Privacy Policy
Last updated: October 7, 2026
1. Introduction
Welcome to FPL AI ("we," "our," or "us"). We respect your privacy and are committed to protecting your personal data. This privacy policy will inform you as to how we look after your personal data when you visit our website (fplai.app) and tell you about your privacy rights and how the law protects you.
2. The Data We Collect
We may collect, use, store and transfer different kinds of personal data about you which we have grouped together follows:
- Identity Data: includes first name, last name, username or similar identifier.
- Contact Data: includes email address.
- Technical Data: includes internet protocol (IP) address, your login data, browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform on the devices you use to access this website.
- Usage Data: includes information about how you use our website, products and services.
3. How We Use Your Data
We will only use your personal data when the law allows us to. Most commonly, we will use your personal data in the following circumstances:
- Where we need to perform the contract we are about to enter into or have entered into with you.
- Where it is necessary for our legitimate interests (or those of a third party) and your interests and fundamental rights do not override those interests.
- Where we need to comply with a legal or regulatory obligation.
4. Google User Data
Our application uses Google OAuth to allow you to sign in with your Google account. When you choose to sign in with Google, we collect your email address and basic profile information (name and profile picture) to create your account and verify your identity. We do not access, collect, or store any other data from your Google account.
5. Optional Assistant Connection
If you connect FPLai to an assistant service, FPLai receives the specific tool requests you send through that connection and returns the requested results. If you choose ChatGPT, OpenAI processes your conversation and the connector results under its own privacy practices. FPLai does not receive your full ChatGPT conversation through the connector.
The information used depends on the permission you approve and the tool you choose:
- Account and team status: FPLai uses your account identity to look up your plan tier and whether an FPL team is linked. For analysis, it uses your linked FPL team ID and relevant team data, including squad picks and season and transfer history, from the official FPL API and FPLai's cache.
- Saved analyses: read requests return the saved-analysis identifier, date, gameweek and recommendation fields for a saved analysis in your account. These can include player names or IDs, captain and vice-captain choices, lineup, transfer recommendations, projection horizon, confidence and rationale.
- Player comparisons: comparison requests can include two to five player IDs or exact player names and a gameweek horizon. FPLai returns current projection and player statistics for those selections.
- Fresh analysis: after you approve a new analysis request, FPLai analyzes your linked team, uses your account's analysis quota and saves a result when the save completes. FPLai reports whether the save was confirmed. It does not submit or execute transfers in the official FPL game.
The connector returns a limited recommendation projection. It does not return original screenshots, user notes, raw extraction data, account identity or internal debug metadata.
FPLai's website, including its OAuth consent page, is hosted on Cloudflare Pages. The authenticated assistant gateway is hosted on OVH and forwards approved requests to FPLai's account, projections and analysis APIs. The gateway stores the assistant client identity, approved permissions, account reference and OAuth session records separately from your FPLai analysis history. Token lookup values are hashed, while session payloads, including server-side FPLai session tokens, are encrypted. Gateway access and refresh tokens expire according to their configured expiry. Expired records are removed during gateway housekeeping. Consumed or revoked records are also eligible for removal once they are at least 24 hours old.
Operational rollback backups may contain OAuth session records. Their session payloads are encrypted, and the backups are stored with restricted access. No automatic schedule currently removes these backups. Disconnecting the assistant or deleting your FPLai account does not immediately erase those records from existing backups.
Saved analyses are stored in your FPLai account and have no automatic expiry in the assistant connector. You can delete saved analyses through supported FPLai app controls or delete your FPLai account from Profile. When account deletion completes, it removes account-linked profile, saved analysis and squad-cache records.
To stop future access, disconnect FPLai from your assistant's connected-app settings. Disconnecting in ChatGPT does not delete information already present in ChatGPT conversations. See OpenAI's connected-app guidance for managing that connection and its conversation data.
6. Data Security
We have put in place appropriate security measures to prevent your personal data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. In addition, we limit access to your personal data to those employees, agents, contractors and other third parties who have a business need to know.
7. Contact Us
If you have any questions about this privacy policy or our privacy practices, please contact us here.