Last updated: August 21, 2026
StrikeLock (“we,” “our,” or “us”) operates the websites at www.strikelock.team and www.strikelock.site, and the StrikeLock football intelligence platform. Application hosting, database, and authentication may run in different regions; see Section 5. For this policy, the controller of personal data processed through the Service is Rahil Raj Mohan, trading as StrikeLock, 144-146 Johnston Road, Wan Chai, Hong Kong.
For privacy-related inquiries, contact us at strikelock@proton.me.
We collect and process the following categories of personal data. Whether a category is required depends on the feature you use.
| Data category | Collected when | Required / Optional |
|---|---|---|
| Account data (display name, email, avatar URL) | Sign in via OAuth (Google, Discord, or X) or passkeys | Required for signed-in features |
| Authentication identifiers (user ID, session tokens, passkey public keys) | Sign in and session maintenance | Required for account use |
| Follow preferences (teams, leagues, and similar entities you follow) | Using follow features in Match Center | Optional |
| Chat messages and conversation data | Use of the Copilot chat feature | Required for chat features |
| BYOK metadata (chosen AI provider, model, encrypted key reference — not the plaintext key) | Configuring Bring Your Own Key for Copilot | Optional |
| Technical usage data (IP address, browser type, request metadata) | Visiting or using the Service | Automatic (necessary for the Service) |
| Device preferences (theme, favourites, recent searches, panel layout — stored locally in your browser; see Section 8) | Using the Service in your browser | Optional |
When you sign in through OAuth providers and/or passkeys, we receive account identifiers such as email and profile details from the provider. We do not offer email-and-password sign-in.
We process your personal data for the following purposes and on the following lawful bases:
We do not use your personal data for direct marketing, nor do we sell or rent your personal data to any third party. We do not engage in automated decision-making or profiling that produces legal or similarly significant effects on you (GDPR Art. 22).
We may transfer personal data to the following classes of recipients as needed to provide the Service:
Your personal data may be transferred to and processed in countries outside your jurisdiction, including regions where we and our service providers operate. Where such transfers occur, we take steps intended to protect your data in accordance with applicable law (GDPR Arts. 44–49). The specific transfer tools we rely on (for example standard contractual clauses) are not listed on this page.
We retain personal data only for as long as necessary to fulfill the purposes for which it was collected (GDPR Art. 5(1)(e)):
| Data category | Retention period |
|---|---|
| Account data, profile, and follows | While your account is active. After an email deletion request, we remove or anonymize personal data within a reasonable period. Automated self-serve deletion is not available yet. |
| Chat messages and conversations | While your account is active, unless you request deletion by email. We do not currently run an automated chat auto-delete job. |
| Authentication tokens, session data, and revocation denylist entries | For the lifetime of your session and access token. Revocation denylist entries expire when no matching token could still be valid (typically tied to access-token lifetime, not a fixed calendar period). |
| Server logs and IP addresses | Only as long as needed for security, troubleshooting, and operations. |
When personal data is no longer required, we take practicable steps to erase or anonymize it (GDPR Art. 17).
We implement technical and organizational measures intended to protect your personal data against unauthorized or accidental access, processing, erasure, loss, or use (GDPR Art. 32). These measures include:
No method of transmission or storage is completely secure. We cannot guarantee absolute security.
We use cookies and local storage needed to run the Service. We do not set advertising or analytics cookies ourselves. Embedded third-party players (for example highlight videos) may set their own cookies.
| Name / key | Type | Purpose |
|---|---|---|
Supabase session cookies (sb-*) | Cookie | Maintain your authenticated session |
| cookie-consent | Cookie | Remember that you dismissed the cookie notice |
| strikelock-tz | Cookie | Store your browser timezone for date-scoped match data |
| theme | localStorage | Remember your light/dark/system theme choice |
| strikelock:favourites | localStorage | Pinned favourite teams |
| strikelock:favourite-leagues | localStorage | Pinned favourite leagues |
| strikelock-recent-searches | localStorage | Recent search queries |
| strikelock:copilot-panel-width | localStorage | Copilot panel layout preference |
| strikelock_chat_session_id | localStorage | Resume your Copilot conversation in this browser. Also sent to our chat service with Copilot requests so the thread can be associated |
| strikelock:copilot-auth-token | localStorage | Short-lived token for Copilot API calls from your browser |
Theme and favourite pins stay in the browser unless you use a signed-in follow feature that stores equivalent data on your account. The Copilot session id and Copilot auth token are stored locally and also sent to our servers when you use Copilot.
Depending on your jurisdiction, you may have the following rights regarding your personal data:
| Right | GDPR |
|---|---|
| Right of access | Art. 15 |
| Right to rectification | Art. 16 |
| Right to erasure | Art. 17 |
| Right to restrict processing | Art. 18 |
| Right to data portability | Art. 20 |
| Right to object | Art. 21 |
To access, correct, or request deletion of your data, contact us at strikelock@proton.me. We aim to respond within 30 days. In-app export and automated self-serve deletion are not available yet. If we refuse a request, we will explain why.
If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), including the right to know what personal information we collect (see Section 2), to delete and correct it, to opt out of sale or sharing, and not to be discriminated against for exercising these rights.
We do not sell personal information. We do not share it for our own cross-context behavioral advertising. Embedded third-party media may still collect data under their own policies. To exercise your CCPA/CPRA rights, contact strikelock@proton.me.
StrikeLock is not directed to children under the age of 13 (or the applicable age of digital consent in your jurisdiction, which may be up to 16 under GDPR Art. 8). We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us and we will take steps to delete it.
If you believe your data privacy rights have been violated, you may lodge a complaint with a supervisory authority in your jurisdiction. EU/EEA users may contact the authority in their member state (see edpb.europa.eu). California residents may contact the California Attorney General’s office or the California Privacy Protection Agency. Users in other jurisdictions, including the United Kingdom, may contact their local data protection authority.
You may also seek compensation through civil action for damage caused by a contravention of applicable data protection laws (GDPR Art. 82), where available.
We may update this Privacy Policy from time to time. Material changes will be noted on this page with an updated “Last updated” date and may be highlighted in the product. We do not currently send policy update emails to registered users. Continued use of StrikeLock after changes constitutes acceptance of the updated policy.
For any questions about this Privacy Policy or to exercise your data subject rights, contact us at:
Email: strikelock@proton.me
Website: www.strikelock.team