Privacy Policy
33 Pool is run by Taurus Media Network LLC. This policy covers 33pool.com, the 33 Pool mobile app, and our matchmaking and live-scoring services.
It is written from what our database actually stores. If anything here does not match what you have seen in the app, tell us and we will fix one or the other.
How you sign in
You sign in with your Kick account. We never see, handle or store a password -- there is no 33 Pool password to forget.
When you sign in with Kick, our server exchanges the one-time code for a Kick access token, asks Kick who you are, and keeps only the identifier: your Kick user ID, plus your Kick display name, email and avatar if Kick supplies them.
Two things we deliberately do not keep: your Kick access and refresh tokens, and your Kick stream key. Both are handed back to the app once and stored in your device's Keychain on iOS or Keystore-backed storage on Android. Neither is written to our database, and the stream key is never written to a log file, because anyone holding it could broadcast to your channel.
What we store about you
- Account: status, sign-in provider IDs, and created, updated and last-login times.
- Email address: your address, whether it is verified, and a verification token while one is outstanding.
- Profile: the display name you choose, avatar, bio, city or region text, timezone, country code, and if you fill them in, your first name, last name, age and sex.
- Kick channel: your Kick handle and channel ID, a coarse subscriber band used for eligibility, and when we last checked it.
- Other socials: handles you add yourself for the other places you stream or post. Self-declared, unverified, and public unless you say otherwise.
- Play record: every ranked and private match. Who played, shot by shot turns, scores, placements, your Rating before and after, disconnects, and season standings.
- Teams: membership, invitations, registrations, queue entries and team match results.
- Presence: whether you are online, and when you last connected and disconnected.
- Messages: the direct messages you send and receive, including their text, and a short copy of the newest one for your inbox list.
- Ratings: the yes or no answers you give other players after a match and the ones they give you, any comments, and whether you skipped.
- Reports and disputes: reports you file or that name you, the reason, your written details, links to the video moment cited as evidence, score disputes, and integrity marks.
- Blocks: who you have blocked.
- Casual boards: sessions you host, the games in them, who sat in each seat and what they scored.
- Stream links: links to the Kick videos of your matches, so they can be played back from match history.
- Membership: your plan, status, billing cycle, renewal and cancellation dates, and your Stripe customer and subscription identifiers.
- Redemption codes you redeem, and when.
- Settings: your in-app preferences, such as the ball style you play with.
- Registrations: which of our apps you have signed up for, when, and where the signup came from.
- Matchmaking: while you are looking for a game, your place in the queue, the ladder and table size you asked for, and when you joined and left it.
- Scorekeeping: if you keep score on, or follow, somebody else's casual board.
- Caster application, if you apply: your questionnaire answers, preferred contact day, time and timezone, and the social links you list.
- Casting, if you are approved to cast: your casting channel, the matches and players assigned to it, and your month-by-month casting status.
- Legal acceptances: which version of which document you accepted and when. On some paths, the IP address and browser user-agent at that moment.
- Why you left, if you tell us: the reason you pick and anything you type in the box when you close your account. Both optional.
- Contact form: the name, email, subject and message you send us, and our internal notes on the reply.
- API keys, if you create one: a salted hash and the last four characters. The key itself is shown once and never stored.
- Server logs: ordinary request and error logs, which can include your IP address.
What we never collect
- Passwords. Sign-in happens at Kick. We never receive one.
- Card numbers. Checkout runs on Stripe's own pages and card details never reach our servers.
- Precise location. No GPS, and no location permission is requested. Your country comes from your IP address; the city or region on your profile is text you typed.
- Advertising identifiers and tracking SDKs. The app ships no analytics, attribution or advertising libraries. We do not track you across other apps or websites, and we run no advertising.
- Your contacts, photo library, microphone or camera roll.
- Your video. When you broadcast, it goes from your device to Kick. It does not pass through or rest on our servers. We store only the link.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
Your IP address and country
Every request carries an IP address. We read yours to work out a two-letter country code, which we use for your flag, for regional pricing, and to decide where free play is available.
