Privacy Policy
The short version
- Your bets, money, and tax inputs stay on your device. The Verodd app is local-first: your bet history, P&L, stakes, and tax details are stored only on your iPhone and in your own iCloud — never on our servers.
- We don't sell or share your data for advertising. Ever. No ad networks, no data brokers, no cross-app tracking, no IDFA, no analytics SDKs.
- The main thing the app sends us is a privacy-safe lookup (a game, market, and pick — no name, no amount) so we can fetch the historical closing line that grades your bet.
- Social features are optional. If you create a profile and join the verified-CLV leaderboard, you sign in with Apple and we store your handle and Apple's relay email — never your bets, stakes, or money.
- AI bet-slip import is optional. If you use it, a slip you choose is sent through our AI provider (Anthropic) to read the bet. We keep nothing from it — but the AI provider is not zero-retention, so read section 1d.
- Usage analytics are optional and anonymous. Off by default in the EU/UK; never tied to your identity, your bets, or your money.
- You must be 18+ (and of legal gambling age where you live) to use Verodd.
This policy explains what Verodd collects and how we use it, across the Verodd iOS app and the verodd.com website (including the tax calculator). We wrote it to be read, not to hide behind. If anything here is unclear, email privacy@verodd.com.
Who we are. Verodd is operated by Verodd LLC ("Verodd," "we," "us," "our"), a Georgia limited liability company. For privacy purposes, Verodd LLC is the "data controller" of the limited personal data described below. Contact: privacy@verodd.com · postal mail: Verodd LLC, 1340 Queens Park Drive, Kennesaw, GA 30152.
1. The Verodd iOS app
a) Stored only on your device and your own iCloud (never sent to us)
Verodd is a local-first tracker. The following live exclusively in on-device storage — and, if you have iCloud enabled, in your own private iCloud (Apple's CloudKit private database), which only you can access. They are never transmitted to Verodd, and we have no ability to read your iCloud:
- Your bets: stake amounts, odds, results, profit/loss, sportsbook names, and the events you bet on
- Your tax inputs: filing status, other income, resident state, deduction choices, and any W-2G figures you enter
- Your progress: grades, XP, streaks, and your Verodd Score
You can erase all of it at any time from the app (You → Delete all my data). Deleting the app also removes it. We have no copy, because we never received one.
b) What the app sends us when you verify a closing line
To independently grade a bet, the app can ask our closing-line service for the historical market price of a game. When, and only when, you tap "Verify my CLV" or import bets with verification enabled, the app sends our service:
- The bet's event identity: sport, the two teams, the market type (e.g. moneyline / spread / total), the line, your pick, and the relevant timestamps
- A random per-install identifier (a UUID generated on your device, kept in the device keychain) used only to rate-limit requests and prevent abuse
This request does not include your name, email, account, stake, payout, or profit/loss. The identifier is not tied to your identity (the tracker has no login) and is never used to track you across other apps or websites. We keep a short-lived request log for abuse-prevention and cache the closing line we look up. Your IP address is processed transiently in transit to deliver and rate-limit the request and is not stored against you.
c) If you opt into social features (Sign in with Apple)
Verodd's profile and verified-CLV leaderboard are entirely optional — the tracker works fully without an account. If you choose to join, you sign in with Apple, and we store on our backend:
- Your Apple relay email — the Hide-My-Email alias Apple provides. It is the account of record; we never see your real email unless you choose to share it with Apple's relay turned off.
- Your public handle, optional display name, and avatar choice (a generated, non-photo avatar — there is no photo upload).
- Your verified-CLV results: a closing-line "beat / missed" verdict, an edge figure (in basis points), the market family, the league, when the bet was graded, whether you entered it by hand or by AI import, and an opaque reference to the bet on your device. To mint that verdict, the app has to send us the price you logged — your odds, your pick, and the line — so our service can re-derive the edge against the closing line it looks up independently. Those prices are used for that one check and then discarded: they are never written to the stored record, which has no odds field at all, and they are never shown to anyone. What we keep holds no stake, payout, profit/loss, dollar amount, or raw odds — your money never leaves your device.
