Legal

Privacy Policy

What we hold about your account, the cookies sign-in needs, and the third-party requests our pages make. No analytics, no ad trackers.

Last updated: September 1, 2026

1.Who we are and what this covers

This Privacy Policy explains how SportzPRED, Inc., a Maryland corporation (SportzPRED, “we”, “us”) handles information in connection with the SportzPRED website and tools (the “Service”). SportzPRED, Inc. is the controller of that information, and can be reached at the postal address in clause 14.

It does not cover any third-party site you reach from here — including any sportsbook, league site or support organisation we link to. Those services have their own policies, and we recommend reading them.

2.The short version

What this comes down to

We hold your account (email, a password we never see in plain text, an optional display name, your preferences, and a record of the terms you accepted), your credit balance and a running history of the predictions you have made, and the server logs and performance measurements needed to keep the Service running. We set sign-in cookies because sign-in cannot work without them. We run no analytics or advertising trackers, and we hold no card details of any kind — card payments are handled on Stripe's own checkout page and never reach us. The only email we send today is what sign-in needs: your confirmation link and password resets. No marketing, no mailing list.

Three things worth knowing that aren't obvious: our authentication and database are provided by Supabase, so your account data is processed on Supabase's infrastructure (clause 7); our pages load their typefaces from Google's font servers, which means your IP address reaches Google when a page loads (clause 4); and our own staff can see your account and act on it, which clause 9 describes rather than leaves to be assumed.

3.Information we collect

Information you provide

  • Account information. Your email address and password when you create an account. The password is handled by our authentication provider (Supabase) and stored only as a cryptographic hash — neither we nor Supabase can read it. Optionally, a display name, and the account preferences you set (timezone, favourite team, default league, notification choices).
  • Your consent record. When you create an account you must accept the Terms, this policy and the responsible-use notice. We record which version of those documents you accepted and when — that record is what makes your acceptance, and our reliance on it, verifiable.
  • Prediction inputs. The scenario you type to run a prediction: player and team names, minutes, lineups, lines and prices, and the other settings on each model page. They describe basketball scenarios, not you — but if you type personal information into a free-text field it will be transmitted with everything else, so please don't.
  • Refund requests. If you ask for a refund from your billing history, we record which purchase it was about, the amount our records say is refundable, anything you chose to write in the optional reason box, and the decision and the reason we gave for it.
  • Correspondence. Anything you send us directly, such as a support email and the address it came from.

Information collected automatically

  • Server logs. Like any web service, our hosting and infrastructure providers record standard request data — IP address, user agent, requested URL, referrer, timestamp and response status — for security, abuse prevention and debugging.
  • Performance telemetry. We record technical measurements for each request and prediction job: which endpoint was called, how long it took, how much memory and CPU it used, how many database and upstream data calls it made, response size, and whether it errored. For signed-in requests this is linked to your account id, so we can attribute usage and investigate problems you report.
  • Rate-limiting counters. To stop one client overwhelming the Service and to make password and token guessing pointless, we keep a short-lived count of recent requests against your IP address, and against your account id once you are signed in, together with a count of failed sign-in attempts from an address. These are counters in a temporary store, not a browsing history: they hold timestamps, not what you asked for. The longest of these windows is fifteen minutes, after which the entries are gone.
  • Your prediction while it runs. A prediction is queued and computed in the background while your browser polls for the result, so the scenario you submitted and the result it produced are held on our side until we have delivered them to you. That record lives in server memory or, where we run a shared job store, in a temporary key-value store; either way it is short-lived and clause 8 says how short. It is operational storage so that a prediction can be handed over reliably, and it is not mined, profiled or kept.

Cookies and browser storage

We set authentication cookies — the session tokens that keep you signed in, managed by our authentication provider. They are strictly necessary for sign-in and are not used for advertising or cross-site tracking. Your browser's local storage holds interface preferences only, such as layout density. We load no analytics platform, tag manager, session recorder, advertising pixel or social media SDK, we do not build behavioural profiles, and we do not track you across sites.

Your credit ledger and prediction history

Your account has a credit balance, and every movement of it is recorded against your account: the free credits granted when you signed up, and one entry for each prediction you run. A prediction entry stores which model ran, a short description of what you asked for, and a one-line summary of the result.

We are flagging this specifically rather than burying it in a list, because it is the one record here that describes you rather than your device: taken together it is a history of what you chose to model and when. We use it to show you your own history, to compute your balance, and to investigate problems you report. It is not sold, not shared for advertising, and not used to profile you for anyone else. It is deleted with your account.

