Skip to privacy policy
CHAINZERO
HomeGuidesPrivacyTerms

The details / Privacy

Your cards.
Your choices.

What stays on your device, what you choose to send, and how to ask for your information to be removed.

Effective September 29, 2026 · Current pilot

On this page

  1. 01 · The current pilot
  2. 02 · Early-access signup
  3. 03 · Your device
  4. Accounts & cloud saves
  5. 04 · Analysis & sharing
  6. 05 · Hosting & providers
  7. 06 · Deletion & choices
  8. 07 · Age & eligibility
  9. 08 · Changes & contact

A few things up front.

Your binder and saved decks are kept on your device. Optional cloud sync is off by default; if you enable it for your account, later account-workspace edits sync automatically when online. Signing in does not import your guest collection. Online analysis sends the information needed for that feature. Sharing an experiment with reviewers is a separate choice. We do not sell your signup information or deck lists.

01The current pilot

This notice covers the CHAINZERO marketing website, early-access form when enabled, and current app. “We” and “our” refer to the operator of the CHAINZERO project. The project contact below handles questions about your information.

The pilot is free and does not collect payments. Joining the early-access list is an invitation request; it does not create a player account or approve access. Optional accounts and cloud sync are being introduced separately. Their controls may appear while the account service and sign-in email delivery are still being connected. The account and cloud-sync descriptions below apply when those services are enabled and you choose to use them.

02When you join early access

When signups are enabled, the form collects:

  • Your email address, to manage your request and contact you about access.
  • Your required confirmation that you are at least 18 and agree to the Terms, plus the policy version shown when you submit.
  • Your optional choice to receive product updates. This is separate from requesting access.
  • Campaign source, medium, and campaign tags from the link you followed, when present, to understand how people find the pilot.

The form does not ask for your name, card collection, deck lists, password, or payment details. There is no active affiliate or ambassador application, referral reward, or referral-code collection.

Netlify Forms receives and stores enabled form submissions for the project operators, including submission timing and technical information used to deliver the form and filter spam. Signup information is not displayed publicly. Submitting the form does not automatically send a confirmation email or subscribe you to a separate mailing service.

We use submissions for access administration and send optional product updates only when you choose them. Form submissions remain in the private dashboard until we delete them; the current form does not have an automatic deletion timer. You may request removal or withdraw product-update permission using the contact below.

03What stays on your device

Your binder quantities, saved deck lists and labels, and settings such as format, music, tutorial progress, and Strategist selection are stored on your device using browser storage, including local storage and, as the updated storage is introduced, IndexedDB. Guest and account workspaces are kept separately. They are not public collections. Account-workspace edits are sent to the cloud automatically only after you enable the optional sync setting described below.

When accounts are available and you sign in, authentication session tokens and a minimal last-known account identifier and email are stored locally to maintain your session and identify the account workspace during offline use. Signing out on this device clears that session and remembered identity but preserves local guest and account workspace copies. On a shared device, clearing site data is the way to remove those local copies.

When offline support is available, the app’s service worker caches the public app shell and previously visited card artwork on your device so they can load without a connection. That offline cache excludes authentication, API, and administration routes. Account sessions and workspaces use their separate browser storage; excluding those routes from the public cache does not mean the device holds no account information.

Browser storage is specific to the browser and website address. Clearing it, changing devices or domains, using private browsing, or losing access to your device can remove access to those saves. Keep an exported backup when you need one. People with access to your browser may also be able to see its locally saved lists.

Optional accounts and cloud saves

Availability: account controls are being introduced, while the live account service and sign-in email delivery are still being connected. A control appearing in the app does not mean those services are ready. Local tools remain available during setup. The marketing form is separate: a pending request does not grant experimental access, and it does not send an automatic acknowledgment or approval email.

When account access is enabled and you sign in, Supabase supports authentication and storage. We process your verified account email and identifier, access or approval status, application and approval timestamps, accepted terms version, and the technical authentication records needed to sign you in and secure your session. Account access does not require a personal name. Your email and application are private. Signing out ends your session; it does not by itself delete server records or local lists.

Cloud sync is optional and off by default. For approved accounts, turning on the cloud-sync setting permits the app to send the current account binder and saved-deck information, including labels, to private storage associated with your account and retrieve its saved cloud version. After you enable sync, later edits are saved locally first and synchronized automatically while online. The app batches edits, normally spacing automatic edit-driven attempts about 20 seconds apart, and can retry when a connection returns or the app regains focus. Offline edits stay queued locally until sync is enabled and a permitted connection succeeds.

Signing in does not enable sync or automatically upload or merge the guest collection. Copying the device’s guest workspace into your account requires a separate confirmation. That action replaces the account workspace; the original guest copy remains separate. If sync is enabled, the copied account workspace can then be uploaded. Avoid personal or sensitive information in labels.

Turning sync off keeps future edits on the device and stops future automatic synchronization; it does not delete a cloud copy already saved. When different versions conflict, the app asks which version to keep. Review that choice and keep a backup before replacing a version. Signing out also preserves local copies, as explained above.

Cloud storage keeps the current workspace, not a history of deck bodies, cached analysis reports, or authentication tokens inside the workspace. Save-operation receipts record an operation identifier, a hash of the saved payload, base and resulting revision numbers, and timing so retried saves can be handled safely. Those receipts remain until account deletion; they do not contain historical deck contents.

Account-gated analysis records limited operational metadata such as your account identifier, request hash, timestamps, request state, and quota usage. These enforce per-account limits, prevent duplicate work, and help investigate abuse. Separate provider accounting records include model, token, and cost-reservation information without your account identifier or deck body. Owner approval and security actions may also create audit records. A request quota is an access limit, not a purchase or subscription.