- Who you follow or block, and any content you report (with the reason you select).
Your profile page is on the open web. This is the part people are most often surprised by, so it is spelled out here rather than left to be discovered. The page exists as soon as you sign in: we start you with a handle we assign, like user49216307, and you can change it to your own right away (the first change away from a starter handle is free; after that, handle changes are limited to once every 30 days). Your handle, display name, and avatar are served on a public web page at verodd.com/u/your-handle. Anyone who has that link can open it. There is no login, and they do not need the Verodd app or an account of their own.
Signing in is how you join the leaderboard. The switch that controls it is called Join the leaderboard (You → the gear → Settings → Your profile), and it is already on when your account is created. The app tells you this before you sign in, on the card that invites you and again directly above the Sign in with Apple button. Once you have at least 30 verified bets two more things are then added: your beat-the-close rate and the number of bets it is based on appear on that public page, and your row appears on the in-app leaderboard of people who follow you. Both are drawn into the preview image that other sites show when your link is shared. These pages ask search engines not to list them, which is not the same as private: holding the link is enough. The page never shows a stake, a payout, a profit or loss figure, or any dollar amount, and it never shows your email. You can turn the switch off at any time, and accounts created before July 23, 2026 keep the off-by-default setting they signed up under. Turning it off withdraws the rate and the leaderboard row at the next refresh of our ranking table, which runs every 15 minutes; the identity part of the page stays until you delete your account or change your handle.
When you share your profile link, we count how many people open it. Tapping Share in the app asks our backend for a short one-time tag and puts it in the link. Your phone sends us nothing else on that call. The tag is what lets us tell your shared links apart from everyone else's, so we can count how many different people have opened a link you shared. That count is the only thing the number is for: it unlocks a cosmetic finish on your avatar at 10, 35 and 85 different openers. We never store who those people are. Each opener is recorded as a salted one-way hash of their IP address and browser user-agent, which we cannot turn back into a person. The hash exists so the same person opening your link five times still counts once. Bots and link-preview scrapers are dropped before any of this runs, and you never see anything about an opener except the total.
You can delete your account and the data tied to it at any time from the app (You → the gear → Settings → Your account → Delete account). This erases your profile, verdicts, follows, blocks, reports, and your share tags and opener counts from our backend, takes down the public page, and revokes the Sign in with Apple link. Your on-device bet history is kept (use "Delete all my data" to remove that too).
One thing deleting your account does not erase, and we would rather say so than let you find out. A note you sent us from the in-app feedback box stays, with your account taken off it, so we can still act on what you told us. From that point it is not tied to you. If you want the note gone as well, email privacy@verodd.com and we will delete it.
What we hold for 30 days when you give up a handle. This happens two ways: you delete your account, or you change your handle and keep the account. Either way we keep two small things about the handle you gave up: the handle itself, and a scrambled code made from your Apple sign-in ID. The scrambled code is not your Apple ID, and we cannot turn it back into one. It does two things, and both are only about you. One: it lets us answer a single question, is the person asking for this name the person who gave it up? Your old links point at your old handle, so if someone else grabbed it right away, those links would start pointing at them. So you can take your old handle back at any point in those 30 days. If you deleted, sign back in with the same Apple ID. If you changed your handle, just change it back. Two: it remembers when you last changed your handle. You can change a handle once every 30 days, and this is what keeps that limit in place even if you delete your account and sign back in. After 30 days we erase both, and the handle is free for anyone to take.
d) If you use AI bet-slip import (optional)
AI import lets you turn a screenshot of a bet slip into a tracked bet. It is opt-in and used only when you choose it. Here is exactly what happens:
- Your phone first reads the slip on-device (Apple's on-device text recognition). By default we send only the extracted text to our import service; we fall back to sending the image only when the text is low-confidence or the slip is a parlay we can't read from text alone.
- Our import service forwards that slip text (or image) to our AI provider, Anthropic (Claude), which returns the parsed fields (book, sport, market, selection, odds, stake, payout, result, date). You review those fields, and the resulting bet is saved on your device only.
