Last updated: TODO set on publication

OnBall is a small, invite-only beta. This page says what it collects, who else handles it, how long it is kept, and how to get rid of it. It is written to be read, not to be survived.

What OnBall collects

Your email address. It is your account. Signing in sends a one-time code to that address, so there is no password: OnBall has never stored one and never will.

Your name. First and last name are both required when you sign up. OnBall greets you by your first name, and the two together make the initials on your avatar.

A profile photo, if you add one. Entirely optional. The file is uploaded to and hosted by Clerk (below). OnBall keeps no copy.

Your conversations. Every question you ask, every answer OnBall gives, and every chart it draws are stored against your account, along with the stats each answer was built from. That storage is what makes history, resuming a conversation, and titles work. It is also what lets OnBall prove where a number came from.

Turns that broke. When an answer streams but fails to save, OnBall records the failure and the answer that did not persist, so the turn can be retried rather than lost.

Your marketing consent, if you give it. Not merely a yes or a no: the time, the context of the request, and the exact wording you were shown. A bare true would be worth nothing later, to you or to us.

What OnBall does not collect: no payment details (the beta is free), no advertising identifiers, no analytics scripts and no advertising trackers. There is one third-party script on the site, and it is the human check on the join form: Cloudflare Turnstile, described below. OnBall sets no cookies of its own; the only cookie it relies on is Clerk's session cookie, which is what keeps you signed in. The human check works by handing back a one-time token rather than by setting a cookie, and Cloudflare states that Turnstile does not use cookies at all. Your browser separately remembers whether the history drawer is open. That preference stays on your device.

Who else handles it

OnBall runs on other companies' infrastructure. These are all of them, and what each one sees:

  • Clerk owns identity: your email address, your name, your profile photo, and your sessions. Clerk also sends your sign-in codes and other account email.
  • Neon is the database: your account row, your conversations, your messages, your charts, your consent records.
  • Anthropic and Google run the models. OnBall does not use one model forever: it runs whichever one currently writes the best answers, so the text of your conversation goes to whichever of them replied. A second, smaller Anthropic model also sees it, to name the conversation and to suggest the follow-up questions under each answer. Nothing else about you goes with any of it. Not your name, not your email address, not your account. This list changes when the models do, and it is updated here when it changes.
  • BallDontLie supplies the basketball data. It receives a stats query (a player, a team, a season) and never your identity, your account, or your question as you typed it.
  • Vercel hosts the application and keeps its server logs.
  • Cloudflare runs the human check on the join form. Its script loads for everyone who opens the front page, before you type anything, and it sees your IP address, your browser, and how your browser behaves, which is how it tells a person from a script. It does not receive your name, your account, your email address, or anything you ask OnBall. When you submit the form, Cloudflare tells OnBall's server that the check passed, and that answer is stored alongside your consent record as proof of how it arrived.

TODO: link each processor's own privacy policy, and confirm this list at ship time against any service added since.

One detail worth being exact about, because most privacy policies are vague here. The log line OnBall writes for each answer records timing, token counts, cost, which model replied, and whether the turn succeeded. It does not contain your question or the answer. Clerk and Vercel do record ordinary request metadata, including IP address and browser, as part of serving and securing the app.

Email: two kinds, one of them optional

Service email is part of the product. Sign-in codes, waitlist confirmation, your invite when a place opens, and security notices. You cannot switch these off while you hold an account, for the plain reason that without the sign-in code you cannot sign in.

Marketing email is opt-in only. It means product updates and nothing else. The box is never ticked for you, it is always separate from the box that agrees to the Terms, and nothing about your access to OnBall depends on it. Leave it untouched and you get precisely the same product.

Changing your mind

You can withdraw marketing consent at any time, by the unsubscribe link at the foot of any marketing email or from email preferences in your account settings. Both do the same thing. TODO: state the turnaround (CAN-SPAM allows ten business days; the intent is immediate).

Unsubscribing never touches service email. Your sign-in code still arrives. That separation is deliberate: unticking a marketing box should never cost anyone the ability to log in.

When you withdraw, the consent record is kept rather than deleted. The record of having opted in, and then out, is the evidence that the mail stopped when you said so.

How long it is kept

  • Conversations stay until you delete them. Note that archiving is not deleting: archiving takes a conversation out of your list, and the conversation remains in the database.
  • Failed-turn records exist for retry and debugging. TODO: set a retention window and delete on that schedule.
  • A waitlist entry that is never approved becomes no account. Your address sits with Clerk's waitlist, and if you ticked the marketing box, a consent record sits in the database keyed to that address. TODO: set a retention window for unapproved waitlist entries and their consent records, and say it here.
  • Server logs are kept for as long as Vercel retains them. TODO: confirm the retention period for the plan in use and state it.

Deleting your account

Ask and it is deleted. Write to TODO contact address. Deleting the account removes the account row, and the database cascades from there: your conversations, your messages, your charts, and your failed-turn records all go with it. Your Clerk identity (email, name, photo) is a separate record and is removed alongside it.

One record deliberately survives: your marketing consent. If you ever ticked the marketing box, the evidence of it (the exact wording you were shown, when, and from where) stays in the database after the account is gone, with its link to your account row broken. That is a decision, not an oversight. The consent record is the proof that mailing you was lawful, and clearing out an old account must not be able to destroy it. If you want that erased too, say so and it will be, as a separate and explicit step.

You can delete your account yourself, from the account page. It takes effect immediately and there is no undo. You can also ask for a copy of what is held about you, or ask for it to be corrected, at the same address. If you want the surviving consent record erased too, that is the separate step described above: ask, and it will be done.

Changes to this page

If this page changes in a way that matters, we will say so. The marketing consent record keeps the wording that was in force when you agreed, so a later edit here cannot quietly rewrite what you agreed to.

Who you are dealing with

TODO: legal entity name, postal address (required in marketing email under CAN-SPAM), contact email, and the data controller named for GDPR purposes.