TablePredict
Games Community Guide
X Sign in

TablePredict legal

Privacy policy

This policy explains what information TablePredict handles when you use table predictions, Team Battles, Match Picks, Fan Votes, or its Change.org-hosted supporter campaign.

Effective: September 5, 2026

Who controls your data

TablePredict is the controller for personal data processed directly through the TablePredict service and for the limited supporter record made available to it as a Change.org petition starter. Change.org separately controls the personal data it processes to operate its platform.

Privacy questions and requests can be sent to contact@tablepredict.com. You can also contact @tablepredict on X.

Information we handle

  • Account data: your email address, authentication identifiers, and passwordless sign-in session data.
  • Profile data: your username, optional bio, and optional self-declared X username.
  • Community badge evidence: public evidence that an X username follows or mentioned @tablepredict, including a canonical username, evidence identifier, source, and timestamps. We privately match this evidence to the optional X username on a TablePredict profile.
  • Prediction data: competition, season, predicted order, scores, timestamps, and public prediction links.
  • Team Battles data: competition, persistent randomized deck seed, battle picks, completion status, Battle rating, result record, and timestamps.
  • Match Pick and Fan Vote data: the poll, selected option, vote and change timestamps, and a poll-specific hashed browser or account identity. We do not store the raw browser voting token or your public account ID in an individual vote row.
  • Friend league data: league names, invite codes, member-room links, membership, entries, and room-scoped rankings.
  • Device and request data: information normally contained in web requests and service logs, such as IP address, browser type or other technical browser identifiers, requested URL, and timestamps.
  • Usage data: aggregate page-view and Web Vitals statistics from Cloudflare Web Analytics, daily aggregate product counters, and privacy-minimal raw event records for page views, confirmed prediction actions, shares, and external clicks. An event may contain a normalized path, country code, referrer hostname, whitelisted UTM source, medium, and campaign values, a strict action type, and a stable competition ID.
  • Local device data: draft prediction orders, score history, creator preferences, authentication session data, and a random poll voting token stored in local storage. Session storage holds a random session-scoped analytics UUID, its short-lived server-signed session proof, and the state used to avoid counting the same poll view more than once during one browser session.
  • Change.org petition starter data: Change.org may make a signer's first and last name or pseudonym, country, postcode or general location, signing date, and optional comment available to TablePredict as petition starter. Change.org does not share signer email addresses with an individual petition starter.

How we use it

We use this information to authenticate accounts, save and score predictions and Team Battles, operate Match Picks and Fan Votes, verify Community badge progress, show aggregate poll results, provide public profiles, leaderboards, and friend leagues, understand aggregate and operational product usage, preserve your browser session, secure the service, diagnose failures, and respond to support or privacy requests.

We use Change.org petition starter data only to operate the supporter campaign, understand where campaign support exists, and document or make a formal delivery to the named decision makers. We never use petition signer data for TablePredict product marketing, fundraising, user profiles, or unrelated analytics, and we do not receive signer email addresses for direct contact.

Our usual legal bases are performing the service you request, our legitimate interests in operating and protecting TablePredict, compliance with legal obligations, and consent where consent is required.

Public information

Your username, bio, public predictions, prediction scores, and public profile links can be viewed and shared by anyone. Your optional X username and the matched Community badge evidence are not shown in public profile payloads. Friend league content, including standings and member prediction tables, is available only to signed-in league members. Invite links and codes are used to join; they do not display friend league content before membership is established.

A qualified Team Battles leaderboard may publicly show your username, Battle rating, win-loss-tie record, resolved count, and rank. Other users' individual battle picks are not included in that public leaderboard.

Match Pick and Fan Vote totals, whole percentages, and closed results are public aggregates. Individual vote rows, hashed voting identities, and raw browser voting tokens are not public. Poll totals represent browser or account votes, not scientifically verified unique people.

TablePredict may combine complete public prediction orders into de-identified competition-level consensus statistics, such as median and average predicted positions and pick rates. Aggregate pages do not show creator names, account or prediction identifiers, or raw tables, and private-room predictions are excluded.

Change.org controls what signer information appears publicly on its petition page. Choosing not to display a name publicly does not stop Change.org from sharing the limited petition starter data described above with TablePredict; Change.org explains this choice before signing. TablePredict may give a relevant signer's name and general location to the petition's named decision makers as part of a formal campaign delivery.

Do not place sensitive personal information in your username, bio, prediction name, or friend league name.

Providers and sources

TablePredict uses Supabase for authentication and database services, Vercel for hosting, delivery, and operational logs, and Cloudflare Web Analytics for aggregate traffic and Web Vitals measurement. These providers process data on our behalf under their own terms and privacy commitments.