- Verodd retains nothing from the slip. We do not store the screenshot, the extracted text, or the parsed stake / payout / result on our servers — only minimal anti-abuse counters (e.g. how many free imports you've used this month, tied to a device attestation, never to your bets).
- If you subscribe, the import also carries a receipt from Apple. Premium raises how many imports you get each month, so our service has to confirm the subscription is real before it grants the higher allowance. Your app attaches the signed transaction Apple issued to your device (Apple's StoreKit "JWS"), and our service checks Apple's signature on it and reads only what that decision depends on: which app and product it was bought in, when it expires, whether it was refunded, whether it is family-shared, whether it is a real or sandbox purchase, when Apple signed it, and Apple's transaction id. It carries no card number, no billing address, and no price. Apple never gives us those. We keep none of it: the check runs in memory on that one request and nothing from the receipt is written to our database. If you are not a subscriber, no receipt is attached at all.
Honest note on AI retention
We do not have a "zero-data-retention" arrangement with our AI provider. That means: although Verodd keeps nothing from your slip, Anthropic may retain the input and output temporarily under its standard API terms (generally up to ~30 days for trust-and-safety purposes) before deletion. Anthropic processes this data as our service provider under a data-processing agreement, and does not use it to train its models (the default for API traffic). If you'd rather not involve a third-party AI provider at all, simply don't use AI import — you can always add bets manually or by CSV. We'll update this section if our retention arrangement changes.
e) If you turn on usage analytics (optional)
To understand which features people use, the app can send a small, fixed set of feature-usage events (for example: app opened, import completed, tax estimator opened, paywall viewed, share card rendered). These contain no dollar amounts, no stakes or P&L, no tax figures, no bet details, and no identity — just the event name, your app version, and your region. They are keyed to a random per-install identifier, never to your account, so they remain "data not linked to you."
- EU / UK / EEA / Switzerland: analytics are off by default and run only if you opt in.
- Elsewhere: analytics are on by default and you can opt out at any time (You → Usage analytics). Turning it off also deletes what was collected from your install.
Region is determined from your device's locale setting, not from IP geolocation.
Stopping floods. So nobody can spam this, our server counts how many analytics requests come from one internet address per hour. To do that it stores a salted one-way hash of your IP address, never the address itself. For analytics, that counter sits in its own table with no event, no install ID, and no account in it, so it can't be tied back to your events or to you, and it's deleted after 24 hours.
We use the same kind of salted hash to stop floods in two other places, and those two are not kept apart the same way, so we describe each one where it belongs instead of leaving this paragraph to speak for them: in-app feedback (the hash is stored on the feedback row itself, next to your message) and website email signups (section 2).
f) Permissions
The app requests no special permissions at all: no location, contacts, photos, camera, microphone, or tracking prompt, and there is no ATT ("ask app not to track") prompt because we don't track you. AI import uses the system photo picker, which needs no photo-library permission and hands the app only the single bet slip you pick — there is no camera feature anywhere in the app. Importing a CSV likewise uses the system file picker, which hands the app only the one file you choose.
Feature availability: AI import and usage analytics may not be enabled yet in your version of the app. The descriptions above apply if and when you use those features.
In-app feedback
If you send feedback from inside the app (the "Send feedback" option, or the "Could be better" reply after a rating prompt), we store one row on our backend (Supabase). Here is everything on it:
- The message you write.
- Your app version and iOS version, for troubleshooting.
- Which of the two places you sent it from (the feedback option, or the reply after a rating prompt).
- Your account, but only if you are signed in to an optional social account, so we can follow up. If you are not signed in, no account is attached.
- A salted one-way hash of the random per-install ID on your device, and a salted one-way hash of your IP address. Both exist for one reason: to stop one person flooding the box. They are hashes, not the values themselves, and we cannot turn either back into the original.
Be aware of two things about those last two. Unlike the analytics counter described in section 1e, these two hashes are stored on the same row as your message, and as your account if you are signed in. And they are not deleted after 24 hours: they last as long as the feedback note itself. So feedback you send while signed in is not anonymous, and feedback you send signed out, while not tied to your name, is tied to a hash we could use to tell that two notes came from the same install. If you would rather we did not store that hash, the app's "Email us instead" option skips it, though of course your email address then identifies you.
