Privacy Policy
Last updated: July 16, 2026
Plain-language summary available on the home page — this document is the one that governs. See also our Terms of Service.
1. Overview
LottoSynapse ("we," "us") is an independent, sole-operator service based in Florida, USA. This policy describes exactly what we collect, why, and your rights. Short version: we collect the minimum needed to run the product, we run no analytics or ad trackers, and we never sell your data.
2. What we collect
Account data (via Supabase Auth): your email address, your sign-in identity if you use Google or Apple OAuth, and sign-in timestamps. We never see or store passwords — sign-in is via OAuth or emailed magic links.
Profile data: your default game, onboarding status, and subscription tier.
Generated combinations: the number combinations we generate for you, with their scores, game, and target draw date — this is the product's core record and powers your dashboard history and result grading.
Anti-abuse signals: with each generation request we compute salted one-way hashes (SHA-256) of your IP address and of a browser-derived device signature (FingerprintJS visitorId). We never store your raw IP address. These hashes exist solely to enforce fair per-draw limits across accounts and devices.
Billing references (if you subscribe): your Stripe customer and subscription IDs, subscription status, and period end date. Card numbers never touch our systems — payment details are collected and stored by Stripe, a PCI-DSS-compliant processor.
3. What we do NOT collect
No usage analytics. No page-view tracking. No advertising trackers or pixels. No data brokers. No sale, rental, or trade of personal data — ever. No precise location. No contacts, no camera, no microphone.
4. How we use your data
Only to operate the Service: authenticate you, generate and store your combinations, grade them against official draw results, enforce fair-use limits, process subscriptions, and respond to support or legal requests. We do not use your personal data to train models — our analysis models are built from public official draw results, not from user data.
5. Cookies
We use only the session cookies required to keep you signed in (set by our authentication provider, Supabase). No advertising or analytics cookies.
6. Who we share data with
Only processors necessary to run the Service, under their own compliance programs: Supabase (database & authentication, US region), Stripe (payments), Vercel (hosting), and Google/Apple (only if you choose OAuth sign-in). We disclose data beyond this only if required by law.
7. Data retention and deletion
Account data is kept while your account is active. When your account is deleted, your profile is permanently removed and your generated-combination records are anonymized (unlinked from any identity). Anti-abuse hashes age out of enforcement windows automatically. Stripe retains billing records as required by financial regulations.
8. Your rights (GDPR / CCPA)
You may request: a copy of your data (access/portability), correction, or permanent deletion of your account and data. Send requests to privacy@lottosynapse.com— we honor verified requests within 30 days. We do not discriminate against users who exercise privacy rights. California residents: we do not "sell" or "share" personal information as defined by the CCPA/CPRA. (A self-serve deletion/export button is planned; until it ships, email is the deletion path.)
9. Security
Data is stored with row-level security (each user can only read their own rows), transmitted over TLS, and anti-abuse identifiers are salted one-way hashes. No system is perfectly secure; we will notify affected users of any breach as required by law.
10. Children
The Service is for users 18+ (and of legal lottery age in their jurisdiction). We do not knowingly collect data from anyone under 18; if we learn we have, we will delete it.
11. International users
We operate from the United States and store data in US regions. By using the Service you consent to processing in the US.
12. Changes
Updates will be reflected in the "Last updated" date; material changes will be flagged in-product where reasonably possible.