← Back to Meld Club

Privacy Policy

Last updated: September 6, 2026

1. Introduction

Meld Club (“Meld Club,” “we,” “us”) is a Hand & Foot Canasta game for iPhone and iPad with offline solo play and invite-only private tables, published by Goldenberg Tech Advisors LLC of Dover, Delaware, United States. This Privacy Policy explains what information the app handles and the choices you have. It applies to the Meld Club app (bundle ID com.meldClub.meldClub), its private-table service, and this website.

Meld Club is built to collect as little as possible. You do not register with a name, email address, password, or social account. Offline games and settings remain on your device. When you use a private table, the app creates a random Firebase anonymous identifier so the service can recognize your seat, enforce access, and let the same installation reconnect.

2. Information we collect

Information stored on your device

Your offline active and saved games, preferences and settings, lesson progress, and local statistics stay on your device. The app also stores its random anonymous online identifier and subscription/entitlement state. Apple handles subscription transactions, and selected product events are sent to PostHog only as described below.

Anonymous identity and display name for private tables

Private tables use Firebase Anonymous Authentication. Firebase assigns a random identifier that is not your Apple ID and does not require your email address or phone number. You choose a display name of up to 20 characters. Please choose a nickname and avoid personal information. That name is sent to our service and shown to the invited people at your table. We strip controls and links and apply automated profanity filtering. Older app versions asked for a first name; updating the app does not erase a previously saved name. You can change the remembered name in Table Settings or choose a different name before entering a new table. This does not rewrite names already used in existing tables or reports.

Private-table game data

To run a live private table fairly, our Firebase service stores the table rules and configuration, seats and teams, accepted game actions, scores, melds, card state (including each player's hidden hand and unrevealed Foot), shuffle commitments and seeds, turn deadlines, computer takeovers, rematch and series state, and a sequenced event history. Each player receives public table information and only that player's authorized private hand; other players' hidden cards and the unrevealed shuffle seed are not made readable to the client.

The service also stores invitation-code lookups in hashed form, command request identifiers used to prevent duplicate moves, protocol and rules versions, hosting-allowance timestamps, and limited operational measurements such as action type, outcome, revision, latency, retries, computer-turn duration, task delay, and cleanup counts. A server-only create receipt temporarily retains its invitation code so the same table can be recovered if the creator's response is lost. Our application logs are designed not to contain invitation codes, display names, cards, shuffle seeds, raw anonymous identifiers, or full command payloads. Google may still process ordinary network and service metadata, including IP address, under its policies.

Presence, connection status, and service integrity

While you are at a private table, the app sends a per-connection identifier and connection state so other players can see whether your seat is connected, reconnecting, or being continued by a computer. We process timestamps for joining, disconnection, deadlines, leaving, and returning. Firebase App Check also receives an app or device-integrity token and related technical request information to help distinguish genuine app traffic from automated abuse. App Check does not replace our seat and table authorization checks.

Reactions, reports, and blocks

Private tables offer only developer-authored reactions such as “Hello,” “Nice play,” and “Good game”; the selected reaction, sender seat, and time are visible to everyone at that table. There is no free-text table chat, partner-only messaging, direct messaging, voice, or video. If you report a display name or conduct, we store the sanitized display name shown at the table, hashed identifiers for the reporting and reported anonymous identities, a hashed match identifier, the selected reason, and time. Blocking stores a hashed identifier for the blocked player under your anonymous identity. These records help us investigate misuse and enforce your preference without exposing raw identifiers to other players.

Pseudonymous analytics and error diagnostics (enabled by default)

When the “Share analytics & diagnostics” setting is enabled — as it is by default — the app sends named product events to PostHog. Examples include completing the lesson, starting a game, finishing a round, viewing the membership screen, and starting or completing a purchase or restore. PostHog groups events under a randomly generated app identifier rather than your name or an account. Events may also include basic technical information supplied by the analytics software, such as app version, device type or model, operating-system version, and a session identifier. As with ordinary internet requests, PostHog receives the request's IP address, which may be recorded with events and used to derive an approximate region.

When analytics and diagnostics are enabled, version 1.2.3 and later may include your currently saved player-experience choice — new, rusty, or regular — with these events. A skipped, missing, or unavailable choice is recorded as unknown. We use this information alongside play and purchase events to understand how players with different experience levels use Meld Club and to improve the playing and membership experience. Changing your saved choice affects future event context; we do not upload a separate history of your earlier answers.

