The short version
- No accounts yet. Guru-frat has no user accounts and no user database during the preseason.
- The invite form doesn't save anything. Your email, password and code are checked, then thrown away.
- Two cookies, only when you log in. They keep you signed in. No analytics, advertising or tracking cookies.
- Your settings stay in your browser. Drafted plays and unit limits live in local storage and are never sent to us.
- Two services see basic request data: our host, Vercel, and Google Fonts. We don't sell data or run ads.
- No contact address yet. During the preseason there is no public contact channel; we'll publish one here before accounts or paid plans launch.
Season 1 preseason. This policy covers Guru-frat as it runs during the invite-only Season 1 preseason. We will update it before accounts or paid plans launch, and the date at the top will change when we do.
Who is responsible
Guru-frat runs guru-frat.com and is responsible for the personal data described in this policy. Guru-frat is a sports betting data and analytics service: it compares sportsbook prices to a no-vig fair price and grades plays from S to F. It is not a sportsbook. We never accept wagers and never hold your money.
This policy works alongside our Terms of Service. During the invite-only preseason we don't have a public contact address; we will publish one on this page before accounts or paid plans launch.
What we collect today
During the preseason the site collects very little. Here is all of it.
When you visit any page
Like every website, our host, Vercel, receives standard request data each time your browser loads a page, a file or an API endpoint: your IP address, your browser's user agent, the URL requested and the time of the request. Vercel keeps these as request logs, which we can see in our hosting dashboard.
When you use the invite form
The Join form asks for an invite code, an email address, a password and a confirmation that you're of legal gambling age. A serverless function checks them and replies. Our code doesn't save any of it to a database, a file or a log, and none of it is put in a URL. A valid code only returns "invite accepted": no account is created, and we don't keep your email address.
When you log in
The Log in page accepts only a single test account set up in our server configuration. What you type is compared against that account and not stored. If it matches, we set the two cookies described below.
Inside the members area
The board, the plays feed, the Game Center, your Player Card, the API Playbook and the /v1 API all check your session cookie before they load. The odds, plays, XP and standings you see there are illustrative sample data, not data about you. The API key shown in the Playbook is a sample too: no API keys are issued yet. We don't connect to your sportsbook accounts and we can't see the bets you place.
What we don't collect
- No payment details. There is nothing to pay for yet.
- No precise location, contacts or device identifiers.
- No analytics, heatmaps, advertising pixels or third-party tracking scripts.
Cookies and browser storage
We set cookies only when you log in, and we use your browser's local storage for a few settings. That's the full list:
| Name | Purpose | Duration | Type |
|---|---|---|---|
gf_session |
Keeps you signed in. Holds the account email, the player handle, and when the session started and expires, signed by our server so it can't be altered. HttpOnly, Secure, SameSite=Lax. | 7 days, or until you log out | CookieStrictly necessary |
gf_user |
Tells our public pages you're signed in, so the menu shows "Open the board" instead of "Log in". Its value is just 1. Secure, SameSite=Lax. |
7 days, or until you log out | CookieStrictly necessary |
gf.drafted |
Which plays you drafted, so your list survives a reload. | Until you clear it | Local storageNever sent to us |
gf.limits |
The unit size and daily unit limit you set on your Player Card. | Until you clear it | Local storageNever sent to us |
gf.games.league |
The league filter you last picked in the Game Center. | Until you clear it | Local storageNever sent to us |
gf.api. |
Remembers that you already got the XP toast for your first call in the API Playbook. | Until you clear it | Local storageNever sent to us |
Logging out deletes both cookies. Local storage stays in your browser until you clear this site's data in your browser settings. We use cookies and storage only to make the site work, never to track you, so we don't show a cookie banner.
How we use data
- To run the site and the API: deliver pages, serve the members area and keep it working.
- To keep it secure: spot abuse and fix errors using request logs.
- To keep you signed in with the session cookie.
We don't use your data for advertising, profiling or marketing emails, and we don't make automated decisions about you.
Who we share it with
We don't sell personal data, we don't run ads and we don't use analytics services. Two providers handle data so the site can work:
- Vercel hosts the site and runs our serverless functions. It processes every request and keeps the request logs described above. See Vercel's privacy policy.
- Google Fonts serves the fonts this site uses. Your browser downloads them from Google's servers on every page, so it sends Google your IP address, your user agent and the fact that the request came from guru-frat.com. See Google Fonts and privacy.
Plays link to sportsbooks such as DraftKings, FanDuel, BetMGM and Pinnacle. When you follow one of those links you leave Guru-frat, and that sportsbook's own terms and privacy policy apply. We don't send them your data and the links carry no tracking codes, although, as with any link, your browser may tell them you came from guru-frat.com. Guru-frat is not affiliated with or endorsed by any sportsbook; their names and trademarks belong to their owners.
Apart from that, we only disclose information to anyone else if the law requires it.
International transfers
Guru-frat serves an international audience. Vercel and Google are based in the United States and run servers in many countries, so the data described here may be processed outside the country where you live, where privacy laws may differ from yours. Both providers publish how they protect the data they handle; their policies are linked above.
How long we keep it
- Invite and login forms: not stored by us. What you type is discarded as soon as the request is answered. After a successful login, the account email travels inside the session cookie in your browser.
- Cookies: up to 7 days, or until you log out.
- Local storage: until you clear it. It lives only in your browser, so we can't see or delete it.
- Request logs: kept by Vercel for a limited time set by its log retention rules.
Security
- The whole site is served over HTTPS, and our cookies are marked Secure so they only travel over encrypted connections.
- The session cookie is HttpOnly, so scripts in the page can't read it. It is signed with a secret key, so it can't be forged or edited, and it expires after 7 days.
- The members area and the API refuse to load without a valid session.
- Login details are compared in constant time, and a wrong password or invite code triggers a short delay to slow down guessing.
- Secret keys and the test account live in our server configuration, never in the source code.
No system is perfectly secure. We will publish a way to report security problems before accounts or paid plans launch.
Your rights
Depending on where you live, you may have the right to:
- Access the personal data we hold about you.
- Correct it if it's wrong.
- Delete it.
- Object to or ask us to limit how we use it.
- Get a copy in a portable format.
- Complain to your local data protection authority.
During the preseason we hold very little that could be about you: there are no accounts and we don't store what you type into our forms. The only personal data tied to your visits is in the request logs that Vercel keeps for a limited time. You can act yourself at any time: logging out deletes our cookies, and clearing this site's data in your browser deletes the cookies and local storage.
We don't have a public contact address yet. We will publish one here before accounts or paid plans launch, so you can send requests about your data; we'll answer within the time your local law requires, and using your rights will be free.
Children
Guru-frat is only for adults of legal gambling age where they live. It is not meant for anyone under that age, and we don't knowingly collect data from them. During the preseason we don't store the information people type into our forms, so there is nothing kept that we would need to delete. For help keeping betting under control, see Responsible gaming.
When accounts and billing launch
The following features are not live yet. We describe them so you know what's coming, and we will update this policy before any of them launch.
- Accounts with Supabase. Real accounts will be stored with Supabase, a database and sign-in provider. That will include your email address, sign-in details and the settings you choose.
- Paid leagues billed by Stripe. Paid plans on the Pricing page will be billed through Stripe, with a 3-day trial and cancel anytime. Card details will go to Stripe, not to us.
- Alerts by email or push. Alerts will need your email address or your browser's permission to send push notifications.
Changes to this policy
When this policy changes, we'll update it on this page and change the "Last updated" date at the top. Before accounts or paid plans launch, we will publish a revised version that covers them.