This Privacy Policy describes how IABET LLC (“IABET,” “we,” “us,” or “our”) collects, uses, shares, and protects your personal information when you use the IABET mobile application and website (the “Service”). This policy applies to all users worldwide and addresses requirements under the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA), and other applicable privacy laws.
1. Information We Collect
Information You Provide:
- Account information: name, email address, and authentication credentials (via Google or Apple Sign-In)
- Profile preferences: language, timezone, odds format, notification preferences
- Support communications: messages you send to our support team
- Referral codes: when you share or use a referral code
Information Collected Automatically:
- Device information: device type, operating system, app version, unique device identifiers
- Usage data: pages viewed, features used, predictions followed, session duration, interaction patterns
- Log data: IP address (hashed and anonymized), timestamps, error reports
- Subscription data: plan tier, purchase history, billing status (processed by App Stores)
Information from Third Parties:
- Authentication providers: Google or Apple provide your name, email, and profile photo when you sign in
- App stores and subscription infrastructure: Apple App Store and Google Play provide purchase status, while Adapty syncs subscription entitlements to your IABET account (we do not receive or store payment card details)
2. How We Use Your Information
We use your information for the following purposes:
- Provide the Service: deliver personalized predictions, manage your account, process subscriptions
- Improve the Service: analyze usage patterns, identify bugs, optimize AI models, develop new features
- Communications: send prediction alerts, account notifications, and service updates (with your consent for marketing)
- Security: detect fraud, prevent abuse, protect against unauthorized access
- Legal compliance: comply with applicable laws, regulations, and legal processes
We never sell your personal information to third parties.
3. Third-Party Services
We share data with the following categories of service providers, strictly for the purposes described:
| Provider | Purpose | Data Shared |
|---|---|---|
| Clerk | Authentication | Email, name, auth tokens |
| Supabase | Database hosting | Account data, predictions |
| Adapty | Subscription entitlement management | App user ID, store purchase status, entitlement state |
| Segment | Analytics routing | Optional product analytics events linked to your account when analytics is enabled |
| PostHog | Product analytics and masked session replay | Optional usage events, device/app metadata, masked session replay linked to your account when analytics is enabled |
| Sentry | Error monitoring and diagnostics | Crash/error reports, device/app metadata, technical diagnostics |
| OneSignal | Push notifications | Push token, subscription state, app user ID when you enable notifications |
| Resend | Transactional email | Email address, name |
| Google AdMob | In-app advertising for non-paying users | Advertising ID (IDFA on iOS, AAID on Android), device/app metadata, coarse location derived from IP, ad interaction events |
All service providers are contractually obligated to protect your data and use it only for the specified purposes.
Optional analytics and masked session replay are disabled until you make a choice in the app. You can later change that choice from Settings.
4. International Data Transfers
Your data may be transferred to and processed in the United States, where our servers and service providers are located. For users in the European Economic Area (EEA) or other regions with data transfer restrictions, we rely on Standard Contractual Clauses (SCCs) approved by the European Commission to ensure adequate protection of your data.
5. Data Retention
- Account data: retained for the duration of your account, plus 30 days after deletion request
- Optional analytics and masked session replay: retained for up to 24 months unless deleted sooner in connection with an account deletion request
- Error logs: retained for 90 days
- Billing records: retained for 7 years as required by tax law
- Support communications: retained for 12 months after resolution
6. Your Rights
Depending on your jurisdiction, you may have the following rights:
- Access: request a copy of the personal data we hold about you
- Rectification: correct inaccurate or incomplete data
- Deletion: request deletion of your personal data (available in-app via Account Info > Delete Account)
- Portability: receive your data in a structured, machine-readable format
- Objection: object to processing based on legitimate interests
- Restriction: request restriction of processing under certain conditions
- Withdraw consent: withdraw consent at any time where processing is based on consent
- Do Not Sell (CCPA): we do not sell personal information. You may still submit a request at privacy@iabet.co
To exercise any of these rights, contact us at privacy@iabet.co. We will respond within 30 days (or 45 days for complex requests, with notice).
