Wise Prediction Privacy Policy
Last updated: September 21, 2026
1. Introduction
This is the privacy policy for Wise Prediction, the AI sports prediction service at wiseprediction.com. Wise Prediction is operated by Loheden AI Solutions AB ("we", "our", or "us"), a company registered in Sweden, which is the data controller for the personal data described here. It explains how we collect, use, disclose and safeguard your information when you use the Wise Prediction website (the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with any part of it, please do not use the Service.
Wise Prediction also publishes mobile apps on the App Store and Google Play. Those apps are covered by their own policies: the Soccer Predictions app privacy policy, the basketball app privacy policy, and the baseball and American football app privacy policy.
2. Information We Collect
We are committed to the principle of data minimisation and only collect personal data that is necessary for the provision of the Service. You can browse every fixture we follow on this website without an account and without giving us anything. The types of information we collect include:
2.1 Account Information
An account on this website is created only through Google Sign-In, so the account information we hold is the information Google gives us, described in section 3. We do not ask you for a password, and we do not hold one.
2.2 Usage Data
We may collect information about your interactions with the Service, including:
- IP address
- Usage related statistics
- Request logs
- Date and time of visits
- Whether the account holds access bought before 16 September 2026, and when it expires
- Browser type and version
- Pages visited and time spent on those pages
- Referring and exit pages
- Operating system
- Other diagnostic data
- Device information
- Approximate location information
- Other technical information collected automatically
Legal Basis: The processing of this data is based on our legitimate interests in improving and securing the Service (Article 6(1)(f) GDPR).
3. Google User Data
Signing in to Wise Prediction with your Google account is optional, and it is the only way to create an account on this website. This section describes exactly what we receive from Google, what we do with it, where it is kept, how long we keep it, and what we will never do with it. Wise Prediction's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
3.1 What we ask Google for
When you choose to sign in, we ask Google for two permissions and no others:
profile, which gives us your name, your Google account ID and your profile picture if you have oneemail, which gives us your Google account email address and whether Google has verified it
We do not ask for access to your Gmail, your Drive, your Calendar, your Contacts, or anything else in your Google account.
Legal Basis: The processing of this data is based on your consent (Article 6(1)(a) GDPR), and on the performance of a contract where you hold paid access (Article 6(1)(b) GDPR). You can review and withdraw the permission you granted us at any time from your Google account settings.
3.2 What we do with it
We use the data Google gives us for these purposes only:
- To recognise you as the same person the next time you sign in, using your Google account ID
- To show your name and email address on your own account page
- To identify which access, if any, your account holds, and until when
- To reply to you if you contact us about your account, or to tell you something you need to know about your account
We do not use it for anything else.
3.3 What we store, where, and how it is protected
What we store from Google is your name, your email address, your Google account ID and the profile payload Google returns at sign-in, together with the date your account was created and the date you last signed in. We do not store Google access tokens or refresh tokens: we ask Google for offline access at no point, and our sign-in library is configured not to keep tokens after the sign-in is complete. We never see and never hold your Google password.
This data is stored in our application database, hosted by DigitalOcean on servers in Germany, inside the European Union. It travels between your browser and us over HTTPS only, the database is not reachable from the public internet, and access to it is limited to the people who operate the Service.
3.4 How long we keep it, and how to delete it
We keep it for as long as your account exists. You can delete your account yourself at any time from your account page, while you can still sign in. If you can no longer sign in, write to [email protected] from the address the account uses and we will delete it for you.
When an account is deleted, your name, your Google account ID, your profile picture and the profile payload Google returned are all deleted with it, and nothing is left that we could use to sign you in again. One thing survives, and we would rather say so plainly: a bookkeeping record that includes the account's email address, when the account was opened and closed, and what was bought. Swedish bookkeeping law requires us to keep it for seven years from the end of the financial year in question, so a request to erase it cannot be honoured until that period ends. It is not used for any other purpose.
