Legal · Privacy Policy

Privacy Policy.

Effective: May 25, 2026 Last updated: May 25, 2026 Version: 2.0

00Plain-English summary

Short version:
  • We collect the minimum data needed to run SmarterPicks: your Whop account info (email, name, user ID, subscription status), your IP address for rate-limiting our APIs, and — if you opt in — your newsletter email.
  • We don't see or store your payment card. Whop is the merchant of record and handles billing.
  • We don't use Google Analytics, the Meta pixel, or any third-party advertising / tracking pixels. There are no advertising cookies on this site.
  • Auth tokens stay in your browser's localStorage. We don't have a backend database of users.
  • If you use the AI Pick Explainer chat, your questions and the pick context are sent to Anthropic to generate a reply. We don't store those conversations on our servers.
  • You can request access, correction, deletion, or export of your data at any time — email privacy@smarterpicks.io.
  • We do not sell or "share" your personal information for cross-context behavioral advertising. Ever.

01Scope & who we are

This Privacy Policy describes how SmarterPicks ("SmarterPicks," "we," "us," or "our") collects, uses, discloses, and protects personal information when you visit smarterpicks.io, the SmarterPicks Terminal, the members area, our newsletter, and any related pages (collectively, the "Service").

It applies to everyone who interacts with the Service — visitors, free-trial users, paying members, and anyone who emails us. It does not cover third-party sites we link to (Whop checkout, Discord, sportsbooks, news sources) — each of those is governed by its own privacy policy.

For the purposes of the EU/UK General Data Protection Regulation, SmarterPicks is the controller of the personal data described here.

02Data we collect

Below is the full list. If a category isn't on this table, we don't collect it.

Whop account dataidentity
When you sign in with Whop OAuth, Whop sends us your user ID, email address, username/display name, and your subscription / access status for SmarterPicks. We do not request, and Whop does not send, your card details, billing address, or government ID.
Browser storageauthentication state
After login, your browser stores the following keys in localStorage on your device:
  • whop_token — short-lived Whop access token
  • whop_refresh — refresh token used to renew the access token
  • whop_user_id — your Whop user ID
  • whop_user — your Whop user object (name, email, avatar URL)
  • whop_access — your subscription access flag
During the OAuth handshake we also use sessionStorage.whop_pkce to hold a temporary PKCE state/verifier; it is cleared once the callback completes. These keys are read only by SmarterPicks JavaScript and sent only to whop.com APIs.
IP addressrate limiting
When you call our APIs (Terminal data feed, AI Pick Explainer, newsletter signup), Vercel passes your IP via the x-forwarded-for header. We hold it in an in-memory counter for at most one minute to enforce per-IP request limits and prevent abuse. It is not written to a database, logged persistently, or correlated with your account.
AI chat contentonly if you use the chat
If you use the AI Pick Explainer on a pick card, the question you type and the relevant pick context (league, teams, the pick, odds, the model's stated reasoning, your prior turns in that conversation) are sent through our server to Anthropic to generate a reply. We do not retain the conversation on our servers after the reply is returned. Anthropic's own retention is governed by their Privacy Policy and our API Terms with them.
Newsletter emailonly if you sign up
If you submit your email to the newsletter form, our /api/newsletter endpoint forwards it (with your IP, for spam protection) to the email-service provider configured in our NEWSLETTER_WEBHOOK_URL environment variable — currently Beehiiv. We do not store newsletter signups on our infrastructure; the ESP is the system of record.
Support emailsonly if you email us
If you contact support@smarterpicks.io or privacy@smarterpicks.io, we receive your email address, the message content, and any attachments. We retain support correspondence for up to 24 months for service quality and dispute resolution unless you ask us to delete it sooner.
Server / access logsoperational
Vercel — our hosting provider — produces standard server logs containing request method, path, status code, response time, country (derived from IP), and a truncated user agent. Vercel retains these for the period stated in their policy (typically up to 30 days for standard logs). We use these only to monitor uptime and debug errors.

Data we explicitly don't collect

03How we use it

We use the data above only for these specific purposes:

  1. Provide the Service. Authenticate you, show you the right tier of content (free vs. members-only picks), display your name in the members area.
  2. Operate, secure, and improve the Service. Rate-limit APIs to prevent abuse, monitor uptime, debug errors, prevent fraud.
  3. Provide the AI Pick Explainer. Forward your chat input and the relevant pick context to Anthropic so the model can reply.
  4. Send transactional or service messages. Confirm a free-trial signup, notify you of policy changes, respond to your support emails. These are not marketing.
  5. Send the newsletter — only to addresses that opted in via the form. Every newsletter includes a one-click unsubscribe link.
  6. Comply with law. Respond to lawful requests, enforce our Terms, defend legal claims.

