Privacy
Pascali collects as little as it can. This page lists exactly what that is. There are no advertising trackers, no analytics scripts, and we do not sell or share personal data for marketing.
1. What we collect
As a guest (everyone, from the first visit):
- A random session token, kept in one secure, HTTP-only cookie, so your play account follows you between page loads.
- Your play records: wagers, outcomes, payouts, and the cryptographic material of each round (seeds and commitments).
- A keyed hash of your IP address, used only to enforce rate limits. The application never stores your raw IP address.
- The two-letter country Cloudflare places your connection in, which arrives with every request. It is read only when deciding whether this deployment may take a wager, or open a bitcoin deposit, from there, and no record of yours carries it.
If you add an email address (optional):
- The address itself, lowercased, tied to your account so you can resume it.
- Short-lived codes: a random code that expires in ten minutes and is deleted afterwards — one to sign you in, and one to confirm a withdrawal before it is sent. There are no passwords.
If you use the bitcoin wallet:
- The deposit addresses we create for you, and the destination addresses you give us.
- The transaction ids, amounts, and timestamps of your deposits and withdrawals, kept as the books of record for the wallet.
If you open a support case:
- What you write to us and what we write back, kept as the thread itself so both sides are reading the same conversation.
- When each message was sent, and whether the case is waiting on us, waiting on you, or resolved.
Our application logs are structured and deliberately exclude email addresses, IP addresses, codes, and session tokens.
2. Why
To run the games and keep your balance correct, to prevent abuse, to refuse a wager or a bitcoin deposit from somewhere this deployment may not serve, to let you keep and resume an account, to send you a login code when you ask for one and a confirmation code before a withdrawal is sent, and to answer support requests. That is the whole list.
3. Who processes it
- Cloudflare fronts the site (DNS, TLS, protection) and routes mail sent to [email protected]. It sees your IP address and approximate location to do that.
- Amazon Web Services hosts the application and the database, in Japan.
- Resend delivers our email: the code that signs you in, and the code that confirms a withdrawal. It sees the address we send to and, for a withdrawal, the amount and the destination address in that message.
- Our bitcoin custody provider holds the wallet keys with us and sees wallet addresses, transactions, and balances.
- Discord carries the alert that tells us a support case is waiting. It sees that reference and a link to it, and never a word of what you wrote — we open the case in our own admin and read it there. Where this deployment refuses wagers or deposits by location, it also carries an alert, at most once a day for each country, that a request from there was refused: it names the country, or that none arrived, and nothing about whose request it was.
When wallet notifications are enabled, Discord receives the counts and total amounts of deposits detected and withdrawals observed on the network or refunded. A daily summary also includes deposit credits, confirmed withdrawals, wallet fees, completed game counts, wagers, payouts, and the number of accounts that played, including guests. These messages carry no account identifiers, wallet addresses, transaction ids, or provider messages.
Each acts on our instructions. Infrastructure providers may keep their own operational logs, which can include IP addresses, under their own policies.
4. What is kept on your device
One cookie for your play session, one recording that this browser confirmed you are 18 or older, plus the security cookies Cloudflare sets to protect the site. The age cookie holds no age and no date of birth — only that the confirmation was given here. No tracking or advertising cookies. Signing out from the Account panel ends that session here and on our side, so a copy of the cookie taken beforehand stops working; your account, its balance and its rounds are untouched, and signing back in returns you to them.
Seven things are also kept in your browser’s own storage. Four of them exist so you can check us, and none of those four is ever sent to us on its own. Two others exist so a round or a withdrawal interrupted part-way through can be picked up again — the round only until the tab closes, the withdrawal until we have told you how it ended. The last tells your other tabs to check which account is signed in after you sign in or out.
- A marker for a round in progress, so a round interrupted by a reload can be recovered instead of lost. It goes when the tab closes. It holds that round’s client seed, which the round itself sends to us when it reveals and which the fairness page then publishes; recovery uses the account and round references to check or retry the original request. The account’s support reference also lets us refuse a retry from another signed-in account.
