Privacy Policy
Effective 28 July 2026 · Last updated 1 September 2026
The short version
- We collect your email address, your name if your sign-in provider gives us one, and the conversations you have with DataBaller. Your email address is your account — Google, Apple and emailed codes all lead to the same one.
- Your conversations are private to your account, with one exception you should know about: some answers are published as public story pages. A story shows your question and DataBaller's answer; it never shows your name or anything else about you, and questions about your own life — fantasy rosters, personal decisions — never publish. The "Published stories" section below has the full picture.
- We do not sell your data and we do not run advertising. We measure the product with our own self-hosted analytics, and that data never leaves our infrastructure. We also use Google Analytics to count visits: it sets one cookie, it is never told who you are or what you asked, and in Europe and the UK it stays off unless you say yes to it. The Cookies section below has the whole picture, and a "Cookie settings" link in the footer turns it off from anywhere.
- Marketing email is off unless you say yes. Sign-in codes and account notices are part of having an account; anything else needs your agreement first, and one click stops it. If you do say yes, links in that email are counted when you click them — the one place in DataBaller where anything of yours is tracked, and the same switch turns it off.
- Your conversations are not used to train any AI model: not ours, not anyone's.
- Everything is stored in the United States, in Amazon Web Services.
- Want it deleted? Email privacy@databaller.com and we will delete it, including any published stories that came from your conversations.
This policy explains what DataBaller collects, why we collect it, and what we do and do not do with it. It covers databaller.com, our staging environment, and the DataBaller application. DataBaller is operated by an individual, not a company; "we" and "us" below mean that operator.
What we collect
1. Your account
DataBaller does not have passwords. There are three ways in: Google, Sign in with Apple, or a one-time code we email you.
If you sign in with Google or Apple, we receive only what that service releases for a basic sign-in: a stable account identifier, your email address, and your name if it is available. We never see your password for either, and we cannot act on your account with them.
Apple lets you hide your real address. If you choose "Hide My Email", Apple gives us a relay address that forwards to you, and that relay address is all we ever hold — we cannot see the mailbox behind it. Everything below that talks about your email address means the relay, for you. Apple also gives us your name only once, on the very first sign-in, and often not at all when the address is hidden; if we have no name, your account simply shows your address.
If you sign in with an emailed code, we store your email address and send a code to it each time you sign in. There is no password to choose, forget, or have stolen.
Your email address is your account, whichever route you use. Sign in with Google today and an emailed code tomorrow, and you land in the same account with the same history, because we match on the address your provider has verified. You do not end up with two DataBallers by using two doors.
Three things follow from that, and they are worth knowing. If a provider will not tell us your address, or will not vouch that it is really yours, we cannot match you and you get a separate account instead. If Apple hides your address, the relay is what we match on — so Apple-with-hiding and Google-with-your-real-address are, to us, two different addresses and therefore two accounts. And if the matching step fails for a technical reason, we let the sign-in through as a new account rather than shutting you out; the cost of that is a duplicate, which we would rather have than a locked door. Email us if you end up with two and want them merged.
2. Your conversations
So that you can close the tab and come back to a conversation, we store each chat: the questions you ask, the answers DataBaller gives, and the working steps behind an answer: which data was looked up and what the model reasoned about along the way. We also store a short title derived from your first message, the sport the conversation is about, and when it was created and last updated. Every stored message is tagged with your account identifier, and the service will not return a conversation to anyone but the account that created it. The one exception is deliberate and described in its own section below, "Published stories": a single question-and-answer pair can be published as a public story page, without anything that identifies you. The conversation as a whole is never public.
3. Technical logs
Our servers keep operational logs so we can tell whether the service is working and diagnose it when it is not. These record events, timings and errors.
4. Cookies
We use no advertising cookies and no tracking pixels, and the one analytics cookie on this site — Google Analytics', described in full below — is the only cookie here that involves anyone but us. What we use:
- Two preference cookies (
db_enter_to_submitanddb_sidebar_width), which remember how you like the interface set up. They stay in your browser, and nothing on our side ever reads them. - A consent cookie (
db_cookie_consent), which remembers your answer to the Google Analytics question so you are not asked again on every visit. It exists only once you have answered. - Sign-in tokens, stored by your browser so you are not asked to sign in on every page load. Signing out removes them.
- Our own analytics identifiers, kept in your browser's local storage rather than in cookies: a random id that lets our own measurement recognize a returning browser, a per-visit id, and a note of how you first arrived here (the referring page and campaign tag, if any). They are random values that contain nothing about you, and they are sent only to our own infrastructure. "How we measure the product" below says what for.
- Google Analytics' cookies (
_gaand one companion per measurement stream), which hold a random identifier so it can tell a returning browser from a new one. The rest of this section is about these.
