PickProof Privacy Policy

Last updated: September 12, 2026

This Privacy Policy explains how PickProof, LLC ("PickProof," "we," "us") collects, uses, stores, and shares information when you use PickProof.

1. Information We Collect

Account Information

We collect information you provide when creating or managing an account, such as:

Do not upload government IDs, payment card images, medical information, or other sensitive documents to PickProof unless a future feature specifically requests them.

Pick and Ledger Information

We collect and store Confirmed Pick data, including:

Confirmed Picks are designed to be immutable for record integrity.

Social, Moderation, and Public Record Information

We collect follows, followers, blocks, user/content reports, public picks, leaderboard rows, badges, public profile data, and public record metrics. Reports may include the reported account or pick, reason, optional details, review status, and timestamps.

Alerts and Device Information

If you allow notifications, we may collect:

Subscription and Billing Information

Subscriptions are processed by Stripe on the web and by the applicable app store through our native entitlement provider on Android/iOS. PickProof stores subscription plan or billing path, billing period, subscription status, product ID, provider ID, customer ID, renewal metadata, entitlement state, and related billing event metadata. Stripe or the relevant app store handles payment details. PickProof may offer a 7-day Pro trial that requires a payment method and renews as a $9.99-per-month Pro subscription if not canceled before the trial ends. PickProof may also offer an immediate monthly no-trial Pro subscription that is charged at checkout and renews monthly until canceled, or an annual Pro subscription that is charged at checkout and renews annually until canceled. Trial eligibility, charges, taxes, renewal timing, cancellation, refunds, and access through a paid period are subject to the rules of the payment provider or app store through which the subscription is offered.

To limit free-trial abuse, PickProof may create and retain keyed, one-way HMAC-pseudonymized values derived from a normalized email address, payment-provider customer identifier, and provider-supplied payment-method fingerprint. These values are used to enforce one trial per eligible customer, account, and payment method and cannot be used by PickProof to recover the original values. Payment providers handle payment-card data. PickProof does not store full card numbers, card security codes, or full payment-card details.

Technical Data

We may collect logs and operational data such as:

First-Party Aggregate Landing Counts

PickProof may keep short-lived, first-party aggregate landing counts for allowlisted campaign links. These counts store only an approved campaign code, UTC day, request method category, HTTP status class, bot category, and aggregate count. They count requests, not unique visitors, people, sessions, or conversions. GET and HEAD requests are counted separately, and browser-like or unknown requests are not treated as verified human visits.

PickProof may receive ordinary platform link decorations in the request URL, but non-approved query values are ignored immediately and are not stored by PickProof application counter code, sent by that counter to Google Analytics, used to identify a visitor, or shared by that counter with ad platforms. The counter does not store raw IP addresses, IP hashes, full URLs, raw queries, raw referrers, user agents, cookies, session IDs, fingerprints, account identifiers, pick details, sportsbook/team/odds/units data, or user-level histories. Existing provider security and diagnostic processing is separate and is not used for this marketing counter.

Optional Google Analytics and Firebase Analytics

PickProof uses Google Analytics 4 on the web and Google Analytics for Firebase in native mobile apps only if you opt in through the privacy or usage-analytics control.

Until you opt in, Analytics collection is disabled or denied. If you decline or later turn off Analytics, PickProof disables collection; on the web, PickProof attempts to delete Google Analytics cookies, and in the native app PickProof resets the app installation's Firebase Analytics data.

If you opt in, Google Analytics may collect limited traffic and usage data such as pages or static top-level screens viewed, sessions, engagement, app version, browser or device type, approximate location derived from IP address, referral/source information, and Google Analytics or Firebase identifiers. On the web, Google Analytics may set or read first-party cookies such as `_ga` and `_ga_*`. In native apps, Firebase Analytics may use an app-instance identifier and similar device or mobile identifiers.

After you opt in, PickProof may also send a small set of parameter-free account/subscription funnel events. On the web, those events may include `signup_start`, `sign_up`, `login`, `go_pro`, and `begin_checkout`; in native apps, those events may include `sign_up`, `login`, `go_pro`, and `begin_checkout`. These events record that the action occurred. They do not include account identifiers, email, username, picks, teams, sportsbooks, odds, units, prices, products, checkout amounts, form input values, or other event parameters.

Native Firebase Analytics is denied by default, uses SecureStore to remember your choice, and can be changed in Help or any available usage-analytics control. Native Analytics uses `analytics_storage` only after opt-in. `ad_storage`, `ad_user_data`, and `ad_personalization` remain denied. Android Analytics Advertising ID collection is disabled, iOS is configured without IDFA support, automatic screen reporting is disabled, and PickProof sends only these custom static screen names: `scores`, `odds`, `my_picks`, and `leaderboard`.

Google does not provide PickProof a per-event suppression control for every automatic Firebase Analytics event after Analytics is enabled. If you opt in on native mobile, Firebase Analytics may automatically collect limited app lifecycle, purchase/subscription lifecycle, or ad-interaction events depending on Google SDK, app-store, and ad SDK behavior.

