1. Who is responsible
Slot Check™ is operated by Jay Fructose; it is built and maintained by Ames Create, which processes data on the operator's behalf. Privacy questions and requests go to brandon@amescreate.com. This policy covers the app at https://slots.jayfructose.com. It does not cover Patreon, Discord, or any casino; those have their own policies.
2. What we collect, and why
Your photo
When you check a machine, the photo you take or choose is uploaded to our server, where it is (1) checked for size and type, (2) sent to our AI vendor, Anthropic, whose model transcribes the text and numbers visible in it, and (3) discarded from our server's memory when the response is sent to you. We do not save your photos, do not build a gallery of them, do not attach them to you, and do not use them to train any model. Large photos are shrunk on your phone before upload; that happens on your device.
Anthropic processes the image under its commercial API terms, which do not permit it to train on customer inputs, and retains inputs only for the limited period its policy allows for operating and abuse-monitoring purposes. We have no control over, and do not receive, anything Anthropic retains.
Please keep people out of the frame. The app only needs the screen and meters. If a photo includes other people, their faces, or anything else you would not want transmitted, do not upload it.
Cookies (two, both essential)
- jsc_mob — a signed, randomly generated unlock token set when you enter the access code. It tells the app this device belongs to a member. It contains no personal information, lasts up to 90 days, and can be revoked individually.
- jsc_caps — a signed counter of how many checks this device has used today. Lasts about 36 hours.
Both are strictly necessary for the Service to function, which is why there is no cookie banner: there is nothing optional to consent to. We do not set advertising, analytics, or third-party cookies, and we do not use fingerprinting.
Usage counters (rate limiting)
To keep the Service fair and affordable, we keep short-lived counters in a hosted Redis store (Upstash): checks per unlock token per day, checks per IP address per minute and per day, wrong access-code attempts per IP, and a global daily total. These counters contain your IP address (as part of the key) and a number, nothing else, and expire automatically within about 30 hours.
Read telemetry
For every check we record one line of anonymous diagnostics so we can answer questions like “is photo quality costing members verdicts?”: the game name the model read, whether the two reads agreed, the verdict and which rule produced it, how many meters were visible, whether a bet amount was legible, how long the read took, and the upload size. This data contains no image, no cookie value, no access code, no IP address, and nothing that identifies you. It is written to our hosting provider's logs and may also be copied to a spreadsheet we control.
Hosting logs
The app runs on Vercel. Like every web host, Vercel records standard request metadata (IP address, user agent, timestamp, path, response code) for security and operations, retained for a limited period under Vercel's policy. We use this only to keep the Service running and to investigate abuse.
Your account (optional)
If you sign in with email, we store: your email address, when the account was made, whether you accepted the Terms, your plan and where it came from (a code or a Stripe subscription), your pack-credit balance, and a per-month count of checks used. Sign-in links are single-use tokens that expire in 15 minutes; sessions are signed cookies you can end any time by signing out. There is no password to store. If you pay by card, the card details go to Stripe — we never see them. Email brandon@amescreate.com to have your account deleted.
Beta waitlist emails
If you join the beta waitlist on our homepage, we store the email address you give us, when you joined, and which page you signed up from, so we can email you when the beta opens and send at most an occasional launch-related update. We send a confirmation when you sign up. These addresses are not shared with anyone, are not used for advertising, and are deleted on request — reply to any waitlist email or write to brandon@amescreate.com and we'll remove you.
What we do NOT collect
- No name, phone number, address, or payment-card details (cards go directly to Stripe), and no account at all unless you choose to sign in.
- No location data. The app never asks for GPS and we never read a photo's embedded metadata. Note that a photo your phone saved with location metadata may carry it to the AI vendor as part of the file; large photos are re-encoded on your phone before upload, which strips it.
- No contacts, no camera access outside the moment you take a photo, no background activity.
- No advertising identifiers, no cross-site tracking, no data brokers.
3. How we use information
- To deliver the check you asked for and show you the result.
- To recognise member devices, enforce daily limits, and stop brute-force or automated abuse.
- To improve read accuracy and the playbook using aggregate, anonymous telemetry.
- To keep the Service secure and comply with law.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
4. Who we share with
- Anthropic — receives your photo to transcribe it (Section 2). United States.
- Vercel — hosts the app and processes request logs. United States.
- Upstash — stores the short-lived rate-limit counters. United States.
- Google — if telemetry is mirrored to a spreadsheet we control (anonymous data only).
- Law enforcement or others when required by law, or to protect the rights and safety of members, the public, or us.
Each vendor acts on our instructions as a processor for the data it receives.
5. Retention
- Photos: not retained by us. Held in server memory only for the seconds a check takes.
- Unlock cookie: up to 90 days, or until revoked. Cap cookie: about 36 hours.
- Rate-limit counters: expire automatically within about 30 hours.
- Anonymous read telemetry: retained indefinitely; it contains nothing that identifies you.
- Hosting logs: per Vercel's retention schedule.
6. Your choices and rights
- Stop using the app — clear the site's cookies in your browser and nothing about your device remains with us beyond expiring counters.
- Revoke a device — email us and we will revoke the unlock token for a device you believe was copied.
- Access / deletion requests — because we hold no account or identifier for you, there is usually nothing to look up; if you believe we hold personal information about you, email brandon@amescreate.com and we will respond within 30 days.
- Residents of California, Colorado, Virginia, Connecticut, Utah, and other states with privacy laws have rights to know, delete, correct, and opt out of sale or sharing. We do not sell or share personal information as those laws define it, and we do not discriminate against anyone who exercises a right.
- If you are outside the United States, note that all processing happens in the United States.
7. Security
Cookies are signed with a server-side secret, marked HttpOnly and Secure, and verified on every request. Unlock tokens are unique per device and individually revocable. The engine, the playbook, and the AI prompts run only on the server and never reach your browser. All traffic is HTTPS with HSTS, a strict Content Security Policy, and no-store caching on every API response. No system is perfectly secure, but we have designed this one to hold as little as possible so there is little to lose.
8. Age
The Service is for adults 21 and older. We do not knowingly collect information from anyone under 21, and under 18 is never permitted. If you believe someone under age has used the Service, contact us and we will revoke their access.
9. Changes
We will update this policy when our practices change and bump the effective date above. Material changes will be announced in the Patreon Discord or in the app.
10. Contact
brandon@amescreate.com. See also the Terms of Use and Responsible Play.