We do not use your data for: advertising profiling, automated decision-making with legal effects, training third-party AI models on your conversations, selling to data brokers, or any cross-context behavioral advertising.

04Who we share with

We share personal data only with the service providers below — each acts as a processor (GDPR) / service provider (CCPA) on our behalf, under contractual terms restricting use to providing the contracted service. We do not sell personal information for monetary or other valuable consideration. We do not "share" it for cross-context behavioral advertising as those terms are defined under CPRA.

Whopprocessor
Authentication, subscription management, billing, refunds, customer identity. Receives everything required to verify your subscription and process payments.
Anthropic, PBCprocessor
Powers the AI Pick Explainer. Receives only your chat input and pick context when you use that feature. Per our API Terms, Anthropic does not train its models on your inputs without consent.
Vercel, Inc.processor
Hosts the Site and serverless functions. Sees IP, request URL, response status, and request body in transit while a request is being served. Operates as a sub-processor for everything above.
Beehiiv, Inc.processor
Newsletter delivery and list management. Receives only the email address you submitted to the newsletter form, plus the timestamp and IP captured for spam protection.
Discord, Inc.third party (external)
We link to our Discord server. We don't share your data with Discord; if you join, your interactions there are governed by Discord's own policies.
Synthesiathird party (external)
Hosts the explainer video on our homepage. The lite-embed pattern delays loading any Synthesia code until you click play. If you click play, Synthesia receives standard request metadata (IP, user agent, referrer).
Google Fontsthird party (external)
Serves the typefaces used across the Site. Google sees your IP and user agent in the font request. We use only the CSS API; no Google tracking scripts run on the Site.
The Odds APIupstream data
Provides odds and lines that appear in the Terminal. We make server-to-server calls; no user data is sent.
ESPN public APIsupstream data
Provides scoreboards, news headlines, and injury reports that appear in the Terminal. We make server-to-server calls; no user data is sent.

We may also disclose information if we believe in good faith it is necessary to (a) comply with a subpoena, court order, or other legal process; (b) enforce our Terms; (c) protect the rights, safety, or property of SmarterPicks, our users, or the public; or (d) facilitate a merger, acquisition, or asset transfer — in which case we will notify you in advance and your data will continue to be subject to a policy at least as protective as this one.

If you are in the European Economic Area, United Kingdom, or Switzerland, Article 6 of the GDPR requires us to identify a legal basis for each processing activity:

06Cookies, local storage & similar technologies

SmarterPicks does not set first-party cookies on its own domain. We use the browser's localStorage and sessionStorage for the keys enumerated in Section 2. These are strictly necessary for the Service to remember that you're signed in.

Third-party services we embed (Synthesia video player, if you click play; Google Fonts; Whop login flow on whop.com) may set their own cookies in your browser when their code runs. Those cookies are governed by their respective privacy policies linked in Section 4.

You can clear SmarterPicks storage at any time by signing out (which calls localStorage.removeItem on every whop_* key) or by clearing site data in your browser. We do not block functionality if you do — but you'll need to sign in again.

07Retention

08Security & breach notification

We protect personal data with technical and organizational measures appropriate to the risk:

If you suspect a security issue, please email security@smarterpicks.io rather than posting publicly. We commit to acknowledging reports within 72 hours.

If we learn of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority within 72 hours as required by GDPR Art. 33 and notify affected users without undue delay where required by Art. 34 or by applicable US state law.

09International data transfers

SmarterPicks is operated from the United States. If you access the Service from outside the US, your information will be transferred to, processed in, and stored in the US and potentially other countries where our processors operate (e.g., Anthropic, Vercel, Whop, Beehiiv all process data primarily in the US).

For transfers from the EEA, UK, or Switzerland to the US, we rely on the Standard Contractual Clauses (SCCs) adopted by the European Commission and the UK International Data Transfer Addendum where applicable, supplemented by the technical measures described in Section 8. Where our processors participate in the EU-US Data Privacy Framework, we rely on that adequacy decision in addition to SCCs.

You can request a copy of our SCC-backed agreements with a specific processor by emailing privacy@smarterpicks.io.

