Privacy Policy

Last updated: June 21, 2026

Summary

PitIQ is designed to work without an account and stores your fantasy team locally on your device by default. We do not show ads, we do not sell or share personal information, and we do not use third-party advertising trackers.

Data controller

The data controller for PitIQ is Kayra Tozan (tozankayra4@gmail.com). By using PitIQ you acknowledge that your data is processed as described below.

Age requirement (COPPA / GDPR)

PitIQ is not directed at children under 13 years of age (or the applicable minimum age in your country — 16 in most EU member states). We do not knowingly collect personal information from children below this age. If you believe a child has provided personal data, please contact us and we will delete it promptly.

Data stored on your device

Your selected team (driver and constructor identifiers, captain choice), price history snapshots, and a cache of public race statistics are stored in the app's local storage. Deleting the app removes this data.

Optional cloud features

When cloud sync is enabled and you sign in, your team selection is stored in our database (hosted by Supabase, EU region) linked to your account identifier, protected by row-level security so only you can read it. Anonymous sessions (no email required) are created automatically to support cloud features. You can delete all stored data at any time via Settings → "Delete my data and reset". The legal basis for this processing is the performance of a contract — these features operate only at your explicit request.

AI coach

When you tap "Explain like a coach", your team selection and our computed analysis (driver names, scores — no personal information) are sent to our server, which forwards them to Anthropic (anthropic.com) to generate the explanation text. Anthropic processes data in the United States. The request contains no identifiers beyond your anonymous account session and is rate-limited. Usage events are logged to enforce rate limits and are deleted after 7 days. The legal basis for this processing is our legitimate interest in providing the AI coaching feature you requested and preventing service abuse.

Analytics (PostHog)

PitIQ uses PostHog (posthog.com) to collect anonymised usage events (e.g., which tabs are visited, paywall views, onboarding completion). These events contain no personal information. PostHog processes data in the United States. The legal basis for this processing is your consent, given during onboarding. You can withdraw consent at any time via Settings → "Data & privacy" → Analytics toggle. Withdrawing consent stops all further event collection and deletes your PostHog identity.

Crash reporting (Sentry)

PitIQ uses Sentry (sentry.io) to automatically collect crash reports and error diagnostics. This data may include device model, OS version, app version, and anonymised stack traces. It does not include your name, email, or team selection. Crash reports are used solely to identify and fix software defects. Sentry processes data in the United States. The legal basis for this processing is our legitimate interest in maintaining the stability and security of PitIQ. For more information, see sentry.io/privacy.

Subscriptions (RevenueCat)

PitIQ uses RevenueCat (revenuecat.com) to manage in-app purchases and Pro subscription status. RevenueCat receives purchase transaction identifiers and subscription entitlement data from the App Store or Google Play. RevenueCat does not receive your name or email address. RevenueCat processes data in the United States. The legal basis for this processing is the performance of a contract — RevenueCat's records are necessary to verify and deliver your Pro subscription. For more information, see revenuecat.com/privacy.

Network requests

The app fetches public race results from the Jolpica-F1 API (jolpi.ca) over HTTPS. That request contains no personal data. Jolpica data is used under CC BY-NC-SA 4.0.

Data retention

DataRetained until
Device-local team dataUntil you delete the app
Cloud team data (saved_teams)Until you use "Delete my data and reset" or delete your account
Anonymous sessionUntil you delete your data, or after 24 months of inactivity
AI rate-limit logs7 days
Crash reports (Sentry)90 days
Analytics events (PostHog)Until you withdraw consent or delete your account
Purchase records (RevenueCat)Duration of subscription + 3 years for legal and dispute-resolution purposes

Your rights

Depending on your jurisdiction (including GDPR, KVKK, CCPA), you may have rights to access, correct, export, or delete your data. To exercise these rights, contact: Kayra Tozan · tozankayra4@gmail.com. We will respond within 30 days.

You also have the right to lodge a complaint with a supervisory authority. In Turkey: Kişisel Verileri Koruma Kurumu (kvkk.gov.tr). In the EU/EEA: your local data protection authority. In the UK: the Information Commissioner's Office (ico.org.uk).