Privacy Statement
Last updated 12 June 2026
Who we are and what this covers
Opono Football is operated by Opono Network Limited (“Opono”, “we”, “us”). For the personal data we decide how and why to process, Opono is the controller. This statement covers the Opono Football website, workbench, accounts, passes, credits, support, and related product communications. It should be read with our Terms and Conditions.
Product context
Opono Football is an AI-assisted football analysis workbench. Users can explore teams, matches, simulated scenarios, probabilistic forecasts, credit-metered analyses, and football data. The product is for information and entertainment only. It is not betting, gambling, financial, legal, professional, or sporting advice, and we do not hold stakes, wagers, gambling funds, or betting-account information.
Personal data we collect
- Account and identity data: email address, name if available, authentication identifiers, sign-in status, session information, and account settings provided through WorkOS AuthKit.
- Workbench and product data: teams, nations, matches, saved boards, pinned or archived items, scenarios, analysis requests, generated outputs, credit usage, and similar product state. Signed-out demo state may stay only in your browser. Signed-in product state may be stored against your account.
- Billing and entitlement data: checkout status, pass or tier, credit balances, transaction identifiers, Stripe customer identifiers, billing email, receipts, refunds, and accounting records. Stripe processes card details; we do not receive or store full card numbers.
- Technical, security, and usage data: IP address, approximate location derived from network data, device and browser details, URLs requested, timestamps, error reports, diagnostic logs, rate-limit signals, fraud-prevention signals, and security events.
- Communications data: messages you send to us, support requests, enterprise or press enquiries, survey responses, and any email preferences. If you previously joined a waitlist or asked for launch updates, we may retain that contact record until you unsubscribe or ask us to delete it.
- Notification data: browser notification permission is controlled by your browser. The current app may use followed teams or matches to trigger local or in-app notifications, but it does not run a separate push-notification backend.
- Sports data: fixtures, teams, squads, players, officials, scores, odds-like market inputs where licensed, and other football data from public or licensed sports-data providers. If you are a player, coach, official, or other person appearing in sports datasets, that data usually comes from those sources rather than directly from you.
Data we do not intentionally collect
We do not intentionally collect full payment-card numbers, government ID numbers, precise GPS location, health data, biometric identifiers, personal data from children under the minimum age described below, or special-category/sensitive personal data through the ordinary Opono Football workflow. Please do not put private or sensitive personal information into prompts, scenarios, notes, support requests, or uploaded material if a future feature allows uploads.
Cookies and local storage
Essential cookies and similar technologies keep the site running, including WorkOS AuthKit session cookies and security-related records. Stripe may use its own cookies and fraud-prevention technologies during checkout. Opono also uses browser localStorage for demo mode and workbench state, including keys such as
opono:* for saved teams, matches, boards, credits, sign-in display state, pins, archives, and similar preferences. Our analytics tools (below) also store identifiers in cookies or localStorage to distinguish visits. You can clear cookies and localStorage in your browser settings.Analytics and session replay
We use PostHog (hosted in the European Union) to understand how the product is used: page views, clicks and interactions, device and browser details, approximate location derived from network data, web-performance measurements, and session replays— reconstructions of how a visitor moves through our pages (typed input is masked by default in sensitive fields, and we do not intentionally capture payment details, which are entered on Stripe's pages). We also use Vercel Web Analytics, a privacy-focused, aggregate traffic measurement that does not use cookies or track individuals across sites. We use this information to fix problems, improve the product, and measure what works; we do not sell it or use it for cross-site advertising. If you object to this processing, contact us at the address below — and you can limit it yourself with browser tracking protections or by clearing storage.
How we use personal data
- Provide, personalise, sync, and secure the Opono Football service.
- Authenticate users, manage sessions, prevent abuse, and enforce account and credit limits.
- Save workbench state, generate analyses, return AI-assisted football outputs, and keep an audit trail of credit grants and spends.
- Process purchases, receipts, refunds, tax, accounting, fraud checks, and billing support through Stripe.
- Monitor uptime, debug errors, improve speed, maintain security, and investigate suspicious activity.
- Respond to support requests and send service, legal, security, billing, product, or optional marketing communications.
- Improve the product, football models, prompts, ranking, safety, and reliability using usage patterns, analysis requests, outputs, logs, and feedback, while minimising direct identifiers where practical.
- Comply with law, enforce our terms, protect rights and safety, and support corporate transactions such as financing, acquisition, or reorganisation.
We do not use full payment details or authentication tokens for model training. The planned analysis service receives the analysis kind and payload needed to run the job; user authentication tokens do not need to leave the Opono web server for that service call. If we materially expand how personal data is used for model training, advertising, or third-party data sharing, we will update this statement and obtain consent where the law requires it.
Legal bases where privacy law requires them
Where UK GDPR, EU GDPR, LGPD, KVKK, or similar laws require a legal basis, we rely on:
- Contract, to provide accounts, saved workspaces, analyses, purchases, credits, support, and service communications.
- Legitimate interests, to secure the service, prevent fraud, debug issues, understand usage, improve Opono Football, and protect our users and business, balanced against privacy rights.
- Legal obligation, for tax, accounting, sanctions, payment, consumer-protection, records, and lawful request obligations.
