Privacy Policy
Last updated: 2026-08-21
1. Who is responsible
The data controller is Masters Of Testing OÜ (registry code 16653388, Tornimäe tn 5, Kesklinna linnaosa, 10145 Tallinn, Estonia). Contact us via the contact page for anything in this policy, including exercising your rights. You can also write to hello@betist.ai.
2. What we hold
For visitors: the public site works without an account and we keep no visitor profiles; our self-hosted, cookieless analytics and self-hosted error monitoring run pseudonymously on our own infrastructure, and nothing leaves servers we control.
For account holders: your email address, optional username, subscription state (plan, status, period end and provider references), your preferences (leagues, risk tiers, currency, language, bankroll and unit settings you enter), and a service event trail (sign-ins, plan changes) with timestamps.
We never see or store card data. Payments run at our payment processor (Stripe), which acts as a separate processor of your payment details; we keep only opaque references to the subscription.
3. Why, and on what legal basis
Running your account and membership — contract performance (GDPR art. 6(1)(b)). Keeping accounting records — legal obligation (art. 6(1)(c)). Service security, abuse prevention and product improvement — legitimate interest (art. 6(1)(f)), weighed narrowly.
4. Monitoring and product analytics
We run error and performance monitoring with session replay (Sentry) on our own infrastructure — no monitoring data leaves servers we control. Replays mask everything you type; text inputs are never recorded in the clear.
We also use first-party product analytics to understand feature usage and to A/B-test interface variants, under pseudonymous identifiers — analytics does not use your email or name. Where consent would otherwise be required, we deliberately run these tools in their cookieless, consent-free configuration; the way this policy describes them is a binding constraint on how they are configured.
There are no third-party advertising trackers on this site — none.
5. Cookies and local storage
Strictly functional only: the session token (signed-in state), and local preferences such as view, sort, language, currency and bankroll settings, stored in your own browser. No advertising cookies, no cross-site tracking.
6. How long we keep things
Your account data lives as long as the account. Delete the account and the personal data goes immediately (next section); accounting records that must be retained by law are kept in anonymized form, no longer linked to you. Monitoring and analytics data are retained on a rolling short-term window.
7. Your rights — and the buttons that exercise them
Under the GDPR you can access, correct, export, delete and object. The two that matter most are one click away on your account page:
Download my data — a complete JSON export of your profile, subscription state and preferences, immediately.
Delete account — permanently removes your profile, preferences and sessions and signs you out everywhere. Subscription records are kept in anonymized form for statutory accounting only. For anything else — correction, objection, a complaint — use the contact page; you also have the right to complain to your supervisory authority.
8. Where data lives
On servers in the EU (Germany). No sale of personal data, ever, to anyone.
9. Changes
Material changes to this policy are announced on the site. The date at the top is authoritative.