SettleAI Privacy Policy
Effective date: September 9, 2026
SettleAI LLC ("SettleAI," "we," "us," or "our") provides accounting and communication tools for poker club owners, agents, and players.
This Privacy Policy explains how we handle information through our desktop application, website, mobile web application, player portals, bots, and related services (the "Service").
1. Information we collect
Information you provide or authorize others to provide
- Account and sign-in information, including email address, user identifiers, and authentication events.
- Profile information made available by a sign-in provider when you choose that sign-in method, such as your name, email address, profile image, and provider identifier.
- Club, player, alias, deal, tax-rate, tipback, settlement, tab, tab-history, and report information entered, imported, or collected at an authorized user's direction.
- Files uploaded or generated, including ClubGG spreadsheets, deals files, accounting reports, and payment screenshots.
- Connected-message contents, commands, attachment metadata, account identifiers and names, and server, channel, or group information, subject to section 5.
- Player-portal verification information and payment-receiving details, including provider name, receiving-account name, username or handle, email address or phone number, notes, and preferred receiving method.
- Subscription and billing information, including customer, subscription, invoice, payment and authorization identifiers, email, billing address or postal code, payment status, and related transaction records.
- Billing measurement records, including weekly unique active player counts, the player identifiers and activity used to distinguish active players, the weeks measured, report requests and calculation timestamps, billing-cycle averages, and records relevant to suspected billing manipulation.
- Support communications and product feedback, including feedback text, sentiment, app type and version, screen identifier, and the submitting user's email address or user ID.
- Records of Terms acceptance, privacy-notice acknowledgement, platform-specific consent, withdrawal, and verified privacy requests, including relevant versions and timestamps.
Firebase Authentication handles password authentication; SettleAI does not receive your plaintext password.
Payment credentials entered into a payment provider's checkout are handled by that provider; SettleAI receives information needed to manage billing rather than your full card number or security code.
Providing a receiving handle does not authorize SettleAI to access that payment account or verify its balance.
Do not put bank account numbers, routing numbers, passwords, or access credentials into receiving-method notes or feedback.
Payment screenshots and free-text submissions can contain additional personal or financial information; include only what is needed and redact unrelated details before uploading.
Information collected through the desktop collector
With the applicable device permissions, SettleAI navigates the visible ClubGG application and captures information needed to index clubs and players and collect requested statistics.
On macOS, this uses Screen Recording and Accessibility permissions.
Collected information may include ClubGG usernames, player IDs, club IDs and names, profile images, member relationships, hands played, rake or tips, and profit-and-loss values.
When you use Create Report, SettleAI also calculates weekly unique active player counts for subscription pricing independently of the players, clubs, or date filters selected for the requested report, within the information you are authorized to access.
This billing measurement may therefore process player activity beyond the selected report scope.
If no unique active player count has been calculated for the current calendar month, the first seven days of that month have passed, and you request data more than seven days old, SettleAI first calculates the count for the most recently completed Monday–Sunday period and then creates your requested historical report.
This additional calculation does not run under this fallback rule during the first seven days of the month or when a count has already been calculated for that month.
The Terms of Service explain how calculated weekly counts determine the next monthly subscription price.
Collector screenshots are processed locally as temporary files, and normal collection cleanup removes them.
An interrupted process, device failure, or diagnostic workflow may leave temporary files or diagnostic records on the device until removed.
Diagnostic records can include player identifiers, visible text, collection results, errors, and timestamps.
Cropped player profile images may be uploaded to Firebase Cloud Storage for display in SettleAI.
The collector also uses camera permission to check that a person remains present at the screen during collection.
Camera frames are processed locally in memory to detect presence, not to identify or recognize who the person is.
This check does not record video, upload camera frames, or use microphone audio.
Presence status is used locally to pause or resume collection; denying or revoking the required camera permission prevents the presence-dependent collector from running.
Technical information and browser storage
SettleAI and its service providers process IP addresses, device and browser information, authentication events, service and diagnostic logs, timestamps, and identifiers used to operate, secure, and troubleshoot the Service.
