Last updated: 9 May 2026
Pitbrain is run by Greg C from the UK. This page explains what data the site collects, why, and what your rights are under the UK GDPR.
When you visit, the site logs the page URL, referrer, user-agent, and a one-way hash of your IP address (used only to approximate uniques and filter bots). No cookies are set for analytics. Bot traffic is filtered server-side and never used for product decisions.
If you sign up to play games, save predictions, or join the leaderboard, the site stores:
You can delete your account from the member dashboard. Deletion removes your account and predictions immediately. Aggregate leaderboard rows that reference you are anonymised.
If you choose the “Continue with Google” option on the sign-in or registration screen, the site receives only the openid, email and basic profile claims — that is, your verified email address, your name, your profile picture, and a stable Google identifier (the sub claim) used to recognise you on subsequent logins. The site never receives your Google password and never requests access to any other Google data: no Drive, no Calendar, no contacts, no Gmail. Your profile picture is read once at sign-in and is not stored.
The site stores: a SHA-256 hash of your verified email (for cross-account lookup), an AES-encrypted copy of your email, your display name, and the stable Google identifier. You can revoke Pitbrain’s access to your Google account at any time at myaccount.google.com/permissions; deleting your Pitbrain member account from the dashboard removes the Google link entirely on the Pitbrain side.
Data Google holds about you is governed by Google’s own privacy policy. Pitbrain has no visibility into and no control over how Google processes your data outside of the sign-in claims described above.
Standard nginx access logs are kept for 30 days. They contain timestamps, paths, status codes, user-agents, and source IPs (used for abuse detection only).
The only cookies set by Pitbrain are session cookies for logged-in members, a Cloudflare Turnstile cookie used during sign-in to block bots, and a short-lived (10-minute) CSRF cookie used during the Google OAuth handshake. There is no analytics cookie, no marketing cookie, no third-party cookie.
You can request access, correction, deletion, or export of any data the site holds about you via the contact form. The site honours all such requests within 30 days, free of charge.
The site is hosted in the UK. The database, backups, and email-sending infrastructure all run within the UK / EU.
This policy may be updated. Material changes are dated and noted on the corrections page.