The app registers installs using Apple's SKAdNetwork attribution system, which allows Apple to send privacy-preserving advertising postbacks. This does not give us your advertising identifier. The current app does not request AdServices attribution tokens or send Apple Ads campaign results to PostHog. If you enable reminders, they are scheduled and stored entirely on your device; the app may send events about reminder permission, scheduling, and opening to PostHog while analytics is enabled.

While that setting is enabled, the app also reports technical exception diagnostics for unexpected Flutter, Dart, and isolate failures, plus selected handled purchase or restore failures. Diagnostics may include the exception type, a sanitized error code, a stack trace, whether the failure was fatal, and the app, device, operating-system, and session information described above. The app removes raw exception messages and Flutter widget diagnostics before sending these reports and disables PostHog's native crash collection. For handled StoreKit exceptions, Meld Club sends a sanitized code and does not send Apple's raw message or details.

The app's PostHog analytics and diagnostics do not send your display name, email, contacts, precise location, advertising identifier, invitation code, the contents of your cards, or a deal seed. (The private-table service necessarily processes the table data described above.) We do not create PostHog person profiles, use session replay or exception breadcrumbs, or build advertising profiles. You can turn analytics and diagnostics off at any time in Table Settings, and telemetry never blocks or affects your ability to play.

Purchases and subscriptions

Meld Club Plus is sold through Apple's in-app purchase system. Apple processes the payment and your subscription status under Apple's own privacy policy. The app and our server receive signed transaction information needed to verify, unlock, and restore Plus, and the server stores product and expiry information plus hashed transaction identifiers linked to your anonymous online identity. We never see your payment card details, Apple ID, or App Store password. When analytics and diagnostics are enabled, related events may include whether checkout or restore started or completed, the App Store product identifier, the displayed product price, and the sanitized error information described above.

When enabled, our subscription-record service receives signed subscription notifications and transaction history from Apple. We retain transaction identifiers, product and subscription dates, currency and price, and renewal or refund status to reconcile purchase records and understand subscription performance. These records can be linked to the subscription identifiers used by our entitlement service. This processing is separate from the optional analytics and diagnostics setting. We do not send these transaction records to PostHog or advertising platforms.

Support correspondence

If you email us for support, we receive the information you choose to include (such as your email address and your message) and use it only to respond.

Website hosting data

This website has no account system, forms, advertising trackers, or client-side product analytics. It is served through Firebase Hosting, which processes ordinary web-request information such as your IP address, browser or user-agent information, the requested URL, and referrer information to deliver and protect the site. If an invitation opens the browser fallback, the requested URL contains its table code; that fallback is marked no-index and uses a no-referrer policy to reduce further disclosure.

3. How we use information

  • To run offline games on your device and create, join, play, reconnect to, and expire invite-only private tables.
  • To enforce seat ownership, turn deadlines, computer takeover, fair shuffling, duplicate-command protection, hosting allowances, rate limits, and other game and security rules.
  • To show your display name, seat status, game actions, canned reactions, and system notices to the other invited players at your table.
  • To honor blocks, review reports, and prevent or respond to abuse.
  • To unlock and maintain Meld Club Plus features after a purchase or restore, reconcile subscription payments and refunds, and understand subscription performance.
  • To understand in aggregate how the app is used and where to improve it (only when analytics is enabled).
  • To diagnose crashes and technical failures (only when analytics and diagnostics are enabled).
  • To deliver, secure, and maintain this website.
  • To respond to your support requests.

We do not sell your personal information, and we do not use it for third-party advertising.

4. How we share information & third parties

We share information only with the service providers needed to operate the app and website:

  • Other invited table members — receive your display name, seat and team, connection/controller status, public game actions, scores, canned reactions, and system events. They do not receive your raw anonymous identifier or authorized hidden hand through the service.
  • Apple — provides the App Store, processes subscriptions, returns signed transaction information, and may provide the device-integrity services used by App Check. See Apple's Privacy Policy.
  • PostHog — our analytics and error-diagnostics processor, which receives the pseudonymous events and technical information described above only while analytics and diagnostics are enabled. Meld Club is configured to use PostHog Cloud in the United States. See PostHog's Privacy Policy.
  • Google Firebase and Google Cloud — provide anonymous authentication, callable and background functions, the realtime database, presence, app-integrity checks, task scheduling, operational logging, and website hosting, and process the private-table and technical information described above. See Google's Privacy and Security in Firebase.