Connected desktop-device identifiers, availability, and collection-job status may be stored to support authorized remote collection requests.
Cookies, browser storage, and similar technologies support sign-in, sessions, preferences, local caches, security, and checkout.
Clearing or blocking essential storage can sign you out, remove local information, or prevent features from working.
We do not use the Service to track you across unrelated websites for behavioral advertising.
We do not change these practices in response to a browser Do Not Track signal.
Third-party services you use through the Service, including sign-in and payment providers, may collect information about your interactions with their services across websites under their own policies, including for authentication, security, and fraud prevention.
2. Where information is stored and who controls it
SettleAI stores account-linked club configuration, deals, aliases, dashboard information, player tabs and tab history in Firebase for cloud features and synchronization.
The application also keeps local preferences, caches, and certain files or records on your device.
Some older versions or records may remain local until migrated, and not every local file or setting synchronizes.
Keep independent backups of important records.
Firebase and Google Cloud also store account information, generated reports and History metadata, connected-conversation records and messages, portal and verification records, receiving-method details, payment reviews and screenshots, messaging settings, profile images, and billing or consent records.
External providers retain information they receive as described below and under their own applicable terms and policies.
SettleAI determines how account administration, security, billing, and support information is used.
Club owners and agents determine which player and accounting information they submit and the accounting purposes for which it is used.
Where we process that information on their behalf, we act on their instructions subject to applicable law and agreements.
Players may therefore have records in SettleAI even if they have not created a SettleAI account or accepted a messaging notice.
A messaging choice does not itself authorize every separate use of accounting information.
3. How we use information
We use information to:
- authenticate users, verify portal access, and provide the Service;
- collect authorized ClubGG information and calculate requested accounting results;
- generate, store, download, and deliver reports, maintain player tabs, and synchronize supported records;
- display receiving-method details to authorized participants and support accounting communications;
- process payment screenshots and extract possible payment amounts using Google Cloud Vision;
- operate subscriptions, reconcile billing status, and send verification, billing, security, and service emails;
- calculate weekly unique active player counts and billing-cycle averages, determine subscription prices, administer the 30-day money-back guarantee, and investigate deliberate attempts to dilute or evade billing measurements;
- evaluate identifiable product feedback, provide support, troubleshoot errors, and improve the Service;
- enforce access controls and collector presence checks, prevent misuse, and maintain legal and consent records; and
- comply with law, resolve disputes, and enforce agreements.
Payment-screenshot OCR identifies a possible amount from an image.
It does not authenticate the image, verify a bank transfer, or reliably establish the payer, recipient, currency, or legal effect of a payment.
Automatic approval, when enabled by the agent, can update accounting tabs without a separate manual review.
The agent remains responsible for reviewing and correcting results.
Where EU or UK data-protection law applies and we act as a controller, our processing bases depend on the purpose: performing our contract with the account holder; legitimate interests in providing requested communications, securing the Service, resolving disputes, and improving reliability; compliance with legal obligations; and consent where required, including the platform-specific messaging choices described below.
Where we rely on legitimate interests, those interests must be balanced against individuals' rights.
Where we act as a processor, the responsible club owner or agent determines the applicable basis and must provide required notices.
Information required for account verification, billing, or a requested feature must be provided for that feature to work; optional feedback is voluntary.
4. Service providers and other recipients
- Google Firebase and Google Cloud provide authentication, databases, file storage, backend processing, and operational infrastructure.
- Google Cloud Vision receives submitted payment images to perform OCR; collector screenshot OCR and camera presence processing described in section 1 occur locally.
- Vercel hosts the website and processes requests and associated technical information needed to serve and secure it.
- Stripe processes subscription checkout and billing information and returns customer, invoice, subscription, and payment-status information to SettleAI.
- Where PayPal is offered and selected, PayPal processes payment authorization and payment information, and SettleAI retains the associated identifiers and status needed to administer billing.