- The fairness commitments this site has shown you, with the date you first saw each one, so the public audit can be checked against something your own browser saw earlier rather than against what we say today. That record is about us, not about you: it holds no account, balance, or round of yours.
- The seed of any round you revealed, written down before it is sent and kept until we tell you how the round ended. A round we settle publishes its seed anyway, so that record is discarded. A round we refund keeps it, because the public record of a refund carries no seed and yours is then the only way to recompute what the round would have paid. At most 64 are kept, each holding the seed, the epoch, the round number, when it was sent, and — once we have told you — how and when the round ended. This one is about your rounds, and you can clear it from the fairness page.
- Any settled round this browser has not recomputed cleanly, so our refusal to take your next wager survives a reload and reaches your other tabs. Every settled round is written here the moment it settles, marked as still being checked, and removed again when it checks out — which is a fraction of a second later, so in ordinary play there is nothing here to find. What stays is a round whose check disagreed, could not finish, or was interrupted by a reload or a crash while it ran. That last one is an ordinary round left behind by an ordinary accident, and the way out of it is the same: recheck it, and it goes. Each record holds what re-running the check needs: the round’s wager, what it paid, its seeds, its receipt and its result. It does not hold your balance. It does hold the entropy you set, if you set any, together with the random value it was folded with — the check cannot be repeated without both. At most 16 are kept.
- The entropy you can set on the fairness page, folded into the seeds this browser mints. We never receive it. The random value it is folded with reaches us only if you send it, in the evidence a failed check offers to copy for support.
- A reference to a withdrawal you authorized, written before the withdrawal is sent so that a reload, a crash or a closed tab cannot leave you unsure whether it went. It holds one identifier we issued for that withdrawal, stored under your account’s support reference; it holds no amount, no address, and no code. We receive it back when the wallet page asks us how that withdrawal ended, and it is removed as soon as we have told you how it ended.
- A sign-in change signal, a random marker updated when you sign in or out. Your other tabs use it to recheck the signed-in account. It contains no account identifier, amount, address, or code, and is not sent to us.
Clearing your browser data removes all seven, which costs you a round in progress, both kinds of evidence, that setting, and the reference that lets a withdrawal you already authorized be picked up again — and lifts the refusal a failed check is holding, on a round that was never answered.
When a check fails, the alert offers to copy that round’s evidence for our support. What that copies is not the whole record: it carries the round, the browser’s verdict, and the random value your entropy was folded with, and it leaves your entropy out. You hold it, it may be a secret, and we do not need it — the two of us recompute the same fold from your half and the half you send.
5. How long we keep it
- A guest session lasts 30 days from the moment it is issued, and is renewed only so that a round already in progress can finish. A guest account holds no money — bitcoin needs an email-linked account — so nothing of value ends with it. When the session ends, the browser starts a new guest account and cannot get back to the old one. What is deleted is the way back in; the rounds that account played stay in the fairness record, which is pseudonymous and is not deleted.
- An email-linked account is the durable one. Its session renews while you keep using it, and signing in from any browser finds the same account and the same balance. It keeps its records until it is closed. This is also why bitcoin can only be held by an email-linked account — real money behind a credential that expires would be money nobody can recover.
- Login and withdrawal codes expire ten minutes after they are issued. Expired records are deleted by periodic cleanup.
- Rate-limit counters expire when their time window ends and are deleted by periodic cleanup.
- Round records are kept for the fairness audit. The fairness page shows each round’s transcript, seeds, and outcome, but never an account, email, IP address, or balance.
- Support conversations are kept, and are not deleted. A thread is the evidence if a round or a payment is ever disputed, so no message can be edited or removed once it is sent — not by you, and not by us.
6. Your choices
- Play as a guest and never give us an email address.
- Ask us to close your account or remove your email address:open a support case, which reaches us from inside your account and needs no reference number, or write to [email protected] with the support reference from the Account panel. The address is removed. What stays is your play records, as pseudonymous fairness evidence, and any support threads you opened — neither of which we can erase. An account holding a bitcoin balance is not closed until that balance has been withdrawn — we will not take a closure request as permission to keep it.
7. Changes and contact
We will update the effective date above when this page changes. Questions: [email protected]. See also the terms of use.