Privacy Policy
Last updated 3 October 2026
This page explains what DiceSim stores about you, why, who can see it, and how to get rid of it. The short version: scripts run in your browser; an account stores what you save; administrators can read saved strategies for moderation and quality work; we do not sell data.
01What DiceSim is (and is not)
DiceSim is a simulator and calculator for provably-fair dice strategies. Nothing is wagered on this site, we hold no customer funds, and we do not operate a casino. Simulations run inside your browser; the results you see are produced by your own device.
We do link to third-party casinos through affiliate links. Those sites have their own privacy policies, and what you do there is between you and them. We never receive your account details or betting history from any casino.
02Using DiceSim without an account
You can use the simulator and calculator without registering. In that case:
- Your Lua scripts and settings are stored in your browser’s localStorage only. They are never uploaded unless you explicitly save or share them.
- Our server logs record the usual request metadata (IP address, user agent, requested URL, timestamp) for security and rate limiting. Logs are rotated and kept for up to 30 days.
- The AI copilot, if you use it, sends the prompt you type and the script in the editor to our server, which forwards them to the model provider to generate a reply. Anonymous usage is limited per session.
We do not use third-party advertising trackers or fingerprinting scripts.
03Data we store when you register
Creating an account stores:
- Username, email address and a password hash (argon2/bcrypt; we never store the password itself). If you sign in with Google or Discord we store the provider’s user id and the email they share with us; we never receive your password for those services.
- Strategies you save: title, description, Lua source, visibility setting, and metadata such as base chance and logic type.
- Simulation runs you log: aggregate statistics (rolls, profit, drawdown, streaks, seeds used) and a downsampled balance curve. We do not store every individual roll.
- Profile details you choose to add: avatar URL, bio, social handles, and the casino referral codes you bind to your profile.
- Notification settings: a Telegram chat id or Discord webhook URL if you enable notifications.
- Marketplace records: listings you create, purchases you make (chain, token, amount, transaction hash, your paying wallet address) and the wallet addresses you add to your profile for payouts.
- API keys: a label, permissions, the key’s prefix and a hash of the secret; the full secret is shown once and not stored.
04Who can see your strategy code
Your Lua source is private by default and stays private in every public surface of the site. Leaderboards, strategy pages, profiles, tournament tables and share cards show only the strategy name, the author and aggregate statistics. The API strips code from every response that is not addressed to the owner.
Your code can be seen by:
- You, from any device where you are logged in.
- Buyers who have completed a marketplace purchase of that specific strategy.
- DiceSim administrators. Admins can open any saved strategy, including private ones, in an admin-only tool. We use this to moderate abusive or malicious scripts, to verify leaderboard submissions, to investigate marketplace disputes, and to study which strategy patterns survive longest so we can improve templates, documentation and the calculator. Admin access is logged. We do not publish, sell or share your source with anyone else, and administrators are not permitted to list your code on the marketplace or enter it into tournaments as their own.
If that level of admin access is not acceptable to you, keep your scripts in the anonymous editor (localStorage only) and do not save them to an account.
05Affiliate links and click tracking
When you click a “Play now” link we record that a click happened: which partner, where on the site the widget was shown, which strategy (if any) you were viewing, which creator’s referral code was used, and a one-way hash of your IP address to filter duplicate clicks. We do not learn whether you went on to sign up or deposit, and the casino does not tell us who you are.
If a registered creator has bound their own referral codes, links shown on their strategies and share cards use their code instead of ours; the click is attributed to them in their dashboard.
07Service providers
We rely on a small number of providers to run the service. Each receives only what is needed to do its job:
- Cloudflare: DNS, TLS and DDoS protection in front of our server. Sees request metadata.
- Anthropic: language model for the AI copilot. Receives the prompt and script you submit when you use the copilot, and nothing else.
- Google / Discord: optional OAuth sign-in. They tell us your id and email; we tell them nothing about your activity here.
- Telegram / Discord webhooks: only if you enable notifications; we send the notification text to the destination you configure.
- Public blockchain RPC nodes: to verify marketplace payments we query transaction hashes on Ethereum, Polygon, Base or Solana. On-chain data is public by nature.
We do not sell personal data, and we do not share it with data brokers or advertisers.
08Retention and deletion
Account data is kept while your account exists. You can delete individual strategies and runs at any time from your dashboard; they are removed immediately. To delete your whole account, use the option in Settings or email the address below; we remove your profile, strategies, runs, API keys and notification settings within 30 days.
We keep marketplace transaction records (purchase id, amounts, transaction hashes, wallet addresses) for as long as needed to resolve disputes and meet accounting obligations, because the buyer has a continuing right to the code they paid for. Server logs expire after 30 days. Aggregate statistics that no longer identify you (for example “total rolls simulated on DiceSim”) may be retained indefinitely.
09Security
Traffic is encrypted in transit (TLS). Passwords are hashed with a modern slow hash. Session tokens are signed and HttpOnly. API keys are stored hashed. Access to production systems is limited to the people who operate them. No system is perfectly secure; if we learn of a breach affecting your data we will notify affected users by email without undue delay.
10Your rights
Wherever you live, you can ask us what we hold about you, ask for corrections, export your strategies (one-click .lua download in the dashboard), or ask us to delete your account. If you are in the EU/EEA, UK or a jurisdiction with similar laws, these are your statutory rights of access, rectification, erasure, portability and objection, and you may also complain to your local supervisory authority.
DiceSim is not directed at anyone under 18. If you believe a minor has created an account, contact us and we will remove it.
11Changes and contact
If this policy changes in a way that matters, we will update the date at the top and, for significant changes, show a notice in the app or email registered users. Continued use after a change means you accept the updated policy.
Privacy questions and deletion requests: [email protected].