3.5 What we never do with it
We do not, and will not:
- Sell it, or transfer it to data brokers or information resellers
- Use it for targeted advertising, or for advertising of any kind
- Use it to train generalised machine learning or artificial intelligence models
- Transfer it to anyone, except to the service providers listed in section 6 who process it on our behalf under a data processing agreement, or where the law requires us to
- Allow a human to read it, other than where you have asked us to help with your account, where the law requires it, or where it is necessary for security
4. How We Use Your Information
We use the collected information for these purposes:
- To provide and maintain the Service
- To manage your account and the access it holds
- To improve the Service
- To communicate with you about matters concerning the Service
- To provide customer support
- To detect, prevent and address technical issues and abuse
- To comply with legal obligations
5. Data Retention
We retain your personal information only for as long as necessary to fulfil the purposes outlined in this policy, unless a longer retention period is required or permitted by law.
5.1 Account Deletion
You may delete your account at any time. If you can sign in, you can do it yourself from your account page. If you cannot sign in, write to [email protected] from the address the account uses and we will delete it for you. On deletion we remove your account, your profile and everything Google gave us, as described in section 3.4.
5.2 Information Retained After Account Deletion
What survives an account deletion is a single bookkeeping record, held separately and linked to nothing else. It contains:
- The email address the account used
- The date the account was created, the date it was last used, and the date it was deleted
- Whether the account holder had agreed to receive email from us
- What was bought, when, in which currency, and the Stripe customer and payment identifiers for it
We keep it because Swedish bookkeeping law requires it, for seven years from the end of the financial year the purchase falls in, and because it is the evidence we would need to answer a payment dispute. We do not use it for anything else.
5.3 Legal Basis for Retention
The legal basis for this retention under GDPR is:
- Compliance with legal obligations (Article 6(1)(c) GDPR)
- Our legitimate interests (Article 6(1)(f) GDPR), which include protecting our business from fraud, maintaining security, and defending against potential legal claims
We have considered and balanced our legitimate interests against your rights and freedoms and believe that retaining this limited information is necessary and proportionate.
6. Sharing Your Information
6.1 Service Providers
We share your information with third party service providers who perform services on our behalf:
- DigitalOcean, which hosts the application and its database, on servers in Germany
- Cloudflare, which serves the website and protects it from attack
- Google Cloud and Firebase, which hold the prediction data the site displays, and which handle sign-in in our mobile apps
- Stripe, which processed payments on this website until 16 September 2026
- Resend, which delivers email we send you
These providers are obliged not to use your personal information for any purpose other than providing their service to us. We have data processing agreements in place with every provider that processes personal data on our behalf, ensuring they comply with GDPR and other applicable data protection laws.
6.2 Payment Processing
This website no longer sells access. Paid access is bought inside our mobile applications, through the Apple App Store and Google Play, and those stores handle the payment and the payment data.
We used Stripe as our payment processor for purchases made on this website until 16 September 2026. We never stored full payment details, and we still do not. What we hold from that period is the record of the purchase itself: the Stripe customer and payment identifiers, the amount, the currency, the date and the billing details Stripe collected. We keep it because Swedish bookkeeping law requires it, for seven years from the end of the financial year the purchase falls in, and because it is the evidence we would need to answer a payment dispute. Please review Stripe's privacy policy for more information on how they handle your data.
6.3 Google Sign-In
When you sign in with Google, your browser talks to Google directly to authenticate you, and Google then tells us who you are. That exchange is governed by Google's own privacy policy, which we recommend reading: https://policies.google.com/privacy. What we do with what Google tells us is described in section 3.
6.4 Legal Requirements
We may disclose your information if required to do so by law, or in response to valid requests by public authorities such as a court or a government agency.
7. Cookies and Tracking Technologies
We use only strictly necessary cookies, and we name every one of them below. None is used for advertising, and none is used to follow you between websites.
7.1 The Cookies We Set
There are three, and this is the whole list:
| Name | Set by | What it is for | How long it lasts |
|---|---|---|---|
__cf_bm |
Cloudflare, which serves this website | Tells automated traffic from people, so the site can refuse bots without challenging you. It cannot be used to identify you across other websites. | 30 minutes |
sessionid |
Us | Keeps you signed in while you are signed in. It holds a random identifier, nothing about you. | Until you close your browser |
csrftoken |
Us | Set when a page shows you a form, and used to check that the form was submitted from this website rather than forged by another one. | One year |
All three are strictly necessary: one keeps the site up, one keeps you signed in, and one stops a form being forged. None of them tracks you, builds a profile, or follows you to another website. You may disable them in your browser settings, but signing in will then not work.