We use feedback only to fix problems and improve the app. We do not sell it, and you can ask us to delete it anytime at privacy@verodd.com. Your bets, stakes, and money are never attached.
2. The verodd.com website
Email signup
If you submit your email (on the calculator or a signup form), we store your email address, plus the page source/referrer, your browser user-agent, and the time, so we can send you product updates. We store this on our own infrastructure (Supabase); your email is not handed to a third-party email marketer. Your IP address is stored only as a salted one-way hash to rate-limit signups, not in a form that identifies you.
The tax calculator
The calculator runs entirely in your browser. The numbers you type are not sent to us unless you choose to submit your email.
Opening a shared profile link
Verodd users can share their public page as a verodd.com/u/ link. When the link carries the sharer's share tag, opening it stores one row on our backend: a salted one-way hash of your IP address and your browser user-agent, and which account's link it was. It is there to count distinct openers for that person and nothing else. We do not store your IP address, we cannot turn the hash back into you, and we never use it to profile you, to advertise, or to follow you anywhere else. The person whose link you opened is only ever shown a number, never anything about you. Bots and link-preview scrapers are excluded before the row is written. The row is kept for as long as that person's account exists and is deleted with it. If you would rather not be counted at all, open the plain verodd.com/u/their-handle address with no ?s= tag on the end.
Cookies & analytics
The site sets no advertising cookies and runs no cross-site trackers, no third-party analytics, and no marketing pixels. We use only what is strictly necessary to serve the pages, so there is no cookie-consent banner to click through. Standard server/CDN logs (Cloudflare) may record requests (including IP and user-agent) for security and reliability for a limited period.
3. How we use your data & our legal bases
We use the limited data above only for the purposes below. For users in the EU, UK, and other regions that require a "legal basis," the basis for each purpose is:
| Purpose | Data used | Legal basis (GDPR/UK GDPR) |
|---|---|---|
| Run the tracker & grade your bets (closing-line lookup) | Event identity, per-install ID | Legitimate interests (delivering the service you requested) / performance of our Terms |
| Optional social profile & leaderboard | Apple relay email, handle, verdicts, follows | Your consent + performance of our Terms once you create an account |
| Optional AI bet-slip import | Slip text/image (transient), anti-abuse counters, and (for subscribers only) Apple's signed transaction, checked in memory and never stored | Your consent (you choose to use it) |
| Optional usage analytics | Feature-event names, app version, region, per-install ID | Consent (EU/UK/EEA/CH); legitimate interests with opt-out elsewhere |
| Product-update emails | Email address you submit | Your consent |
| In-app feedback | Message text, app/OS version, which place you sent it from, optional account, hashed install ID, hashed IP | Your consent (you choose to send it); legitimate interests for the two hashes (stopping floods) |
| Counting who opens a shared profile link | The sharer's one-time share tag, and a salted hash of the opener's IP and user-agent | Legitimate interests (running the share feature the sharer chose to use, and keeping its count honest) |
| Security, abuse-prevention, reliability | Per-install ID, hashed IP, request/rate logs | Legitimate interests (protecting the service) |
| Legal compliance & safety | Whatever a law or valid legal process requires | Legal obligation / legitimate interests |
We do not use your data for advertising, for selling or sharing to third parties, or for any automated decision-making that produces legal or similarly significant effects about you within the meaning of Article 22 of the GDPR. We do not build advertising profiles or otherwise profile you. You can withdraw any consent at any time (see your rights); withdrawing it doesn't affect processing already carried out.
