PICK / ONE

Privacy

Updated September 9, 2026

Pick One is run by Aleksei Petukhov, Individual Entrepreneur (Einzelunternehmer), Plievierpark 10, 81737 Munich, Germany. We are responsible for the processing described here. Contact us at alekseipetukhov1990@gmail.com.

Why we use data

We use account, content, and vote data to provide the service you ask for: publishing a pick, showing it, counting one vote per pick as best we can, and protecting the service. We use limited security data to prevent abuse and enforce the Rules. The legal bases are performance of our agreement for accounts and publishing (Article 6(1)(b) GDPR), our legitimate interests in operating a trustworthy service and preventing abuse (Article 6(1)(f)), and your consent for optional analytics (Article 6(1)(a)). We also process information where a legal obligation requires it (Article 6(1)(c)).

Data we collect

  • Voting data. A vote, its side, time, source, a session identifier and a one-way hash derived from a signed browser identity, plus your account ID if you are signed in. We do not show voter identities publicly.
  • Account and content data. Your email address, any name/profile information returned by your sign-in provider, text and images you publish, reports, and records needed to administer a pick or account. We also receive the information you send when contacting support. Your creator name is public only if you choose to show it.
  • Security data. We receive your IP address when you connect. The application stores an HMAC-derived IP value as an abuse signal rather than raw IP addresses in its application tables.
  • Device storage. Draft text stays in local storage. Draft images stay in IndexedDB until you clear, replace, or publish them. Voting progress also stays in local storage. Your session pick breakdown stores each pick’s identifier and its majority, minority or even-split outcome in this tab’s session storage. Later votes do not change that saved outcome.

New image uploads are re-encoded to remove embedded camera and location metadata before storage. That does not remove visible personal information in an image. Do not upload an image if you do not have permission to share what it shows.

Cookies and browser storage

  • po_voter is a signed, HTTP-only cookie used to limit duplicate votes. It lasts one year and renews on a visit.
  • po_session groups a voting session. It lasts 30 minutes and renews on a visit.
  • Supabase authentication cookies keep you signed in. Signing out removes them.
  • po_analytics records your analytics choice for 180 days. Analytics remain off unless this records your explicit allowance.
  • PostHog storage is used only after you allow analytics. Its cookie duration is 180 days; related local storage remains until you withdraw consent or clear browser data.

Voting and sign-in cookies are necessary to provide the service you request; optional storage requires your consent under section 25 TDDDG. Optional analytics are off until you choose otherwise. Clearing browser storage can affect sign-in and duplicate-vote protection.

Your analytics choice

We use PostHog only when you allow it on this browser. It collects selected product events, not automatic page capture, session replay, surveys, or IP geolocation. Events use pseudonymous identifiers and limited device information; we filter email addresses, full URLs and free text. Pseudonymous identifiers can still be personal data. If you withdraw consent, we stop new browser and server analytics for this browser and clear known PostHog browser storage. Your choice does not affect voting or publishing. Withdrawal does not affect the lawfulness of earlier processing. To request deletion of earlier analytics data, email us. Choose separately on other browsers and devices.

Optional analytics are currently disabled for this service.

Who receives data

We use Supabase for the application database, authentication, and file storage. Website hosting and delivery services process network requests and technical access information to serve the app. Authentication email providers deliver your requested sign-in links. If you choose Google sign-in, Google handles that sign-in choice. Messages sent to our contact address are received in the operator’s Gmail mailbox. PostHog receives optional analytics only with consent. Sentry receives minimized error reports only when separately enabled and is off by default. Stripe would receive payment information only if paid Community Boost is enabled in the future. Card details stay with Stripe.

Providers and their subprocessors may operate outside the European Economic Area, including in the United States. International transfers require an applicable adequacy decision or appropriate safeguards, such as the European Commission’s standard contractual clauses. Contact us for the recipients, locations and safeguards applicable to your data, and for copies of relevant safeguards where available. We do not sell personal data or use your content to train AI models.

Public content

Public picks, their images, and result previews can be viewed and shared by anyone. They may be copied, indexed, cached, or re-shared outside our control. An unlisted link is not private: anyone with the link can view and share it. Founder-created starter picks may combine a simulated starting baseline with later community votes in their displayed totals and percentages. The interface shows one combined total. The baseline is not a vote record and does not correspond to an identified or pseudonymous person. It is excluded from vote-related metrics and paid Community Boost delivery.

Retention and deletion

You can delete your account from Yours. We remove your profile, published content and images, and the account link from votes. Account and published content are retained while the account or pick remains in use. Pseudonymous vote records remain while associated results are needed, to preserve totals and prevent duplicate voting; they remain personal data while linkable to you. You may request access or erasure of votes made without an account too. Payment references are retained only where needed if payments become available.

  • Rate-limit records: 7 days.
  • Abuse events and skips: 90 days.
  • Vote IP hashes and session IDs: cleared after 30 days.
  • Resolved report details and reporter links: minimized after 1 year.

Open safety cases and support requests are kept while needed to resolve them or address a legal claim. Financial records, if any, are retained for the statutory period applicable to the record. Provider backups and security logs can outlast deletion from the live service under their recovery and retention arrangements. We cannot recall copies made by other people or social platforms.

Your rights and complaints

Under the conditions set out in the GDPR, you can request access, correction, erasure, restriction and data portability, or object to processing based on legitimate interests. You can withdraw analytics consent at any time. Email us from the relevant account address where possible. We may ask for proportionate information to confirm identity. We respond within one month, or explain any lawful extension within that period. Do not send passwords or sign-in links. Automated safety signals can restrict activity or remove a pick from discovery pending review; you may ask for human review. We do not use solely automated decisions with legal or similarly significant effects.

You can complain to a data-protection authority. Our local authority is the Bavarian Data Protection Authority (BayLDA).