Coachee
← Coachee homeAnalyze my ticket

Privacy

Your inputs stay private.

How Coachee handles ticket inputs, saved reports, sharing and product data.

← Back to Coachee
01

Who controls your data

The Coachee product operator is the controller of personal data processed through this service.

For privacy questions or to exercise a right, use the Contact page. That route is the authoritative contact path and does not require an account.

02

Data we collect

We collect the complete ticket text or photos you submit, the normalized ticket produced from them, evidence references, model and provider metadata, analysis status, and the resulting report. Original ticket inputs remain private report records.

We also process an opaque signed device token, a one-way HMAC-derived device or IP subject for ownership and abuse prevention, request and job identifiers, security logs, coarse technical data, contact-form details you submit, and any public report snapshot you deliberately create. We do not offer user accounts and do not store raw IP addresses as product records.

03

Why we use it

We process ticket inputs and related evidence to provide the analysis you request, store and restore the immutable report, calculate scenarios, create a public-safe share when requested, deliver your report by email, secure the service, answer support requests, and meet legal obligations.

Depending on the context, our legal bases are performance of the service you request, our legitimate interests in operating and protecting Coachee, consent where required for optional technologies, and compliance with law.

04

Cookies and analytics

Coachee uses an essential signed, HttpOnly device cookie for private-report continuity and a readable CSRF token for request security. These are not account or advertising identifiers. Do not block them if you want private analysis and report restoration to work.

Google Tag Manager delivers approved site tags. PostHog is the product-analytics provider when configured. Coachee disables PostHog autocapture, session recording, heatmaps, form capture, text capture, URL capture, and person profiles. Explicit analytics events use anonymous identifiers and coarse properties only; ticket text, images, teams, picks, odds, stake, report prose, contact content, and dynamic report or share IDs are excluded. You can restrict non-essential storage through your browser and relevant provider controls.

05

Processors and sources

We use Netlify for the web application; Amazon Web Services for application hosting, PostgreSQL-compatible database services, encrypted object storage, email delivery, keys, backups, and operational logs; OpenAI for multimodal ticket reading, structured analysis, and bounded web retrieval; API-Sports/API-Football for football data; PostHog for privacy-limited product analytics; and Google Tag Manager for controlled tag delivery.

The Odds API is used only when bookmaker comparison is enabled and real matching results exist. These providers process data under their own terms and only for the service role described here.

06

Public reports and bookmakers

A report stays private to the signed device unless you choose to create a separate read-only public snapshot. Public reports and OG images exclude original ticket text and photos, contact details, owner/device data, raw reasoning, private evidence payloads, and stake by default.

Bookmaker cards appear only when the integration is enabled and a real match exists. An outbound link can identify the selected bookmaker and may be an affiliate link, but commission never changes the report, match quality, or ordering.

07

Retention

Private ticket inputs, normalized records, evidence references, and reports are retained while the report remains available and for as long as reasonably necessary to provide, secure, and document the service. Contact records are retained while the request is handled and for reasonable follow-up or legal needs. Security and operational logs follow shorter access-controlled schedules; backups expire through the hosting provider’s normal rotation.

Coachee does not promise automatic deletion of ticket screenshots. You may request erasure through Contact. We may retain limited information where required for security, fraud prevention, legal claims, or other legal obligations.

08

International transfers

Our providers may process data in countries outside your own. Where data-protection law requires it, transfers rely on an adequacy decision, contractual safeguards such as standard contractual clauses, or another lawful transfer mechanism.

09

Your rights

Depending on your location, you may ask for access, correction, erasure, restriction, or portability of your personal data; object to processing based on legitimate interests; or withdraw consent without affecting earlier lawful processing. You may also complain to the data-protection authority that applies to you.

Because Coachee has no account, we may ask for information needed to verify that a request relates to your device or report without collecting unnecessary identity data.

10

Security, children, and changes

We use access controls, encryption in transit, encrypted production storage, separation of private and public objects, request validation, and restricted operational logging. No internet service can guarantee absolute security.

Coachee is for adults aged 18 or older and is not directed to children. We may update this policy when the service, processors, or law changes. Material updates will be shown through the service, and the effective date below will change.

Effective August 1, 2026 · Questions? Contact Coachee.

Responsible gamblingTermsPrivacyHow the analysis worksContact
Coachee18+