- Resend receives recipient email addresses and email contents to deliver verification, billing, security, and other service messages.
- Feedback Pulse receives submitted feedback, sentiment, app and screen metadata, and the submitting user's email address or user ID; feedback sent through this feature is not anonymous.
- Telegram and Discord receive information transmitted through connected conversations, including messages or reports you direct us to send.
- Sign-in providers receive the information necessary to complete your chosen sign-in flow and supply the account information you authorize.
An authorized club owner or agent may view player accounting records, submitted payment screenshots and reviews, and receiving-method details used in their workflow.
Players and other recipients can receive reports, balances, payment instructions, and messages directed to them.
Information delivered to a group or channel may be visible to its participants under that platform's permissions.
Storing a Zelle, Venmo, Cash App, PayPal, Apple Cash, or other receiving identifier does not, by itself, transmit it to that named provider or establish a direct integration with it.
We may also disclose information when required by law or valid legal process; to protect rights, safety, security, users, or the Service; in a merger, financing, acquisition, reorganization, bankruptcy, or sale of assets subject to applicable law; or with your consent or direction.
Provider-specific restrictions on disclosure continue to apply to data obtained through that provider.
We do not sell personal information for money or other valuable consideration, or share it for cross-context behavioral advertising.
If these practices change, we will provide updated notices and legally required choices before doing so.
5. Telegram, Discord, and player portals
A connected player receives a private portal and a platform-specific data notice.
Provider events and setup commands may be received and processed to establish a connection, enforce permissions, and provide privacy controls before messaging is enabled.
SettleAI does not store ordinary connected-message content in the accounting inbox until the email-verified player affirmatively accepts the applicable notice.
Current connected-messaging setup also requires at least one receiving method in the portal.
After setup, message contents, account identifiers and names, channel or group information, attachment metadata, and outgoing-message records may be stored for the accounting conversation.
Do not add unrelated participants; one person's acceptance does not provide consent on behalf of everyone in a group.
Telegram and Discord image attachments are not processed as payments.
Payment screenshots must be uploaded through the private portal and are processed separately using Google Cloud Vision.
The verified portal provides platform-specific consent withdrawal, export, correction-request, and connection-deletion controls.
Withdrawal stops further ordinary-message storage and accounting replies through that connection but does not itself erase existing records.
Setup, security, and privacy-control requests may still be processed as needed to honor your choices.
After fresh verification, connection deletion removes SettleAI's stored message copies for that connection.
Telegram deletion does not delete the independently operated group; Discord deletion removes the dedicated channel when Discord permits it.
Separate accounting records and direct portal-payment submissions are not automatically deleted with messaging data.
Contact us for requests that extend beyond the portal controls.
6. Retention, deletion, reset, and cancellation
Retention depends on the type of information, whether it remains needed for the requested feature, user deletion instructions, security and dispute needs, applicable provider requirements, and legally required recordkeeping.
- Local caches, downloaded reports, temporary files, and diagnostics may remain on a device until removed through applicable controls or by clearing the relevant application data.
- Cloud accounting records, reports, portal records, receiving methods, screenshots, reviews, and profile images remain while needed for the account or requested workflow, unless deleted through applicable controls or a verified request, subject to lawful exceptions.
- Billing, measurement, refund, and transaction records may be retained to administer subscriptions, explain calculated charges, reconcile payments, investigate billing manipulation, address disputes, and meet tax or other legal obligations.
- Consent and privacy-request records may be retained to document the applicable choice, enforce it, and demonstrate compliance.
- Security and diagnostic records are retained according to their operational, investigation, and legal needs; provider backups and logs follow the applicable provider's retention arrangements.
- Discord API data is deleted when no longer needed for the permitted functionality, when requested by the applicable user or Discord, or when the application stops operating, except where retention is required by law.
A factory reset removes the workspace information covered by that control but retains the Firebase Authentication login account and billing subscription information.
It does not cancel a subscription or erase billing-provider records, previously delivered messages or files, external feedback submissions, or every security and compliance record.