We set nothing else. Our analytics is measured without cookies and without an identifier for you, so it places nothing on your device.
7.2 No Consent Required
Under the ePrivacy Directive as implemented in Swedish law, and under the GDPR, consent is not required for cookies that are strictly necessary for the provision of a service the user has explicitly asked for. All three above are of that kind, which is why this site shows you no cookie banner. If we ever set a cookie that is not strictly necessary, we will ask you first.
7.3 Managing Cookies
Most web browsers allow some control of cookies through the browser settings. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org.
8. Data Transfer and Storage
Loheden AI Solutions AB is registered in Sweden, a member state of the European Union. Your account data is stored with DigitalOcean on servers in Germany, also inside the EU.
Please be aware that:
- We may change our cloud service provider in the future.
- The location of the servers where your data is processed and stored may change.
- Your information may be transferred to, and maintained on, computers located outside your state, province, country or other governmental jurisdiction.
For transfers of data outside the EU and EEA, we use standard contractual clauses approved by the European Commission, or other appropriate legal mechanisms, to ensure adequate protection of your data.
9. Security of Your Information
The security of your information matters to us, but no method of transmission over the internet, and no method of electronic storage, is completely secure. While we use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
9.1 Data Breach Notification
In the event of a data breach likely to result in a risk to your rights and freedoms, we will notify you and the relevant supervisory authority within 72 hours of becoming aware of it, in accordance with GDPR requirements.
10. Your Data Protection Rights Under GDPR
If you are a resident of the European Economic Area, you have certain data protection rights. We take reasonable steps to let you correct, amend, delete or limit the use of your personal information.
Your rights include:
- The right to access, update or delete the information we hold about you
- The right of rectification, meaning the right to have your information corrected if it is inaccurate or incomplete
- The right to object to our processing of your personal data
- The right of restriction, meaning the right to ask us to restrict the processing of your personal information
- The right to data portability, meaning the right to be given a copy of your personal data in a structured, machine readable and commonly used format. This right applies to data you provided to us, that we process based on your consent or for the performance of a contract, and that we process by automated means.
- The right to withdraw consent at any time, where we rely on your consent to process your personal information
10.1 How to Submit a Request
To exercise any of these rights, contact us at [email protected]. We may need to verify your identity before responding. We will respond to all legitimate requests within one month.
11. Children's Privacy
The Service does not address anyone under the age of 18. We do not knowingly collect personally identifiable information from anyone under 18. If you are a parent or guardian and you become aware that your child has provided us with personal data, please contact us. If we learn that we have collected personal data from a child without verification of parental consent, we take steps to remove that information from our servers.
12. Changes to This Privacy Policy
We may update this policy from time to time. We will notify you of any change by posting the new policy on this page and updating the "Last updated" date at the top. If we change how the Service uses data received from Google, we will say so here before the change takes effect. You are advised to review this policy periodically. Changes are effective when they are posted on this page.
13. Email We Send You
We send two kinds of email, and they are not treated alike.
Email about your account. If something happens that you need to know about, such as a change to your access or to this policy, we may write to you at the address on your account. You cannot opt out of these, because they are part of providing the Service.
Email about the product. News, offers and anything else that is not strictly about your account is sent only to people who have said yes to it. You are asked once, plainly, and your answer is recorded on your account. If you say no, nothing of this kind is sent. If you say yes, you can change your mind at any time, from your account page or by using the unsubscribe link in any such email. We never add you to this on the basis of having signed in with Google.
We use Resend to deliver email.
14. Contact Us
If you have any question about this policy, about our data practices, or you want to exercise your data protection rights, write to us at [email protected].
By using the Service, you acknowledge that you have read, understood and agreed to this Privacy Policy.