Privacy Policy
// effective: 2026-09-09
PickBits.AI ("PickBits", "we", "us") respects your privacy. This policy explains what we collect, how we use it, who we share it with, and the choices you have. It applies to pickbits.ai, CyberHawk, Daily Signal, the PickBits SDK and account system, consulting inquiries, and legacy purchase records we remain responsible for.
Information We Collect
- Account information: email address, username, display name, optional avatar URL, and any profile fields retained from earlier versions of the service. If you sign in with Google or GitHub OAuth, we receive the basic profile fields those providers expose.
- SDK and product data: cloud saves, achievements, leaderboard scores, activity timestamps, game or app identifiers, and related metadata submitted by connected PickBits products.
- Legacy entitlement data: historical subscription tier, period end date, Track Pack entitlements, and learning or progression records needed to support earlier purchases.
- Historical payment data: for purchases previously processed by Stripe, we do not see or store your card information; we receive the checkout email, Stripe customer/payment identifiers, and product metadata needed for access, support, refunds, accounting, and fraud prevention.
- Consulting inquiry data: the name, email, company, and message you send through our contact form.
- Patreon and other external services: when you follow a link to Patreon, Steam, PickBits Studio, PickBits Academy, or a social platform, that service handles your activity under its own privacy policy. PickBits.ai does not receive your Patreon payment details through the website.
- Usage analytics: page views, feature use, AB-test exposure, and basic device info (browser, screen size, country at the IP-region level) collected via PostHog and Google Analytics. Google Analytics 4 does not log or retain raw IP addresses. PostHog is not loaded at all for visitors we detect as being in the EEA, UK, or Switzerland — no PostHog identifier, cookie, or event is created for them.
- Advertising: some pages carry Google AdSense. Where ads are served, Google may set its own cookies (for example
__gads,__gpi) to deliver, measure and frequency-cap ads. Ads are never requested for signed-in PickBits users, and are currently held entirely for visitors we detect as being in the EEA, UK, or Switzerland pending a certified consent-management platform. - Server logs & error reports: request logs (path, status, timestamp), edge-function logs, and uncaught errors captured by Sentry. These may contain a hashed user ID for diagnostic correlation.
- Consulting booking data: when you book or request a call through our booking form, we collect your name, email, chosen or preferred times, and the details you provide about your company, phone number, topic, and how you found us. We also record the referring page, submission time, IP address, and browser information. We use this information to arrange the call, send confirmations, and prepare for the conversation.
- Communications: if you email us, we keep the email and any attachments to provide support.
How We Use Your Information
- Create and operate your account.
- Operate SDK features such as saves, achievements, scores, and connected-product identity.
- Respond to consulting inquiries and prepare for scheduled conversations.
- Support historical purchases, entitlements, refunds, and accounting obligations.
- Diagnose technical issues and improve the service.
- Send transactional email related to your account, inquiry, booking, security, or historical purchase.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations.
Third-Party Services
We share data only with the third-party services necessary to operate PickBits. We do not sell personal information.
| Provider | Purpose | What it sees |
|---|---|---|
| Supabase | Authentication, database, SDK and edge functions | Account profile, saves, scores, entitlements, and server logs |
| Stripe | Historical purchase and subscription records | Card data handled by Stripe, email, billing address, and transaction metadata |
| Substack | Historical subscriber records | Email and legacy subscription state governed by Substack's own privacy policy |
| FormSubmit | Delivering consulting inquiry forms | Name, email, company, message, and standard request metadata |
| Resend | Booking notifications and confirmation emails | Email addresses, booking details, and request metadata included in notification emails |
| Patreon | Experimenters membership on Patreon's site | Information you provide to Patreon; Patreon acts under its own privacy policy |
| PostHog | Product analytics, feature flags, A/B tests | Anonymous or pseudonymous usage events, distinct ID |
| Google Analytics (GA4) | Aggregate website analytics | Page views, country-level IP region, device class |
| Google AdSense | Advertising on a subset of public pages | Ad impressions and Google's own advertising cookies; not served to signed-in users or to EEA/UK/CH visitors |
| Sentry | Error and performance monitoring | Exception traces, sometimes a hashed user ID |
| AWS | Website hosting, booking processing, and booking storage | Booking form details, reserved slots, and HTTP request logs (IP, path, user-agent) |
| Vercel | Hosting for adjacent apps (e.g., Ask Mark) | HTTP request logs |
| OpenAI / Anthropic / other model providers | AI features and content generation | Prompts you submit through AI features; we do not pass your account email |
We may also disclose information if required by law, valid legal process, or to protect the safety of our users, the public, or PickBits.
