Privacy Policy
Effective date: August 30, 2026
The short version
- Beloti is an online game, so unlike our other apps it does have a server. Playing a hand means sending your moves to it, and your account lives there rather than on your phone.
- The server is in Falkenstein, Germany. Nothing is stored outside the EU.
- You can play without giving us anything. A guest account needs no email, no name, and no sign-in — just tap start.
- Signing in with Apple or Google gives us an identifier from them and, if you allow it, an email address. Apple's Hide My Email works normally, and we never see your password.
- The app is free, funded by optional rewarded ads (Google AdMob) that you choose to watch for coins, as described in Section 6.
- You can delete your account from inside the app, and it takes effect at once — your email address is erased, your name is replaced, and the account can never be signed into again. What survives, and why, is set out plainly in Section 9.
1. Who this policy covers
Beloti ("the app", "we", "our") is an iOS and Android app for playing Beloti, the Georgian form of Belote, against other people or against the game's own bots. Unlike the other apps on this site, Beloti is not an offline app: four people play the same hand at the same time, so there is a server between them, and it is ours. This policy explains what that server stores, what the app stores on your device, what a third-party advertising SDK accesses on our behalf, and what you can do about any of it.
The server runs on hardware we rent from Hetzner Online GmbH in Falkenstein, Saxony, Germany. All account data, game history and coin balances are stored there and nowhere else. The only other outside party involved is Google, through the AdMob SDK described in Section 6.
2. Your account
There are two kinds of account, and the difference is what you have given us.
| Kind | What it needs from you | What it is for |
|---|---|---|
| Guest | Nothing. No email, no password, no sign-in. You may type a display name; if you don't, the game invents one. | Playing immediately. A guest account is a real account — it holds your coins and your match history — but it exists only on the device that created it. |
| Apple or Google | An identifier from Apple or Google that is unique to you and to this app, plus an email address if you allow one to be shared. | Keeping your account when you change phone. Signing in on a second device brings your coins and history with you. |
We never see your Apple or Google password, and we never receive a general-purpose account identifier. Apple and Google give each app its own opaque subject identifier, so the one we hold cannot be used to look you up anywhere else. If you use Sign in with Apple and chooseHide My Email, we store the relay address Apple generates and never learn your real one.
If you start as a guest and later sign in, the app offers to join the two together. Doing so closes the guest account and continues as the signed-in one; the closed account's row is kept but can no longer be signed into.
3. Information we store on our server
This is the complete list. There is no analytics service, no advertising profile, and no tracking of you across other apps or websites.
| Data | Why it's collected | How long it's kept |
|---|---|---|
| Display name | Shown to the three other people at your table so they know whose turn it is. | Until you delete your account. Replaced with an anonymous placeholder on deletion. |
| Apple or Google subject identifier, and email if shared | The only thing that says a sign-in on a new phone is the same person as before. | The email is erased the moment you delete your account; the identifier goes with the record thirty days later — see Section 9. |
| Coin balance and the entries behind it | Coins pay the entry fee for a match and are earned by watching ads. The ledger is append-only so a balance can always be explained. | Kept after deletion in anonymised form, because entries reference each other and a ledger with holes in it cannot be audited. |
| Match history — who played, the result, and a short code per hand | Showing you your own results, and settling "what actually happened in that hand". The code is a compact seed the game can replay rather than a stored copy of the cards. | Kept after deletion in anonymised form. |
| Reports you send about another player | Acting on abusive names and behaviour. A report records who sent it, who it names, the reason, the table, and that player's display name at the time. | Kept as a moderation record. This is the one place a name is retained after it changes. |
| Sign-in sessions | Keeping you signed in without asking again. Stored as a hash — the token itself is not stored on the server. | Until it expires, you sign out, or your account is deleted. |
| Account counters — matches finished, matches abandoned, whether the account is banned | Bans, and discouraging people from walking out of games other people have paid to play. | Until you delete your account. |
Your IP address is used, in the moment, to limit how fast requests can be made — a protection against automated abuse. It is shortened first (an IPv4 address is reduced to its first three numbers), it is held only in the server's memory, and it is discarded whenever the server restarts. It is never written to our database and never associated with your account.
4. Information the app stores on your device
| Data | Why it's stored | Where it's stored |
|---|---|---|
| Your sign-in session | So the app does not ask you to sign in every time you open it. | The device's own secure storage — Keychain on iOS, the encrypted keystore on Android. |
| An installation identifier | A random value created by the app on first launch, used to spread the request limit fairly across devices. It is not an advertising identifier and it is not shared with anyone. | The same secure storage. Removed when you uninstall the app. |
5. Device permissions we ask for
Beloti asks for no runtime permissions at all. It does not request the camera, the microphone, your location, your contacts, your photos, or your files, and it has no code that could use them. The only capability it needs is network access, which is not a permission you are asked to grant.
6. Advertising & third-party SDKs
Beloti is free and funded by optional rewarded ads instead of a purchase price or a subscription. Ads are never forced and never interrupt a hand: you choose to watch one, from the lobby, in exchange for coins. If you would rather not, the game also gives coins when you have too few to sit down, so you are never stuck at a screen whose only way forward is an ad.
Ads are served by Google AdMob, a third-party advertising SDK we embed but don't control. To request, deliver and measure ads, Google's SDK can access and process:
- Device and advertising identifiers, such as the Android Advertising ID or Apple's identifier for advertisers.
