statshawk

// legal

Privacy Policy

Last updated: September 2, 2026

StatsHawk is operated by EdgeHawk, LLC (“StatsHawk”, “we”, “us”). This policy describes what we collect when you use statshawk.ai, the StatsHawk API, and the StatsHawk MCP server, how we use and store it, who we share it with, and how to reach us about it.

Data we collect

Account data. When you create an account we collect your email address, name, and a credential (stored as a salted hash, never as plaintext passwords).

API and MCP usage. We record the requests your account makes: endpoint or tool called, timestamps, request parameters, response status, and the weighted units consumed. We use this for metering, plan caps, billing, debugging, and abuse prevention. API keys are stored hashed; managed MCP credentials are encrypted at rest.

Billing data. Payments are processed by Stripe. We store your Stripe customer reference and subscription state; your card details go to Stripe and never touch our servers.

Site analytics. We use PostHog to understand how the website and dashboard are used (pages viewed, device and browser info, interaction events).

Advertising measurement.We advertise StatsHawk on Google, and use Google's conversion measurement tag to learn which ads lead to signups and subscriptions. When you sign up or subscribe, we may share a one-way hashed (SHA-256) version of your email address with Google to improve the accuracy of that measurement (Google calls this "enhanced conversions"); Google cannot recover your address from the hash unless it already knows it. Like any web tag, Google's tag also receives standard request data as part of measurement: your IP address, the page URL (including the ad-click identifier when you arrived from an ad), and browser information. We configure the tag with ad personalization disabled, so this data is used for conversion measurement only, not to build advertising profiles or remarketing lists. We do not share your usage data, queries, or billing details with advertising platforms, and we do not use your data to target ads at you elsewhere.

Support communications. If you email us, we keep the correspondence.

MCP connections (Claude and other clients)

When you connect StatsHawk to Claude or another MCP client, the client sends us the tool calls it makes on your behalf (for example, a player search or a box-score lookup) under an OAuth grant scoped to your account. We process those tool inputs to serve the response and meter usage. We do not receive, request, or store your conversations with the assistant beyond the tool calls themselves.

How we use data

To provide and operate the service; to meter usage and enforce plan allowances; to bill paid plans; to secure the service and prevent abuse; to improve the product; to measure the performance of our own advertising (see Advertising measurement above); and to communicate with you about your account. We do not sell personal data, and we do not show ads or use your data to advertise other products to you.

Storage and security

Data is stored in managed databases and infrastructure located in the United States. All traffic is encrypted in transit with TLS. API keys are stored as one-way hashes; managed MCP credentials are encrypted at rest with AES-256-GCM. Access to production systems is limited to the small team that operates StatsHawk.

Third parties

We share data only with the subprocessors that run the service:

  • Stripe: payment processing and subscription management
  • Metronome: usage-based entitlement and billing calculations
  • Vercel: application hosting
  • Railway: database hosting
  • PostHog: product analytics
  • Google: advertising conversion measurement (standard tag request data plus hashed email; ad personalization disabled)

Each receives only what it needs for its function. We may also disclose data if required by law.

Data retention

Account data is kept while your account is active. Usage and billing records are kept as long as needed for invoicing, accounting, and audit. If you delete your account (or ask us to), we delete or anonymize your personal data within 30 days, except records we are legally required to retain.

Your rights

You can access and update your account details from the dashboard. To export or delete your data, or to ask anything about this policy, email support@statshawk.ai. We respond to all requests.

Changes to this policy

If we make material changes we will update this page and the date above, and notify account holders by email where the change meaningfully affects how their data is handled.

Contact

EdgeHawk, LLC · support@statshawk.ai