Resetting tabs, deleting a messaging connection, deleting an account, and canceling a subscription are separate actions.
Use Account & Billing for available subscription controls, and contact support@settleaiapp.com for account deletion or requests not covered by an in-product control.
Deletion requests may require identity and authority verification.
If SettleAI determines that you deliberately attempted to dilute or manipulate unique active player counts to reduce subscription charges, your account will be banned and access through the Service to historical reports and other historical data will immediately end, as described in the Terms of Service.
Loss of product access does not mean immediate deletion of the underlying records; the retention criteria above continue to apply.
It does not remove privacy rights that applicable law gives you, and you may still submit a verified privacy request to support@settleaiapp.com.
Where information is retained despite a request, we will explain the applicable reason as required by law.
Backup copies may persist until the applicable backup cycle expires and remain subject to access restrictions.
Recipients may retain their own copies of reports and communications under their obligations; we cannot erase independent copies outside our control.
7. Security
We use administrative, technical, and organizational safeguards designed to protect information, including authentication, Firebase access rules, and backend authorization checks.
Access depends on the feature and can include the account owner, an authorized player portal, backend services, and personnel or providers supporting the Service.
Server-side provider secrets are kept outside the distributed desktop application.
No method of storage or transmission is completely secure.
Protect your account, device, portal access, connected conversations, and downloaded reports, and report suspected unauthorized access promptly.
8. Privacy choices and rights
Depending on applicable law, you may request access, correction, deletion, or a portable copy of your information; object to or restrict processing; withdraw consent for consent-based processing; or appeal a decision on a request.
Withdrawal does not invalidate processing that lawfully occurred before withdrawal.
You may have a right not to receive discriminatory treatment for exercising your rights.
Send requests and appeals to support@settleaiapp.com, describe the information or decision involved, and identify the relevant account or connected platform.
Authorized agents may submit requests where permitted, subject to verification.
We respond within the time required by applicable law and explain any permitted extension or refusal.
Where an agent or club controls the relevant records, we may coordinate the request with them or explain how to contact the responsible party.
You may complain to your applicable data-protection authority, including the UK Information Commissioner's Office or the relevant EU supervisory authority where those laws apply.
California residents may have rights to know, correct, and delete personal information and opt out of sale or sharing where the applicable California law covers the processing.
The information categories, purposes, sources, recipients, and retention criteria are described above.
We do not currently sell personal information or share it for cross-context behavioral advertising, so we do not offer a sale/sharing opt-out link.
9. International processing
SettleAI is based in Connecticut, United States.
We and our providers may process information in the United States and other countries where they operate, whose protections may differ from those where you live.
Where transfer safeguards are required, the applicable arrangement may include an adequacy determination or contractual safeguards, such as standard contractual clauses and a UK addendum where applicable.
Contact support@settleaiapp.com for information about the safeguards applicable to a particular transfer and how to obtain a copy, subject to necessary redactions.
10. Children
The Service is intended for people who are at least 18 years old and legally permitted to use it.
Do not submit children's information to the Service.
If you believe a child has provided information, contact us so we can investigate and take appropriate action.
11. Third-party services
ClubGG, Google services, Vercel, Stripe, PayPal, Resend, Feedback Pulse, Telegram, Discord, and other services you choose have their own applicable terms and privacy practices.
Their availability and permissions may change.
SettleAI does not claim affiliation, endorsement, or permission to use another provider contrary to its rules.
A receiving-method label does not mean that provider approves a particular payment or accounting activity.
12. Changes to this Policy
We revise the effective date when this Policy changes.
For material changes, we will provide a prominent in-product or website notice or contact affected users by email, as appropriate and required by law.
Where a new use requires consent, we will request it before that use; continued use alone does not substitute for required consent.
13. Contact us
Legal entity: SettleAI LLC
Founders: Akshay Shivdasani and Dougie Brown
Privacy and support email: support@settleaiapp.com
Mailing address: 33 Stonehenge Drive, New Canaan, CT 06840, United States