Payment details

We hold no card details. Payments are processed by Stripe. When you buy credits we send you to Stripe's own checkout page, hosted on Stripe's domain, and your card number, expiry and CVC are entered there. They do not pass through our servers, are not stored by us, and do not appear in our logs. There is no card field anywhere in SportzPRED.

What we do keep is the record of the purchase: the amount, the date, a reference number, and the card brand and last four digits Stripe reports back — the same details printed on a receipt, and what lets you identify a payment when you ask about a refund. We keep that history even if you close your account, because tax and accounting law requires us to.

Stripe is a payment processor in its own right and handles your card details under its own privacy policy, not ours. If you are in the EU or UK, note that Stripe may process your payment outside your country under its own transfer safeguards.

We also collect no location data beyond what an IP address inherently implies. If any of this changes we will update this page before the feature ships and revise the date above.

4.Third-party requests: web fonts

Our pages load the Barlow and Barlow Condensed typefaces from Google's font servers (fonts.googleapis.com and fonts.gstatic.com). Your browser makes that request directly, which necessarily discloses your IP address, user agent and the referring page to Google. Google's handling of that request is governed by Google's Privacy Policy, not this one.

Google states that the Google Fonts API does not set cookies and does not use these requests to build advertising profiles. Even so, this is a transfer of your IP address to a third party that you did not separately agree to, and in some jurisdictions — Germany in particular — that has been held to require consent. We disclose it here so the choice to proceed is an informed one. Self-hosting these fonts would remove the transfer entirely and is a change we may make.

Apart from web fonts and our own infrastructure (including our authentication and database provider, clause 7), the Service makes no third-party browser requests: no CDN scripts, no embedded video from external hosts, no remote images.

5.How we use information

  • To create and administer your account, sign you in, and keep your session valid.
  • To run the prediction you asked for and return the result.
  • To email you — which today means authentication only. The only messages we currently send are the ones sign-in requires: your signup confirmation link and password resets, sent through Supabase (clause 7). We do not send marketing, and no mailing list exists.
  • To honour your notification preferences when those emails exist. Your account holds three switches — receipts, product updates and low-balance alerts. Receipts and product updates are not being sent yet; the switches record your choice in advance. When we do start sending them, product updates and low-balance alerts will go only to accounts that switched them on, every such email will carry an unsubscribe link, and we will revise this page and the date above before the first one goes out. Service messages — a security notice, a billing notice, or a material change to our terms — are not optional while you hold an account, because they are how we reach you about the account itself.
  • To take payment, keep your balance right, and assess and settle a refund you ask for.
  • To operate, maintain, debug and secure the Service, including applying rate limits and blocking repeated failed sign-in attempts, and otherwise preventing abuse.
  • To understand aggregate load and compute cost so we can size infrastructure and keep the Service responsive.
  • To improve model coverage and correctness — for example, spotting that a player name consistently fails to resolve.
  • To respond to you if you contact us.
  • To comply with law and to enforce our Terms of Service.

We do not use your information for advertising, and we do not use it to make automated decisions that produce legal or similarly significant effects about you.

7.Sharing and disclosure

We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We disclose information only in these situations:

  • Service providers. Our authentication and database provider, Supabase, processes your account data and our application data on our behalf. Hosting and infrastructure providers that operate the Service similarly receive what they need to run it, and are bound to protect it.
  • Payments. Card payments are processed by Stripe. When you buy credits you enter your card on Stripe's own checkout page and Stripe receives your card details and billing information directly — we never see them. We send Stripe only the amount, the pack you chose and your account identifier so the purchase can be credited to you, and Stripe returns the fact of payment plus the card brand and last four digits. Stripe acts as a data controller in its own right for the payment and handles that data under its own privacy policy.
  • Legal requirements. Where we are required by law, regulation, legal process or an enforceable governmental request, or where disclosure is necessary to protect our rights, safety or property, or those of our users or the public.
  • Business transfers. In connection with a merger, acquisition, reorganisation or sale of assets, in which case we will take reasonable steps to ensure the information remains protected and will notify you of any material change to this policy.

8.Data retention

We keep information only as long as we need it for the purposes above.

