own storage so nothing is lost, and on Android the device identifier described in §3.3 is provided by the operating system and is not cleared by uninstalling or clearing app data.
- Records on our own servers — your free-prediction allowance record, your referral code, the record of who referred whom, and referral grant audit records: these are currently retained indefinitely, until you ask us to delete them (see §10). We do not operate an automatic expiry for them today. Uninstalling the App does not delete them, and on Android reinstalling will re-associate you with the same record.
- Purchase tokens and receipts: we do not store them. They are forwarded to Google or Apple for validation and discarded. The only exception is the one-way hash retained in a referral grant record when a referral bonus is actually paid out, which we keep for the statutory tax and accounting period as proof the bonus was granted.
- Firebase Analytics: retained per Google Firebase default (up to 14 months).
- Crash reports: retained up to 90 days.
10. Your Rights
Depending on your jurisdiction (e.g., EU/UK GDPR, California CCPA/CPRA, India's Digital Personal Data Protection Act 2023), you may have the following rights regarding your personal data:
- Right to access the data we hold about you, and to know who we have shared it with
- Right to correct or complete inaccurate data
- Right to delete your data ("right to be forgotten" / right to erasure)
- Right to data portability — see §3.1: the in-App export gives you your full session history and pattern database as a JSON file at any time, with no request needed
- Right to object to processing carried out on the basis of our legitimate interests
- Right to nominate another individual to exercise these rights on your behalf in the event of death or incapacity (India, DPDP s.14)
- Right to grievance redressal (India, DPDP s.13) and to lodge a complaint with your local data protection authority or, in India, with the Data Protection Board
How to make a request, and what we need from you. Because the App has no account, the records we hold are keyed to a one-way hash of your device identifier, which we cannot reverse and which you cannot read off your device. The one handle that lets us find your record is your referral code, shown in the App under Invite Friends. Email apps3mb@gmail.com with that code and tell us what you would like us to do. Without it we have no way to identify which record is yours. We respond within 30 days.
Deleting your records will also reset the free-prediction allowance associated with your device and will remove any referral bonus and referral link. We will tell you before we act if that is the effect.
Analytics and crash reporting. We want to be straightforward about this: the App does not currently offer an in-App switch to turn Firebase Analytics or Crashlytics off, and uninstalling the App is not an opt-out in any meaningful sense — on Android it does not even reset the device identifier used for the free-prediction limit. What you can do today is limit Google's use of analytics identifiers through your device settings (Android: Settings → Privacy → Ads; iOS: Settings → Privacy & Security → Tracking and Apple Advertising), and you can email us to object to this processing, in which case we will delete the records we hold and stop the processing we control. We intend to add an in-App toggle; until this page says otherwise, it does not exist.
11. Children's Privacy
This App is strictly for users 18 years and older. We do not knowingly collect personal information from anyone under 18.
If you are a parent or guardian and believe a minor has used this App, please contact us immediately at apps3mb@gmail.com and we will delete the server-side records associated with that device. To do so we need the referral code shown in the App under Invite Friends, for the reason explained in §10. Session history, statistics and pattern data are held only on the device itself and can be removed by clearing the App's data or uninstalling it.
12. Legal Compliance
The App and its operators comply with applicable laws in the jurisdictions where the App is available. The App contains no functionality that would constitute an "online money game" or "online money gaming service" under applicable law.
The App makes no representation that it is legal in every jurisdiction. Users are solely responsible for ensuring that their use of the App complies with all laws applicable in their location.
13. International Transfers
Your data is transferred internationally. The specific destinations are the United States (Firebase's own services, and our Cloud Functions in us-central1) and Singapore (the Firebase Realtime Database in asia-southeast1 where our free-allowance and referral records are stored). If you use External AI mode, your chosen provider may process the request in the United States or elsewhere under its own policy.
Where the GDPR applies, transfers to both the United States and Singapore are made under Google's Data Processing Terms and the Standard Contractual Clauses approved under Art. 46, with Google acting as our processor. For users in India, this constitutes a cross-border transfer under s.16 of the Digital Personal Data Protection Act 2023 to countries not restricted by the Central Government.
14. Changes to This Policy
We may update this policy from time to time. The "Effective date" at the top reflects the latest version. Material changes will be highlighted in the App or on this page. Continued use of the App after an update constitutes acceptance of the updated policy.