We may also disclose information if required by law, or to protect our rights, safety, or the integrity of the service.

5. Data retention

Device-stored data remains until you delete the app. Private-table records follow these service windows:

  • An unused, inactive lobby and its invitation lookup expire after 30 minutes.
  • An active, between-round, or suspended game without accepted activity is available for recovery for 24 hours.
  • A completed or abandoned game and its redacted event history are retained for seven days.
  • Create and join idempotency receipts expire after 24 hours. A scheduled cleanup physically removes expired receipts, so deletion may follow after a short operational delay.
  • Per-identity action rate-limit records become obsolete after their 60-second window and are physically removed later by bounded scheduled cleanup.

The API rejects access as soon as a table expires. A scheduled cleanup then physically deletes expired table data, so deletion may occur after a short operational delay and a backlog may require more than one cleanup run. Presence connection records normally disappear on disconnect and otherwise are deleted with the table. When Firebase's managed anonymous-account cleanup is enabled, anonymous authentication accounts older than 30 days become eligible for deletion; returning after that can create a new random identifier, and authentication-account deletion does not itself accelerate the table-data schedule above. Hosting-allowance, entitlement, block, and safety-report records are retained as long as reasonably needed to provide the applicable feature, enforce safety and subscription rights, resolve disputes, and meet legal obligations.

For this subscription-record service, we retain a production subscription's purchase history until 730 days after its latest recorded purchase, subscription expiry, grace-period end, refund/revocation date, or original subscription notification event, whichever is later. We preserve the latest lifecycle date already recorded even if a later update reverses a refund. This keeps the complete history of an active subscription together. Sandbox subscription records follow a 30-day window after the same dates; standalone notification records, including delivery tests, expire 30 days after their signed date. Daily cleanup deletes expired records in batches, so physical deletion may follow after an operational delay or take additional runs during a backlog. Re-reading old history or receiving a newly signed copy of unchanged purchase information does not extend this window. Apple maintains its own purchase records under its policies. For a request about your purchase records, contact us using the address below; we may need information that verifies the subscription belongs to you before acting. Deleting these ledger records does not cancel your Apple subscription.

We do not currently enforce an automatic deletion deadline for pseudonymous analytics and diagnostic events in our PostHog project. These events can remain available for longer than 30 days; we do not promise deletion or aggregation after 30 days. Turning analytics off stops the app from capturing new analytics and diagnostic events. Events captured before that change may still be delivered, and turning the setting off does not delete previously collected events. You can contact us about deletion, subject to the identification limits described below. Firebase states that incoming IP addresses collected by Hosting are retained for a few months. Support emails are kept only as long as needed to resolve your request and for reasonable record-keeping.

6. Data security

Offline gameplay data is protected by your device's own safeguards. Private-table traffic is transmitted over encrypted connections (HTTPS/TLS). We use anonymous authentication, per-table membership and seat checks, separate public and per-player private projections, server-authoritative rules, app-integrity checks, rate limits, and short retention periods. No method of transmission or storage is perfectly secure, but we take reasonable measures to protect the information we handle.

7. Your rights & choices

  • Analytics and diagnostics opt-out. Turn “Share analytics & diagnostics” off at any time in Table Settings. The app stops sending new product and exception events after you turn it off.
  • Table controls. You can mute canned reactions, block another player, report a display name or conduct, and leave a table. System events remain visible because they communicate game state.
  • Deletion. Delete the app to remove its device-stored data and local anonymous credential. Cloud table data expires automatically on the schedule above; deleting the app does not accelerate an active table's scheduled deletion. Analytics events are grouped under a random app identifier, not your name or a registered account. We therefore may be unable to connect a request to an identifier after you delete the app, but you can contact us with any request.
  • Access & questions. Contact us using the details below to ask about this policy or your data.
  • Subscriptions. Manage or cancel Meld Club Plus in your Apple ID subscription settings.

