Legal
Privacy Policy
Last updated: September 17, 2026
This is a plain-language policy written to be genuinely readable, not a substitute for a lawyer's review -- have this reviewed before scaling beyond a small trusted group, especially if you'll ever have users in the EU/UK (GDPR) or California (CCPA), which impose specific additional requirements not fully covered here.
1. What We Collect
- Account info: your email address and authentication data (handled by Supabase Auth).
- Usage & app data: picks you choose to track, your bankroll figure, theme preference, and similar data you enter or generate while using the app.
- Device fingerprint: a non-identifying technical hash (browser, screen size, timezone, etc.) used only to detect the same device claiming more than one free trial. It is not used for advertising or tracking you across other sites.
- Subscription status: whether you have an active paid plan and which one, and your PayPal subscription ID -- we never see or store your card number, bank details, or PayPal password. All payment details are handled entirely by PayPal.
2. How We Use It
- To operate the service: show your tracked picks, calculate your tier-appropriate access, run the Oracle/Leaderboard/Bankroll tools against your own data.
- To prevent free-trial abuse (see the device fingerprint above).
- To respond to support requests.
- To improve the product (aggregate, non-identifying usage patterns).
We do not sell your personal data, and we do not share it with advertisers.
3. What Appears Publicly
If you subscribe to Entry+ and choose to have your results tracked, an anonymized handle (a hashed ID, e.g. "Trader_a1b2c3" -- never your email or name) and your win rate/ROI may appear on the public Leaderboard. The public marketing site's "Global Feed" shows generic system activity (new milestones reached, general signal activity) -- it never shows your personal data, and as of September 2026 it no longer shows specific pick details at all (team, odds, matchup are kept behind the paywall, not published to the logged-out marketing page).
4. Data Retention & Deletion
We keep your account data for as long as your account is active. To request deletion of your account and associated data, email inagge242@gmail.com. Some records (e.g. transaction history required for tax/accounting purposes) may be retained as required by law even after a deletion request.
5. Cookies & Local Storage
We use browser local storage for things like your light/dark theme preference and session tokens -- not third-party ad-tracking cookies.
6. Children's Privacy
OmniAlpha is not directed at, and is not intended for use by, anyone under 18. We do not knowingly collect data from children.
7. Security
Your data is stored with Supabase (Postgres with row-level security) and access to sensitive account/administrative functions is restricted server-side. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable, industry-standard measures to protect your data.
8. Changes to This Policy
We may update this policy from time to time; material changes will be flagged in the app.
9. Contact
Questions about this policy, or a data deletion request: inagge242@gmail.com.