Privacy Policy
Last updated: 2026-09-10
TrueProps collects as little as possible: no account is required to use the Service, and an account needs only an email address. We never store passwords, we never sell personal information, and we do not track you across other websites. This policy spells out exactly what we collect, why, who processes it, and how to reach us about it.
1. Overview
This Privacy Policy explains what information TrueProps LLC, an Arizona limited liability company ("TrueProps", "we", "us"), collects when you use our sports-analytics platform (the "Service"), how we use it, who we share it with, and the choices you have. We collect little: the Service works without an account, and an account needs only an email address. We never ask for or store a password, and we do not track you across other websites.
2. Information we collect
- Email address — if you create an account, we collect the email address you sign in with. Sign-in is passwordless (a one-time emailed link), so we never collect or store a password.
- Session tokens — when you sign in, a session token is issued and stored in your browser so you stay signed in.
- Sign-in history — each time you sign in, we record the time and the method you used (emailed link or Google). We keep this as part of your account's security and billing record — for example, to answer a payment dispute — for up to 18 months. It records no location or device details, it is included in your account data export, and it is erased with your other account records when your account is deleted.
- Usage and log data — standard server logs (IP address, browser type, pages requested, timestamps) generated when you use the Service, used for operations, debugging, and abuse prevention.
- Preferences in local storage — display preferences (like theme and density) and in-app state (like a saved pick slip) are kept in your browser's localStorage on your device.
- Signup source — when you first arrive, we note in your browser's storage which channel brought you here (a campaign tag from the link you clicked, or the referring site's hostname — never a click-level identifier). It is kept in localStorage on the app, and — if you land on our marketing site first — in that site's sessionStorage for that visit only, so the tag survives the move between the two. If you later create an account, that one short label is stored on it so we know which channels work. It is first-party, never shared, and not captured at all when your browser sends Do Not Track or Global Privacy Control.
- Product usage events — a small set of first-party, cookieless events (a page view, a sign-up completed, a locked row or sign-in prompt clicked, a slip leg added, a bet logged) sent to our own servers so we can see which parts of the Service are used. Each event carries the page path (never the query string), an event name, and a random per-tab session id that your browser forgets when the tab closes. It carries no cookie, no device identifier, no email and no IP address; if you are signed in, a one-way salted hash of your account id is attached so we can count distinct signed-in sessions, and it cannot be reversed to you. No third party receives these events. We honour the Do Not Track and Global Privacy Control browser signals — with either set, no events are sent at all.
- Card identifier — if you pay us, our payment processor gives us an opaque identifier for the card you used. We store only a one-way hash of it, never the card number and never the last four digits, and only to keep an offer limited to one per payment card. It is described under Data retention, where its 18-month window is set out.
We do not ask you for your name, physical address, date of birth, phone number, card details, or government identifiers — card details go to our payment processor and never to us. We do not collect precise geolocation. We do not buy personal information about you from data brokers, we do not use tracking pixels or advertising cookies, and we do not run third-party advertising on the Service.
3. How we use information
We use the information above to:
- authenticate you and keep your session working (email, session tokens);
- operate, maintain, secure, debug, and improve the Service (usage and log data);
- prevent abuse, fraud, and automated scraping;
- send service emails — sign-in links and important account or policy notices. We do not send marketing email without your consent, and any marketing email we ever send will be identifiable as an advertisement and carry a working unsubscribe link. Our emails contain no tracking pixels and no per-recipient identifiers in any link or image — the only image is our logo, served from our own site at the same address for every recipient.
- send marketing email, only if you ask for it — there is an unchecked checkbox beside the sign-in form. Leaving it alone is the default and nothing about signing in depends on it. If you tick it while creating your account, we record what you agreed to: the exact sentence shown to you, the date, and the coarse network you were on, never your full IP address. If you already have an account, the setting is yours to change in Settings and signing in again never changes it for you. You can turn it off at any time in Settings, or from the unsubscribe link in any marketing email — either one stops the mail. We keep the record of an opt-in even after you opt out, and we keep the record of the opt-out too; the later of the two is what governs whether we may send you anything.
- comply with legal obligations.
