1. Data we collect
Account and verification data. If you create an account through the website or mobile app, we process the full name and email address you provide when those fields are requested, together with authentication provider identity metadata such as the provider name, provider-specific account ID and verification status. For password sign-up, Supabase stores a secure representation of the password; Oddzy cannot read it. For Google or Apple sign-in, the provider authenticates you and Oddzy does not receive your Google or Apple password. We also keep account status and security metadata such as email-verification status and timestamps, the date and version of the Terms you accepted, and confirmation that you met the stated age requirement.
Free-trial eligibility. For each account with a confirmed email address, Oddzy stores a one-way code derived from that address, made with a secret key held only in our database, together with the date the address was first used. It lets us recognise an address that has already had Oddzy’s free trial, so each address receives the trial once. Before the code is made, the address is lower-cased and anything after a “+” is removed; for Gmail addresses, dots are removed too, so variations of one address count as the same address. The code contains no email address, name or account ID, cannot be converted back into the address, and is used only to decide free-trial eligibility.
Subscriptions and App Store purchases. Oddzy Pro subscriptions are currently sold only through Apple in-app purchase in the iOS app. Apple processes the payment, so Oddzy never receives your card or bank details. When you buy or restore a subscription, or Apple notifies us of a change to it, we receive Apple’s signed transaction and notification data and keep the details it contains, including transaction ids, the product, purchase, expiry and grace-period dates, the environment (live or test), auto-renew and billing-retry status, revocation or refund status, and the price, currency and App Store country or region that Apple reports. This data is linked to your account’s internal user id so that the subscription unlocks your account. We also keep the start and end dates of your account’s free trial.
Session data. When you sign in, essential authentication cookies on the website or session data in the mobile app keep you signed in and protect access to member features. They are required for the account service and are not used for advertising or cross-site profiling.
Technical, interaction and diagnostic data. Oddzy and its hosting providers may record standard request and service logs, including IP address, request time, user agent, requested page or API endpoint, response status, error and diagnostic details, and similar app-interaction information. We use this information to deliver the Service, prevent abuse, investigate faults and understand whether core features are operating correctly. We do not use a third-party mobile analytics or crash-reporting SDK.
Network and device signals. A hosting, security, image or content-delivery provider may infer an approximate location from an IP address and may receive ordinary browser, operating-system, device and request identifiers. Oddzy does not request precise GPS location for the Service and does not use an advertising identifier to build an ad profile.
Mobile applications. The current Oddzy mobile app offers email/password account creation and sign-in, together with Google sign-in. Authentication requests are handled by Supabase and, for Google sign-in, by Google; Oddzy does not receive a Google password. The app also requests published schedules, results and forecasts over the internet, so the account, network, interaction and diagnostic data described above may be processed when you use it. The current native release uses text initials in place of third-party player portraits and team badges.
2. What we do not do
We do not operate advertising networks, embed third-party analytics SDKs or marketing pixels, or build cross-application advertising profiles. We do not sell personal data or share it for cross-context behavioural advertising. Oddzy does not intentionally collect precise GPS location, biometric or health data, contacts, private photographs, or payment card details as part of the Service. Approximate location or device signals derived from an ordinary network request are covered in section 1.
3. Forecast and result records
Oddzy keeps an append-only record of forecasts it publishes and the verified sporting results against which they are graded. These records describe events and model outputs; they are not designed to identify a user and are not linked to an Oddzy account.
4. Why we process data, and on what basis
Account, verification and session data are processed to provide the account service you request and to enforce its terms. Network, interaction, security and diagnostic data are processed to deliver a reliable Service, protect Oddzy and its users, prevent misuse and resolve faults. Subscription and App Store purchase data are processed to provide the subscription you buy, keep refunds and subscription history correct, prevent refund fraud, handle billing disputes and meet legal obligations. These purposes rely on performance of our contract, our legitimate interests, compliance with law, or consent where the law requires it.
5. Service providers and direct media requests
We use a small number of service providers to run Oddzy: Supabase for authentication and database storage, Vercel for website hosting, Render for the prediction API, and Upstash for caching published sports data. These providers process account or technical data as needed to deliver, secure and maintain the Service for us.
Apple is the payment processor for subscriptions bought in the Oddzy iOS app. Apple takes the payment under its own terms and privacy policy and sends us the purchase details described in section 1. It does not send us card or bank details.
Our servers also retrieve schedules, results and market data from sports-data providers. Those server-side feed requests concern fixtures and events and are not sent with your Oddzy account profile.
Where Oddzy shows a team crest or a fighter photograph, that image is loaded by your device directly from a third-party sports image host or content-delivery network, currently API-Sports and SportMonks. A direct request necessarily gives that provider ordinary network information such as your IP address, user agent, request time and the requested image address. Oddzy does not send your password or account profile with that image request, and the image address identifies a team or fighter rather than you. The provider handles the request under its own privacy terms.
6. International transfers
Our providers operate infrastructure in several regions, so personal data may be processed outside the country in which you live. Where such transfers occur, they rely on the transfer mechanisms and safeguards offered by those providers, including standard contractual clauses where applicable.
7. Retention and deletion
Account data is kept while the account exists and for only as long afterwards as needed to complete deletion, meet legal obligations, prevent fraud, resolve disputes or protect the Service. Technical and diagnostic logs are retained for a limited period under the relevant provider settings and operational need, then deleted or aggregated. Encrypted backups may take additional time to cycle out and are not used for ordinary operations. The free-trial eligibility code described in section 1 is kept after an account is deleted, because its only purpose is to stop the same email address receiving a second free trial. It is not linked to any account.
App Store purchase evidence is also kept after an account is deleted. It is Apple’s signed transaction and notification data described in section 1: transaction ids, the product, dates, the environment, and revocation or refund status. With it we keep an account-binding audit that records which Oddzy account each purchase was linked to, which can include a previous account’s internal user id. We keep both to keep refunds and subscription history correct, to protect against refund fraud, to handle billing disputes and to meet legal obligations. They are not used for marketing and never include card or bank details, because Apple processes payment. Deleting an account does not cancel an App Store subscription; cancel it in your Apple Account settings.
A signed-in account holder can permanently delete an account created on the website or in the mobile app, together with its associated account data, through the public Delete your Oddzy account page. Email is retained only as a fallback for a person who can no longer access the account.
8. Your rights
Depending on where you live, you may have the right to access the personal data we hold about you, correct it, request deletion, obtain a portable copy, object to or restrict certain processing, and withdraw consent where processing relies on it. You may also complain to your local data-protection authority.
To exercise a right, contact us using the details in section 11. We may need to verify that you control the relevant account before disclosing, changing or deleting its data, and we will respond within the period required by applicable law.
9. Security
Traffic to the Service is encrypted in transit. Passwords are handled as secure password representations by our authentication provider rather than stored as readable text. Administrative credentials are not exposed through the public Service. No system is perfectly secure, but we work to limit collection and access to what the Service needs.
10. Children
The Service is not directed at children. You must be at least 18 years old, or the age of legal majority where you live, to create an account or use adult-oriented features. We do not knowingly collect personal data from children. If you believe a child has provided personal data to Oddzy, contact us so the matter can be investigated and the data deleted where appropriate.
11. Contact
For privacy questions, rights requests or complaints, contact privacy@oddzy.in. For general help, see our support page.
12. Changes
If this policy changes, the date at the top of this page is updated. Where a change materially affects how personal data is handled, we will provide notice through the Service before it takes effect where required.