4. Who we share your data with
We don't sell or rent your personal data, and we don't "share" it for cross-context behavioral advertising (as those terms are defined under California law). We have not sold or shared personal data in the preceding 12 months, and we don't process personal data for "targeted advertising" as defined under other US state privacy laws. We disclose data only to the infrastructure providers ("processors" / "service providers") that operate the service on our behalf, each under a data-processing agreement and only for the purpose shown:
| Provider | Role | What it receives |
|---|---|---|
| Apple | Sign in with Apple; iCloud (CloudKit private DB); App Store & in-app purchases | Your sign-in identity & relay email (if you opt in); your own private iCloud data (which we can't access); purchase processing (we never receive your card details) |
| Supabase | Our backend database, authentication, and serverless functions | The opt-in social account data in section 1c; in-app feedback you send; website email signups; anti-abuse logs. Processed in the United States (see Section 5). |
| Anthropic | AI provider for bet-slip import — only if you use it | The slip text or image you import (transient; see 1d). No identity, no account, no money totals. |
| The Odds API | Licensed sports-odds data provider (closing lines) | No personal data. We send only a sport, market, and date to fetch historical prices; matching happens on our side. |
| Cloudflare | Website hosting / CDN for verodd.com | Standard web request logs (IP, user-agent) for delivery, security, and reliability |
We may also disclose information if required by law (e.g. a valid subpoena), to protect our rights or users' safety, or in connection with a business transfer (merger, acquisition, or asset sale) — in which case we'll require the recipient to honor this policy and notify you of any change of controller.
5. International data transfers
Verodd is based in the United States, and the providers above process data in the United States and other countries. If you are in the EEA, UK, or Switzerland, transferring your data to the US means it may be processed in a country whose data-protection laws differ from yours. Where we transfer personal data internationally, we rely on appropriate safeguards — the European Commission's Standard Contractual Clauses and the UK's International Data Transfer Addendum, and/or a provider's certification under the EU-US Data Privacy Framework where that provider is actively certified for the relevant data (our backend provider Supabase, for example, relies on the Standard Contractual Clauses rather than the Framework). You can request a copy of the relevant safeguard by emailing privacy@verodd.com.
6. Data retention
- On-device & your iCloud data: kept until you delete it (it never reaches us).
- Closing-line request logs: short-lived, kept only as long as needed for rate-limiting and abuse-prevention, then pruned.
- Cached closing lines: retained as reference market data (they contain no personal data).
- Social account data (profile, handle, relay email, verdicts, follows): kept until you delete your account, then removed.
- A handle you gave up: when you delete your account, or change your handle, we keep the old handle and a scrambled code of your Apple sign-in ID for 30 days, so nobody else can take that name the moment you let go of it, and so the once-every-30-days limit on handle changes still holds if you delete your account and sign back in. You can take it back yourself in that time. Then both are erased.
- AI-import anti-abuse counters: minimal, auto-expiring usage records; no slip content or financial data is retained.
- Usage-analytics events: retained about 30 days, then deleted; removed immediately if you opt out.
- Share tags and opener counts: the tags your app mints for a shared link, and the salted opener hashes counted against your account, are kept for as long as the account exists and are deleted with it. They are not on any timed sweep, because the count they add up to is the feature.
- Website email signups: kept until you ask us to remove you or unsubscribe.
- In-app feedback: kept while we work through it to improve the app; deleted sooner on request. The two anti-flood hashes on the row (install ID and IP) are not on the 24-hour sweep that clears the analytics counter. They are part of the row and go when the note goes.
7. Your privacy rights
Wherever you live, you can ask us to access, correct, delete, or export the personal data we hold about you, and to object to or restrict certain processing or withdraw consent. The fastest routes:
- In the app: delete your account (You → the gear → Settings → Your account → Delete account), wipe all local data (You → Delete all my data), or turn analytics off and purge it (You → Usage analytics).
- Anytime: email privacy@verodd.com and we'll honor your request. We will verify your request (and may ask for limited information to do so) and respond within the timeframe your law requires. We won't discriminate against you for exercising your rights.
Because most of your sensitive data (bets, money, tax figures) lives only on your device and never reaches us, for that data the most complete "deletion" is the in-app wipe.
