Privacy
Last updated 25 July 2026
The short version
Niekie scores online casinos. You can read every score without an account, without cookies that track you, and without telling us who you are.
An account is only needed to submit evidence or use the member tools. The browser extension works signed out, and matches casinos on your own machine rather than reporting your browsing to us.
We do not sell personal data, and we do not share it with advertisers or data brokers.
The website
Reading the site. Public pages are served without a login. Our host records standard server logs (IP address, user agent, requested URL) for security and reliability. We use Google Analytics to count traffic, Microsoft Clarity to see how pages are actually used, and the Meta pixel to measure whether our own ads and posts bring anyone here. All three set their own cookies and record approximate location and the pages you viewed. The Meta pixel reports that visit back to Meta, which may match it to a Facebook or Instagram account if you have one. Microsoft Clarity records how you move through a page, including mouse movement, scrolling and clicks, and can replay that session to us; it is configured to mask text input, and we use it to find broken layouts and confusing pages rather than to identify anyone. Nothing on the public pages is personalised to you by us.
Accounts. If you sign up we store your email address and, if you connect one, your wallet address. Authentication is handled by Supabase, which stores your session tokens. We use your email to sign you in and to reply to something you sent us, not for marketing you did not ask for.
Submissions. If you submit a payout report, complaint, correction or other evidence, we store what you sent, including any screenshot, and link it to your account so a moderator can review it and so it can be credited to you. Accepted evidence feeds the payout-reliability part of a casino's score. We publish the aggregate result, never your email or wallet.
Operator submissions. If you apply on behalf of a casino for verification, we store the business contact details on the form so we can process and respond to the application.
The browser extension
The Niekie extension looks up a casino's safety score and, if you choose to use them, keeps play limits and a gambling-site block. The two builds differ in one way and it matters here: the Firefox build can see the casino page you are on, so it shows the score there. The Chrome build has no access to gambling sites at all and cannot read the page you are on, so there you type the operator's name instead. Everything below that begins with the site you are on, page content, or time played applies to the Firefox build only. What it collects, precisely:
- The site you are on. The extension downloads our public casino directory and caches it locally for 12 hours. Matching the site you are on against that list happens entirely on your machine, so simply browsing does not tell us where you have been. When you open the badge or the toolbar popup, the hostname of that tab is sent to our lookup API to fetch the detailed report. That request carries the hostname only, not the full URL, the page content or anything you typed.
- Page content, only when you ask. If you are signed in and choose to submit payout evidence, clicking "Capture screenshot" takes an image of the visible tab, and clicking "Submit contribution" uploads it. Nothing is captured or uploaded without those two deliberate clicks. The extension never reads page text, form fields or keystrokes.
- Your email and session. Signing in inside the extension uses a one-time code sent to your email. Your session tokens are stored in the extension's local storage on your device so you stay signed in.
- Amounts you enter. A payout submission can include the withdrawal amount and how long it took. You type these; we do not read them from the page or from any account.
- Local settings. The cached casino list, a "dismissed until" timestamp so a closed badge stays hidden for a day, and your light or dark theme preference. These stay on your device.
- Time played, if you turn on play controls. While a casino we rate is the tab in front of you, the extension counts the seconds. When you stop, it saves how long and which operator, to your account. It records minutes and a name, never a web address, never page content, and nothing at all on sites we do not rate. Turning the feature off stops the counting.
- Deposits you type in. If you set a monthly deposit budget, the extension asks what you deposited when you leave a casino. We cannot see your money and we do not try to; the figure is whatever you enter, and entering nothing is a valid answer.
- That you set a block, and until when. Blocking is tied to your account so it survives a reinstall, which means we hold a record that you asked to stop gambling for a period. We treat that as the sensitive thing it is: it is readable only by you, it is never used for marketing, it is never shared or sold, and deleting your account deletes it along with everything above. You can ask us to delete it at any time without closing your account.
- What the block list is not. The list of gambling domains ships inside the extension and the blocking happens in your browser. We are not told which sites you tried to open while blocked, because nothing reports that anywhere.
The extension talks to two hosts only: niekie.app and our Supabase backend. It contains no third-party analytics, no advertising code and no remote code: all of its JavaScript ships inside the extension package.
It does not request access to all sites. The manifest names the operators we rate, so on every other page the extension is not loaded at all rather than loaded and silent. Adding an operator therefore needs an extension update, which is a fair price for an extension that is structurally incapable of seeing your bank.
The Android app
The app shows the same scores as the site and reads them without an account. Signing in is only needed for the member tools, and it is the same account as the website.
Play controls use a VPN, and here is exactly what that means. Blocking gambling sites across a whole phone is only possible through Android's VPN interface, so while a block is running Android shows a key icon and the app holds a VPN connection. It is not a VPN service in the usual sense: nothing is routed to us, no traffic is proxied through our servers, and your IP address is not changed. The connection exists so the app can answer DNS lookups on the device.
What the VPN sees and what it keeps. It sees the domain names your phone looks up while a block is running. A name on the block list is answered with "does not exist" and the request goes nowhere. Every other name is forwarded to your normal DNS resolver unchanged. None of it is written to a log, stored on the device, or sent to us or to anyone else, and the block list ships inside the app rather than being fetched per lookup. We cannot tell you which sites you tried to open while blocked, because nothing anywhere records it.
When it runs. Only while you have an active block. Starting one asks for Android's VPN permission first, and the connection stops when the block ends. Removing the app also removes it.
Deleting your account. Account settings in the app deletes your account and everything attached to it. Payout reports and forum posts you contributed stay published with your account removed from them, because other people's scores are computed from them, and a row with no account attached is no longer about you. If a block is running, deletion waits until it ends, so that deleting an account cannot be used as a way around a block you set.
What we never do
- Sell or rent your personal data.
- Transfer your data to third parties except the processors below, who act on our instructions.
- Use your data to assess creditworthiness or for lending.
- Use your data for anything unrelated to showing you casino safety scores and running your account.
- Let a casino pay to change, remove or influence its score, or to learn who reported it.
Who processes data for us
- Supabase, database, authentication and file storage for screenshots.
- Vercel, hosting and server logs.
- Google Analytics, aggregate traffic measurement on the public site. Not used in the extension.
- Microsoft Clarity, session analytics on the public site. It records page interactions and can replay a session to us, which is how we find layout faults. Not used in the extension.
- Meta, the Facebook pixel on the public site, used to measure whether our ads and posts bring visitors. Not used in the extension.
- Anthropic, the models used to read public operator pages and registry records during scoring. We do not send it your personal data.
How long we keep things
Account records last until you delete the account. Submitted evidence is kept while the score it supports stands, because a score has to remain auditable. Server logs roll off on our host's normal schedule. Extension local storage lives on your device and is cleared when you remove the extension.
Your rights
You can ask for a copy of what we hold about you, ask us to correct it, or ask us to delete it. Deleting your account removes your email, wallet and session. Evidence you submitted may be retained in anonymised form where a published score depends on it; if that is not acceptable to you, say so and we will discuss it.
Use the contact form for any of this. If you are in the UK or EU you also have the right to complain to your data protection authority.
Children
Niekie is for adults. It is not directed at anyone under 18, and we do not knowingly collect data from anyone under 18. Gambling carries real financial risk, and nothing on Niekie is a recommendation to gamble.
Changes
If this policy changes in a way that affects what we collect or why, we will update the date at the top and, for anything material, say so on the site.