OneMillion
Effective August 22, 2026

Privacy Notice

This notice describes how OneMillion handles information across Demo and conditionally available Real features.

Data we process

Google account identifier, display name, profile image, authentication metadata, Demo and Real wallet balances, ledger activity, room entries, draw results, payment and payout records, operational validation records, lobby messages, moderation status, support requests, customer feedback, optional contextual feedback answers, investor inquiry details, technical request data, campaign and broad referral attribution, optional email and browser-notification preferences, room invitation records, and your device analytics preference.

Why we use it

To authenticate users, prevent duplicate or abusive actions, maintain balances, operate rooms and draws, publish verifiable receipts, answer support requests, review feedback and investor introductions, moderate the lobby, investigate errors, and secure the service.

Public information

Demo results are private to participating accounts. Completed Real draw receipts may be public and read-only. They include proof and a masked winner name, but not account identifiers, email addresses, private wallet balances, or payout details. Lobby messages are visible only to signed-in users.

Product analytics

Google Analytics is enabled by default when you first use OneMillion on a device. It may use a pseudonymous browser identifier and receives the current app view, language, selected Demo or Real mode, selected room size, room and deposit funnel stage, checkout method category, campaign parameters, and a broad referral source or referring domain. Sensitive URL parameters are removed before measurement. OneMillion does not send account identifiers, names, email addresses, usernames, messages, form contents, wallet balances, deposit or payout amounts, PayPal identifiers, invitation tokens, or whether you won or lost. Advertising storage, advertising personalization, and Google Signals are disabled.

You can disable analytics without losing app features. Change the setting at any time from Account settings or Analytics settings in the navigation menu. Disabling stops new product events and removes accessible Google Analytics cookies from this site.

Optional contextual feedback

After sign-in, OneMillion may ask one short question about how you discovered the service, what prevented you from progressing after Demo, or why you cancelled checkout. Each prompt is optional and dismissible. An answer is stored only after you select the separate consent checkbox. The record contains the prompt stage, selected answer, optional written detail, language, account identifier, and verified account email. Responses are restricted to administrators, limited to one stored response per stage and account, and rate-limited to prevent abuse.

Optional Live room activity emails

Live room activity emails are promotional and are off by default. They are sent only after you make a separate affirmative choice. To avoid irrelevant or harmful alerts, the service checks whether you have enough currently available Real balance for the listed entry, whether you already joined the room, whether the room remains open, and whether account, payment, cooling-off, self-exclusion, or responsible-play restrictions apply. Demo activity, wins, and losses are not used to select recipients.

Alerts state the current room occupancy and economics, do not reserve a place, and are limited to one every 12 hours and three in a rolling seven-day period. You can turn them off in Account settings or use the unsubscribe option in any alert. Consent, revocation, delivery timestamps, and hashed delivery identifiers are retained as needed to enforce your choice, frequency limits, security, and delivery auditing.

Optional browser room notifications

Browser notifications are off until you grant browser permission and enable them. They are limited to operational updates for Real rooms you joined, such as when a room becomes ready or its private result is available. Lock-screen notifications do not reveal whether you won or lost. You can disable them from Account settings or your browser settings.

The service stores the push endpoint and encryption keys issued by your browser notification service, a hashed browser identifier, delivery timestamps, and your preference. Payloads are encrypted for delivery. Signing out removes the current device subscription, and account deletion removes remaining subscription records.

Room invitation links

A participant can create an expiring invitation link for an open Real room. The link contains a random token and no account identifier. Opening it provides only limited room occupancy and economic details. It never signs a visitor in, joins a room, changes data, reserves a place, or charges a wallet. Normal authentication, eligibility, balance, safety, capacity, and rate-limit checks remain required.

Service providers

Google Firebase provides authentication, database, hosting, and backend functions. Google Analytics provides product measurement that you can disable in Account settings. Browser push services operated by Google, Mozilla, Apple, or Microsoft may route encrypted notifications when you enable them. PayPal may process payment, card, dispute, refund, and payout data when Real payment features are available.

Retention and account deletion

Account deletion removes the login and private wallet record after unresolved activity is cleared. Ledger, payment, withdrawal, room, lobby, and public proof records may be retained in anonymized form for integrity, security, and accounting verification. Support, feedback, and investor inquiry records are restricted to administrators and retained only while needed for follow-up, security, or legal obligations.

Security

Private balance changes are restricted to backend functions, direct client writes are denied, sensitive records require the account owner or an administrator, and repeated actions are rate-limited. No online service can guarantee absolute security.

Your choices

You can sign out, stop using the service, change analytics, email, and browser-notification choices, unsubscribe from promotional room alerts, or request account deletion from the Account screen. Privacy questions and access, correction, or deletion requests can be sent to onemilliondollars39@gmail.com.

Policy changes

This notice will be updated when a material change affects how personal information is processed.