- An approximate location derived from your IP address — the app itself requests no location permission and has no access to your precise location.
- Interaction signals relating to ad requests and impressions.
- Diagnostic and performance information about ad delivery.
Google collects this data and processes it as a third party for advertising, analytics and fraud prevention. None of it is collected, stored or seen by us — it is handled inside Google's SDK under Google's own privacy policy, available atpolicies.google.com/privacy.
The app asks Google for non-personalised ads only. It does not show the iOS App Tracking Transparency prompt, because it does not ask to track you across other companies' apps and websites. You can further limit how the advertising identifier is used from your device's system settings at any time — on iOS under Settings → Privacy & Security → Tracking, and on Android under Settings → Privacy → Ads. Doing so does not stop ads; it makes them less targeted.
Nothing about your account, your cards, your coins or your opponents is sent to Google. Aside from AdMob, and from Apple or Google when you choose to sign in with them, the app uses no third-party SDKs, no analytics and no crash-reporting service.
7. What we don't do
- We don't require an account to play — a guest needs no email address and no sign-in.
- We don't ask for your real name, your date of birth, your phone number or your address.
- We don't collect analytics, crash reports or usage statistics of our own.
- We don't sell, rent or share your personal information with anyone.
- We don't track you across other apps or websites, and we don't build an advertising profile of you.
- We don't have chat or any other way to send free-form messages to other players, so there is no message content to store. The only things you can say at a table are a fixed set of emoji.
- We don't take payments. Coins have no monetary value, cannot be bought, and cannot be exchanged for anything outside the game.
- We don't store your Apple or Google password, and we never receive one.
8. Your choices and rights
Because the server is in Germany, European data-protection rules apply to it regardless of where you are, and we extend the same handling to everyone.
- Play without giving us anything. A guest account collects no identifying information at all.
- Change your display name from the lobby, once every 24 hours.
- Keep your email private. Sharing one with us is optional at sign-in, and Apple's Hide My Email is supported.
- Delete your account from the lobby, at any time. What that does is described in Section 9.
- Ask us what we hold about you, ask for it to be corrected, or ask for a copy, by emailing the address in Section 13. Section 3 is the complete list, so there is nothing held back from it.
9. Data retention & deletion
You can delete your account yourself, from the lobby — it is not a request that waits on us, and it takes effect the moment you confirm it. The one time it is refused is while you are in a match: three other people are in that game, so finish it or leave the table first. When you delete it:
- Your display name is replaced with an anonymous placeholder.
- Any email address we hold is erased at once.
- Your Apple or Google sign-in is marked permanently revoked, and the account can never be signed into again. Signing in afterwards with the same Apple or Google account creates a brand-new account with no connection to the old one.
- Every sign-in session is revoked, so any device still holding one is signed out.
- Thirty days later the remaining stripped row is removed altogether, automatically.
Then, after thirty days, the record itself is removed. Deletion is deliberately two steps: everything that identifies you goes the moment you press the button, and the stripped row survives a month only so the coin ledger and the match history are not left pointing at nothing while anyone might still be reading them. After that a scheduled job removes the row outright, along with the opaque identifier Apple or Google gave us and every stored sign-in session. Nothing is left that could be matched back to you.
Coin ledger entries and match history rows outlive even that, in anonymised form, because they reference each other: a ledger with holes in it cannot be audited, and a finished match that lost a player would misreport what the other three did. After deletion they carry no name and no email.
Reports about another player are kept as moderation records, including the reported display name as it was at the time. This is deliberate: a report that only stored a name would be useless the moment the person changed it.
Uninstalling the app removes your session and the installation identifier from the device, but it does not delete your account — for that, use the delete option in the lobby. If you uninstall while playing as a guest, the account simply becomes unreachable rather than deleted, because a guest has no way to sign in from anywhere else.
10. Security
All traffic between the app and the server runs over HTTPS. Your session is held in the device's own secure storage — the Keychain on iOS and the encrypted keystore on Android — rather than in ordinary app storage. Sign-in tokens are signed, short-lived, and refreshed with a separate long-lived token that is stored on the server only as a hash; presenting a refresh token twice is treated as theft and revokes the whole session family.
What we do not claim: the database itself is not encrypted at rest beyond the disk encryption of the machine it runs on, and there is currently no off-site backup of it. We say so plainly rather than implying more than is there.
11. Children's privacy
Beloti is for people aged 16 and over, as set out in ourterms of service. It is not directed at children and we do not knowingly collect personal information from anyone under 16. The game asks for very little in any case: a guest account requires nothing at all, and the only personal information any account can hold is what Apple or Google passes on when somebody chooses to sign in. If you believe someone under 16 has created an account, contact us at the address in Section 13 and we will delete it.
12. Changes to this policy
If Beloti's data practices change — for example, if a new online feature, an analytics service, or an additional third-party SDK is added — this policy will be updated and the effective date above will change accordingly. Continued use of the app after an update constitutes acceptance of the revised policy.
13. Contact us
Questions about this policy, requests about your data, or anything else about the app can be sent to avtukalaz@gmail.com.
Beloti is an online game with accounts and a server in Germany, which makes it the only app on this site that stores personal data away from your device; its advertising data collection happens inside the embedded Google AdMob SDK, as described in Section 6. This policy describes the app's actual behavior as implemented; it is provided as a starting point and has not been reviewed by a lawyer — consider a legal review before publishing to an app store, especially given that the server holds account data in the EU and the game uses a virtual currency.