Privacy Policy

Last updated: 13 July 2026

The short version: we collect the minimum we need — your account details when you sign up (handled by Clerk) and standard technical logs. No advertising trackers, no third-party analytics cookies, and we never sell your data. Data lives with established providers, our database is hosted in the EU, and you can ask for a copy or deletion of your data at any time.

01Who we are

This policy explains how Melven (“we”, “us”), the football-analytics service at melven.ai, handles personal data when you visit the site or create an account. We are the data controller for that data.

For anything privacy-related — questions, requests, complaints — contact us at vestra@vestra.is.

02What we collect

Account data. When you sign up, our authentication provider (Clerk) collects and stores your name, email address, profile picture and authentication identifiers. If you sign in through a third-party provider (for example Google), we receive the basic profile information that provider shares.

Technical data. Like practically every website, our hosting and infrastructure providers keep standard server logs — IP address, browser type, device information, pages requested and timestamps — used for security, abuse prevention and diagnosing problems.

Correspondence. If you email us, we keep the correspondence for as long as needed to handle the matter.

Payment data — none today. The Service is currently free and we collect no payment information. If paid plans launch, payments will be processed by a dedicated payment provider (such as Polar); card numbers would go directly to that provider and never touch our systems. This policy will be updated before that happens.

03What we deliberately don't do

  • No advertising trackers or ad networks.
  • No third-party analytics cookies.
  • No selling or renting of personal data — to anyone, ever.
  • No profiling for marketing purposes.

The published pick ledger, match data and model outputs contain no personal data.

04Cookies

We use only strictly necessary cookies: the session and security cookies our authentication provider (Clerk) sets so you can sign in and stay signed in. These are essential for the Service to work and cannot be switched off while using an account. We do not set advertising or cross-site tracking cookies.

05Why we process data (legal bases)

  • To provide the Service (contract, GDPR art. 6(1)(b)) — creating and operating your account, showing you the product.
  • To keep the Service secure (legitimate interests, art. 6(1)(f)) — abuse prevention, rate limiting, debugging, security logging.
  • To communicate with you (contract or legitimate interests) — service messages and replies to your requests.
  • To comply with the law (legal obligation, art. 6(1)(c)) — where record-keeping or disclosure is legally required.

We do not use your data for automated decisions with legal effect.

06Who processes data for us

We use a small set of established infrastructure providers as data processors:

  • Clerk — authentication and account management (stores your account profile and sign-in credentials).
  • Convex — application database; our deployment is hosted in the EU (eu-west-1).
  • Vercel — website hosting and content delivery (processes technical request data).

Our statistical model runs on separate infrastructure that holds no personal data at all. Each processor is bound by a data-processing agreement and processes data only on our instructions. Beyond these processors, we disclose personal data only if required by law or to protect our legal rights.

07International transfers

Some providers (for example Clerk and Vercel) may process data in the United States or other countries outside the EEA. Where that happens, transfers are protected by recognised safeguards — the EU Standard Contractual Clauses and/or certification under the EU-US Data Privacy Framework.

08How long we keep data

  • Account data: for as long as your account exists. When you delete your account (or ask us to), account data is deleted from our systems and our processors' systems within the timeframes their platforms allow.
  • Technical logs: kept for a short, rolling window appropriate for security and debugging, then deleted or anonymised.
  • Correspondence: for as long as needed to handle your request and any follow-up.

09Your rights

If you are in the EEA/UK (and in many other places), you have the right to:

  • access the personal data we hold about you, and get a copy;
  • correct inaccurate data;
  • have your data deleted (“right to be forgotten”);
  • restrict or object to certain processing;
  • receive your data in a portable format;
  • withdraw consent at any time, where processing is based on consent.

To exercise any of these, email vestra@vestra.is. We respond within one month. You also have the right to lodge a complaint with your data-protection authority — in Iceland, that is Persónuvernd (dpa.is).

10Security

All traffic to the Service is encrypted in transit (TLS). Data is stored with providers that maintain industry-standard security programs, and access to production systems is restricted to people who need it. No system is perfectly secure — if a breach affecting your personal data ever occurs, we will notify you and the relevant authority as the law requires.

11Children

The Service is for adults aged 18 and over. We do not knowingly collect personal data from anyone under 18; if we learn that we have, we will delete it and close the account.

12Changes to this policy

We will update this policy when our data practices change — for example, if paid subscriptions launch. The “Last updated” date above always reflects the current version, and material changes will be signposted on the site.

See also our Terms & Conditions.