That lookup happens on our own server, against a country database shipped with our code. Your IP address is not sent to any geolocation service, and the country code is all we keep on your profile. Your IP itself is not stored against your account, with two exceptions: our server logs, and the legal-acceptance record described above.
What other players can see
33 Pool is a public competitive ladder, so parts of your profile are public by design:
- Your display name, avatar, country flag, Rating and ladder position on the rankings pages.
- Your match history, including results, per-match statistics and disconnects.
- Your Kick channel and any social links you marked public, so people can find you streaming.
- The aggregate of the ratings other players have given you, once enough matches have been rated.
What stays private: your email address, your real name, age and sex, your city or region text, your payment records, your direct messages, and the reports you file.
Streaming and recordings
Ranked play is streamed. If you connect your Kick channel, the app can set your stream title and read back the link to the resulting video, which we attach to the match so it can be rewatched from your match history. The broadcast itself, and the recording Kick keeps of it, lives on Kick and is governed by Kick's privacy policy and terms.
Casters and opponents can cite a moment in a recording as evidence in a report. We store the link and the timestamp, not a copy of the video.
Casual boards and guest names
A casual board is for a night of games in a room together. The host types a name for each seat, and those players may not have 33 Pool accounts. Those names are stored as typed, alongside the scores.
If you host a board, only enter names the people at the table are happy to have on screen. A board can be shared with a watch code and shown on a stream overlay. A first name or a nickname is enough. Hosts can remove a player, and anyone named on a board can ask us to remove their name.
Messages, ratings and reports
Direct messages are visible to you and the person you are talking to. They are not end-to-end encrypted, and our moderators can read a conversation when it is reported.
When moderation removes a message or voids a rating, it is hidden from both sides but the record is kept as evidence rather than deleted. The same applies to reports, disputes and integrity marks: they are a moderation record, and they outlive the match they came from.
When you report someone, we do not show them your name. When you rate someone, your individual answers feed an aggregate; we do not publish who said what.
Payments
Memberships are billed by Stripe. When you start a checkout we send Stripe only the plan and your 33 Pool user ID; you give your name, email and card details to Stripe directly. Stripe tells us whether the subscription is active and when it renews or ends, and we store that alongside your Stripe customer and subscription identifiers. We never see or store your card number.
Who else handles your data
- Kick, for sign-in, your channel, and the streams and recordings of your matches.
- Stripe, for payments and subscription billing.
- Mailjet, for sending email such as address verification. They receive your email address and the message.
- Apple and Google, for app distribution. They report crashes and aggregate install statistics to us under their own policies.
- Linode, our hosting provider, which runs the servers this service and its database sit on, in Dallas, Texas.
We also disclose data when the law requires it, to enforce our terms, or to protect players from harm.
Cookies and device storage
The website sets one cookie that matters: auth_token, which holds your signed session so you stay logged in. It expires after seven days. A short-lived session value also stops an article view being counted twice. We set no advertising or analytics cookies, so there is nothing to opt into.
In the app, your session token and your Kick tokens are held in the device Keychain or Keystore and are cleared when you sign out.
How long we keep it
- Your account and profile: while your account exists.
- Match results, ratings and season standings: kept as the competitive record of the ladder, including after an account closes, shown against the display name you used at the time.
- Moderation records, meaning reports, disputes, integrity marks, voided ratings and removed messages: two years after the matter is resolved.
- Direct messages: until deleted by you or by moderation, and 90 days after removal.
- Contact-form messages: 12 months after the matter is closed.
- The record that an account was closed: when, from which surface, what membership it had at the time, and anything you said on the way out. Two years. It outlives the account on purpose -- it is the answer to a billing question that can arrive months later.
- Billing records: seven years, as tax and accounting law requires.
- Server logs: 30 days.
Your choices and rights
You can change your display name, avatar, bio, location, timezone, Kick channel and social links yourself, from your profile. You can block another player, and you can make a social link private.
Whatever country you live in, you can ask us to:
- Show you a copy of the data we hold about you.