Google Analytics is the one third-party service on this site, and this is its full description — added 1 September 2026. We use it to count visits: which pages get read, and where visitors arrive from. It receives the addresses of the pages you view, the site that referred you, and technical facts about your browser and device. It is never told your name, your email address, your account, or anything you type into DataBaller — conversation addresses are stripped to a placeholder before they are sent, so not even the random id of a chat reaches Google. Google Analytics does not log or store complete IP addresses. Google processes this data on our behalf, and explains what it does with information from sites that use its services at How Google uses information from sites or apps that use our services. Its advertising features, "Google Signals" and personalization are switched off, and retention is set to the shortest Google offers — fourteen months.
Whether it runs depends on where you are. In the European Economic Area and the United Kingdom, nothing loads and no cookie is set unless you say yes to the banner that asks — declining is one click, is remembered, and costs you nothing. Everywhere else, including the United States, it runs without a banner, and the "Cookie settings" link in the footer of any page turns it off just as durably; turning it off also removes the cookies it set. Where we cannot tell where you are, we ask first.
5. Payment details
If you buy a paid plan, the payment is handled entirely by Stripe and your card number never reaches us. Stripe holds your card and billing details under its own privacy policy; what we store is the identifier of your Stripe customer record, which plan you are on, and whether the subscription is active. That is enough to know what your account can do and nothing more.
Changing a card, reading an invoice, or cancelling happens on Stripe's own pages, reached from your account page.
How your questions are processed
When you ask DataBaller something, your question is sent to a large language model running on Amazon Bedrock in the United States, along with the relevant statistics and reference material needed to answer it. Amazon Bedrock does not use the content of those requests to train models, and does not share it with the model's developer.
We do not use your conversations to train, fine-tune or evaluate any model. We may read individual conversations when we are debugging a specific problem — for example, if you report that an answer was wrong — and when we need to investigate abuse.
How we measure the product
We run our own analytics, self-hosted in our AWS account. It records product events — a page was viewed, a conversation started, feedback given — each with a timestamp, the page involved, how the browser first arrived here (the referring site and campaign tag, if any), and the random browser id described under Cookies. If you are signed in, events are attributed to your account, which is how we tell real usage from noise. This data stays in our infrastructure, is read by us alone, and is never shared or sold. The one thing measured by anyone else is the visit counting Google Analytics does, described in full under Cookies — a separate and smaller stream that sees pages, referrers and devices, never your account, your conversations, or any of the events above.
These records hold no part of what you asked or what we answered — a row says which sport a question was about, what kind of analysis it was, and how long it took, and nothing else. When you delete your account, we replace your id on every one of those rows with a meaningless one, so the records survive as counts and stop being about you. We do that rather than deleting the rows because deleting them would silently change what we know about how the product was used months ago. The change is immediate; the old copies of the underlying files are cleared out within a day.
That is true of this website's own measurement, and it is worth being precise about the one other exception anywhere in DataBaller: marketing email, where links are rewritten so that clicks can be counted, by the company that delivers the mail. "Email we send you" below says exactly what that records. Nothing about it reaches this site, and it only exists for people who asked to receive marketing email in the first place.
Email we send you
There are two kinds, and the difference is whether you asked for it.
Service email is part of having an account. Your sign-in codes, and notices about your account or a payment when something genuinely needs your attention. These carry no unsubscribe link and you cannot switch them off while the account exists, because they are how the account works — a sign-in code arrives because you just tried to sign in, and treating that as a subscription would be dishonest in both directions. Deleting your account is what stops them.
Everything else needs your agreement first, and you will not have given it by accident. Product news, new features, and occasional writing about what DataBaller can do are marketing email, and we send none of it to anyone who has not explicitly agreed to receive it. We ask with a plain yes or no. We do not use a pre-ticked box, we do not bundle it into accepting the terms, and continuing to use the product is never taken as agreement. Declining, or simply ignoring the question, means no — and we will not keep asking. When you do agree, we record that you agreed, when, and the wording you were shown, so there is an honest answer to "why am I getting this".
Stopping it is one click, from either end. Every marketing email carries an unsubscribe link, and your account page has a switch for the same thing. Use whichever is nearer; they do the same job. Unsubscribing takes effect straight away, needs no explanation, and changes nothing else — not your service email, not your plan, not your account.
Asking us for something is not the same as agreeing to marketing. If you register interest in a paid plan, that is a request to be told when it is ready, and we will tell you. It does not sign you up for anything else, and stopping one does not stop the other.
Who delivers it. Our email — service and marketing alike — goes out through Resend, which receives your email address and the contents of the message in order to deliver it, and tells us whether it arrived, bounced, or was marked as spam. For marketing email, Resend also holds the record of who has agreed to receive it, so that an unsubscribe is honored even if our own systems are down. Resend acts on our instructions as our email provider and does not use your address for its own purposes.
Marketing email records which links you click, and we would rather say so plainly. Links in a marketing email do not point straight at their destination: they go first through engage.news.databaller.com, which notes that your account followed that link, and then forwards you on. So for marketing email we know who clicked what, and when. We use it for one thing — telling whether anything we send is worth reading — and it is never sold, shared, or used to advertise to you anywhere.
