FoldWise
Privacy

What we know about you, explained.

Updated on May 26, 2026

FoldWise is built independently. We don't sell data, we don't do external ad profiling, we don't share with data brokers. This document covers what we store, why, and how to remove it.

What we store

Your email (via Supabase Auth), optional name, chosen language, visual theme. The poker sessions you log, your knowledge base notes, bankroll transactions, Game Assistant analyses. Your AI provider API keys are encrypted in Supabase Vault — no one on FoldWise can read them. If you subscribe, we store the Paddle customer ID for billing reconciliation.

Why

To make the app work (contract). To improve it (aggregated analytics, no per-user profiling). To email you about your own activity (weekly digest, bankroll-low alerts — opt-out in Settings). Never to sell you third-party stuff.

Third parties that touch your data

Supabase (auth, database, Vault) — data in the region you pick when creating the project. Vercel (hosting + privacy-friendly Analytics without invasive cookies). Resend (transactional email delivery). Paddle (payment processor, Merchant of Record, supports Uruguay). When you use the Game Assistant with your own API key, prompts travel to Anthropic / OpenAI / Google / Groq / OpenRouter per the model you pick — that relationship is between you and them; FoldWise just encrypts and forwards your key.

Retention

As long as you have an active account. If you delete the account, data is removed immediately (database cascade). Operational logs at Vercel and Supabase retain ~30 days under their own policies — those are outside our direct control.

Your rights (GDPR Art. 15-20)

Access, rectification, deletion, portability. Actions live under Settings → Privacy: export your data as JSON (Art. 20) and delete the account (Art. 17). No email request needed — fully self-service.

Cookies

Minimal and functional: Supabase session cookie (`sb-*-auth-token`), theme cookie (`theme`), and `mobile_shell` when the mobile-embedded app sets it. None for tracking or advertising. We do NOT use Google Analytics.

Changes to this policy

If something material changes, we email you 30 days before applying it, so you can review and decide whether to stay or delete the account. The last-updated date is at the bottom.

Contact

Gustavo (BagOfLuck95) — gustavo@brokenrubik.co. I'm a person, not a legal team; I reply in days, not hours.