- Correct anything that is wrong.
- Delete your account. What that destroys and what it leaves is spelled out below, under Deleting your account.
- Export your data in a portable format.
- Stop relying on your consent, or object to a particular use.
Email aaron@33pool.com and we will answer within 30 days. We will not restrict your account or charge you for asking.
If you are in the UK or the EEA: we process your data to perform our contract with you, which is running your account and your matches; on our legitimate interests in keeping the ladder fair, preventing cheating and abuse, and securing the service; on your consent where we ask for it; and to meet our legal obligations. You can complain to your national data protection authority.
Our servers are in the United States, so playing on 33 Pool means your data is held outside your own country. Kick, Stripe and Mailjet each handle their part of it under their own policies, wherever they operate.
If you are in California: we do not sell personal information or share it for cross-context behavioural advertising, and we make no automated decisions about you beyond the match-fairness checks described above. You can use the same address to exercise your access, deletion, correction and portability rights.
Deleting your account
You can close your account yourself, from the account screen in the app or the account page on the website. What happens next depends on whether you are paying us.
If you do not have a membership, the account is deleted immediately and it cannot be undone. Everything below happens at once.
If you do have a membership, the account is switched off rather than deleted, and nothing below happens until that membership ends. You come off the ladder and out of matchmaking straight away, and every row is kept. Signing in on the app at any time before the membership ends brings the whole account back and cancels the deletion. The last paragraph of this section explains why, and what to do about the billing.
Destroyed: your email address, the link to the account you signed in with, your Kick channel and stream settings, your social links, your app settings and preferences, your block list in both directions, your direct messages -- which takes the other person's copy of the thread with them -- anything you were queued for or invited to, any caster application, the casual boards you hosted and the guest names on them, and everything on your profile except the name you played under: avatar, bio, location, first and last name, age, sex and country.
Because the sign-in link is destroyed, nobody can get back into the account. Signing in again with the same Kick account produces a brand new account with no history. That is intended, not a mistake.
Kept: your display name, the matches you played and their scores, your ladder standings and season statistics, the ratings you gave and received, and any reports, disputes or integrity marks in either direction. Your display name stays because the leaderboards and your opponents' match histories read the handle the games were played under, and a ladder full of "deleted player" is a worse record for the players still on it. The rest stays because a match is not one player's to erase: a rating you gave is part of somebody else's profile, and a report about you must not be removable by the person it is about.
We also keep which version of these documents you accepted and any codes you redeemed. Both are records of something that happened rather than facts about you.
About the membership. Closing your account does not cancel it: memberships are billed by Stripe on their own schedule, and we will not quietly stop your billing from a button marked delete. That is also the reason a paying account is switched off instead of deleted -- deleting it would destroy the only login that can stop the charge.
So: cancel the membership, and the deletion completes by itself once it ends. You can cancel from the website, or from the billing link we show you, which works without a 33 Pool login at all. If you never cancel, the account stays switched off indefinitely and we do not delete something you are still paying for.
If any of that goes wrong, email aaron@33pool.com. We keep your subscription record and a note of what you were paying for at the moment you closed the account, so we can sort it out.
Age limit
33 Pool is for players aged 16 and over, and signup will not accept a lower age. We do not knowingly collect data from children. If you believe a child has an account, write to us and we will remove it.
Security
Traffic to our website and API is encrypted with TLS. Sessions are signed tokens with a seven-day life. API keys are stored salted and hashed, never in the clear. Credentials that pass through our servers, above all your Kick stream key, are deliberately kept out of our logs and out of our database.
No service is perfectly secure. If we discover a breach affecting your data, we will tell you and the relevant regulator as the law requires.
Changes and contact
This policy is versioned, and the version and the date it was published are at the top of this page. You are not asked to accept a privacy policy -- it tells you what we do rather than asking you to agree to it -- so there is nothing to sign and nothing we record about your reading it. Material changes are announced in the app and on the website before they take effect.
Questions, requests, or anything in here that does not match what you have seen: aaron@33pool.com.
