Privacy Policy

Effective August 8, 2026.

Data we collect

Account data includes your verified email, your Google account identifier or a pseudonymous email sign-in identifier, internal account identifier, Stripe customer identifier, and subscription status. Workflow data includes uploaded projections, imported slate data, build state, preferences, generated lineup snapshots, and export metadata. We also keep limited usage, billing-event, and security records needed to enforce limits and operate the service. The public landing page records one page_view category when its script loads and an allowlisted action category when someone selects a connect link, pricing link, endpoint-copy control, or first-build prompt copy control. GameScript also records an allowlisted milestone category when an authorization is approved, a Stripe Checkout link is created, a subscription becomes active or trialing, an account completes its first optimization, and a new address joins the notify list. These application events carry the category and a count only, and contain no email, account identifier, page text, referrer, URL parameters, or IP address, so no event identifies you, and GameScript does not join them to accounts to build a per-person funnel. To count the first optimization once per account, GameScript stores one timestamp on your account row; it is deleted with your account. Structured application logs omit request bodies, full request URLs and query strings, OAuth codes and tokens, signed-download signatures, email addresses, account identifiers, projections, and lineups. Automatic Worker invocation logs are disabled; Cloudflare still processes request metadata as the hosting and security provider. Browser protections can block or drop these events, clients can forge them, and Cloudflare may sample them, so page-view and intent counts are estimates rather than unique visitors or verified signup or payment conversions. To enforce one trial and billing-action limits per sign-in identity, GameScript derives a one-way pseudonymous marker that contains neither your email nor your raw provider identifier. If you submit the landing page’s notify form, GameScript stores the email address you enter with surrounding spaces removed and the whole address lowercased, the single topic you selected, the page you submitted it from, and the time, so that it can send you the one email you asked for. Lowercasing is what lets one address and topic count as one signup however you capitalize it; mail providers treat the domain as case-insensitive, and the ones GameScript can reach treat the part before the @ that way too. This is the only place GameScript keeps a readable email address that is not an account: a sign-in counter can hold a one-way digest because it only ever has to recognize an address again, while a notify-list row exists to be written to, and a digest cannot be mailed. It is not linked to a GameScript account, is never sold, shared, or used for any other message, and submitting the same address again replaces nothing and adds nothing.

How we use data

We use this data to authenticate your MCP connection, persist your DFS workflow, enforce subscription access, generate requested lineups and exports, prevent abuse, troubleshoot failures, and operate the service. GameScript does not sell personal data or use your projections and lineups to train a projection model.

Assistant and payment providers

Your Claude or ChatGPT provider handles the conversation under its own privacy terms. GameScript receives tool calls and the data you choose to send through them. Google provides sign-in; where email one-time-code sign-in is enabled, Cloudflare Email Service instead delivers a short-lived code to the address you enter. Stripe processes payment details; GameScript does not store full card numbers.

Essential sign-in state and cookie

During Google sign-in, GameScript temporarily stores your verified Google email and account identifier in an expiring server-side sign-in record so it can display and complete the authorization step. Where email one-time-code sign-in is enabled and chosen, the same expiring record instead holds the address you enter, a hashed one-time code, and a small attempt count, and a pseudonymous daily counter of code requests is kept for up to 90 days to limit abuse. The secure, HTTP-only cookie contains only signed flow state. Submitting the consent form consumes the sign-in record immediately; otherwise, the record and cookie become unusable after 10 minutes and the record is removed during scheduled cleanup. GameScript creates a durable account only after you select Authorize. GameScript does not use advertising or cross-site tracking cookies.

Hosting and retention

Cloudflare hosts the Worker, D1 database, structured application logs, Analytics Engine, and R2 object storage. Structured application logs are retained under the Cloudflare Workers Logs retention window, currently up to seven days. Landing page-view, action, and milestone categories are retained in Analytics Engine for up to three months. Signed export links and export metadata expire after 24 hours; R2 export objects are deleted after one day. Generated lineup snapshots and old user-imported slates are deleted after 30 days. Usage and Stripe event records are deleted after 90 days. Active account data, preferences, and current build data remain until deletion, subject to operational backups and legal retention requirements. A notify-list address is kept until you ask for it to be removed, or until GameScript decides not to build the thing it was collected for and deletes the list. A redeemed one-way trial marker remains after account deletion to prevent repeat trials. Aggregate Checkout and customer-portal counters keyed only by the same one-way marker may remain for up to 90 days to prevent billing API abuse. After account deletion, GameScript also retains the raw, provider-linkable Stripe customer identifier and deletion timestamp as a deleted-customer safety record solely to suppress delayed Stripe webhooks and prevent account recreation. That safety record is retained for at most 90 days and is not linked to a live GameScript account. The trial marker and aggregate counters are likewise not linked to a live GameScript account.

What we do not access

We do not request DraftKings credentials, access your DraftKings account, or submit contest entries. You review and upload generated files yourself.

Your choices and contact

You can disconnect GameScript in your assistant settings to stop future tool access. To erase the connected account, ask your assistant to call dfs_delete_account; the tool requires your exact connected email and a strong confirmation phrase. An active, trialing, or past-due subscription must first be resolved in the Stripe customer portal. You can also request an account export, correction, or deletion at support@gamescriptai.app using your connected sign-in email. To leave the notify list, email the same address from the address you signed up with and the row is deleted; leaving the notify list is separate from deleting an account, and neither one removes the other. Legal retention may apply to billing records.