  • Your account and preferences, and the record of the terms you accepted: for as long as the account exists.
  • Your credit ledger — which is also your prediction history. Every entry, including the model you ran, the description of what you asked for and the one-line summary of the result, is kept for as long as the account exists. It has to be: your balance is calculated by adding the entries up, so deleting an entry would change your balance. This is a standing record of what you modelled and when, and clause 3 explains why we single it out.
  • Server logs and performance telemetry: retained on a rolling short-term basis for security, debugging and capacity planning, then deleted or aggregated into non-identifying statistics.
  • Rate-limiting counters: minutes. Each entry is dropped as soon as it falls outside its window, and the longest window we operate is fifteen minutes. Nothing accumulates and nothing is archived.
  • A prediction held while it runs: discarded within minutes of the result reaching you — within about thirty seconds of it where we run the shared job store — and in no case kept beyond an hour, which is also when a result nobody ever collects is thrown away. What survives is the one-line ledger entry described above, not the simulation.
  • Refund requests: kept for as long as the account exists, and deleted with it. They are the record of what was asked and what was decided, which is what lets either of us revisit a decision.
  • Correspondence: as long as needed to handle the matter and to keep a record of it.

Deleting your account deletes all of it, including the whole ledger — the database removes those rows with the account rather than orphaning them. The one future exception is money: once credits can be bought, tax and accounting law will require us to keep the record of a purchase (what was bought, when, for how much, and by whom) for the statutory period even after the account is gone. We will name that period here before the first charge, and it will cover the purchase record only, not your prediction history.

9.Security

We take reasonable technical and organisational measures to protect information against unauthorised access, loss and misuse: encryption in transit everywhere, passwords stored only as cryptographic hashes by our authentication provider, row-level security on the database so account data is only readable by its owner, session cookies scoped against cross-site use, rate limits that block repeated failed sign-in attempts from an address, and restricted administrative access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. Not collecting payment details is itself part of our current security posture.

Who at SportzPRED can see your account

Staff holding an administrator role can see your account and the data described in clause 3 — your profile and preferences, your credit ledger and prediction history, your purchases and refund requests, and when you last signed in — and can act on an account: correcting a balance, deciding a refund, or suspending access. This is what running a paid service requires; we would rather say so than let you assume otherwise.

It is bounded in three ways. The administrator role is granted deliberately and to individuals, and access is refused outright if the role cannot be confirmed rather than being allowed through on a technicality. Every action that changes something — every credit granted or removed, every suspension, every refund decision — is written to an audit record naming who did it, when, to which account and for what stated reason, and that record cannot be edited from the panel that writes it. And administrative sign-in can be required to carry a second factor in addition to a password.

10.Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict or object to our processing of your personal information, to portability, and to withdraw consent where we rely on it. These rights exist under the EU and UK GDPR, the California Consumer Privacy Act as amended, India's Digital Personal Data Protection Act 2023, and comparable laws elsewhere.

Because your data is held against your account, we can act on these requests: you can view and correct your profile and your email preferences yourself from the account pages, and you can see your full prediction and credit history there too.

Deletion and export are handled by email, not in the app. The “Delete account” button on the profile page is deliberately disabled — an irreversible deletion wired to a single click, with no confirmation step and no way to restore a balance afterwards, is worse than no button. Write to privacy@sportzpred.com and we will do it: deleting your account removes your profile and preferences, your consent record and your entire credit ledger and prediction history, subject only to the financial-record retention described in clause 8. We will confirm when it is done.

To exercise a right, contact privacy@sportzpred.com from the email address on your account. We will respond within 30 days, or tell you if we need longer. We will not discriminate against you for exercising any of these rights. If you are in the EEA or UK and believe we have handled your information improperly, you may also complain to your local supervisory authority.

11.International transfers

We and our service providers may process information in countries other than your own, whose data protection laws may differ from those of your jurisdiction — our database and authentication infrastructure is currently hosted in the Asia-Pacific region. Where we transfer personal information out of the EEA or the UK, we rely on an appropriate safeguard — such as the European Commission's Standard Contractual Clauses — or another lawful transfer mechanism.

12.Children

The Service is not directed to children and is not intended for anyone under 18. We do not knowingly collect personal information from children, and creating an account requires confirming you meet the age requirement. If you believe a child has provided us with personal information, contact privacy@sportzpred.com and we will delete it.

13.Changes to this policy

We may update this Privacy Policy as the Service changes. When we do, we will revise the “Last updated” date above, and for material changes — particularly any change that introduces analytics, payments or new categories of collection — we will take reasonable steps to bring it to your attention within the Service before it takes effect.

14.Contact

Questions, or to exercise a data right: