Privacy Policy
Last updated 30 September 2026
1. The short version
- We collect your email address, a hash of your password, and whatever you choose to put into the Service (a bet log, fantasy settings).
- We run no advertising, no tracking pixels and no third-party scripts. We count how the site is used — visits, which pages are opened, questions asked in Ask, plan buttons pressed, and trials and subscriptions started or ended — as daily totals only. The totals carry no cookie, no identifier and no IP address, and cannot say what any one person did. Nothing on this site follows you anywhere else.
- We never see your card details. Stripe takes the payment on its own page; we hold a customer reference and a status.
- We do not sell or share your personal information, and we never have. There is no advertising business here to sell it to.
- You can delete your account and everything attached to it from the account panel, yourself, at any time.
2. What we collect, and exactly where it lives
This is the complete list. Each item names the table it is stored in, so it can be checked against the code.
2.1 Account
- Email address — your login, and how we reach you about
your subscription. (
users.email) - A password verifier — a scrypt hash. We do not store
your password and cannot recover it; we can only reset it.
(
users.verifier) - Account created and last seen timestamps (last seen is
refreshed at most once a day while you are signed in).
(
users.created_at,users.last_seen) - That you confirmed you are 21 or over, and when you accepted
the Terms. (
users.age_confirmed,users.terms_accepted_at) - Session tokens, stored hashed, with an expiry. The cookie
in your browser is the only copy of the raw token; a stolen
database does not yield a working session.
(
sessions.token_hash)
2.2 What you put in
- Your bet log — the wagers you choose to record: sport,
market, price, stake, result. Entered by you, for your own
record-keeping. We do not place these bets and cannot see any
account you placed them on. (
user_data) - Your settings — bankroll size, unit size, fantasy league
preferences, alert choices. (
user_data, sectionsbankrollandfantasy) - Your search history on this site — the player and team
searches you run here, kept so the search box can offer them back
to you. This is our own search box only; it has nothing to do with
anything you search anywhere else, and there is a button on the
account page to clear it.
(
user_data, sectionsearch)
Those four sections — mybets, fantasy,
bankroll, search — are the complete list of
what an account can hold. It is the same list the code enforces
(accounts.SECTIONS); nothing else can be written against
your account.
2.3 Subscription
- A Stripe customer id and subscription id, the status, the
paid-through date, and which plan. That is the entire
payment-related record on our side.
(
subscriptions) - Stripe event ids we have already processed, so a repeated
webhook cannot grant twice. (
billing_events) - Discount codes you redeemed, and failed attempts, the
latter only to rate-limit guessing.
(
code_redemptions,code_attempts)
2.4 Server logs
Our web server keeps ordinary access logs — IP address, timestamp, path requested, user agent — as every web server does. They are used for security and debugging, are not joined to your account, and are not used to build a profile of you. Your IP address is also read at request time to enforce security rules (for example, refusing a password over an unencrypted connection); it is not written to any database table.
A security log records sign-ins, failed passwords, refused codes and blocked requests, so that an attack on an account can be seen: the time, what happened, the network the request came from (the first three parts of an IPv4 address, or the first three groups of an IPv6 one — not your full address) and, for account events, a short one-way tag made from the account’s email. It never holds a password, a code, a session token or the email itself, it is not joined to your account, and it is rotated as it grows.
2.5 Usage counts
- Usage counts (
analytics.counts): per day, an event name, the name of the page, a broad source (direct, search, social, another site, or a campaign link) and whether the visitor was signed in or subscribed, with a count. No identifier of any kind.
3. What we do NOT collect
- Your sportsbook password, or any betting-account credential. We never ask for them and there is nowhere on this Service to enter one. A DraftKings or FanDuel login can move real money and cannot be scoped or revoked by us, so we do not want it.
- Card numbers, expiry dates or security codes. These are typed on Stripe’s page and never reach our servers.
- Advertising or tracking cookies. There are none. No third-party analytics tags, no pixels, no fingerprinting, no third-party scripts of any kind.
- Your location. We do not request it, infer it, or store it.
- Your contacts, photos, files or device identifiers.
- Anything about children. See §9.
4. Why we use it (and the legal basis)
| What | Why | Basis |
|---|---|---|
| Email, password hash, sessions | To create your account and keep you signed in | Performance of a contract |
| Subscription record | To know whether you have paid, and to bill you | Performance of a contract |
| Your bet log and settings | To show them back to you across your devices | Performance of a contract |
| Age and Terms acceptance | To evidence eligibility | Legal obligation / legitimate interest |
| Server logs, failed code attempts | Security, abuse prevention, debugging | Legitimate interest |
| Email about your subscription | Receipts, renewal notices, service notices | Performance of a contract |
We do not use your data to train models. The models here are built from public sports statistics and market prices, not from subscribers.
5. Cookies
We set one cookie: a session cookie that keeps you signed
in. It is HttpOnly (JavaScript cannot read it),
SameSite-restricted, and marked Secure
when served over HTTPS. It contains a random token and nothing
about you.
Some preferences (theme, bankroll display) are kept in your browser’s local storage. That never leaves your device and we cannot read it.
There are no advertising, analytics or third-party cookies, which is why this site has no cookie banner: there is nothing to consent to.
6. Who else sees it
Each of these because they have to be involved, and each receiving the minimum:
- Stripe, Inc. — if you subscribe. They receive your email address and payment details (entered on their page) so they can take the payment and send you a receipt. They hold the card details we deliberately never see. Stripe’s privacy policy governs what they do with it.
- DigitalOcean, LLC — our hosting provider. The Service runs on a virtual server they operate, so they hold the disk the database sits on. They do not use it; they house it. Their privacy policy governs what they do as a provider.
- Cloudflare, Inc. — every request to this site passes through their network before it reaches our server. That is what provides the HTTPS certificate, absorbs traffic floods and blocks automated abuse. To do it they necessarily see the same things our own logs see — your IP address, the page requested, your browser’s user-agent string — and they terminate the encrypted connection at their edge, which means they can see the contents of requests in transit. We use their standard proxy and their privacy policy governs what they do with it. We do not run any Cloudflare analytics or tracking product.
- Backblaze, Inc. — encrypted backups of the database are copied to their B2 storage service so that a failed disk is not the end of your account. The backup contains the same data described in §2 and nothing more. It is stored in a private bucket that only we can read.
- Discord — only if you choose to join our server. We do not pass them anything about you: you follow an invite and they see whatever your own Discord account shows them. We can see who is in the server and what is posted in it, the same as any other member. Their privacy policy governs the platform.
- Yahoo — only if you choose to connect a Yahoo fantasy league, and only to read that league. You approve it on Yahoo’s own screen, we never see your Yahoo password, and you can revoke it from your Yahoo account at any time.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising, as those terms are used in US state privacy law. We have never done either.
We may disclose information if legally required to — a valid subpoena, court order or comparable process. Where we are permitted to tell you, we will.
7. How long we keep it
- Account data — until you delete your account.
- Your bet log and settings — until you delete them, or your account.
- Subscription records — deleted with your account, except where a payment record must be retained for tax or accounting purposes. Stripe keeps its own transaction records under its own retention rules.
- Sessions — expire on their own, and are deleted when you sign out or change your password.
- Failed code attempts — rolled off after one hour.
- Processed webhook ids — 60 days.
- Server logs — a short rolling window for security and debugging.
Backups outlive deletion, and we would rather say so. The account database is included in a weekly encrypted backup — it has to be, or one failed disk erases the records of every user who did not ask to be deleted. We keep six weeks of those archives. So an account you delete disappears from the live site immediately and can still exist in an archive for up to six weeks, after which it is gone from those too. Backups are used only to restore the service after a failure; they are never queried, analysed or shared.
8. Your rights, and how to use them
Wherever you live, you can:
- See what we hold — most of it is visible on your account page; ask and we will send the rest;
- Correct it — change your email or password from the account page;
- Delete it — the account panel deletes your account and everything attached to it. You do not have to ask us, and we do not put a retention flow in front of it;
- Export it — Download my data on the account page gives you everything we hold, as JSON, immediately and without asking us;
- Clear your search history — Clear search history on the account page, separately from the rest;
- Object or complain — email us.
The first three are buttons, not requests. Delete my account on the account page removes your account and every section attached to it. We do not put a retention offer, a phone call or a waiting period in front of any of them.
California residents (CCPA/CPRA): you have the rights above, plus the right to know the categories of personal information collected, disclosed and sold or shared. The categories we collect are identifiers (email) and commercial information (subscription status, your own bet log). We sell and share none of it. We will not discriminate against you for exercising any of these rights.
If you are in the EU or UK: the Service is aimed at the US and we do not target it at you, but if the GDPR applies to your use of it you also have rights of access, rectification, erasure, restriction, portability and objection, and the right to complain to your local supervisory authority. Our legal bases are in §4.
We will respond to a request within 30 days. We may need to verify that you control the account before acting on it.
9. Children
The Service is for adults aged 21 and over. We do not knowingly collect information from anyone under 18. If you believe a child has created an account, tell us and we will delete it.
10. Security
- Passwords are stored as scrypt hashes, never in plain text, and never recoverable.
- Session tokens are stored hashed; the raw token exists only in your browser cookie.
- The Service refuses to accept a password over an unencrypted connection rather than accepting it and hoping.
- Card data never touches our infrastructure, so a breach here cannot expose it.
- Payment webhooks are rejected unless they carry a valid cryptographic signature.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will tell affected users without undue delay, and comply with applicable breach-notification law.
11. Do Not Track, and Global Privacy Control
We do not track you, so there is nothing for a Do Not Track signal to switch off. We honour it by construction rather than by policy.
The same goes for the Global Privacy Control signal. Under California law a GPC signal is a request to opt out of the sale or sharing of personal information. We do not sell or share personal information and never have, so there is no sale to opt out of and the signal changes nothing about how we treat you. We are saying that plainly rather than staying silent, because silence on this point is usually the tell.
12. Where your data is, and where it travels
The Service, its database and its backups are operated in the United States. If you use the Service from outside the US, your information is transferred to and processed in the US, where privacy law differs from the law where you live. By using the Service you understand that.
Requests reach us through a global network. Cloudflare operates data centres worldwide and routes each request through the one nearest you, so the request itself — your IP address, the page you asked for, your browser’s user-agent — may pass through a Cloudflare facility outside the US before arriving at our server. The stored data does not: the database and its backups stay in the US.
We do not currently offer a region choice. If that changes, this section changes with it.
13. Changes to this policy
If this policy changes in a way that materially affects you, we will say so on the Service and email the address on your account before it takes effect. We will not quietly change the date.
14. Contact
To ask what we hold, to get a copy, to correct it, or to have it deleted — anything in §8 — write to us. We will not ask you why.
Privacy questions: privacy@qellysbook.com
Anything else: support@qellysbook.com
Who is responsible for your data: Ethan Lee, sole proprietor, trading as Qellys Book, operator of qellysbook.com. [Postal address to be added.]
We answer email, and a request under §8 gets an answer within 30 days. If you are in the EU or UK you also have the right to complain to your national data protection authority; we would rather you came to us first.