This applies to marketing email and to nothing else. Your sign-in codes and account notices are sent from a different domain that has no such link rewriting, so nothing you click in those is recorded. Neither is anything you do on the website itself: "How we measure the product" above describes what happens there, and the only third party anywhere in it is the Google Analytics visit counting under the Cookies section's rules — which sees pages, and knows nothing about your email or what you click in it. If you would rather not be counted at all, turning marketing email off stops this along with the mail — it is the same switch.
Published stories
Some of DataBaller's best answers are published as public story pages: standalone pages that anyone can read and share, and that search engines index. This is the one place your use of DataBaller can produce something public, so here is exactly how it works.
Publication is on by default for every account. A free account has no setting to turn it off; a paid plan does, for the whole account or for a single conversation. On a free account, what protects you is what gets excluded, and the fact that nothing on a story identifies you.
What decides. An automated editorial review looks at each answer after it is given. Only clear, well-supported analysis of licensed sports is eligible, and the review is built to exclude by class anything with a person in it: fantasy-roster and keeper-league questions, anything that reads as a personal decision rather than sports analysis, and betting-related analysis never publish. Most conversations — quick lookups, casual back-and-forth — are not stories and stay private.
What a story shows: the question as you typed it, DataBaller's answer, the sport and the teams and players it is about, and its dates. What it never shows: your name, your email address, or any account identifier. There is no byline: a published story is DataBaller's analysis, presented as ours and nobody else's.
Treat the question box accordingly. Your question appears on the page exactly as you asked it. The review excludes personal questions, but the safest rule is the one in the Security section: do not type things into a chat that you would not want on a web page.
Views and likes. Story pages count how many times they were viewed; the count is anonymous: we record that a browser loaded the page, not who you are. Signed-in readers can like a story, and we store which account liked which story; that is what makes a like removable. The account whose conversation produced a story can see its view and like counts.
Taking a story down. Email privacy@databaller.com and we will unpublish it: the page, its search listing, and its stored record are removed. Deleting your account removes every story published from your conversations as part of the same deletion. If the stories cannot be removed, the deletion is refused and nothing is half-deleted, rather than reported as done when it is not.
Who else sees your data
| Who | Why | What they get |
|---|---|---|
| Amazon Web Services | Hosting, storage, and the AI models that generate answers | Everything described above, as our infrastructure provider |
| Signing you in, if you choose that route | That you signed in to DataBaller. They see none of your conversations. | |
| Google (Analytics) | Counting visits, under the rules in the Cookies section | Page addresses viewed, the referring site, browser and device facts, and a random cookie id. Never your name, email address, account, or conversations. |
| Apple | Signing you in, if you choose that route | That you signed in to DataBaller. If you use Hide My Email, Apple also relays our email to you, so they carry the messages we send. They see none of your conversations. |
| Resend | Delivering the email we send you | Your email address and the contents of that email. For marketing email, whether you have agreed to receive it, and which links in it you clicked. They see none of your conversations. |
That is the entire list. We do not sell, rent, or trade your personal information, and we do not share it with advertisers or data brokers. We would disclose data if we were legally compelled to, or where it is necessary to protect someone's safety.
Where it lives, and for how long
All data is stored in Amazon Web Services in the us-west-2 region, in the United States. If you are outside the United States, using DataBaller means your data is processed there.
- Conversations are kept until you delete them or ask us to delete your account. They do not expire on their own.
- Technical logs are kept for a limited period — currently 30 days — and then deleted automatically.
- Product measurement records are kept indefinitely, because they are how we understand the product over time. They stop being linked to you when you delete your account — see "How we measure the product" above.
- Google Analytics data is kept by Google for fourteen months — the shortest retention it offers — and then deleted automatically. It was never linked to your account in the first place.
Your choices
You can ask us to give you a copy of your data, correct it, or delete it. Delete means delete: your conversations, your account record, and any published stories that came from your conversations are removed, not deactivated.
Marketing email you can change yourself, whenever you like, from your account page or the unsubscribe link in any marketing email. "Email we send you" above explains what that does and does not cover.
Google Analytics you can also change yourself, whenever you like, from the "Cookie settings" link in the footer of any page — the same control whether the banner asked you or you never saw one, and turning it off also removes the cookies it set.
Self-service deletion is not built yet. Email privacy@databaller.com from the address on your account and we will action it by hand. We would rather say that plainly than point you at a button that does not exist.
Note that deleting your DataBaller account does not affect your Google or Apple account. You can also revoke DataBaller's access from your Google account settings, or from "Sign in with Apple" in your Apple ID settings, though doing that alone does not delete data we already hold, so email us as well. Turning off Apple's email relay stops our mail reaching you but does not delete anything either.
Security
Access to the application requires a valid sign-in, and every request that reads or writes a conversation is checked against the account that owns it. Data is encrypted in transit and at rest. No system is perfectly secure, and DataBaller is early-stage software run by one person. Please do not put sensitive personal information into a chat with it.
Children
DataBaller is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a child has given us information, email us and we will delete it.
Changes to this policy
If we change how we handle your data, we will update this page and move the "last updated" date at the top. If the change is significant, we will tell account holders directly rather than relying on you to re-read this page.
Contact
Questions, requests, or anything that looks wrong: privacy@databaller.com.