We do not sell your personal information. We do not share it with third parties for their own advertising or for cross-context behavioral advertising, and we do not use it to train machine-learning models — our statistical models are built on public sports data, not on user data.
4. Service providers (third-party processors)
We rely on a small set of providers that process data on our behalf to run the Service. This is the complete list:
- Hosting, database, and CDN — Fly.io (application hosting), Neon (database), and Cloudflare (content delivery, proxying, and protection against automated abuse). Requests to the Service pass through or are stored with these providers. Cloudflare also measures page performance and traffic for us with its cookieless Web Analytics: it records the page, the referring page and timing, sets no cookie, and builds no cross-site profile of you.
- Email delivery — Resend, which processes your email address to deliver sign-in links and service emails.
- Google Identity Services — used only if you choose "Continue with Google" to sign in: Google verifies your identity and returns your verified email address to us. We keep only that email address — we do not store your name, your profile picture, or your Google account identifier. Our typefaces are served from our own site, so Google receives nothing from an ordinary page load.
- Business email and support mail — Google Workspace hosts our mailboxes, so anything you send to our support address — including a privacy or deletion request — is stored and processed there.
- Support telephone — Twilio operates the support line printed at the end of this policy. If you call, Twilio processes your telephone number and holds any voicemail you leave, together with an automatic transcript of it.
- Postal mail — iPostal1 operates the mailing address printed at the end of this policy, and receives, scans and forwards anything you send there.
- Error monitoring — Sentry, which receives technical details of an error that occurs while you are using the Service. Email addresses are stripped before an error report is sent to Sentry, from our servers and from your browser alike.
- Sports and odds data — The Odds API and public sports-data sources supply the data we analyze. These providers receive requests from our servers, not your personal information.
Each provider processes only what it needs to perform its function, under its own security and privacy commitments.
5. Other disclosures
We may disclose personal information:
- when required by law — in response to a valid subpoena, court order, or other lawful request, and we will notify you where we are permitted to do so;
- to protect rights and safety — where we reasonably believe disclosure is necessary to investigate fraud or abuse, enforce our Terms, or protect the rights, property, or safety of any person;
- in a business transfer — if we are involved in a merger, acquisition, financing, or sale of assets, in which case we will notify you and the acquirer will be bound by commitments no less protective than these.
We will not disclose your personal information to any sportsbook, gambling operator, or data broker.
7. Data retention
We keep account information (your email address) for as long as your account exists. Server logs are retained for a limited operational window and then deleted or aggregated. Your sign-in history is kept for up to 18 months and then deleted, and is permanently erased with your other account records within 30 days if you delete your account. If you request account deletion, we remove your personal information within a reasonable period, except where a legal obligation requires longer retention or as described in the paragraphs below.
A closure leaves a closure record behind, and deliberately so: one-way hashes of your email address — including a normalised form, so an alias of it is treated the same — the date, whether you closed the account, asked to be self-excluded, or we closed it, and, where one of our operators recorded one, a short internal note. If you asked us by email to be excluded, it also holds a reference to the message we checked that request against and the date we checked it — that is how an exclusion stays distinguishable from one nobody asked for. There is also a closure record for someone who had no account left to close when they asked to be excluded. It has no retention end. Those hashes are what a self-exclusion is enforced against, and an exclusion a later sign-up could reset would be a promise with a hidden end date — so the record has to outlive the account it came from. They are one-way hashes rather than stored copies of your address, and they are used only to refuse a new sign-in from an excluded address and as the record that the closure happened — never for marketing, analytics or profiling. If you asked to be excluded — or if mail to you bounced, or you reported one of our messages as spam — your address itself also stays on our do-not-email list, for the same reason: a list that forgot would start mailing you again.
Anything you logged yourself — your bets and your bankroll entries — is not destroyed with the account either. The link to you is removed instead, so what is left is a row attached to nobody.
If you pay us, we keep a one-way hash of an identifier our payment processor derives from your card — never the card number, never the last four digits, and nothing that names you. It is what keeps an offer that is limited to one per payment card actually limited to one per payment card. We keep it for 18 months after the last payment on that card and then delete it automatically, and we keep it even if you close your account in the meantime — an offer limit a new sign-up could reset would not be a limit. It is never used for marketing, analytics, profiling or advertising, and it is not shared.
