Skip to main content

Privacy Policy

Last Updated: 2025-11-01 | Version: 1.0

Welcome to Lottery Winners ("we," "our," or "us"). We are committed to protecting your privacy and ensuring the security of your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and related services.

By using Lottery Winners, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy. This policy complies with GDPR, CCPA, COPPA, and app store requirements.

1. Information We Collect

Personal Information

  • Email address (for authentication and notifications)
  • Account credentials (hashed passwords)
  • Profile information (optional)

Lottery Ticket Data

  • Scanned ticket images
  • Ticket numbers and draw dates
  • State and game information
  • Win/loss history

Usage & Device Information

  • Device model and operating system
  • Usage analytics and app interactions
  • IP address and access logs

Payment Information

  • Subscription status (via RevenueCat)
  • Note: We do NOT store credit card information. All payments are processed securely through Apple App Store or Google Play Store.

2. How We Use Your Information

  • Process lottery ticket scanning and result checking
  • Send win notifications and alerts
  • Manage your account and subscriptions
  • Improve our services and develop new features
  • Provide customer support
  • Detect and prevent fraud or abuse
  • Comply with legal obligations

3. Third-Party Services

We use the following third-party services:

  • Google Cloud Vision API: OCR processing of lottery tickets
  • Google Gemini: LLM-based ticket data extraction
  • RevenueCat: Subscription management
  • Google/GitHub OAuth: Authentication services
  • AWS S3: Secure image storage

4. Data Security

We implement industry-standard security measures:

  • Encryption: All data encrypted in transit (TLS) and at rest (AES-256)
  • Password Protection: Passwords hashed using bcrypt
  • Access Controls: Strict limits on who can access user data
  • Regular Audits: Security assessments and updates

Note: While we use robust security measures, no method of transmission over the internet is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.

5. Your Rights

Depending on your location, you have the following rights:

GDPR Rights (EU Residents)

  • Right to access your personal data
  • Right to correct inaccurate information
  • Right to delete your data ("right to be forgotten")
  • Right to data portability
  • Right to restrict processing
  • Right to object to processing

CCPA Rights (California Residents)

  • Right to know what personal information we collect
  • Right to delete your personal information
  • Right to opt-out of data sales (we do NOT sell your data)
  • Right to non-discrimination

To exercise your rights, contact us at: admin@lottery-winners.com

6. Children's Privacy

Our service is NOT intended for users under 18 years of age (or the minimum legal age to participate in lottery games in your jurisdiction, typically 18 or 21).

We do not knowingly collect information from children. If you believe a child has provided us with personal information, please contact us immediately and we will delete it.

7. Data Retention

  • Account data retained while your account is active
  • Ticket data retained indefinitely unless you request deletion
  • Deletion requests processed within 30 days

8. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by:

  • Updating the "Last Updated" date
  • Sending an email notification
  • Displaying a notice within the app

Your continued use of the service after changes constitutes acceptance of the updated policy.

9. Contact Us

If you have questions about this Privacy Policy or our privacy practices:

Email: admin@lottery-winners.com

Subject Line: "Privacy Policy Question" or "Privacy Rights Request"

We will respond to all legitimate requests within 30 days.