A note on identification. Because Meld Club has no accounts and groups data only under random identifiers, we often cannot link a person to their data — especially after the app is deleted. Where we genuinely cannot identify you in our records, data-protection law (for example Article 11 GDPR) may limit our ability to fulfil an individual request, and we will tell you if that is the case. We will never ask you for extra personal information solely to answer a privacy request except the minimum needed to handle it.

8. Children's privacy

Meld Club is a general-audience card game and is not directed to children under 13 (or any higher minimum age your country sets for children's digital consent — up to 16 in parts of the EEA), and we do not knowingly collect personal information from children below that age. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.

9. Where the app is offered & international data transfers

Meld Club is operated from the United States and is offered through Apple's App Store in the countries where it is listed. The limited data described in this policy is processed in the United States, where we and our service providers operate: Meld Club is configured to use PostHog Cloud US, and our Firebase services run in United States regions.

If you use Meld Club from outside the United States, your information is therefore transferred to and processed in the United States, which may have different data-protection laws than your country, and information held in the United States may be accessible to courts, law enforcement, and national-security authorities there under US law. For personal data originating in the European Economic Area, the United Kingdom, or Switzerland, our processors rely on recognized transfer safeguards: Google and PostHog participate in the EU-U.S. Data Privacy Framework, its UK Extension, and the Swiss-U.S. Data Privacy Framework, and also offer Standard Contractual Clauses in their data-processing terms. Apple processes App Store and payment data under its own regional legal entities and safeguards.

10. Your rights in the EEA, United Kingdom & Switzerland

Although Meld Club is deliberately built without accounts or profiles, the pseudonymous identifiers, gameplay records, and technical data described in this policy can still be personal data under the EU and UK GDPR and Swiss law, and we treat them that way. For that data, Goldenberg Tech Advisors LLC is the data controller, and our contact details are in Section 14.

We rely on the following legal bases:

  • Performance of a contract (Art. 6(1)(b) GDPR) — running the app and private tables you ask for, and unlocking and maintaining Meld Club Plus purchases and restores.
  • Legitimate interests (Art. 6(1)(f)) — keeping the service secure and fair (seat authorization, rate limits, abuse prevention, App Check), maintaining accurate subscription records and understanding subscription performance, and understanding aggregate product usage and diagnosing failures through the pseudonymous, opt-out analytics described in Section 2. We chose the least intrusive setup we could: no accounts, no person profiles, no advertising identifiers, no cross-app tracking, a random app-scoped identifier, and an off switch in Table Settings.
  • Legal obligations (Art. 6(1)(c)) — where we must retain or disclose limited records to comply with law.

If you are in the EEA, UK, or Switzerland you have the rights to access, rectify, and erase your personal data, to restrict or object to processing (including objecting to our legitimate-interest processing), and to data portability. You can exercise the analytics objection instantly and without contacting us by turning “Share analytics & diagnostics” off in Table Settings. For anything else, email us at the address in Section 14; the identification limits described in Section 7 may apply. We do not use your data for automated decisions with legal or similarly significant effects, and we do not profile you.

You also have the right to lodge a complaint with a supervisory authority — in the EEA, the data-protection authority of your country of residence or workplace; in the UK, the Information Commissioner's Office; in Switzerland, the FDPIC. We would appreciate the chance to address your concern first, but you are not required to contact us before a supervisory authority.

11. Other countries

Residents of other jurisdictions with privacy laws (for example Canada, Brazil, Australia, or Japan) may have similar rights under their local law — typically including access, correction, and deletion. Contact us using the details in Section 14 and we will honor applicable requests. The identification limits described in Section 7 may apply.

12. US state privacy rights

Depending on where you live (for example California under the CCPA/CPRA), you may have rights to know, access, delete, or opt out of the “sale” or “sharing” of personal information. We do not sell or share your personal information as those terms are defined by these laws, and we do not use it for cross-context behavioral advertising. To exercise any applicable right, contact us below. We will not discriminate against you for exercising your rights.

13. Changes to this policy

We may update this policy from time to time as the app evolves. When we do, we will change the “Last updated” date above.

14. Contact us

Questions about this policy or your data? Email contact@meld-club.com. Privacy requests are handled by the managing member of Goldenberg Tech Advisors LLC.

Read the Supplemental Terms →