Privacy Policy

Last updated: 19 May 2026

We respect your privacy. This Policy explains what data Big Brainer Intelligence (“we”, “us”) collects, why, how we use it, and the choices you have.

1. What We Collect

We collect only the data we need to operate the Service:

  • Account data: email address, hashed password, display name, role (free / pro / premium), account creation date.
  • Authentication metadata: session tokens, last sign-in timestamp, IP address of sign-in events (handled by Supabase Auth).
  • Usage data: which pages you view, which matches you drill into, search queries — aggregated and anonymised for service improvement.
  • Subscription data (paid tiers only): billing email, payment processor reference (we do not store card numbers).
  • Optional: custom watchlists, journal entries — only if you create them.

2. What We DO NOT Collect

  • We do not sell your data. Ever.
  • We do not track you across the wider web.
  • We do not use third-party advertising networks.
  • We do not collect bank account details — payment processors do.
  • We do not require your real name.

3. Why We Collect It

  • Account management — to give you a personal account, remember preferences, and protect against abuse.
  • Service delivery — to gate features by subscription tier and provide personalised dashboards.
  • Communication — transactional emails (verification, password reset, billing receipts). We do not send marketing emails without explicit opt-in.
  • Service improvement— to understand what works and fix what doesn't.
  • Legal compliance — when required by law.

4. Where Your Data Lives

Your account data and profile are stored with Supabase (PostgreSQL infrastructure in the EU). Our application runs on Vercel (frontend) and PythonAnywhere (backend, UK region). Fixture and odds data come from API-Football. We choose providers with strong security practices and data-processing agreements that meet GDPR standards.

5. Cookies & Local Storage

We use the bare minimum needed for the Service to work:

  • Session cookies / tokens — to keep you signed in. These are essential and cannot be disabled.
  • Theme preference — stored in localStorage so the app remembers light/dark mode.
  • Profile cache — your role + display name cached for faster UI rendering.

We do not use analytics cookies, advertising trackers, or social-media pixels. If we add any in the future, you will see a consent banner first.

6. Your Rights

Under GDPR, the Tanzania Data Protection Act, and similar laws you have the right to:

  • Access — request a copy of the personal data we hold about you.
  • Rectify — correct inaccurate data.
  • Delete — request deletion of your account and all associated data.
  • Export — request your data in machine-readable form.
  • Object — to processing for legitimate-interest purposes (e.g. usage analytics).
  • Withdraw consent — at any time for processing based on consent.

To exercise any of these rights, email support@bigbrainer.app. We respond within 30 days.

7. Data Retention

We keep your account data for as long as your account is active and for a reasonable period afterwards to support disputes and legal obligations. On account deletion, we erase identifying data within 30 days. Aggregated, de-identified analytics may be retained indefinitely.

8. Children

The Service is not directed at children under 18. We do not knowingly collect data from anyone under 18. If we learn that a child has provided data, we will delete it.

9. Security

Passwords are hashed (bcrypt via Supabase) — we never see them in plaintext. All traffic is encrypted in transit (HTTPS). Database access is restricted to least privilege. We monitor for unauthorised access. Despite best efforts, no system is perfectly secure; report suspected breaches to security@bigbrainer.app.

10. International Transfers

Your data may be transferred to and processed in countries other than your own (EU, UK, US). We rely on standard contractual clauses and equivalent safeguards approved by EU and Tanzanian data-protection authorities.

11. Changes to This Policy

We may update this Policy from time to time. Material changes will be communicated via email or in-app notice. The “Last updated” date at the top reflects the current version.

12. Contact

Data protection questions: privacy@bigbrainer.app. General support: support@bigbrainer.app.