Privacy Policy
1. Information We Collect
- Account information: email, password (stored as scrypt hash; the platform cannot view your plaintext password), optional display name, phone number, Google OAuth identifier.
- Usage records: teams you follow, matches you subscribe to, your Q&A interactions with the AI, archive, subscription and renewal records.
- Technical information: access IP (used for risk control and aggregate statistics, not permanently linked to personal identity), device / browser UA, cookies.
- Payment information: payment amount, order number, payment channel; payment credentials are handled directly by PayPal / Alipay / WeChat Pay. The Service does NOT store credit card numbers, payment passwords, or card CVV codes.
2. How We Use This Information
- To provide subscription, AI commentary, Q&A and paid billing services
- To protect account security (anomaly login detection, credential-stuffing detection)
- To analyze overall usage patterns for product improvement (aggregated statistics, not individual targeting)
- To comply with applicable laws and regulations
3. Cookies & Session
The Service uses the following cookies:
sa_session: session cookie, valid for 30 days, HttpOnly, used to maintain login state.sa_locale: language preference cookie, valid for 1 year, readable by frontend JavaScript, used to remember your Chinese / English language selection.sa_theme: theme preference (stored in localStorage rather than as a cookie), used to remember your dark / light mode selection.
The Service does NOT use any cross-site tracking cookies and does NOT participate in any advertising network. We use Umami (a privacy-respecting open-source analytics tool) for anonymous page-view statistics; we do not collect personally identifiable information for analytics purposes.
4. Data Storage & Security
- Data is stored on servers located in mainland China, using industry-standard security measures (TLS in transit, database access control, password hashing).
- Passwords are stored using scrypt hashing; platform staff cannot read your original passwords.
- The Service does not proactively sell or exchange your personal data with third parties. If data must be processed by a partner, this will be disclosed before sharing.
5. Third-Party Services
- api-football: used to fetch publicly available match data; no user personal information is uploaded.
- PayPal / Alipay / WeChat Pay: when processing payment orders, only the necessary amount and order number are transmitted; your email or password is not transmitted.
- Google OAuth: on sign-in we receive your Google email and basic profile (only name / picture); we do not access your contacts or email content.
- LLM Services (OpenAI / Gemini-compatible API gateways): only factual evidence related to the specific match is transmitted when generating commentary and Q&A; your account information is not transmitted.
- Cloudflare: provides CDN and Tunnel for network requests; see Cloudflare's Privacy Policy for details.
6. Your Rights
- Access and correct your account information: directly editable in Account Settings.
- Delete your account: request via email at [email protected]; typically processed within 7 days.
- Export your account data: request via the email above; we will provide JSON-formatted data within 30 days.
- For any questions or complaints regarding data usage, please contact us via the email above.
7. International Users
If you are located in the European Union, the United Kingdom, or California, you have rights under the GDPR / UK GDPR / CCPA — including access, deletion, restriction of processing, and data portability. You may exercise these rights through the email address listed in Section 6. We will respond within a reasonable time.
8. Policy Updates
When this policy undergoes material changes, the Service will publish a prominent notice on the site. Material changes will be announced at least 7 days before they take effect.
Last updated: 2026-05-26