Change.org is the sole platform for campaign signatures, supporter accounts, withdrawals, supporter updates, and the authoritative signature count. Change.org processes that activity under its own privacy policy and terms, and shares the limited petition starter data described in this policy.

Standings data may be obtained from ESPN. The Prediction Scoring page includes privacy-enhanced YouTube embeds. Loading or playing third-party content may send request and device information to that provider. Some external image fallbacks may be served through images.weserv.nl.

Providers may process information in countries other than your own, including the United States, subject to the provider's contractual and transfer safeguards.

Cookies and storage

We do not use advertising or analytics cookies. Cloudflare Web Analytics provides aggregate page-view and Web Vitals statistics without cookies, local storage, or persistent visitor identifiers.

TablePredict stores daily aggregate counts when selected product surfaces are viewed or used. Those older product counters do not include account IDs, email addresses, IP addresses, anonymous voting tokens, referrers, user-agent strings, or raw event records.

TablePredict also keeps narrowly scoped operational analytics events. The browser creates one cryptographically random, session-scoped analytics UUID and obtains a short-lived server-signed session proof before an event is accepted; the server stores only an HMAC-derived session identifier. Global and per-session budgets limit event volume. When you are signed in, the server may attach your internal member ID only after it verifies the current authentication token, and it accepts meaningful prediction actions only for verified members. The stored event never contains the token or email. Paths exclude query strings, and private-room invite codes are not stored in operational analytics: private-room paths are reduced to /room/:private. Referrers are reduced to the hostname, location is limited to an edge-derived country code, and only UTM source, medium, and campaign values are accepted.

We do not store raw IP addresses, emails, auth tokens, fingerprints, full user-agent strings, full referrer URLs, precise location, keystrokes, mouse movement, or persistent anonymous identities in operational analytics.

For save, profile-preparation, and poll-loading failures, we separately record a fixed failure category, the HMAC-derived session identifier, language (English or Spanish), a broad mobile/tablet/desktop size band, and time. These reports contain no account identifiers, prediction contents, URLs, or raw error messages. They are rate-limited, deduplicated, and deleted after seven days by the scheduled reliability monitor. Alerts contain aggregate failure counts only.

The service uses browser local storage to keep draft predictions, score history, preferences, authentication session data, and one random poll voting token on your device. It uses session storage for the temporary analytics UUID, its short-lived signed proof, whitelisted UTM source, medium and campaign values from the latest tagged arrival in that tab, and the state used to avoid counting the same poll view more than once during a browser session. These campaign values let us connect an arrival to a confirmed action after navigation or sign-in; they exclude rankings and full URLs. The poll token never appears in a poll URL or analytics event and is stored only as a poll-specific one-way hash in the database.

You can clear local or session storage through your browser settings. Doing so may sign you out, remove locally saved draft state, and create a new anonymous poll identity. A cleared browser may therefore vote again in these casual, non-prize polls.

Retention and security

We keep account, profile, prediction, Team Battles entry, poll vote, Community badge evidence, and friend league data while it is needed to operate the service, maintain public records you chose to publish, resolve disputes, protect users, or meet legal obligations. Privacy-minimal raw operational analytics events are retained for approximately 90 days and then deleted; canonical product records and longer-lived aggregate counters are not deleted under that traffic-retention rule. Closed poll aggregates and aggregate usage counters may be retained to preserve the Fan Vote archive and compare product trends over time. Provider logs and backups may remain for limited periods under provider retention practices.

TablePredict does not maintain a parallel signature database. If a Change.org supporter export is needed for formal delivery to the named decision makers, access is restricted to the campaign operator, the file is used only for that delivery, and local copies are deleted after the delivery record is complete. Change.org retains platform data under its own policy.

We use access controls, row-level database security, encrypted transport, and restricted service credentials. No online service can guarantee absolute security.

Your choices and rights

You can edit your username, bio, and optional X username from your account. To request access, correction, export, restriction, objection, or ask us to delete account, public prediction, Team Battles, poll, or Community badge evidence data, email contact@tablepredict.com from the address connected to your account.

Petition signatures, public-display choices, supporter emails, and withdrawal are managed through Change.org. Requests about the limited supporter record already received by TablePredict can be sent to contact@tablepredict.com; requests about Change.org's platform data should be made through Change.org's privacy and support channels.

Depending on where you live, you may also have the right to withdraw consent and complain to your local data protection authority. We may need to verify your identity before completing a request.

Children and changes

TablePredict is not directed to children under 13. If local law requires parental consent at an older age, you must meet that requirement before using an account or publishing personal information.

We may update this policy when the service or legal requirements change. The effective date above will be updated when material revisions are published.

TablePredict
Privacy Terms Contact Follow us on X