Privacy Policy
Last updated: August 31, 2026 · Effective immediately for all users.
This is the only Privacy Policy for LINEHAWK. It supersedes every earlier version, including the separate document previously published at /privacy, which now redirects here. It shares its effective date with our Terms of Service and Financial Disclosure.
1. What we collect
Only what we need to run the Service:
- Account: email, hashed password (or an OAuth ID via Google/Apple — we never see your password), display name, handle.
- Profile you choose to add: avatar, favorite sports, timezone, notification preferences, and a private self-reported bankroll if you enter one.
- Billing: handled entirely by Stripe. We store only a Stripe customer ID, plan, subscription status and renewal date — never card data.
- Usage: pages viewed, session duration, anonymized IP — used solely for product analytics and security.
- Optional: phone number for SMS alerts and push subscription tokens, only if you opt in.
- Legal record-keeping: every disclosure acceptance and every export download, with timestamp and IP address.
2. What we don't collect
We do not collect government IDs, Social Security numbers, financial account numbers, or credit card details. We never sell, rent, or trade your data to third parties for advertising.
3. How we use it
- Provide and improve the Service
- Send the digests, alerts and notifications you opted into
- Surface the sport-specific content you prefer
- Detect and block security threats, fraud, and abuse
- Communicate billing and account changes
- Comply with law
4. Who processes it (vendor transparency)
Only the processors required to operate the Service: Supabase (database + authentication), Vercel (hosting), Stripe (payments), SendGrid (transactional email), Twilio (SMS alerts, only where you opt in), Anthropic, OpenAI, Google and xAI (AI inference on anonymized prompts — your personal data is not sent), Upstash Redis (caching), and the public odds feeds and regulated U.S. prediction-market venues whose prices we analyze.
Each processor is contractually required to protect your data and use it only to provide their service. These vendor names are listed for compliance transparency — none of them endorse or control LINEHAWK output.
5. Cookies
We use first-party cookies for authentication (signed-in sessions) and to remember your age-verification acknowledgement for 30 days. We do not use third-party advertising or tracking cookies.
6. Your rights (CCPA / GDPR)
You can:
- Access and download your data from your account page
- Delete your account at any time — all personal data is purged within 30 days
- Correct inaccuracies
- Opt out of marketing email (transactional email still sends)
- Disable SMS and push alerts from Alerts settings
California residents have additional rights under the CCPA. Email privacy@linehawk.bet to exercise any of these. We respond within 30 days.
7. Data retention
Account data is retained while your account is active. Usage data is retained for up to 13 months for analytics and is then aggregated and anonymized. Security event logs are kept for 90 days.
8. Security
TLS in transit and AES-256 at rest, the bankroll field encrypted at the row level, signed session cookies, row-level security on all data, an active intrusion-detection system, and all payment processing offloaded to PCI-compliant Stripe. We do not store passwords or card data.
9. Age — 21 and over
LINEHAWK is for users 21 and older. We do not knowingly collect data from anyone under 21. If you believe we have, contact us and we will delete it.
10. Changes
We may update this policy. Material changes are announced in-app and emailed to active accounts, and the date at the top is updated.