1. Introduction
GroundRules (“we,” “our,” or “us”) respects your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application (the “App”). Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the application.
2. Information We Collect
We collect information that you provide directly to us:
- Account Information: Username, email address, password (encrypted), date of birth, country
- Profile Information: Profile photo, display name, bio
- KYC Verification: Full name, address, phone number, government ID photos, selfie, SSN last 4 digits (for tax compliance at $600+ earnings)
- Phone Number: For two-factor authentication (optional)
- Financial Information: Wallet balance, transaction history, challenge stakes, winnings, fees
- User-Generated Content: Challenges you create, votes you cast, chat messages, proof photos/videos
- Device Information: Device type, operating system, unique device identifiers, FCM push notification tokens, IP address
- Usage Data: App interactions, challenge participation, voting patterns
- Location Data: US state verification (required for legal compliance — app is restricted to legal US states only)
3. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the App
- Process transactions and send related information
- Verify your identity (KYC) and screen against OFAC sanctions lists
- Send you technical notices, updates, security alerts, and support messages
- Respond to your comments, questions, and customer service requests
- Monitor and analyze trends, usage, and activities in connection with the App
- Detect, prevent, and address technical issues, fraud, and suspicious activity
- Enforce our Terms of Service and prevent abuse
- Send you push notifications (with your consent)
- Generate tax documents (1099-MISC) for users earning $600+ per year
- Enforce geo-restrictions (US states only, VPN/GPS spoofing detection)
4. How We Share Your Information
We may share your information:
- With other users: Your username, profile photo, and challenge activity are visible to other users
- With service providers: Payment processors, cloud hosting (Firebase/Google), analytics providers
- For legal reasons: To comply with legal obligations, protect our rights, or respond to lawful requests
- With government agencies: OFAC sanctions screening, IRS tax reporting (1099-MISC)
- Business transfers: In connection with a merger, acquisition, or sale of assets
We do NOT sell your personal information to third parties.
5. Data Security
We use industry-standard security measures to protect your information:
- Passwords are encrypted using secure hashing
- KYC documents are encrypted before upload
- Sensitive data is stored in iOS Keychain (not UserDefaults)
- All data transmission uses HTTPS/TLS encryption
- Firebase Authentication and Firestore security rules protect your data
- Two-factor authentication available for enhanced security
- Fraud detection and risk scoring automatically flags suspicious activity
However, no method of transmission over the internet is 100% secure. We cannot guarantee absolute security.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide you services. You may request deletion of your account at any time through the app settings or by emailing support@groundrules.app.
After account deletion:
- Your profile and personal information will be permanently deleted
- Challenge history and transactions will be anonymized but retained for legal/audit purposes
- Some data may remain in backups for up to 90 days
7. Your Privacy Rights
You have the right to:
- Access your personal information
- Correct inaccurate information
- Request deletion of your account and data
- Opt out of marketing communications
- Disable push notifications
- Withdraw consent for two-factor authentication
To exercise these rights, contact us at privacy@groundrules.app or use the in-app account deletion feature.
8. Children’s Privacy
The App is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If you are under 18, do not use the App or provide any information. If we learn we have collected information from a child under 18, we will delete that information immediately.
9. International Data Transfers
Your information may be transferred to and maintained on servers located outside of your country. By using the App, you consent to the transfer of information to the United States and other countries where privacy laws may differ.
We comply with applicable data protection laws, including GDPR for European users and CCPA for California residents.
10. Third-Party Services
We use the following third-party services:
- Firebase (Google): Authentication, database, cloud functions, storage, analytics
- QuantumRand API: Provably fair random number generation for tie-breaking
- OFAC (US Treasury): Sanctions screening
- Apple Push Notification Service: Push notifications
- Google AdMob: Advertisements
- Payment processor (coming soon): Deposits and withdrawals
These services have their own privacy policies. We encourage you to review them.
11. Changes to This Privacy Policy
We may update our Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the “Last Updated” date. You are advised to review this Privacy Policy periodically for any changes.
12. Contact Us
If you have questions about this Privacy Policy, please contact us:
Email: privacy@groundrules.app
Support: support@groundrules.app
Phone: (516) 387-2140
132 W Merrick Rd
Freeport, NY 11520
United States
By using GroundRules, you acknowledge that you have read and understood this Privacy Policy.
