Privacy Policy
Effective April 2026
Summary
We collect only what we need to run Pick Pilot: your account info, read-only league data from the provider you connect, the analytics we compute from it, and a minimal product-event stream. We do not sell your data, we do not run third-party ads, and you can export or delete your account from Settings at any time.
1. Who we are
Pick Pilot ("we") is the data controller for the information described below. Contact: privacy@pick-pilot.com.
2. What we collect
- Account data. Email, display name, password hash (argon2id), timezone, session tokens, plan tier.
- League data (read-only). Yahoo uses OAuth authorization. Compatible Sleeper NBA leagues use a username and Sleeper's public read API, not OAuth. Imported data can include rosters, matchups, transactions, settings, and provider-exposed manager names. Fantrax is request-access only and ESPN is planned, not a public connection. Pick Pilot does not execute roster transactions on your provider.
- Derived analytics. Projections, z-scores, win probabilities, dynasty valuations, schedule weights, and similar computations stored per-league for caching and explainability.
- AI interactions. Prompt, completion, model, token count, cost, latency, citations. We redact roster data from prompts sent to third-party AI providers where identity is not required.
- Product telemetry. A fixed set of events (signup, connect, import, first-insight view, paywall view, checkout start) and page views when configured and analytics consent is enabled. Signed-in analytics can include user ID, email, and workspace identifiers; these events are not anonymous.
- Operational logs. Request ID, user ID, workspace ID, surface, method, path, status, latency. The operational retention target is 30 days; production enforcement remains a release-verification gate.
3. How we use it
- Operate and secure the Service (authentication, rate limiting, abuse prevention).
- Compute and display the analytics you requested.
- Route AI requests to our model providers under a data-processing agreement.
- Measure product performance and diagnose bugs.
- Send service-related email (receipts, security alerts, incident notices).
We do not use your league data to train third-party AI models. Providers we route to (OpenAI, Anthropic) are configured with zero-retention data-processing terms where available.
4. Legal bases (EU/UK)
Contract (to deliver the Service), legitimate interests (security, abuse prevention, product improvement), consent (for non-essential cookies and marketing email), and legal obligations (tax, fraud).
5. Sharing
We share data with processors acting under contract:
- Infrastructure: AWS / Cloudflare / Vercel (hosting, network, edge).
- Data: managed Postgres, Redis.
- AI: OpenAI, Anthropic.
- Payments: Vandly, only after its subscription contract is accepted and billing is explicitly activated.
- Email: Resend.
- Error reporting: Sentry (DSN-gated).
- Product analytics: PostHog (EU cloud where available).
We do not sell personal data and do not share it for third-party advertising.
6. Retention
- Account + league data: lifetime of the account.
- AI event metadata: 90-day target, then aggregation or deletion. Automated enforcement and production evidence remain release gates.
- Operational logs and encrypted backups: 30-day rotation targets, subject to operational verification.
- Account deletion: a seven-day cancellation period follows a scheduled deletion request. Sessions and provider credentials are revoked immediately. After the grace period, staged deletion removes or anonymizes personal content rather than deleting every related record. Narrowly scoped security, data-request, and future billing audit evidence may be retained up to 24 months or longer where required by law. Ownership and billing blockers can prevent completion; the account controls report those limits.
7. Your rights
Depending on your jurisdiction you may:
- Access and export your data in Settings: Privacy & data.
- Request account deletion in Settings: Privacy & data.
- Correct or restrict processing — email privacy@pick-pilot.com.
- Object to processing based on legitimate interests.
- Lodge a complaint with your supervisory authority (EU/UK residents).
8. International transfers
Data may be processed in the United States. For EU/UK residents, transfers rely on Standard Contractual Clauses with our processors.
9. Children
Pick Pilot is not directed at children under 13 (under 16 in the EU/UK). We do not knowingly collect their data.
10. Security
Argon2id password hashing, session tokens stored as HttpOnly cookies, TLS in transit, encryption at rest, least-privilege service accounts, per-request audit trail. For privacy and security questions, contact privacy@pick-pilot.com.
11. Changes
We will post material changes at this URL and notify affected users in-app and by email at least 14 days before they take effect.