Account records and the current cloud workspace remain until you remove them through an available control or request deletion. Operational analysis metadata, provider accounting, and owner audit records become eligible for cleanup after 90 days, with current-month budget records preserved as needed. Cleanup runs opportunistically in bounded batches when relevant service operations occur, so eligibility is not a promise that every stored copy disappears exactly on day 90. These records are separate from the optional shared experiments described below.

04When you run an analysis

Strategist and Mad Scientist are optional online features. Pressing their analysis controls sends selected card IDs and quantities, the relevant deck or test hand, and the settings needed for the request to our server. Depending on the feature, these include format, relevant ownership counts, spending cap, comfort level, and the selected goal.

Our server combines this information with card text and supported game actions, then sends the relevant structured information to TypeSafe AI, the provider behind the judgments. You do not type a chat prompt, but the feature still involves sending data for processing. The analysis request does not need your signup email or your personal name. See TypeSafe’s privacy policy. We do not promise that provider processing has zero retention.

Short-lived server caching and request counters help avoid duplicate work and limit abuse. Account-backed automated answers may be reused for five minutes. Expired cache entries are removed opportunistically on later status or provider operations in bounded batches; inactive stored entries can remain until cleanup runs. Where accounts are required, per-account usage records also support the limits described above. Running an experiment alone does not save it to our private review collection.

Sharing an experiment is a separate choice

If you select “Share this experiment to improve the lab,” we save the selected deck and test hand, format, goal, result, software and model versions, timing, and any structured feedback you choose to give. Reviewers may inspect the run and request an additional automated assessment to understand mistakes. Sharing does not automatically train a model.

The shared record does not include your deck name, full binder, signup email, account identity, IP address, or freeform feedback. This does not prevent our hosting providers from processing ordinary network request information.

Shared records are kept in private Netlify storage. Access expires 30 days after creation. Expired records are removed as reads and cleanup operations run; inaccessible copies can remain in inactive storage until that cleanup happens. The feedback receipt is not a public link to your deck and does not currently provide a self-service deletion control.

05Hosting, providers, and tracking

Netlify hosts the site and app and supports forms, server functions, security controls, and shared experiment storage. Hosting and analysis providers process technical information needed to deliver requests and operate their services, such as IP addresses, request timing, and browser information. See Netlify’s privacy statement for information about its own practices; its processing of customer content is also governed by its service agreements.

When enabled, Supabase provides account authentication and private cloud storage. See Supabase’s privacy policy. Account sign-in messages, where available, support authentication; they do not opt you into product news. Resend is not currently an active provider for marketing confirmations or approval emails.

We provide relevant information to service providers to run the features described here. We may also disclose information when legally required or reasonably necessary to protect people, investigate abuse, or secure the service. Information handled by providers may be processed in the United States and other countries where they operate.

The current site does not install behavioral advertising pixels or scripts designed to track you across unrelated websites. We do not sell personal information or share it for cross-context behavioral advertising. Campaign tags describe the link that brought you here; they do not create a cross-site advertising profile.

Browser “Do Not Track” signals do not change the current functional storage or request processing. We do not intentionally enable third parties to collect cross-site browsing histories through our pages. Following an external link takes you to a service with its own privacy practices.

Public connections use HTTPS. Access to stored submissions and review records is restricted. No online service or browser storage can be guaranteed completely secure; avoid including sensitive personal information in deck labels or correspondence.

06Your choices and deletion

  • Local decks: use the app’s deck deletion and card-removal controls. While account sync is enabled, account-workspace changes, including deletions, can synchronize to the cloud. To remove all local binder, deck, preference, session, and offline-cache data, clear site data for the app in your browser settings. This removes local copies; it is not a request to erase the server copy.
  • Cloud sync: leave it off to keep account-workspace changes on this device, or turn it off to stop future automatic sync. Disabling sync does not delete data already uploaded. Use the account-deletion control or contact us to request removal of server records.
  • Signup information: request access to, correction of, or deletion of your submission using the contact below. You can decline optional updates and still request early access.
  • Accounts and cloud saves, when available: the account-deletion control requires a recent sign-in (within 15 minutes) and a typed confirmation. Account deletion removes the authentication account and its linked application, current workspace, save receipts, and analysis metadata. You can also email the project contact from your account address to request deletion; we may verify account control. Independent provider accounting, owner security audit records, and separately shared experiments follow their own retention described above. If you also want your marketing signup removed, say so: it is a separate record. Clearing your browser does not delete the server copy, and deleting an account does not clear other devices’ local saves.
  • Shared experiments: contact us with the run reference if available. We may need information that verifies your control of a record before changing or deleting it. Do not post a feedback receipt publicly.
  • Online analysis: choose not to run it. Clearing local data does not retract requests already processed or remove separately shared records.

We handle requests under applicable law and may retain information where legally required or necessary to address a specific security or abuse issue. Provider backups and security records may follow separate retention processes; we do not promise immediate erasure of every backup. We will explain any applicable limit when handling your request.

07Age and eligibility

Early-access signup is for adults 18 and older. The browsing tool is not directed to children under 13. We do not knowingly seek personal information from children under 13. If you believe a child has submitted personal information, contact us so we can review and remove it as appropriate.

08Changes and contact

We will update this page and its effective date when our practices change. Material changes will be highlighted on the site and, where appropriate, communicated to affected signup contacts. We will seek any additional permission required before using information for a materially different purpose.

For questions or requests about your information, use the project contact below. Please send only the details needed to locate your request.

For privacy, deletion, support, or rights-holder requests, email privacy@chainzero.co. Include only the information needed to locate your request; never send passwords or API keys.

Independent tools for your next move.
Read the Terms for the pilot’s scope and limitations.

Back to CHAINZERO