Privacy Policy
Lottery Check (Lottery Check) · Effective 2026-06-15 · Version 1
This policy explains what data Lottery Check collects, why, and how it's protected. The app is a lottery-results checker — it does not sell tickets or accept payments.
1. What you give us
- Email address at signup, used to identify your account and send verification emails. If you sign in with Google or Apple, only the verified email and an opaque provider identifier are delivered to us — never your password, contact list, or anything beyond identity.
- Password (only for email/password signup), stored as a one-way bcrypt hash. The plaintext is never written to disk or logs.
- Ticket data you scan or enter — the lottery type, drawn numbers, and date. Photos of physical tickets are processed by AWS Textract for OCR and discarded after extraction; only the parsed text is retained.
- Pool memberships, if you create or join a play pool. Pool name, optional emoji, and invitations you send are stored.
- Age confirmation — when you tick the 18+ checkbox at signup, we record that you confirmed and the timestamp.
2. What we do not collect
- We do not use third-party advertising SDKs, analytics SDKs, or tracking pixels.
- We do not have an App Tracking Transparency prompt because we don't track you across apps.
- We do not request location, contacts, or photo-library access beyond the ticket image you explicitly share.
- We do not sell, rent, or share your personal data with third parties for marketing.
3. How we use it
- To authenticate you and keep your session secure (RS256 JSON Web Tokens with refresh-token rotation).
- To check whether tickets you submit match drawn winning numbers, and tell you the result.
- To enable social features (pools, invites) that you opt into.
- To send transactional emails (verification, password reset). No marketing emails are sent without your explicit opt-in.
4. Third-party services
- Google & Apple Sign-In — used only at the moment you tap their button; they verify your identity and hand us a signed token. Google and Apple's own privacy policies apply during that handoff.
- AWS — runs our database, file storage, and the OCR engine (Textract) for ticket scans.
- SMTP provider — for sending verification and reset emails.
5. Audit logs & PII redaction
Security-relevant events (logins, refresh attempts, failed credentials) are written to internal logs. Email addresses and IP addresses in these logs are redacted with a keyed HMAC-SHA256 hash, so engineers can correlate events without seeing your real email or IP.
6. Data retention & deletion
You can delete your account from inside the app at any time: Menu → Delete account → confirm with your password. Deletion is immediate and permanent. We remove your user row, refresh tokens, ticket history, and pool memberships. Where pool records reference a ticket you scanned, those references are also deleted. There is no recovery window.
If for any reason the in-app flow fails, email support@lottery-check.com from the address on the account.
7. Children
Lottery Check is intended for adults. Users must confirm they are 18 or older at signup. We do not knowingly collect data from anyone under 18. If you believe a minor has signed up, email support@lottery-check.com.
8. Security
Transport is TLS end-to-end. Passwords are bcrypt-hashed. Access tokens are short-lived (30 min) and signed with an RSA private key the client never sees. Refresh tokens are rotated on every use and revoked on suspected theft (re-use of a revoked token revokes the whole family).
9. Your rights
- Access — what we have on you is the data described above plus your ticket history. Email support@lottery-check.com for an export.
- Correction — edit your profile inside the app (Menu → Profile).
- Deletion — described above (§6).
- Withdraw consent — uninstall the app and delete your account.
10. Changes
If we materially change this policy, we'll bump the version and the app will prompt you to re-accept before continued use.
Contact
Privacy questions: support@lottery-check.com.