Cookies & Local Storage
The table below lists what PickBits and its providers store in your browser. "Strictly necessary" items are required to deliver a service you asked for and are not used for tracking.
| Name | Type | Set by | Purpose | Lifetime |
|---|---|---|---|---|
sb-<project>-auth-token | Local storage | PickBits (Supabase) | Strictly necessary — keeps you signed in | Until sign-out |
pb-redesign-tweaks | Local storage | PickBits | Preference — your light/dark theme and accent choice | Until cleared |
pb_internal | Local storage | PickBits | Preference — marks staff devices so we can exclude our own traffic from analytics | Until cleared |
_ga, _ga_<id> | Cookie | Google Analytics | Analytics — distinguishes visitors and sessions | Up to 2 years |
ph_<key>_posthog | Cookie | PostHog | Analytics — product usage and feature flags. Not set for EEA/UK/CH visitors | Up to 1 year |
__gads, __gpi | Cookie | Google AdSense | Advertising — ad delivery, measurement and frequency capping. Not set for signed-in users or EEA/UK/CH visitors | Up to 13 months |
External services such as Patreon, Steam, FormSubmit, Studio, Academy, and social platforms may set cookies after you follow a link or submit a form; their privacy policies govern those interactions.
Your Choices About Tracking
We do not currently show a cookie banner to visitors outside the EEA, UK and Switzerland, because we apply the stricter setting to those regions by default rather than asking:
- Google Consent Mode v2 runs on every page and defaults analytics, advertising, personalisation and functionality storage to denied for visitors in the EEA, UK and Switzerland. Google's tags then operate without cookies unless and until consent is granted.
- PostHog is not loaded at all for those visitors — the script exits before the SDK is fetched, so there is no identifier, cookie, network request or event.
- Advertising is held for those visitors pending a Google-certified consent-management platform, and is never requested for signed-in PickBits users.
Everywhere else, analytics run by default. You can opt out at any time by using your browser's Do Not Track / tracking-protection settings, by installing the Google Analytics opt-out add-on, or by emailing owner@pickbits.ai and asking us to exclude you. You can clear cookies and local storage through your browser at any time, though doing so will sign you out and reset preferences.
Data Retention
- Account, profile, SDK, and connected-product data: kept while your account is active or as needed to provide the service.
- Consulting inquiries and booking correspondence: kept while reasonably needed to respond, scope work, and maintain business records.
- Stripe payment records: kept as long as required by tax and accounting law (typically 7 years).
- Server access logs: 30–90 days, depending on the provider.
- Aggregated, de-identified analytics: kept indefinitely.
- Email correspondence: kept while reasonably needed to provide support and comply with legal obligations.
If you delete your account, we remove or anonymise your personal data within 30 days, except for records we are legally required to retain (notably Stripe payment records).
Legal Bases for Processing (UK / EU)
If you are in the UK or EEA, we rely on the following bases under the UK GDPR and EU GDPR:
| What we do | Legal basis |
|---|---|
| Create and operate your account; deliver SDK services and support historical purchases | Performance of a contract |
| Process payments and keep the resulting financial records | Performance of a contract; legal obligation (tax and accounting) |
| Send transactional email (receipts, scheduling, security alerts) | Performance of a contract |
| Respond to consulting inquiries and schedule requested conversations | Steps at your request before entering a contract; legitimate interests |
| Analytics and advertising cookies | Consent. Not collected in the EEA, UK or Switzerland — see Your Choices About Tracking above |
| Security, fraud and abuse prevention; diagnosing errors; keeping the service working | Legitimate interests (running a secure, functioning service), balanced against your rights |
| Responding to legal requests | Legal obligation |
Your Rights
- Access: request a copy of the personal data we hold about you.
- Correction: update or correct inaccurate information from your dashboard or by emailing us.
- Deletion: request account deletion by emailing owner@pickbits.ai.
- Portability: request a machine-readable export of your data.
- Objection / restriction: object to or restrict particular processing where the law allows.
- Withdraw consent: for any processing based on consent, withdraw at any time without affecting the lawfulness of prior processing.
- Complaint: users in the UK or EU may lodge a complaint with their national data-protection authority.
Data Security
We use industry-standard security measures: HTTPS for all traffic, Supabase row-level security, secure password hashing for the auth provider, scoped service-role keys for privileged edge functions, and an admin-secret-protected reconciliation interface. No system is 100% secure; we cannot guarantee absolute protection against every form of unauthorised access. Significant data breaches will be communicated to affected users and regulators where required by law.
International Data Transfers
PickBits is operated from the United States. By using the service, you consent to your information being processed in the US and in any country where our service providers operate. Where required, we rely on Standard Contractual Clauses or equivalent safeguards for transfers from the UK / EU.
Children Under 13
PickBits is not intended for children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.
Changes to This Policy
We may update this policy from time to time. Material changes will be communicated via the website or by email to your account address. Continued use after the effective date of an updated policy constitutes acceptance.
Data Controller & Contact
The data controller for the processing described in this policy is PickBits.AI, at the address below. For any privacy question, or to exercise any of the rights above, email us — a named person reads that address and we aim to respond within 30 days.
PickBits.AI
Glendale, Arizona, USA
Email: owner@pickbits.ai