Legal

Privacy policy

Last updated · 9 June 2026

This policy explains what data Pickoo collects, why, who we share it with, and what you can do about it. It applies to everything on the Pickoo website and any related domains we operate. Plain English first, lawyer second.

01Who we are

Pickoo is operated by Overflow LLC, a company registered in the United Arab Emirates, the data controller for the information described below. For any privacy question or request, write to hello@pickoo.app.

02Data we collect

  • Account information: your email address, the password you set (stored hashed — we never see the plaintext), your display name, and your chosen username.
  • Game data: the picks you make, the points you earn, when each pick was made or scored, and your total ranking.
  • Technical data: IP address, user agent string, and basic request metadata — used for security and to keep the service running, not for advertising.
  • Cookies: one strictly-necessary cookie for the authenticated session, plus any cookies set by the analytics services we use to measure page views and performance.

03How we use your data

  • Run the game — let you sign in, make picks, see scores, climb the leaderboard.
  • Compute and display rankings and the public activity feed.
  • Send transactional email: confirmation, password reset, and — if you finish in the top three — the digital prepaid gift card that carries your prize.
  • Prevent abuse — detect bots, multi-accounting, and exploitation attempts.
  • Measure aggregate usage and performance (page views, load times) so we can improve the Service. This doesn't identify you personally.
  • Debug bugs and improve performance.

We don't sell your data. We don't use it for advertising. We won't send you marketing email unless you explicitly opt in.

04What's public on Pickoo

Some of your data is visible to other users — this is core to a pickem game. Specifically:

  • Your display name and username appear on the public leaderboard, alongside your total points and picks made.
  • Your picks appear in the public real-time activity feed as they're made and scored, attributed to your username.
  • Your email address is never public and your password is never seen by anyone, including us.

05Who we share data with

We use the following subprocessors to operate the Service. Each only receives what they need to do their job:

  • Supabase — authentication and database (hosted in the EU).
  • Vercel — application hosting and CDN.
  • Resend — transactional email delivery.
  • Analytics services — for aggregate page views and performance measurement. None receive your email, password, or pick content.

We don't share your data with advertisers, data brokers, or any party not listed above except when legally required (e.g. a valid court order).

06How long we keep it

  • Account data: until you ask us to delete your account, or up to 6 months after the tournament ends if you stop using the Service.
  • Picks and scores: retained during the tournament and a short period after for prize fulfillment and dispute resolution.
  • Technical logs: up to 90 days, then deleted or anonymised.

07Your rights

You can ask us to:

  • Send you a copy of the data we hold about you.
  • Correct anything inaccurate.
  • Delete your account and all associated data.
  • Stop processing your data for a specific purpose.

Email hello@pickoo.app and we'll respond within 30 days. If you live in the EU/UK and think we've mishandled your data, you can complain to your local data protection authority.

08Security

We use HTTPS everywhere, password hashing handled by Supabase Auth, and least-privilege access to the production database. No system is unbreakable, but we take reasonable steps to protect your data and will notify affected users promptly if a breach occurs.

09Children

Pickoo is for adults — see Terms §02. We don't knowingly collect data from anyone under 18. If you believe a minor has signed up, email hello@pickoo.app and we'll delete the account.

10Changes to this policy

We may update this policy. The "last updated" date at the top reflects the current version. For substantial changes we'll surface a notice on the site.