Scry Pro

Privacy Policy

Last updated: May 24, 2026

1. Introduction

Scry Pro ("we," "our," or "us") respects your privacy and is committed to protecting your personal data. This Privacy Policy explains how we collect, use, and safeguard your information when you use our Service.

2. Information We Collect

Information You Provide

  • Account Information: Email address, name, and profile picture when you sign up via Google or X/Twitter OAuth
  • Payment Information: Billing details processed securely through Stripe (we do not store your full card number)
  • DraftKings Username: If you provide your DraftKings username, we use it to display your contest history and performance analytics
  • Discord Username: If you connect your Discord account for community access
  • Preferences: Your settings, theme preferences, and fresh start date configuration
  • Newsletter Information: Email address and opt-in details when you subscribe to newsletters or accept newsletter emails during signup
  • Support Communications: Information you provide when contacting support

Information Collected Automatically

  • Device Information: Browser type, operating system, screen resolution, device identifiers
  • Log Data: IP address, access times, pages viewed, referral URLs
  • Cookies: Session cookies for authentication and preferences (see Section 7)
  • Analytics Data: Feature usage, click patterns, and session recordings (with your consent)

Information from Third Parties

  • OAuth Providers: Basic profile information from Google or X/Twitter when you sign up
  • DFS Contest Data: Publicly available contest results and leaderboard data from DraftKings for competitor analysis features

3. How We Use Your Information

We use your information to:

  • Provide and maintain the Service, including personalized analytics and projections
  • Process payments and manage your subscription
  • Send important service updates, notifications, and transactional emails
  • Send newsletters and marketing emails when you opt in, with unsubscribe controls in those emails
  • Provide competitor profiling and contest analysis features
  • Improve our features and user experience through analytics
  • Respond to your requests and support inquiries
  • Detect and prevent fraud, abuse, or unauthorized access
  • Comply with legal obligations

4. Legal Basis for Processing

We process your personal data based on:

  • Contract Performance: Processing necessary to provide the Service you requested
  • Legitimate Interests: Improving our Service, preventing fraud, and ensuring security
  • Consent: For analytics cookies, session recordings, newsletters, and marketing emails (you can withdraw consent at any time)
  • Legal Obligation: When required by applicable laws

5. Information Sharing

We do not sell your personal information. We may share information with:

  • Service Providers: Companies that help us operate the Service:
    • Stripe - payment processing
    • Resend - transactional emails
    • Cloudflare - content delivery and security
    • Google/X - OAuth authentication
  • Legal Requirements: When required by law, court order, or government request, or to protect our rights, property, or safety
  • Business Transfers: In connection with a merger, acquisition, bankruptcy, or sale of assets (you will be notified of any change in ownership)

We require all service providers to maintain confidentiality and use your data only for the purposes we specify.

6. Data Security

We implement industry-standard security measures to protect your data:

  • Encryption in transit (HTTPS/TLS 1.3)
  • Encryption at rest for sensitive data
  • Secure authentication via OAuth providers (Google, X/Twitter)
  • Row-level security policies on our database
  • Regular security audits and vulnerability scanning
  • Rate limiting and abuse prevention
  • Secure headers (HSTS, CSP, X-Frame-Options)

However, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security. You are responsible for maintaining the security of your account credentials.

7. Your Rights

You have the right to:

  • Access: Request a copy of your personal data
  • Correction: Request correction of inaccurate data
  • Deletion: Request deletion of your account and data
  • Export: Receive your data in a portable format
  • Opt-out: Unsubscribe from marketing emails and disable analytics tracking
  • Withdraw Consent: Withdraw consent for analytics cookies at any time via Settings

To exercise these rights, contact us at [email protected] or use the self-service options in your account Settings.

8. Data Anonymization

If you have provided your DraftKings username for competitor profiling features, you can request to have your DFS identity anonymized while keeping your Scry Pro account active. This process:

  • Replaces your DraftKings username with a random identifier in our systems
  • Removes you from public leaderboards and competitor profiles
  • Disassociates your contest history from your identity
  • Is irreversible once completed

You can submit a data anonymization request through your account Settings page.

9. Cookies and Tracking

We use cookies and similar technologies for:

  • Essential Cookies: Required for authentication, security, and basic functionality. These cannot be disabled.
  • Preference Cookies: Remember your settings (theme, fresh start date) and preferences
  • Analytics Cookies: Help us understand how you use the Service to improve it (requires your consent)
  • Session Recording: Records your interactions to help us identify bugs and improve UX (requires your consent)

When you first visit our site, you will see a cookie consent banner. You can change your preferences at any time in your account Settings under "Cookie Preferences." You can also control cookies through your browser settings, though this may affect functionality.

10. Third-Party Services

Our Service integrates with the following third-party services that receive your data:

  • Stripe: Payment processing - receives billing information (Privacy Policy)
  • Google: OAuth authentication - provides profile data when you sign in (Privacy Policy)
  • X/Twitter: OAuth authentication - provides profile data when you sign in (Privacy Policy)
  • Resend: Transactional email delivery - receives your email address for service emails (Privacy Policy)
  • Cloudflare: Content delivery and security - processes requests to our servers (Privacy Policy)

If you join our Discord community, Discord's privacy policy applies to your participation there (Discord Privacy Policy).

Our analytics and database systems are self-hosted on our own infrastructure and do not share your data with third parties.

11. International Data Transfers

Our servers are located in Germany (European Union). If you access the Service from outside the EU, your information will be transferred to and processed in Germany. We use Cloudflare's global network for content delivery, which may route your requests through servers in various locations.

For users in the European Economic Area (EEA), UK, or Switzerland, we rely on Standard Contractual Clauses approved by the European Commission for any transfers to service providers outside the EEA.

12. Data Retention

We retain your data for as long as your account is active or as needed to provide services.

  • Account Data: Retained while your account is active
  • Analytics Data: Retained for up to 2 years
  • Payment Records: Retained for 7 years for tax and accounting purposes
  • Support Communications: Retained for 3 years

After account deletion, we will delete or anonymize your personal data within 30 days, except where we are required to retain it for legal, tax, or accounting purposes.

13. Children's Privacy

The Service is not intended for users under 18 years of age (or the age of majority in your jurisdiction, whichever is higher). We do not knowingly collect personal information from minors. If you believe we have inadvertently collected data from a minor, please contact us immediately and we will take steps to delete such information.

14. Changes to This Policy

We may update this Privacy Policy periodically to reflect changes in our practices or for legal, operational, or regulatory reasons. We will notify you of material changes by email or through a prominent notice on the Service at least 30 days before the changes take effect.

Your continued use of the Service after the effective date of the revised Privacy Policy indicates your acceptance of the changes.

15. Contact Us

For privacy-related questions, concerns, or to exercise your rights:

We aim to respond to all privacy requests within 30 days.