STUPID PRO / TRUST & TRANSPARENCY

Privacy Policy

1. Who we are and how to contact us

Stupid Pro is the research, news and points-based forecasting service at stupidpro.com. Saurabh Suman is the founder and contact person for the service. For privacy requests, complaints, corrections or questions, use our protected contact form and select “Privacy request”. This policy covers our website and its account, research and prediction features. Linked third-party sites have their own policies.

2. Information we collect and why

  • Account information: your authentication-provider user identifier, name, email address and email-verification status, to create and secure your account and provide support. Google/Firebase handles Google sign-in and email/password authentication; we do not receive your Google password.
  • Participation: forecasts and revisions, comments, follows, favourites, practice trades, points, referral records and timestamps, to operate questions, portfolios and leaderboards and prevent manipulation.
  • Research: watchlists, saved research, report requests, report results and usage limits, to provide the research workspace.
  • Submissions and support: information you supply in founder stories, contact messages or support correspondence, to review submissions and resolve requests.
  • Technical information: requests, IP addresses and device/browser information may be processed by hosting and authentication providers for delivery, security and abuse prevention. We do not request precise GPS location.
  • Optional approximate location: if you enable location sharing, country, city, rounded approximate coordinates and last-seen time derived from the network are stored for the administrator’s member map. Location sharing is optional and can be turned off in member controls; turning it off removes the current presence record.
  • Optional usage analytics: when you select Allow, we record supported question/story views and sharing events to understand engagement. Declining does not prevent public browsing or account use.

3. Google user data

Google sign-in is used to authenticate you and obtain basic identity information, including your name, email address and account identifier. The service does not request access to your Gmail messages, contacts, Drive files or calendars. We use Google identity data for sign-in, account administration, security and support. We do not sell it, use it for personalised advertising, or send it to an AI provider to train a general-purpose model. Access and use of Google API information will comply with the Google API Services User Data Policy, including its Limited Use requirements.

4. Cookies, browser storage and your choices

Essential authentication/session mechanisms keep you signed in and protect the service. Browser storage remembers preferences such as your region lens and analytics choice. Optional analytics require your choice in the site banner; you can change that choice in your dashboard. Some member controls are available only after sign-in. You can clear browser storage or revoke the Google connection in your Google Account. Revoking Google access or signing out does not by itself delete records already held by Stupid Pro.

5. What is public and what is private

Comments and submitted material approved for publication may be visible publicly. Leaderboards use forecaster labels rather than publishing your email. Public research datasets contain aggregated question-level participation and outcomes, not user emails, member location or individual vote history. Account emails and optional member-map information are restricted to authorised administrators. Avoid posting sensitive personal information in public comments, submissions or research prompts.

6. Service providers and disclosures

We use Cloudflare for hosting, delivery, security, database and media storage; Google Firebase for authentication; and Resend for transactional email. When an AI research feature is enabled, the relevant question, public source material and your research request may be sent to the AI service provider, such as OpenAI, to generate a response. We do not intentionally include account email, login credentials or member-location records in AI prompts. AI availability is shown in the product and is not guaranteed by this policy. Providers process data under their applicable terms and privacy policies. We may disclose information when legally required, to investigate abuse, protect rights or security, or complete a lawful business transfer with appropriate notice and safeguards. We do not sell personal information.

7. Storage, transfers and security

Providers may process or store information in India and other countries. Transfers are subject to applicable Indian legal restrictions and provider safeguards; we do not promise India-only storage. We use HTTPS, authenticated access and role-based restrictions to protect information. No system can guarantee absolute security. If a personal-data breach requires notice under applicable law, we will notify affected people and the appropriate authorities as required.

8. Retention and deletion

Account and participation records are retained while needed to provide the service, resolve questions and disputes, prevent abuse and meet legal obligations. Optional analytics and member-presence records are designed for a 90-day rolling window with scheduled cleanup; deletion timing may vary if a scheduled job fails. Backups, security logs, legal holds and provider records may follow different retention periods. You may request account deletion through our contact form. We will verify the request, delete or de-identify data no longer needed, and explain any lawful retention. Published comments, completed question outcomes and aggregate statistics may remain where lawful, with identifiers removed where appropriate. There is currently no self-service account-deletion button.

9. Your privacy rights and complaints

You can request access to or a summary of your personal information, correction, withdrawal of optional consent, and deletion by using our contact form with your registered email address. Contact forms use a single-use, time-limited image CAPTCHA and request limits; if enabled, Cloudflare Turnstile also processes verification signals. We may request proportionate identity verification and will not ask for your password. Withdrawal may prevent functions that require the relevant information. We aim to acknowledge complaints within 48 hours and resolve them within 30 days, subject to applicable legal deadlines and a reasonable explanation if more time is needed. Indian rights and complaint routes apply under the Information Technology Act, 2000 and its applicable rules, and the Digital Personal Data Protection Act, 2023 and Rules, 2025 as their relevant provisions come into force. Where applicable, statutory grievance, nomination and Data Protection Board remedies remain available after using the required grievance process.

10. Children

Accounts and interactive participation are intended for people aged 18 or over. We do not knowingly seek personal information from children. If you believe a child has supplied information, contact us so we can investigate and remove it where appropriate.

11. Changes to this policy

We will publish changes here and update the date. Material changes to purposes or optional processing will be notified through the service or email, and fresh consent sought where required. This policy describes current practices; adding future paid or advertising features will require appropriate updated disclosures.