Skip to main content
SportPicker

AI transparency

SportPicker publishes AI-assisted analysis for informational purposes and keeps legal and transparency information accessible throughout the product.

Responsible use

Odds, statistics, and predictions are not advice and do not guarantee outcomes. SportPicker does not accept bets or hold gambling funds.

Introduction

This Privacy Policy describes how SportPicker processes personal data on sportpicker.ai and its connected apps.

Data Controller: IAMA L.L.C-FZ — support@sportpicker.ai.

Our legal bases are: performance of a contract for accounts, service, and subscriptions (GDPR Art. 6(1)(b)); legitimate interests for security, abuse prevention, and technical diagnosis (Art. 6(1)(f)); consent for analytics, campaign attribution, and optional communications (Art. 6(1)(a)); and legal obligations where required (Art. 6(1)(c)).

Data We Collect

We process these categories of data:

• Account: name, email, hashed password, optional Google or Apple sign-in identifiers, and saved preferences or content

• Session: the sp_session technical cookie and information needed to authenticate a device

• Security: email, IP address, and user agent in access, verification, and abuse-prevention logs

• Diagnostics: error message and stack, path without query string or fragment, browser type, language, and related technical details

• With analytics consent: pages, interactions, duration, campaign source, app version, and coarse device or locale data associated with a random pseudonymous app-install identifier stored on the device until consent is withdrawn; it is never an email, account ID, IDFA, IDFV, or advertising ID

• Server-verified operational facts: account activation, issued sessions, and subscription status or outcome, linked to the account for security, deduplication, and service reconciliation

• User-requested AURA and support conversations: the question, generated answer, account email, and separate daily usage counters; AURA may also store extracted personalization preferences

• Subscriptions: plan, status, and customer, subscription, or transaction identifiers; SportPicker does not receive full card details

• Notifications, if enabled: the Expo push token, platform, locale, app version, category choices (service, free prediction, and marketing), optional account link, and one-way hashes of the random installation identifier and secret; we do not use IDFA, IDFV, or advertising IDs. We record provider tickets and technical outcomes to prevent duplicates, handle errors, and disable invalid tokens; an accepted ticket does not guarantee that a notification was displayed. With analytics consent, when a user taps a notification we record its open time on the corresponding delivery, optionally linked to the account already associated with it, to show opens and the open rate in the admin dashboard; we cannot detect a banner that was merely viewed

How We Use Your Data

We use data for accounts, the service, subscriptions, security, and support. Pseudonymous product analytics activates only with its separate, revocable consent; refusing it does not limit the service. Purchase and trial conversion measurements are based on a server-verified outcome and use only an opaque identifier, plan, value, and currency. We do not sell personal data.

Cookies

We use sp_session for authentication and browser storage for cookie choices and preferences. Analytics is optional, remains disabled until consent, and can be withdrawn at any time through “Manage cookies”.

Meta marketing measurement

Only with separate, revocable marketing consent, Meta Pixel loads exclusively on the canonical Premium, Premium/success, and app download landing pages, and only when the URL and referrer contain no sensitive data: fragments, non-allowlisted queries, or sensitive referrers block loading. A validated fbclid alone may be removed with marketing consent; UTM and Google/TikTok click IDs are removed only after analytics consent and successful persistence. It may measure PageView, ViewContent, and InitiateCheckout, including clicks on the App Store and Google Play buttons; only after Stripe verification may it measure Purchase or StartTrial. We send Meta the _fbp/_fbc cookie identifiers and clean path; for app CTAs, the selected store destination; for verified economic events, an opaque event ID, the real event timestamp, plan, value, and currency. We do not send email, phone, account IDs, session tokens, or Stripe IDs, and we do not add IP address or user-agent fields to the server payload; as with any direct browser request, Meta may receive network technical data under its own policy. Consent lasts up to 12 months; _fbp/_fbc remain on the device for up to 90 days. Withdrawal blocks later transmissions and removes known Meta cookies. Meta Platforms Ireland Limited processes data under its own terms, including possible international transfers.

Meta in the mobile apps

In the mobile apps, Meta campaign measurement is off by default, separate from product analytics, and revocable under Account management > Tracking. On iPhone, Apple's ATT request is the explicit choice for this measurement; on Android, the explicit choice is made in SportPicker's prompt. Only after the applicable authorization does the app initialize Meta App Events SDK and enable collection of any available IDFA/Android advertising ID. Automatic lifecycle and purchase logging remain disabled: the app explicitly sends Meta's standard app activation and, only on Android after consent, asks Meta for the one-time app-install ping, which can use the available Android advertising ID and Google Play Install Referrer. These events use the anonymous app-device ID generated and retained by the SDK for that installation, plus ordinary app, device, operating-system, and network technical data. SportPicker's server may separately send RevenueCat-verified StartTrial and Purchase events through Conversions API with the same anonymous ID, a stable opaque event ID, product, value, currency, actual time, platform, app version/build, and OS version. Economic events remain CAPI-only and are not duplicated by the SDK. We do not send email, SportPicker account/session IDs, RevenueCat identifiers, or checkout-start events. Withdrawal stops new collection, explicit activations, new install pings, and server conversions and removes SportPicker's copy of the ID, but cannot guarantee deletion of the SDK's internal installation ID, cancel requests already started, or retract events created while consent was active and already queued or received by Meta.

Third-Party Services

We use Cloudflare for hosting and security; Resend for service email; Stripe for web payments; RevenueCat, App Store, and Google Play for mobile purchases; Google and Apple for sign-in; Expo Push, Apple Push Notification service (APNs), and Firebase Cloud Messaging (FCM) for notifications you select; Google Analytics 4, Amplitude, and Umami only with analytics consent; AppsFlyer in the mobile app and Meta Pixel/Conversions API only with marketing consent, to attribute installs, registrations, and conversions using available advertising identifiers, anonymous IDs, technical data, and Android Install Referrer; the AppsFlyer ID is linked to RevenueCat for verified purchase events; Sentry for privacy-filtered technical crash diagnostics; and sports-data and AURA services for requested features.

Data Retention

Account data and related content remain while the account is active or as needed to deliver the service. Sessions expire after 30 days. Account-linked AURA and support questions and answers are deleted after no more than 90 days; their separate daily quota counters after no more than 35 days. Access, security, and abuse-prevention logs are deleted after 90 days; pseudonymous analytics events after 90 days; technical error logs after 30 days. Push tokens, installation technical data, and preferences remain while at least one category is active; you can revoke them in the app or system settings. Account deletion removes linked installations. Revoked tokenless installations and the technical delivery-outcome ledger are deleted within 30 days. Enabled anonymous installations that remain inactive are deleted within 180 days and register again on their next use. After deletion, a technical RevenueCat identifier may remain for up to 30 days, plus only the time needed to finish an already in-flight deletion request (up to 15 minutes), and is then redacted even if provider cleanup is not confirmed; its one-way hash may remain for up to 13 months, solely to detect and remove recreations caused by offline devices. A new authenticated webhook proving a recreation may open a new identifier window, still limited to 30 days. Payment providers may retain tax and transaction records for legally required periods. Backups and mandatory records may require an additional technical or legal period.

Your Rights

Within the limits of the GDPR, you may request access, correction, deletion, restriction, or portability of your data, or object to processing. You may withdraw consent at any time without affecting earlier processing and lodge a complaint with the competent supervisory authority.

To exercise your rights: support@sportpicker.ai.

Changes to This Policy

We reserve the right to update this Privacy Policy. Users will be notified of significant changes through the site.

Contact

For privacy-related questions: support@sportpicker.ai