LEGAL

Privacy Policy

Effective September 6, 2026. This Privacy Policy explains the information processed when you use onemillion and how that information is used.

1. Account information

If you create an account, Supabase Auth processes information needed to authenticate you, such as your email address, authentication credentials or OAuth identity, user identifier, and optional profile information such as a display name.

2. Game and account data

onemillion stores information needed to operate your account and game progress, including roll results, timestamps, roll type, generated number, EP, rarity, badge associations, collection progress, aggregate game statistics, free-roll eligibility, and paid-roll balance.

3. Anonymous first roll and abuse prevention

Before account creation, the service can use a secure HTTP-only browser identifier to preserve and limit the initial anonymous roll. The server may also process a one-way keyed hash derived from network information for short-window abuse prevention. The abuse-prevention mechanism is designed so the raw network identifier is not stored as that hash value.

4. Payments

Stripe processes checkout and card-payment information. onemillion does not store raw card numbers. The service stores payment and fulfillment references needed to verify purchases and prevent duplicate credits, including Stripe Checkout Session identifiers, payment-intent references where available, purchased pack, amount, currency, payment status, rolls granted, and processed webhook event identifiers.

5. Technical and security information

Hosting, authentication, payment, and security systems may process ordinary technical information associated with web requests, such as IP address, browser or device information, timestamps, requested pages, and security or diagnostic events. This information is used to deliver the service, prevent abuse, investigate failures, and protect accounts and payment flows.

6. Cookies and browser storage

Supabase authentication and the anonymous first-roll flow use cookies or browser storage necessary for authentication, session continuity, security, and game state. Stripe may use its own cookies or similar technologies when providing checkout and fraud-prevention services.

7. Public roll pages

A roll may have a public result URL that displays the generated number and its non-private analysis. Public result pages do not expose your account email address, paid-roll balance, or private account history. Because these links are public, anyone who receives a public result URL may be able to view that result.

8. How information is used

Information is used to authenticate users, generate and save rolls, maintain collections and statistics, enforce free and paid roll entitlements, process and verify purchases, prevent duplicate fulfillment, secure the service, diagnose errors, enforce usage limits, and operate the features you request.

9. Service providers

onemillion currently relies on Supabase for authentication and database infrastructure, Stripe for payment processing, and Vercel for application hosting and delivery. These providers process information as necessary to provide their respective services and under their own applicable privacy terms.

10. Sale of personal information

onemillion does not sell personal information or sell game results, account data, or payment information to advertisers.

11. Retention and account deletion

Account-linked information is retained while needed to operate the account, maintain the service, meet legitimate security and payment-record requirements, or comply with applicable law. You can delete your account from the Account page. Account deletion removes the authentication account and private account-linked profile, collection, and user-statistics records according to the database relationships. Certain non-identifying records, such as previously generated public roll results, payment accounting records, security records, and aggregate statistics, may remain after the account identifier has been removed or detached where necessary for service integrity, fraud prevention, accounting, or legal obligations.

12. Security

onemillion uses reasonable technical safeguards including server-side entitlement enforcement, access controls, row-level database security, secure payment verification, HTTPS, and restricted server credentials. No internet service can guarantee absolute security.

13. Your choices

You can update available account profile information, sign out, control whether you publicly share a result link, and delete your account through the controls provided by the service.

14. Changes to this Policy

This Privacy Policy may be updated when the service or its data practices change. The effective date at the top of this page will be updated when material changes are made.