HIT·ENGINE v.001 / 2026
Quenchy →

Legal

Privacy

Effective · DRAFT — not yet in force

This page describes how Hit Engine handles personal data connected with a prize draw entry. It does not yet apply to anything live on this site — we are not yet running a prize draw — and is published in advance so the rules are settled before entries open.

A demonstration round is published at /raffle. It is a fixture: no prize, no entrants, and the entry list is synthetic. It exists so the draw verifier can be checked against real cryptography before a real round opens, and it is labelled as such wherever it appears.

What we collect for a bet entry

When you submit a bet reference to enter a round, we collect: your Stake username, the bet reference, the game the bet was placed on, the multiplier it reached, and the time you submitted it.

To check the bet against Stake’s public record without keeping your IP address tied to it indefinitely, we also store a salted hash of the IP address you submitted from. The salt rotates daily, and the hash is retained for 30 days.

Where an entry needs a resolver to check the bet, we keep the raw evidence the resolver gathered — for example, a copy of the page it checked — for 180 days, so a decision can be re-checked or a dispute investigated.

What we collect about our own staff

The studio’s operators and administrators sign in to the admin console with their email address. We keep those addresses to authenticate them and to record who did what in the audit trail — this is about our own staff, not entrants.

What we never collect

We do not store your stake amount, your payout, or the currency you bet in. To check a round’s minimum-stake requirement, your stake is converted to its USD-equivalent value for that one comparison and then discarded: we keep only whether the bet passed or failed the minimum, never the amount itself.

What we publish, and why

While a round is open, the public entry list shows a masked version of your username and a banded version of the multiplier you reached — enough to show the list is growing, not enough to identify you or your exact result.

Once a round closes and the entry list is sealed, we publish the full entry list: username, bet reference, game, and exact multiplier, for every entry, unmasked.

We do this because the fairness proof described in the Raffle rules only means something if anyone can check it. If the entry list were private, or entries could be quietly added or removed after the randomness became available, “the draw was fair” would be a claim you’d have to take on trust. Publishing the full, frozen list is what makes it checkable instead.

For a bet entry, this is not new exposure: your username, the game you played, and your multiplier are already visible on your own public Stake bet page — we are not disclosing anything Stake does not already show. A postal entry has no bet page behind it, so publishing a postal entrant’s username is new exposure. We publish it anyway, because the entry list has to be completely and publicly auditable for the fairness proof to mean anything — an entry list with some entrants hidden could conceal exactly the manipulation the proof exists to rule out. It is not published because it was already public some other way; it is published because the list would not be a fairness proof otherwise.

Hit Engine, not Stake, is the controller for this publication: it is our choice to publish it, and our responsibility if you have concerns about it.

Postal entries

If you enter by post under the Free entry route, we collect your full legal name, postal address, and Stake username. Your name and postal address are used only to check the per-person entry limit and to resolve a dispute if one arises; they are not published and not used for marketing. Your Stake username is different: once the round is sealed, it is published in the public entry list exactly as it is for a bet entry — see What we publish, and why above for why.

Why we hold this data

We hold this data to run a prize draw honestly, and to be able to prove, afterwards, that we did: to check whether a bet qualifies, to enforce the per-user and per-round limits described in the Raffle rules, and to publish a result anyone can verify. Where we ask you to send postal details, we rely on your consent in sending them; everywhere else, we rely on our legitimate interest in running a fair, checkable draw and preventing abuse of it.

Retention

What we can’t delete after seal

Once a round is sealed, the published entry list is the fairness record for that draw. We cannot delete or amend a single entry from a sealed list without undermining every other entrant’s ability to verify the result. A deletion request affecting a sealed round is limited to data that was never published — such as a postal address kept for dispute purposes — and does not remove your entry from the public record.

Where this is processed

We keep the number of processors to what running the draw actually needs: Cloudflare (hosting, rate limiting, and admin sign-in), Turnstile (the bot check on entry submission), Supabase (the database), Sentry (error reporting), and R2 (storage for archived resolver evidence). None of them receive more of your data than they need to provide that function.

Requests

To ask what we hold about you, correct it, or ask us to delete what can be deleted under the section above, write to the address on Terms.

HIT ENGINE ✱EVERY SPIN A HIT ✱PRECISION SLOT MACHINERY ✱