PickProof does not send Google Analytics your PickProof account ID, email, username, picks, odds, sportsbook activity, profile content, reports, custom user-generated content events, custom event parameters, or event details beyond the limited opt-in event names described above. PickProof does not set Analytics user IDs. Google signals are off, and Analytics ads personalization is disallowed in all regions. The Analytics control is separate from advertising consent and does not grant or revoke separate advertising consent. On the web, ad storage, ad user data, and ad personalization are denied by default until a certified advertising consent-management platform responds where required.

After you opt in, PickProof may also use a first-party opaque campaign code to measure whether a PickProof campaign or social link led to an Android install, account signup, first Confirmed Pick, D1 or D7 pick activity, or Pro access. The campaign code contains no email, username, account ID, pick details, advertising identifier, raw URL, UTM value, click ID, referrer path, query, or hash. On the web, PickProof may convert an approved campaign URL into a fixed opaque campaign code for this attribution. On Android, Google Play Install Referrer may provide the code attached to the Play Store link. PickProof creates a random installation identifier, sends it only through an encrypted connection, and stores only a one-way hash on the server for deduplication. PickProof shares only identity-free campaign totals with its social-content learning system.

Google explains how it uses information from sites and apps that use Google services at https://policies.google.com/technologies/partner-sites.

Free-tier advertising and sponsored Pro Pick unlocks use Google Mobile Ads. Google and its advertising partners may receive device or other identifiers, IP-derived approximate location, app interactions, diagnostic information, and ad impression or engagement data. PickProof may also store limited unlock or impression metadata needed to enforce feature limits, troubleshoot delivery, and prevent abuse. Consent choices are requested where required, and PickProof requests non-personalized ads by default.

PickProof may also store source-audit metadata such as when odds, scores, line moves, grading, CLV capture, and alert workers last ran. This operational metadata helps keep the ledger accurate and detect source failures.

2. How We Use Information

We use information to:

3. Public Information

Public picks, public records, usernames, selected badges, avatars, leaderboard rows, and public profile information may be visible to other users.

Private picks are intended to remain hidden from public feeds and leaderboards unless a user-selected feature or future published rule says otherwise.

Avatar images and other profile media may be cached, resized, or moderated to operate the service. PickProof may remove or restrict uploaded media that appears unlawful, infringing, abusive, misleading, or otherwise inconsistent with PickProof policies.

4. Sharing

We may share limited information with:

We do not sell betting credits, wagers, deposits, or payout services.

We do not sell personal information for sportsbook wagering. Advertising tools are configured to avoid using PickProof as a gambling conversion or sportsbook affiliate funnel. PickProof does not intentionally display gambling advertising.

5. Data Retention

We retain information for as long as needed to operate PickProof, preserve record integrity, comply with law, prevent abuse, resolve disputes, and maintain backups.

When you complete in-app account deletion, PickProof deletes the account and associated profile, picks, follows, settings, push tokens, and public account data. Limited provider transaction, security, tax, legal, abuse-report, and backup records may be retained where legally required or reasonably necessary, with account identifiers removed where appropriate.

The HMAC-pseudonymized email, payment-provider customer, and payment-method fingerprint values used to enforce one-trial eligibility may be retained after account deletion so that deleting or recreating an account does not reset trial eligibility. These retained values are limited to fraud and abuse prevention and do not contain full card details.

Generated receipt images, QR verification data, line-move history, source snapshots, and audit logs may be retained to prove when a Confirmed Pick was created and whether it was altered. PickProof may later purge large generated media after the related game has completed while retaining the underlying verification record.

Optional Google Analytics/Firebase Analytics data is retained under PickProof's unified Google Analytics property retention settings and Google's Analytics controls. PickProof's current GA4/Firebase setup uses 2-month event data retention and 2-month user data retention, with reset on new user activity turned off. Standard aggregated Analytics reports may remain available separately without the same user-level or event-level retention period.

Raw Android install-attribution hashes are retained for up to 90 days. Account-linked campaign attribution is deleted when the associated PickProof account is deleted. Identity-free aggregate campaign reports may remain after deletion because they cannot be used to identify an account or installation.

Detailed first-party aggregate landing-count rows are kept for up to 30 days and then deleted. These rows are not joined to account-linked campaign attribution or provider security logs.

6. Your Choices

You can:

You can also choose whether your avatar, selected badge, and public profile elements are displayed where those settings are available.

Turning Analytics off stops future optional Analytics collection and, where supported, resets or deletes local Analytics identifiers or cookies. You may also use browser or device controls to limit cookies, advertising identifiers, or analytics storage.

If you cannot access the in-app deletion tool, contact the privacy email below.

7. Security

We use reasonable technical and organizational measures to protect information. No system is perfectly secure, and PickProof cannot guarantee absolute security.

8. Children

PickProof is not intended for children. PickProof is intended for adults who may lawfully use sports-information and analytics services in their location. PickProof does not knowingly collect information from children.

9. International and State Privacy Rights

Depending on your location, you may have rights to access, correct, delete, or restrict certain data. Contact us to make a privacy request.

10. Changes

We may update this Privacy Policy as PickProof changes. Continued use after an update means the updated policy applies.

11. Contact

Operator: PickProof, LLC, Louisiana, United States

Privacy contact: [email protected]

© 2026 PickProof, LLC. All rights reserved.

This Privacy Policy should be reviewed by qualified counsel before public launch.