// legal
Privacy Policy
Last updated: July 20, 2026
StatsHawk is operated by EdgeHawk AI (“StatsHawk”, “we”, “us”). This policy describes what we collect when you use statshawk.ai, the StatsHawk API, and the StatsHawk MCP server, how we use and store it, who we share it with, and how to reach us about it.
Data we collect
Account data. When you create an account we collect your email address, name, and a credential (stored as a salted hash — we never store plaintext passwords).
API and MCP usage. We record the requests your account makes — endpoint or tool called, timestamps, request parameters, response status, and the weighted units consumed. We use this for metering, plan caps, billing, debugging, and abuse prevention. API keys are stored hashed; managed MCP credentials are encrypted at rest.
Billing data. Payments are processed by Stripe. We store your Stripe customer reference and subscription state; your card details go to Stripe and never touch our servers.
Site analytics. We use PostHog to understand how the website and dashboard are used (pages viewed, device and browser info, interaction events).
Support communications. If you email us, we keep the correspondence.
MCP connections (Claude and other clients)
When you connect StatsHawk to Claude or another MCP client, the client sends us the tool calls it makes on your behalf (for example, a player search or a box-score lookup) under an OAuth grant scoped to your account. We process those tool inputs to serve the response and meter usage. We do not receive, request, or store your conversations with the assistant beyond the tool calls themselves.
How we use data
To provide and operate the service; to meter usage and enforce plan allowances; to bill paid plans; to secure the service and prevent abuse; to improve the product; and to communicate with you about your account. We do not sell personal data and we do not run advertising.
Storage and security
Data is stored in managed databases and infrastructure located in the United States. All traffic is encrypted in transit with TLS. API keys are stored as one-way hashes; managed MCP credentials are encrypted at rest with AES-256-GCM. Access to production systems is limited to the small team that operates StatsHawk.
Data retention
Account data is kept while your account is active. Usage and billing records are kept as long as needed for invoicing, accounting, and audit. If you delete your account (or ask us to), we delete or anonymize your personal data within 30 days, except records we are legally required to retain.
Your rights
You can access and update your account details from the dashboard. To export or delete your data, or to ask anything about this policy, email support@statshawk.ai. We respond to all requests.
Changes to this policy
If we make material changes we will update this page and the date above, and notify account holders by email where the change meaningfully affects how their data is handled.
Contact
EdgeHawk AI · support@statshawk.ai