- Consent, where required for optional marketing, browser notifications, non-essential cookies, or certain future data uses. You may withdraw consent through the relevant control or by contacting us.
How we share personal data
We do not sell personal data. We also do not currently share personal data for cross-context behavioural advertising. We may share personal data with:
- Service providers that help us run Opono, including WorkOS for authentication, Convex for database and backend functions, Vercel for hosting and aggregate web analytics, Stripe for payments, PostHog for product analytics and session replay (EU-hosted), Google Cloud for data storage and future analysis compute, Better Stack or similar uptime-monitoring tools, Resend or similar email tools, support tools, and security vendors.
- Sports-data providers, such as SportMonks and any future licensed football-data suppliers, where needed to provide fixture, team, player, live-match, and analytics features.
- Professional advisers, including lawyers, accountants, auditors, insurers, banks, and corporate advisers.
- Authorities or other parties when we believe disclosure is legally required, protects rights or safety, prevents abuse, enforces our terms, or responds to valid legal process.
- Corporate transaction parties if we explore or complete a merger, acquisition, financing, restructuring, or sale of assets, subject to appropriate confidentiality and legal safeguards.
International transfers
Opono is UK-based, but our providers may process data in the United Kingdom, the European Economic Area, the United States, and other countries. Where required, we use contractual, technical, and organisational safeguards such as data processing agreements, standard contractual clauses, transfer risk assessments, encryption in transit, access controls, and vendor due diligence.
Retention
We keep personal data only for as long as reasonably needed for the purposes above:
- Account and workbench data is generally kept while your account is active or while needed to provide the service.
- Billing, tax, accounting, and fraud-prevention records may be kept for up to seven years, or longer if required by law or a dispute.
- Security logs, diagnostics, and server logs are kept for shorter operational periods unless needed for investigation, safety, legal, or abuse-prevention reasons.
- Analytics events and session replays are kept for the retention period configured with our analytics provider and then deleted or aggregated; session replays are kept for a shorter period than event statistics.
- LocalStorage data remains in your browser until you clear it, change browser profile, or the app overwrites it.
- Backups may retain deleted data temporarily until they are overwritten according to ordinary backup cycles.
- Marketing or waitlist contact records are kept until you unsubscribe, object, or ask us to delete them, unless we need a suppression record to respect that request.
Security
We use reasonable technical and organisational safeguards, including encrypted connections, hosted authentication, signature-verified payment webhooks, server-side entitlement checks, secret-managed service calls, access controls, least-privilege practices, dependency review, and provider security controls. No internet service can guarantee perfect security. If you believe your account or data has been compromised, contact us promptly.
Your choices and rights
Depending on where you live, you may have rights to access, correct, delete, export, restrict, object to, or obtain a copy of personal data; withdraw consent; opt out of marketing; complain to a supervisory authority; and appeal certain decisions. California and other US state privacy laws may also give rights to know, delete, correct, opt out of sale or sharing, and limit certain sensitive-data uses. We do not currently sell personal data, share it for cross-context behavioural advertising, or intentionally collect sensitive personal data for ordinary product use. Brazil’s LGPD and Turkey’s KVKK provide similar rights, including confirmation/access, correction, deletion or anonymisation in some cases, information about sharing, objection where allowed, and review of certain automated decisions.
How to exercise rights
Email privacy@opono.com. We may need to verify your identity and account before acting on a request. We will not discriminate against you for exercising privacy rights, but some requests may limit our ability to provide account, payment, or saved-workbench features. If you are in the UK, you may complain to the Information Commissioner’s Office. If you are elsewhere, you may contact your local data-protection authority.
Children
Opono Football is not directed to children under 13, or under the minimum age required in their country to consent to use online services. We do not knowingly collect personal data from children below that age. Users under the age of legal majority should use accounts, paid features, and credit-metered analysis only with permission from a parent or legal guardian. If you believe a child below the minimum age has provided personal data, contact us and we will take appropriate steps.
AI and automated outputs
Opono produces probabilistic football analysis, simulations, and generated explanations. These outputs concern football events and product usage, not legally significant decisions about users. Do not use Opono outputs to make decisions about employment, credit, insurance, healthcare, eligibility, legal rights, gambling, or other high-impact matters. If we introduce AI features that make or materially support decisions about people, we will update this statement and provide the notices, controls, and safeguards required by law.
Marketing communications
We may send service, legal, security, and billing messages even if you opt out of marketing. Optional product or launch marketing emails will include an unsubscribe option where required. You can also contact us to change preferences.
Third-party services and links
Links to WorkOS, Stripe, sports-data providers, social platforms, app stores, or external websites are governed by those services’ own privacy notices. We are not responsible for third-party websites that we do not control.
Changes to this statement
We may update this statement as Opono Football, its providers, data flows, AI capabilities, or legal obligations change. If a change is material, we will take reasonable steps to notify users, for example by updating this page, sending an account email, or showing an in-product notice.
Contact
For privacy questions, requests, or complaints, email privacy@opono.com.
Opono Football is an AI-assisted engine for exploring real-world football dynamics. Its outputs are probabilistic forecasts for information and entertainment only - not betting advice, professional advice, or a guarantee of any outcome.