Consent records are the exception, and deliberately so: if you agreed to something — our subscription terms, or marketing email — we keep the record of what you agreed to and when, because that record is your protection as much as ours. The network your consent came from is recorded coarsely rather than as a full address, and is removed after three years. We record opt-ins only; declining is simply the absence of a record, never a stored "no". If you delete your account, the consent record stops being linked to you — your account row and your email address go, and what is left is the sentence and the date, attached to nobody.
8. Security
We use reasonable technical and organizational measures appropriate to our size and the sensitivity of the data: encrypted connections (HTTPS/TLS), passwordless sign-in so we store no passwords, short-lived single-use sign-in links, scoped credentials and secrets management, access controls, and deliberate data minimization. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify you as required by applicable law.
9. Your rights and choices
We extend these to everyone, wherever you live:
- Access — ask what personal information we hold about you. For most users this is an email address.
- Portability — download your information in a portable, machine-readable form (JSON) yourself, from Settings. It covers your account record, your bets, your bankroll entries and your sign-in history.
- Correction — ask us to correct inaccurate information.
- Deletion — delete your account yourself, from Settings. Your email address is scrubbed and every session is signed out immediately; remaining records are permanently erased within 30 days. We keep only what a legal obligation requires, plus the narrow anti-abuse records described under Data retention: a one-way hash of your email address, which is what makes a self-exclusion permanent, and — if you asked to be excluded, or mail to you bounced — an entry on our do-not-email list. Neither is used for marketing, analytics or profiling; the closure record is also what we would read if a closure were ever disputed, or if we closed the account ourselves. If you have paid us, a one-way hash of the card identifier behind an offer limited to one per payment card is kept on the same footing, and is deleted 18 months after the last payment on that card. It holds no name, email address or card number, and it is not used for anything else.
- Opt out of marketing email — turn it off yourself in Settings, or use the unsubscribe link in any marketing message. Either one stops it; neither affects sign-in links, receipts or account notices, which are part of the Service and are not marketing.
Export and deletion are self-serve — you do not need to ask us, and we cannot delay them. For anything else, contact us (see Contact below). We will respond within 45 days, and we will not discriminate against you for exercising a right. We may need to verify that a request comes from you, which for most accounts means confirming control of the account email address. Depending on where you live you may have additional rights — for example under the California Consumer Privacy Act.
"Do Not Track" signals. Some browsers transmit a "Do Not Track" signal, and there is no common standard for interpreting it. We do not track users across third-party websites, so there is no cross-site tracking for such a signal to disable.
10. California residents
We do not sell or share personal information as those terms are defined under the California Consumer Privacy Act, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information for purposes that would require a right to limit. California residents may exercise the rights described above — including the right to know, delete, correct, and receive their information in a portable form — without discrimination.
11. Nevada residents
Nevada law gives consumers the right to submit a verified request directing an operator not to sell their covered personal information. We do not sell personal information. You may nonetheless submit a request to the address in the Contact section below with the subject line "Nevada Opt-Out", and we will respond within 60 days.
12. Users outside the United States
The Service is operated from, and directed to users in, the United States. We do not target our services to, or market in, the European Economic Area or the United Kingdom. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States, where privacy laws may differ from those in your country.
13. Age restriction
The Service is not directed to anyone under 21, and we do not knowingly collect personal information from anyone under 21. It is likewise not directed to children under 13. If we learn that we have collected personal information from anyone under 21, we will delete it and close the account. If you believe someone under 21 has provided us personal information, contact us.
14. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page, and for material changes we will make reasonable efforts to notify account holders by email at least 15 days before the change takes effect. Prior versions are available on request.
15. Contact and notices
Questions or requests about this policy or your data — including access, correction, deletion, and marketing opt-out requests — go to support@trueprops.app. We respond within 45 days and will not treat you differently for asking.
We are the controller of the personal information described in this policy. Our legal entity and postal address:
The postal address is a commercial mailbox, not a staffed office — written requests will reach us there, but email is faster and is the channel we monitor. The phone line is for support questions; it is not required for any request in this policy, and privacy requests are handled in writing so there is a record of them.