10Your rights

Subject to applicable law, you have the right to:

How to exercise these rights

Email from the email associated with your account. We will verify your identity (typically by sending a confirmation link to that address), respond within 30 days, and let you know if we need to extend by up to 60 more days for complex requests. There is no charge for the first request in a 12-month period.

You may use an authorized agent to submit a request on your behalf; we will require documentation of their authority and may verify directly with you.

11California residents (CCPA/CPRA)

If you are a California resident, the California Consumer Privacy Act (as amended by the CPRA) gives you specific rights with respect to your personal information.

Categories collected in the last 12 months

We collect these from you directly (when you sign up, type in chat, submit the newsletter form) and from Whop (when you authenticate via OAuth). The business purpose for each category is described in Section 3. The processors we disclose to are listed in Section 4.

"Sale" and "sharing" of personal information

SmarterPicks does not sell personal information for monetary or other valuable consideration. SmarterPicks does not "share" personal information for cross-context behavioral advertising as defined by CPRA. We have not done so in the preceding 12 months and have no plans to do so.

Because we do not sell or share, there is no "Do Not Sell or Share My Personal Information" link in our footer — there is nothing to opt out of. If we ever change that, we will add the link and disclose the change here.

Sensitive personal information

We do not collect, use, or disclose sensitive personal information beyond what is necessary to perform the service you requested (e.g., your account email). Accordingly, the right to limit use of sensitive PI under CPRA § 1798.121 does not apply, but you may still email us with any such request.

Your California rights

In addition to the rights in Section 10, you have the right to:

To submit a California rights request, email privacy@smarterpicks.io with the subject line "California Privacy Request." We will verify your identity using the email associated with your account.

Shine the Light

California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for direct-marketing purposes. We do not share personal information for third-party direct-marketing.

12Other US state privacy laws

If you are a resident of Virginia, Colorado, Connecticut, Utah, Iowa, Indiana, Texas, Montana, Oregon, Delaware, New Hampshire, New Jersey, Kentucky, Maryland, Minnesota, Nebraska, Rhode Island, Tennessee, or another US state with a comprehensive privacy law in effect, you have rights similar to those described in Sections 10 and 11 — including the right to access, correct, delete, port, and opt out of targeted advertising, sale, or certain profiling.

We do not engage in targeted advertising, do not sell personal data, and do not conduct profiling that produces legal or similarly significant effects, so the opt-outs available under these statutes have nothing to apply to today. If you still wish to file a request, email privacy@smarterpicks.io and we will respond within the statutory timeframe (typically 45 days, extendable by 45 more for complex requests).

You may appeal a decision regarding your request by replying to our response email; we will respond to the appeal within 60 days. If your appeal is denied you may contact your state Attorney General.

13Age requirement & children

The Service is intended only for adults 21 years of age or older in jurisdictions where sports wagering is legal. We do not knowingly collect personal information from anyone under 21, and the Service is not directed at children under 16 within the meaning of GDPR Art. 8 or under 13 within the meaning of COPPA.

If we learn that we have collected personal information from a person under the required age without verifiable parental or guardian consent, we will delete it promptly. Parents or guardians who believe their child has provided us with personal information should email privacy@smarterpicks.io.

14Do Not Track & Global Privacy Control

Some browsers transmit "Do Not Track" (DNT) or Global Privacy Control (GPC) signals. Because we do not sell or share personal information and do not run cross-site tracking, our handling does not change based on those signals — there is nothing for them to opt out of. We treat valid GPC signals received from California residents as a deemed opt-out request for any "sale" or "sharing" that might apply in the future.

15Changes to this policy

If we materially change how we collect, use, or share personal information, we will:

Prior versions are kept in the public GitHub repository where this Site lives, so the change history is auditable.

16Contact & complaints

For any privacy question, request, or complaint:

Privacy contact

Email:
General support:
Security:

Postal mail: c/o SmarterPicks · 1207 Delaware Ave #1145 · Wilmington, DE 19806 · USA. (Mail-handling address; please prefer email for faster response.)

EEA/UK supervisory authority complaints: If you believe we have not handled your data properly, you have the right to lodge a complaint with your local data-protection authority. A list of EU supervisory authorities is available at edpb.europa.eu. UK residents can complain to the Information Commissioner's Office at ico.org.uk.

US state attorneys general: Most US state privacy laws allow you to complain to your state attorney general. California residents can contact the California Privacy Protection Agency at cppa.ca.gov.