Privacy Policy
Last updated 14 September 2026
The short version
There are no accounts, no sign-up and no tracking cookies on Ballileo. We do not sell or share your data, and we run no advertising.
The only personal data we handle is what every web server records automatically — including your IP address — which we keep briefly to run the site securely. That is why you see no cookie banner: there is nothing to consent to.
01Who is responsible
This site is operated by Ștefan-Cristian Tudorache. Under the GDPR that makes us the data controller for the data described below.
For anything in this policy, including a request about your own data, write to privacy@ballileo.com.
02What we collect
Server access logs.Every request to our server is recorded: your IP address, the date and time, the page or endpoint requested, the browser's user-agent string, and the referring page. This is automatic and standard — a web server cannot answer a request without knowing where to send the reply.
Rate-limit counters. To stop one visitor from overloading the prediction engine, we count recent requests per IP address. These counters live in memory only, expire within minutes to hours, and are lost whenever the service restarts.
Usage analytics.Where enabled, we use privacy-preserving, cookieless analytics that stores no IP addresses and cannot identify you or follow you between sites. It tells us things like “this page was viewed 400 times today”, never who viewed it.
What we do not collect: no accounts, no names, no email addresses, no passwords, no payment details, no location data beyond what an IP address implies, and no advertising or cross-site identifiers.
03Why we are allowed to (legal basis)
We rely on legitimate interests (GDPR Article 6(1)(f)): operating the site, keeping it available, detecting and preventing abuse, and understanding in aggregate how it is used so we can improve it.
We have weighed that against your privacy. The data is minimal, it is not used to build a profile of you, it is not combined with anything else, it is never sold, and it is deleted quickly. You can object to this processing at any time — see section 08.
04How long we keep it
Access logs: at most 30 days, after which they are rotated away and permanently deleted.
Rate-limit counters: minutes to hours, in memory only.
Analytics: retained as aggregate counts, which contain no personal data and cannot be traced back to a visitor.
05Who else is involved
We use a small number of service providers, all of whom process data on our instructions:
- Hetzner Online GmbH — our server hosting, located in Germany. Your requests reach their infrastructure and appear in the logs described above.
- Cloudflare — content delivery and protection against attacks. Traffic passes through their network before reaching us, so they process IP addresses to filter malicious requests.
- Sentry — error monitoring, where enabled. When something on the site fails, a report of the error is sent so we can fix it. It is configured not to include IP addresses, cookies or request contents, so these reports describe the fault rather than the person who hit it.
Our analytics runs on our own server rather than a third-party service, so usage data is not shared with anyone. We do not use advertising networks, and we never sell or rent your data.
06Content loaded from elsewhere
Team badges and player photographs are served directly by API-Football (media.api-sports.io). When your browser loads one of those images it connects to their servers, which means they can see your IP address and which image was requested. That connection is between your browser and them; we do not control it and receive nothing from it.
Everything else — including our fonts — is served from our own servers, so simply viewing a page does not hand your IP address to any other company.
07Cookies
We set no cookies for analytics, advertising or tracking, and we do not use browser fingerprinting.
Cloudflare may set a strictly necessary security cookie to tell human visitors from bots. Cookies of that kind are exempt from the consent requirement, which is why this site shows no cookie banner.
If that ever changes — for example if we introduce advertising — we will ask for your consent first, before any such cookie is set.
08Your rights
Under the GDPR you may request access to your personal data, its correction or erasure, a restriction of how we use it, a copy in portable form, and you may object to processing based on legitimate interests.
In practice we hold very little: log entries linked to an IP address for up to 30 days. Because there are no accounts, we cannot look you up by name — so if you make a request, tell us the IP address and the approximate time, or we will have no way to find the records.
Write to privacy@ballileo.com. If you believe we have handled your data improperly you may complain to the Romanian supervisory authority, the National Supervisory Authority for Personal Data Processing (ANSPDCP), or to the authority in your own EU country.
09Children
This site is not directed at children. Because the subject matter sits close to sports betting, it is intended for people aged 18 or over. We do not knowingly collect data from children.
10Changes to this policy
If we change how we handle data, we will update this page and the “last updated” date at the top. Significant changes will be announced on the site rather than made quietly.
See also our Terms of Use and How it works.