If you are in the EEA, UK, or Switzerland (GDPR)
You have the rights of access, rectification, erasure, restriction, portability, and to object to processing based on legitimate interests, plus the right to withdraw consent. You also have the right to lodge a complaint with your local supervisory authority (in the UK, the Information Commissioner's Office). Providing personal data is not a statutory or contractual requirement; for optional features (social, AI import, analytics, email updates), declining simply means you can't use that particular feature. We have not appointed a Data Protection Officer (we are not required to); direct any GDPR query to our privacy contact below. If we are required to appoint a representative in the EU or UK under Article 27, we will identify them in this policy.
If you are in California (CCPA/CPRA) or another US state with a privacy law
You have the right to know/access, delete, and correct your personal information, to data portability, and to opt out of "sale" or "sharing" and to limit the use of sensitive personal information. Verodd does not sell or share your personal information, does not use it for cross-context behavioral advertising, and does not use sensitive personal information to infer characteristics — so there is nothing to opt out of on those fronts, but we honor the Global Privacy Control signal regardless. We also do not collect precise geolocation and do not store your sportsbook account logins or passwords, so we do not collect or process "sensitive personal information" as defined under these laws. The statutory categories of personal information are summarized below:
| Category (CCPA) | Do we collect it? | Sold or "shared"? |
|---|---|---|
| Identifiers — device/install ID, Sign in with Apple ID, Apple relay email, handle, website-signup email | Yes — the limited, mostly opt-in set described above | No |
| Internet / network & usage activity — opt-in feature-usage events; server/CDN logs | Only if you opt into analytics; basic security logs otherwise | No |
| Financial information — your bets, stakes, P&L, tax figures | No — stays on your device/iCloud; only transiently processed during opt-in AI import, never retained by us | No |
| Commercial information (records of a subscription you bought) | Only if you subscribe: Apple's signed transaction reaches our import service so it can confirm your allowance. Checked in memory on that request and never stored; it carries no card number, billing address, or price | No |
| Geolocation | No precise location; region is read from your device locale only | No |
| Sensitive personal information (logins, precise geolocation, etc.) | No | No |
| All other categories (biometric, health, demographics, inferences, etc.) | No | No |
Residents of states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana and the other states with comprehensive privacy laws have equivalent rights, including (in most) the right to appeal a declined request — to appeal, reply to our decision or email privacy@verodd.com. You may use an authorized agent where the law allows.
8. Security
Verodd is built local-first specifically to minimize the data at risk: your most sensitive information (bets, money, tax inputs) is engineered to stay on your device — we store no bet records, no stakes, and no tax figures on our servers. Network requests use standard HTTPS/TLS. Our backend tables are locked down with row-level security and reachable only through our server-side functions, so client apps can't read each other's data, and secret keys never ship in the app. No system is perfectly secure, but we keep the attack surface deliberately small. If a breach ever affects your personal data, we will notify you and the relevant authorities as required by law.
9. Children & age
Verodd is not directed to children. It concerns sports-betting records and is intended only for adults who are at least 18 years old and of legal gambling age in their jurisdiction (which is 21 in many U.S. states). We do not knowingly collect personal data from anyone under 18. If you believe a person under 18 has provided us data, email privacy@verodd.com and we will delete it. We do not knowingly collect data from children under 13, consistent with the U.S. Children's Online Privacy Protection Act (COPPA).
10. Region-specific notices
Canada (PIPEDA / Quebec Law 25), Australia (Privacy Act / APPs), Brazil (LGPD), and other regions: we apply the protections in this policy globally and will honor the access, correction, and deletion rights your local law provides. Contact privacy@verodd.com with any request or to reach our privacy contact.
11. Changes
If we change this policy we'll update the date above and, for material changes, note it in the app or by email. We'll describe what changed. Continued use after an update means you accept the revised policy.
12. Not tax advice
Verodd's tax features (in the app and the calculator) are estimates only and not tax, legal, or financial advice. Verify with a qualified professional before filing. See our Terms of Use.
13. Contact
Privacy questions or requests: privacy@verodd.com. General support: support@verodd.com. Postal mail: Verodd LLC, 1340 Queens Park Drive, Kennesaw, GA 30152, USA. We acknowledge requests promptly and respond within the time your law requires.