7. Legal Basis for Processing (GDPR)
For users in the EEA, we process your data under the following legal bases:
- Contract performance: to provide the Service you subscribed to
- Legitimate interests: to improve the Service, prevent fraud, and ensure security
- Consent: for optional analytics/session replay and any marketing communications you choose to receive
- Legal obligation: to comply with applicable laws and regulations
8. Data Security
We implement industry-standard security measures to protect your data:
- All data encrypted in transit (TLS 1.3) and at rest (AES-256)
- Authentication via OAuth 2.0 (Google, Apple) with secure token management
- IP addresses hashed with HMAC-SHA256 before storage
- Regular security audits and penetration testing
- Rate limiting, circuit breakers, and abuse detection
- Role-based access controls for internal systems
9. Children's Privacy
IABET is not intended for children under 18. We do not knowingly collect personal information from anyone under 18 years of age. If we learn that we have collected data from a child under 18, we will delete that information promptly. If you believe a child under 18 has provided us with personal data, please contact us at privacy@iabet.co.
10. Advertising (Google AdMob)
The IABET mobile application shows advertisements to users on free or trial tiers, served by Google AdMob (a Google service). Users on paid subscription tiers do not see ads.
What AdMob processes:
- The mobile advertising identifier (IDFA on iOS, Android Advertising ID on Android), which you can reset or limit at any time in your device settings
- Device information (model, operating system, language, app version, network type)
- Coarse location inferred from IP address
- Interactions with the ad (impressions, clicks, watch completion for rewarded ads)
Why: ad delivery, frequency capping, fraud prevention, measurement, and — where permitted — ad personalization. On iOS, personalized ads require your explicit permission via the App Tracking Transparency (ATT) prompt. If you decline ATT or use the “Limit Ad Tracking” / “Reset Advertising ID” controls on Android, AdMob serves you non-personalized ads only.
Your controls:
- Subscribe to a paid tier to remove ads entirely
- iOS: Settings > Privacy & Security > Tracking — turn off “Allow Apps to Request to Track”
- Android: Settings > Google > Ads — “Delete advertising ID” or “Opt out of Ads Personalization”
EEA, UK, and Switzerland (EU User Consent Policy): If you are located in the European Economic Area, the United Kingdom, or Switzerland, the app uses Google's User Messaging Platform (UMP) — a Google-certified Consent Management Platform — to obtain your consent before processing personal data for advertising. You can choose between personalized ads (which use your device's advertising ID and ad-interaction history) or non-personalized ads (which rely only on contextual signals such as the content of the screen and approximate location from IP). You may change your choice at any time from within the app. If you do not consent, only non-personalized ads are served — no personal data is used for ad targeting.
Children: IABET is intended for users 18 and older (see Section 9). The app is not directed at children under 13 within the meaning of the U.S. Children's Online Privacy Protection Act (COPPA). We instruct AdMob to disable personalized advertising for any user we treat as a child or for whom personalized ads cannot lawfully be served, in line with Google's tag-for-child-directed-treatment requirements.
How Google uses information from sites or apps that use its services: policies.google.com/technologies/partner-sites. Google's advertising policies: policies.google.com/technologies/ads. Manage Google ad settings: adssettings.google.com.
11. Push Notifications
If you enable push notifications, we use your device token and push subscription state to send prediction alerts, account updates, and optional promotional messages. You can disable notifications at any time through your device settings or the Notifications page in the app.
12. Changes to This Policy
We may update this Privacy Policy periodically. We will notify you of material changes via the app or email. The “Last updated” date at the top of this page indicates when this policy was last revised. Continued use of the Service after changes constitutes acceptance.
13. Contact
For privacy-related inquiries:
IABET LLC
Privacy Team
Email: privacy@iabet.co