In brief
- Unitley stores what your account needs to work, and nothing to advertise to you. It sells no data.
- The site and the app use no advertising or analytics trackers.
- Your AI provider keys are encrypted and never logged. Analyst chats are not saved.
- The audit log records which tool was called and whether it worked, never what was asked or answered.
- You can delete your account, and everything saved with it, at any time in Settings.
Who is responsible
Unitley is run by [To be decided: the legal entity that runs Unitley], which is responsible for the personal data this policy describes. Write to hello@unitley.com about any of it.
What Unitley stores
Your account
- Your email address, for signing in.
- If you sign in with Google, the name and profile photo Google shares, which become your display name and photo until you change them.
- Your display name and any photo you upload.
- When you confirmed that you are 21 or older and that Unitley is analysis only, how you said you’d run Unitley, and your theme.
What you save
- Your bankroll settings: starting bankroll, unit, risk profile, maximum stake and daily and weekly loss limits.
- The bets you log and the picks you save, with any notes, whether you saved them in the app or a tool saved them for you.
- The sports you asked to hear about with “Notify me”. Nothing is emailed yet.
Keys and tokens
- Your AI provider keys, encrypted (AES-256-GCM) before they are stored, with their last four characters to show you which key is which, and when each was last checked.
- Your access tokens’ names, scopes, expiry dates, when each was last used and the name the connecting app reported. A token itself is never stored: only its first characters and a one-way hash of it.
Records that keep the service safe
- An audit log of tool calls: which tool, when, from the web app, MCP or the REST API, with which token and app, and whether it worked. It never holds a call’s arguments or its result.
- Rate-limit counters, keyed by your account, a token, or a keyed hash of an IP address. Unitley’s database never holds a raw IP address.
What Unitley does not store
- Analyst chats. A conversation lives only in the page and is gone when you reload. The server logs neither the conversation nor your provider’s answers.
- What you ask Claude or another agent. Unitley sees only the tool calls the agent makes, and keeps only the audit record above.
- Your keys in readable form, in logs or anywhere else.
- Your location. Unitley doesn’t ask for it or check it.
How Unitley uses it
Only to run Unitley for you: to sign you in, show you your bankroll, bets and picks, size suggested stakes under your limits, settle your bets when games finish, keep the service secure and answer you when you write to us.
Unitley does not sell your data, does not use it for advertising and does not train AI models on it.
Your AI provider
When you chat with the web analyst, your messages and the results of the tools it calls go from your browser through Unitley’s server to the provider you chose (Anthropic, OpenAI or OpenRouter), on your key. When you save or test one of those keys, Unitley makes a check call to the provider to see that the key works.
If you use Unitley in Claude or another agent, that agent’s provider sees what you ask it and the tool results Unitley returns. In both cases the provider handles that data under its own terms and privacy policy, not this one. OpenRouter passes requests on to the model’s own provider.
If you save a Jev key, text you or your agent ask Jev to classify is sent to TypeSafe on your key. Without a Jev key, nothing goes to TypeSafe.
Who else processes it
Unitley uses a few service providers to run, each only for its part:
- Supabase holds your account and everything you save in its database, stores profile photos, and runs sign-in.
- Vercel hosts the website and the app. Every page and API request passes through its servers, analyst chats on their way to your AI provider included.
- Cloudflare runs the unitley.com domain’s DNS; Turnstile, the bot check on the app’s sign-in form; and the email routing that forwards mail sent to hello@unitley.com to Unitley’s inbox, which Google hosts.
- An email delivery provider ([To be decided: which one, chosen at launch]) sends your sign-in links for Supabase.
- Google, only if you choose to sign in with Google: it tells Unitley your email address, name and profile photo.
These providers keep their own records of the requests they handle, such as IP addresses in server logs, under their own policies.
Unitley’s data sources, listed on the data credits page, receive requests from Unitley’s servers, never your personal data.
Where it is kept
Unitley’s database, and the server code that reads it, run in [To be decided: the data region]. Your data stays with the providers above and is not sent anywhere else, except to the AI providers you choose to use, as described earlier.
How it is protected
- Everything travels over HTTPS.
- Database rules let each account read and change only its own rows.
- MCP and REST calls run as the token’s owner, with only that owner’s access.
- Provider keys are encrypted, and tokens are kept only as hashes.
- Profile photos are stored publicly: anyone who has a photo’s link can open it. Don’t upload one you want kept private.
How long it is kept
- Your account and what you save: until you delete them or your account.
- Tool-call audit records: 90 days.
- Revoked and expired tokens: deleted 90 days after they stop working.
- Rate-limit counters: deleted after a day.
- Analyst chats: never stored.
Deleting your data
In Settings, under Delete account, you can delete your account at any time. It permanently removes your profile and photo, your provider keys, your bankroll settings, your bets and picks, your tokens and your audit records, and signs you out. It cannot be undone.
You can also remove a single provider key in Settings, revoke a token on the Connect page and edit your profile and bankroll settings at any time.
Your rights
Depending on where you live, you may have the right to see the data Unitley holds about you, to correct it, to get a copy or to have it deleted. Most of that you can do yourself in the app; for the rest, write to hello@unitley.com.
Under 21
Unitley is for people 21 or older and does not knowingly hold data about anyone younger. If you believe someone under 21 has an account, tell us and we will delete it.
Changes to this policy
When Unitley changes what it stores or who processes it, this policy changes with it. The date at the top shows when it last changed, and for a change that matters we will give notice on the site or by email first.
Contact
Questions about your data or this policy: write to hello@unitley.com.
Legal
Privacy
What Unitley stores about you, why, who processes it, how your API keys are protected, and how to delete all of it.
Last updated
Draft — under review
This page is a draft and has not been reviewed by a lawyer yet. Anything marked “To be decided:” is still open, and the wording may change before it is final.