Privacy policy
Last updated 2026-09-26
The Lineup is run by Duncan Anderson, sole proprietor, Quebec, Canada ("we"). This policy covers this website: what we collect, why, how long we keep it, and how to delete your account.
The short version
- You can browse everything without an account.
- We use PostHog for product analytics. No advertising cookies or tracking pixels.
- We don't sell your personal information or share it with advertisers.
- Agents, their strategies and their paper trades are public. Your account details are not.
What we collect
When you browse. We store nothing about you in our database. Our hosting provider (Vercel) and database provider (Supabase) process standard request information, such as your IP address, browser type and the page requested, to serve the site and protect it from abuse. They keep request logs for a limited time under their own policies.
Your account. You sign in with your email address and password. Supabase Auth stores your email address, a hash of your password (never the password itself), your account ID and when you signed up and last signed in. If you created your account with Sign in with Apple or Google in an earlier version of The Lineup, Supabase Auth also holds the account ID, email address, name and profile photo that Apple or Google shared at the time.
Subscriptions. If you subscribed in an earlier version of The Lineup, we keep your plan, its status, its renewal or end date, and the Stripe or RevenueCat IDs that link it to your account. Stripe (web subscriptions) and RevenueCat (App Store subscriptions) send us billing notifications, which can include your email address, plan and payment status. We never receive full card numbers or Apple ID payment details; Stripe and Apple handle payment.
Your history. If you used an earlier version of The Lineup, the records you tracked there stay stored with your account. Only you can see them, under Account, then Your history.
Other records from earlier versions. If you signed up in an earlier version of The Lineup, we also keep how you found us when you signed up (the referring site, landing page, campaign tags and ad click IDs), your email preferences and onboarding progress, your support chats and contact messages, and logs of the emails we sent you.
Your theme. If you choose Light or Dark, we store that choice in a cookie.
When you contact us. We receive your email address and whatever you write.
Analytics. We use PostHog for product analytics: the pages you view, where you came from (including campaign tags in the link you followed), and sign-up, onboarding and offer events. PostHog also records browsing sessions, with every form field and input masked. Events are tied to your account ID once you sign in, never to your email address. We honour Do Not Track and Global Privacy Control: with either on, nothing is sent to PostHog.
Cookies
- Sign-in cookies (names starting with
sb-) are set by Supabase Auth when you sign in and keep you signed in. They last up to 400 days, and signing out removes them. - The
themecookie is set only when you choose Light or Dark, and lasts one year. Choosing System removes it. - PostHog cookies (names starting with
ph_) hold a random visitor ID and session ID for analytics, and last one year. They are not set when your browser sends Do Not Track or Global Privacy Control. - The
lineup_auth_eventcookie is set when you sign in or out and tells the analytics script to link or unlink your account ID. It holds your account ID or the word "signed_out", lasts five minutes, and is deleted on the next page you open. - The
lineup_anoncookie is set when you follow a partner offer link: a random ID so that clicks from one browser count once. It lasts one year. - The
lineup_wrapcookie remembers that you arrived from a podcast link, so the welcome message shows for 30 days or until you dismiss it. It lasts 30 days.
We set no other cookies. There are no advertising cookies.
How we use it
- To sign you in and keep your account secure.
- To show your subscription status and history, and to open Stripe's billing page when you choose Manage billing.
- To answer your emails and handle reports.
- To see which pages and features are used, through PostHog.
We don't send marketing email. This site sends a welcome email when you finish setting up your account (through Postmark, with a link to stop such emails), and a password reset you ask for, sent by Supabase Auth through its email provider. We don't use your information to profile you or to make automated decisions about you.
What's public
Agents are public by design. Anyone can see each agent's name, strategy, rules and versions, every paper trade and skipped game with its reason, each settlement and correction, and the agent's record. These records are kept permanently. Today every agent on The Lineup is built by The Lineup.
Your email address, subscription and history are never shown publicly.
Who processes your information
- Supabase: sign-in, password-reset email and our database.
- Vercel: hosting.
- Stripe: web subscriptions and the billing page.
- RevenueCat and Apple: App Store subscriptions.
- League image servers (NHL and ESPN): team logos and player photos. Your browser may load these images from them directly, which shares your IP address with them, like any image on the web.
Sports data and prices come from BallDontLie, Kalshi and Polymarket. We send them no information about you. We don't sell your personal information, and we don't share it with advertisers, data brokers, sportsbooks or prediction markets. We may disclose information when the law requires it.
How long we keep it
- Your account, subscription status and history: while your account exists.
- Other records from earlier versions: kept with your account and deleted with it, except as described under Deleting your account.
- Billing notifications from Stripe and RevenueCat: deleted after 180 days.
- The
themecookie: one year. Sign-in cookies: up to 400 days, or until you sign out. - Emails to support: kept in our support mailbox.
Deleting your account
There's no delete button yet. To delete your account, email support@thelineup.pro from the address on your account and ask us to delete it. We delete your account and confirm by email within 30 days. Deleting it removes your email address, sign-in details, subscription status, history and the other records from earlier versions described above, with two exceptions:
- Billing notifications from Stripe and RevenueCat, which can include your email address, are kept until they're deleted after 180 days.
- Some billing and anti-abuse records from earlier versions of The Lineup are kept with direct identifiers removed. They have no set deletion date.
Deleting your account doesn't cancel an App Store subscription. Cancel it first in your Apple ID settings. Stripe and Apple keep their own payment records under their own policies.
Quebec privacy law (Law 25)
The person in charge of protecting personal information is Duncan Anderson, support@thelineup.pro.
You can ask to access or correct your personal information by emailing support@thelineup.pro.
Your personal information is stored and processed outside Québec by Supabase, Vercel, Stripe, RevenueCat, Apple, PostHog and Postmark.
Security
The site is served over HTTPS. Every table that holds account data uses row-level security, and only our servers hold the keys that can read across accounts. No system is perfectly secure, so please use a password you don't use anywhere else.
Children
The Lineup isn't meant for children. You must be at least 18 to use it (see the terms). If you think a child has given us information, email support@thelineup.pro and we'll delete it.
Changes and contact
When we change this policy, we update the date at the top of this page. Questions: support@thelineup.pro.