Privacy Policy
Last updated: September 29, 2026
The short version. We collect what we need to run the service: your email address, your questions and the answers to them, your watchlist, and any trading accounts you choose to connect. Your questions are processed by an AI provider (Google) to generate answers. Payments go through Stripe, and we never see your card number. We do not sell your personal information, and we do not use advertising or tracking cookies. You can ask us to see or delete your data at any time.
This Privacy Policy explains how ProjectionsLab ("we," "us") collects, uses, shares and protects information when you use projectionslab.com, golfapp.projectionslab.com, our API and connector endpoints, and our emails (the "Services"). It is part of our Terms of Service.
1. Information we collect
Information you give us
- Account information: your email address, which we use to create your account and send you sign-in links. We do not use passwords.
- Questions and conversations: the messages you send the Trade Assistant and the answers it gives, saved as your chat history, plus any ratings you give answers.
- Watchlist and lineups: the markets, assets, games and public wallet addresses you save, and DFS lineups you build or save, including any salary file you upload to build one.
- Connected accounts (optional):
- Kalshi: your API key ID and private key.
- Polymarket US: your API key ID and secret key.
- Polymarket: a public wallet address (no private key).
- API keys (eligible plans): a label you choose and usage counts. We store only a one-way hash of each key, not the key itself.
- Communications: what you send us when you email support.
Information created as you use the Services
- Call records: when the Trade Assistant takes a position in an answer, we record the market, side, stated probability, the market price at the time, a short summary of the reasoning, and later whether it was right.
- Usage and billing records: your plan, question counts and limits, credit balance, subscription status, and the time, processing cost and outcome of each question.
- Email records: which emails we sent you, whether they were delivered, and your email preferences.
- Agreement records: the date you agreed to our Terms of Service and this Privacy Policy, and which version you agreed to.
Information from payment processing
Stripe processes all payments. We receive and store your Stripe customer ID, your plan and your subscription status. Stripe collects your card details and billing information under its own privacy policy. We never receive or store your full card number.
Technical information
Like any website, our hosting and database providers receive your IP address, browser and device details, and request logs when you use the Services. We use these for security, abuse prevention and troubleshooting. Your browser stores your sign-in session, a few display preferences, and a short-lived note that you ticked the agreement box in local storage. We do not use advertising cookies, analytics trackers, tracking pixels or third-party ad networks. Our pages load a font from Google Fonts, which gives Google your IP address and browser information.
2. How we use information
- To provide the Services, including answering your questions, showing your history, watchlist and portfolio, and building lineups.
- To run your account and plan: sign-in, question limits, credits, billing and API access.
- To send emails: sign-in links and purchase confirmations, plus optional reports and highlights. You can turn off the optional ones with one click.
- To measure and improve the assistant. Graded call records from all users are combined in de-identified form. That lets us compute the assistant's track record and calibration and derive general lessons it applies to everyone. Examples of its calls (the market, prices and reasoning, never who asked) may appear in product emails and on the site.
- To keep the Services secure, prevent fraud and abuse, and enforce our Terms.
- To comply with law, and to respond to lawful requests.
We do not use your information for targeted advertising, and we do not make decisions about you that have legal or similarly significant effects based solely on automated processing.
3. AI processing
To answer a question, we send it to our AI provider, Google (Gemini), along with the context needed to answer. That context can include your recent conversation, your watchlist, and any positions from accounts you have connected. Some questions also trigger web searches, which send search terms derived from your question to Google. Google processes this under its terms for paid API services, and states that it does not use that content to train its models. Please do not put sensitive personal information in your questions.
4. How we share information
We share personal information only as described here:
| Who | Why |
|---|---|
| Cloudflare | Hosts the website and runs our servers |
| Supabase | Database and sign-in (authentication) |
| AI answers (Gemini), web search for answers, and website fonts | |
| Stripe | Payments, subscriptions and billing |
| Resend | Sending email, including sign-in links |
| Kalshi, Polymarket US, Polymarket | Only if you connect an account. We contact them with your credentials or wallet address to read your account data |
These providers may process information only to provide their services to us. We also get sports, market and odds data from public sources such as league and sports-data sites, exchanges and DFS platforms. Those requests do not include your personal information.
We may also disclose information:
- if required by law, subpoena or court order;
- to protect the rights, safety or property of our users, the public or ProjectionsLab;
- to investigate fraud or violations of our Terms;
- as part of a merger, acquisition, financing or sale of assets, in which case we will tell you before your information becomes subject to a different privacy policy;
- with your consent.
If you joined through an affiliate or referral partner, we may tell that partner how many customers they referred and the payments attributable to them. We do not share your questions, history or connected-account data with partners.
We do not sell your personal information, and we do not "share" it for cross-context behavioral advertising, as California law defines those terms. We have not done so in the past 12 months.
5. How long we keep it
- Account, chat history, watchlist and lineups: for as long as your account exists, or until you delete them or ask us to.
- Connected-account credentials: until you disconnect the account, your paid plan ends, or you delete your account, whichever comes first.
- Billing records: as long as tax, accounting and legal requirements need them.
- De-identified call records and aggregate statistics: these may be kept after you delete your account, because they no longer identify you.
- Logs and backups: kept for limited periods and deleted on a rolling basis.
6. Security
- Connected-account credentials are encrypted with AES-256-GCM before we store them.
- API keys are stored only as one-way hashes.
- Data is sent over encrypted connections, and database access is restricted per account.
No system is perfectly secure, and we cannot guarantee absolute security. If a breach affects your personal information, we will notify you as the law requires.
7. Your choices and rights
- Email: every report or highlights email has a one-click unsubscribe link. Sign-in and purchase emails are transactional and cannot be turned off.
- Connected accounts: disconnect at any time from Integrations in the Trade Assistant. This deletes the stored credentials.
- Access, correction, deletion and a copy of your data: email [email protected] from your account's email address. We will respond within 30 days, and within 45 days where California law gives us that long. We may need to confirm the request came from you. Deleting your account removes your profile, chat history, watchlist, lineups, connected accounts and API keys. Billing records and de-identified data are kept as described in Section 5.
California residents have the right to know what personal information we collect, use and disclose; to delete it; to correct it; and to opt out of its sale or sharing (we do neither). You may also have an authorized agent make a request for you. We will not discriminate against you for exercising these rights. The categories we collect are:
- identifiers (email address, account ID, IP address);
- commercial information (plan and purchase history);
- internet activity (usage of the Services);
- financial account information (connected-account credentials and positions, if you connect them);
- inferences reflected in your call records.
We collect these from you, from your use of the Services, and from services you connect, for the purposes in Section 2.
Residents of other U.S. states with privacy laws, and people in the European Economic Area, United Kingdom or elsewhere, may have similar rights. Those can include the right to object to or restrict processing, and the right to complain to a data protection authority. Contact us to use them.
Where the law requires a legal basis, we rely on:
- performing our contract with you (providing the Services);
- our legitimate interests (security, and improving the assistant with de-identified data);
- your consent (optional emails, connected accounts);
- legal obligations.
We honor Global Privacy Control signals, although we do not sell or share data in the first place.
8. International users
The Services are operated from the United States, and our providers may process information in the United States and other countries. By using the Services, you understand that your information will be transferred to and processed in the United States, whose data-protection laws may differ from yours.
9. Children
The Services are not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child under 13 has given us personal information, contact us and we will delete it.
10. Changes to this policy
We may update this Privacy Policy. If a change is material, we will tell you in advance by email or through the Services. The date at the top shows when it last changed.
11. Contact
Privacy questions or requests: [email protected].