Privacy & data notice
Invite-only pilot disclosure. This describes what Crushid does today, not a complete public privacy program or a statement of legal compliance.
Notice version: stage-a.v1 · Effective 2026-09-06
What Crushid is
Crushid is an invitation-only product for invited poker players. You bring your own poker evidence and see what Crushid can learn from it. Public registration is not enabled, and you can access only data that belongs to your own Account.
What Crushid stores
When you use Crushid, it stores the poker files and information you supply, the records created while it inspects, processes, and analyzes them, and the analysis derived from them. These are kept in four distinct roles:
- Database (Product Core) — the authority. Crushid's database owns your Account, your Uploads and their processing status, ownership and access, lineage, and deletion state. It is the source of truth for what exists and who may see it.
- Source files in object storage. The poker files you upload may be retained as stored objects behind account-bound authorization. They are not served from public URLs.
- Immutable Reports in object storage. A finished Report is kept as an immutable file and is shown to you through short-lived, access-controlled links, not a permanent public address.
- Derived retained analysis. Structured records derived from your Uploads (for example your history and results over your own Account) may be retained in the database so features can read them without re-deriving a Report.
Why Crushid stores it
During this invite-only pilot, Crushid uses your data to process your Uploads, produce and retain your Reports, and show your History. The same account-scoped data supports Crushid's Results, Explore, Progress, and Coach features, which operate only over your own Account's retained data. Some of these features are still expanding; where information is not available, Crushid shows it as unavailable rather than inventing a result.
Your data stays inside your own Account
You can access and query only data belonging to your own Account. Crushid does not give any customer access to another user's data, a shared or cross-account pool, population-level analysis, or multi-account / opponent-database queries. Access to a stored file or Report is re-checked against your Account on the server; a direct link or identifier cannot bypass that check.
AI and service providers
Crushid's current production Upload-to-Report pipeline does not send your poker data to an external AI analysis provider. The software includes an optional, not-yet-activated integration point for future AI-assisted explanation. That integration only operates when an operator supplies several separate settings — a specific runtime image, an explicit provider and model policy, and provider credentials — none of which is present in Crushid's deployed configuration today. If that changes, this notice will be updated before it takes effect.
Infrastructure and authentication providers may process the limited information required to run Crushid's storage and sign-in. The final list of providers will be named here before this notice is used as the pilot acceptance notice.
Retention and deletion
You can request deletion of an Upload. When you do, Crushid records the deletion in its database and removes that Upload's stored source and Report objects, verifying each object is gone before marking the deletion complete.
Account-level deletion is not currently available, and some audit and operational records may be retained after an Upload is deleted so Crushid's history and accounting stay consistent. Crushid does not promise a fixed retention period for stored data during this pilot.
Pilot status and pending items
Because this is an invite-only pilot, the following are still to be finalized and are not yet claimed here: the operating entity and jurisdiction, the lawful basis and any user-rights program, and the final infrastructure and authentication provider list. Crushid makes no guarantee of legal sufficiency in this notice.
Contact
For invitation or sign-in help, use the support route. Do not send credentials, session cookies, or private evidence in a support request.