Privacy Policy
Effective: 2026-06-21 ยท Last updated: 2026-08-08
ColesAlgoPicks ("the site," "we") operates nba.colesalgopicks.com (The NBA King) and related subdomains. This page describes what data we collect, why, and what your rights are.
Short version: we don't sell your data, we don't run ads, we don't share with third parties beyond what's needed to run the product. We collect the minimum required, and you can delete your account anytime.
What we collect
- Anonymous browsing: by default, nothing personal โ we use your browser's
localStorage for app state (watchlist, slips, tracker). That data lives on your device only.
- If you sign in with Discord (optional): we receive and store your Discord user ID, username, display name, and avatar URL โ solely to identify you across devices and to determine your access. We use the
identify scope (plus the read of your membership/role needed to grant access); no access to your messages, friends, or anything else.
- Account data: your synced app state, session tokens (hashed), and any profile fields you explicitly set.
- Server logs: standard Cloudflare HTTP logs (IP, user-agent, request URL, timestamp) used for abuse detection and uptime monitoring, retained briefly and then auto-deleted by Cloudflare.
What we don't collect
- No payment or card data. Subscriptions are processed by Winible as merchant of record โ your card details go to Winible (and its payment processor), never to us. We never see or store your full card number.
- No third-party advertising trackers. No Google Analytics ad SDKs, no Facebook Pixel.
- No location data beyond what your IP implies for server logs.
- No background telemetry across other sites.
How we use it
- To deliver the product: cross-device sync, signed-in personalization, and granting/checking your paid access.
- To detect abuse: rate limiting, blocking malicious bots, investigating suspicious sign-in patterns.
- To improve the product: aggregate, non-identifying usage patterns โ never individual behavior sold to anyone.
Who we share it with
Only the providers needed to run the service:
- Discord when you sign in โ it validates your identity and access role via OAuth. Privacy policy: discord.com/privacy.
- Winible when you subscribe โ as merchant of record it processes your payment and manages your subscription. Privacy policy: winible.com.
- Cloudflare hosts the site and processes every HTTP request. Privacy policy: cloudflare.com/privacypolicy.
Your rights
- Delete your account anytime โ wipes your profile, sessions, and synced state. (Payment records held by Winible are subject to Winible's own policy.)
- Export your data โ request a copy of everything we hold via our Discord.
- Stay anonymous โ the public parts of the site work without sign-in.
Cookies
We set only first-party cookies, and we set no third-party tracking cookies. All of them are HttpOnly; Secure; SameSite=Lax, so no script on the page can read them.
cap_fv โ set on your first visit, before you sign in. A random identifier (a UUID) with no name, email or account attached. It exists to run the one-free-article-per-24-hours meter, so that the free view follows the browser rather than only the IP address. It lasts 400 days. This is the only cookie we set for an anonymous visitor, and deleting it (or browsing privately) simply resets your free view.
cap_grant โ a short-lived signed token (about 15 minutes) that lets the data files belonging to the page you are already reading load as part of that same free view.
- Session cookie โ set only if you sign in with Discord, so we know it is you.
- CSRF token โ short-lived, used only during the Discord sign-in flow.
We do not use cookies for advertising, and we do not sell or share them with anyone.
Contact
Questions, data requests, or concerns: open a ticket in our Discord.
Changes to this policy
We'll update the "Last updated" stamp and post a notice if anything material changes. We won't retroactively reduce protections on data you've already shared.