Legal
Privacy Policy
Last updated: 21 April 2026
Who's the data controller
Diary of a Pro Gambler is the controller of personal data you give us. We're a UK-based service. You can reach us at privacy@diaryofaprogambler.com.
What we collect
Account
- Email address
- Username and optional display name
- Password, stored only as a bcrypt hash (we never see it in clear text)
- ISO country code (you pick this at registration)
- Optional avatar, banner, and bio
- Role (member / moderator / admin)
- Email-verification status and timestamps for creation and last update
Billing
- Stripe customer ID and subscription metadata (tier, status, billing period, price id)
- A local mirror of Stripe invoices (invoice number, amount, currency, status, PDF url)
- Your actual card details are held by Stripe, not by us. We receive only the parts necessary to show billing history.
Activity on the site
- Chat messages, reactions, and comments you post
- Bets you track in the personal bet tracker
- Activity-feed events derived from the above (e.g. "you placed a bet")
- Reports you file and moderation actions taken against you
Communications
- Per-channel notification preferences (email, push, Telegram)
- Browser push-subscription endpoints if you opt into web push
- Telegram chat id if you link a Telegram account
Technical
- Session cookie (
dopg_session), associated IP address, and user-agent at session creation - Server logs containing request paths, status codes, and timestamps
- Small localStorage items for UI preferences (saved audio volume, whether you've dismissed the install prompt). Those never leave your device.
How we use it
We use your data to:
- Run your account and authenticate you
- Process subscriptions, show billing history, and send transactional email
- Deliver chat, tips, live audio, and notifications
- Moderate the community and investigate abuse
- Keep the service secure, e.g. rate-limit abuse, block banned users from reconnecting
- Understand aggregate platform health (members, subscription counts) — we do not run third-party analytics or ad-tracking today
Legal bases (UK GDPR)
- Contract — account creation, authentication, subscription fulfilment, delivery of purchased content.
- Legitimate interests — moderation, security, fraud prevention, operating and improving the service. Aggregate analytics on our own server logs.
- Consent — email verification, push notifications, Telegram linking, marketing email (if we ever send any). You can withdraw consent any time in notification preferences.
- Legal obligation — retaining records where law requires (e.g. invoicing records).
Who we share data with
We use these third-party processors to deliver the service. Each processes the minimum data they need; none receives your password.
- Stripe (US, GDPR-adequate via EU SCCs) — payments and subscriptions. Receives email, name, country, and payment details.
- Brevo (EU) — transactional email delivery. Receives email address and message content.
- LiveKit Cloud (US) — UFC live-audio streaming. Receives a short-lived access token containing your user id and display name.
- Telegram — for users who opt into Telegram DM notifications or join a paid broadcast channel. Receives the message we ask Telegram to deliver and your Telegram chat id.
- Web-push providers(your browser's push service — e.g. Google or Mozilla) — if you enable push notifications. Receives the notification payload.
- Giphy — if you use the GIF picker in chat. Your search terms are sent to Giphy.
International transfers
Some of the processors above are based outside the UK/EU (Stripe, LiveKit Cloud). Those transfers rely on the UK Addendum to the EU Standard Contractual Clauses (or equivalent). You can ask us for a copy of the relevant agreement.
How long we keep it
- Account data: until you ask us to delete your account. Once deleted, backups roll off within 30 days.
- Chat messages and uploaded media: chat images / videos are retained for 90 days. Text messages stay while the room exists or until you delete your account.
- Invoice records: 7 years, to satisfy UK statutory bookkeeping requirements.
- Moderation audit log: 2 years after the relevant action, to handle later appeals.
- Server logs: 30 days.
Your rights
Under UK GDPR you have the right to:
- Ask for a copy of the data we hold about you
- Ask us to correct inaccuracies
- Ask us to delete your account and data ("right to erasure")
- Ask for a machine-readable export of your data ("portability")
- Object to or restrict processing based on legitimate interests
- Withdraw consent you previously gave
Email privacy@diaryofaprogambler.com to exercise any of these. We aim to respond within 30 days.
Complaints
If you think we've mishandled your data, please let us know first. You also have the right to complain to the Information Commissioner's Office, the UK data-protection regulator, at ico.org.uk.
Children
The service is 18+ — we don't knowingly collect data from anyone under 18. If you believe a child has registered, contact us and we'll remove the account.
Changes to this policy
We may update this policy. Material changes are communicated by email or in-app notice. The "last updated" date at the top of the page always reflects the current version.