For the complete documentation index, see llms.txt.

Privacy Policy

Last Updated: August 26, 2026

1. Who We Are

Daily Locks AI ("Service") is operated by Hoyne Labs LLC ("Company," "we," "us," or "our"), an Illinois limited liability company. This Privacy Policy explains what information we collect when you use our website at dailylocks.ai, why we collect it, who we share it with, and the choices you have.

This policy covers the entire Service, including the sports analysis features, your account, and any optional third-party account connections you choose to enable.

This policy works alongside our Terms & Conditions and our Legal & Disclaimers. If you do not agree with this policy, please do not use the Service.

2. Information We Collect

2.1 Account Information

When you create an account, we collect your email address and a password. Passwords are hashed by our authentication provider and are never visible to us in readable form. You may optionally provide a display name.

2.2 Your Questions and Conversations

The Service is built around a question-and-answer interface. We store the questions you submit and the responses generated for you, along with timestamps, so that we can show you your history, diagnose problems, enforce usage limits, and improve answer quality. Please do not include sensitive personal information in your questions.

2.3 Usage and Device Information

  • IP address. We record the IP address associated with your requests. For visitors who are not signed in, the IP address is also how we count daily usage against the free limit, because there is no account to count against.
  • Usage records. Which features you use, how many questions you ask, which AI model answered, and the computed cost of serving you.
  • Device and browser information. Browser type, operating system, and similar technical details sent by your browser.
  • Error diagnostics. When something breaks, we record the error and the technical context around it.

2.4 Payment Information

Subscription payments are processed by Stripe. We never see or store your full card number. We retain a customer identifier, your plan, and your subscription status so we know what you have access to.

2.5 How You Found Us

We record the channel that brought you to the site for the first time, such as a search engine or a link from another site, so we understand which channels are working. This is stored in your browser and, if you create an account, saved with your profile.

3. Connecting Your TikTok Account

Daily Locks AI offers an optional feature that lets you share a video you have created on our Service to your own TikTok account. This feature is entirely opt-in. If you never connect a TikTok account, nothing in this section applies to you, and the rest of the Service works exactly the same.

3.1 What We Receive From TikTok

When you choose to connect your TikTok account, you are sent to TikTok to sign in and approve the connection. We never see your TikTok password. After you approve, TikTok sends us:

  • Your TikTok open ID - a unique identifier for your account, specific to our application;
  • Your display name - so we can show you which account is connected;
  • Your avatar URL - the address of your profile picture, shown next to the connected account;
  • An OAuth access token and refresh token - the credentials that let us send a video to your account when you ask us to.

We request only two permissions: user.info.basic and video.upload.

3.2 Why We Use It

We use this information for two purposes, and no others:

  • To show you which TikTok account is connected, using your display name and avatar, so you can confirm you are sending to the right account and disconnect if you are not.
  • To create a video upload that you explicitly initiate, using your access token.

WE NEVER POST WITHOUT AN EXPLICIT ACTION BY YOU

We do not post to your TikTok account on a schedule, in the background, or on your behalf without you asking. Every single upload is the result of you pressing a share control in our interface for one specific video. There is no setting that changes this.

3.3 Draft Mode Only

We use the TikTok Content Posting API in inbox / draft mode only, under the video.upload scope. When you share a video, it is delivered to your TikTok inbox as a draft. You then open TikTok yourself and decide the caption, cover, privacy setting, and whether to publish it at all. Nothing we send becomes public on its own.

To be explicit about what we do not do:

  • We do not use Direct Post. We cannot publish a video straight to your profile.
  • We do not request the video.publish scope.
  • We do not read your TikTok content. We do not access, collect, store, or analyze your videos, drafts, comments, direct messages, followers, following list, likes, or viewing activity. The permissions we hold do not allow it.

3.4 How Your Tokens Are Stored

  • Encrypted at rest. Access and refresh tokens are stored encrypted, never in plain text.
  • Scoped to your user account. Your tokens are associated only with your account and are used only to fulfil a request you personally initiated.
  • Never shared with third parties. We do not transmit your TikTok tokens or profile information to any advertiser, data broker, analytics provider, or other third party.
  • Never sold. We do not sell your TikTok data, or any of your data, under any circumstances.

3.5 How Long We Keep Them

We keep your TikTok tokens and connected profile details only while the connection is active:

  • When you disconnect, we delete them. Disconnecting removes your access token, refresh token, open ID, display name, and avatar URL from our systems.
  • After 12 months of inactivity, we delete them. If you have not shared a video for 12 months, we remove the stored connection and you will simply be asked to reconnect the next time you want to use the feature.
  • Deleting your Daily Locks AI account also deletes any stored TikTok connection.

3.6 How To Revoke Access

You can end the connection at any time, by either method, and you do not need our permission:

  1. Disconnect inside Daily Locks AI. Use the disconnect control on the TikTok connection in your account settings. This deletes the stored tokens on our side immediately.
  2. Revoke access at TikTok. In the TikTok app, go to Settings and privacySecurity & permissionsManage app permissions, and remove Daily Locks AI. This invalidates the tokens at the source.

We recommend doing both if you want to be certain. If you revoke at TikTok first, any tokens we still hold stop working immediately, and we remove them.

4. How We Use Information

We use the information described above to:

  • Provide the Service and generate answers to your questions;
  • Create and maintain your account and show you your history;
  • Process payments, manage subscriptions, and apply the correct plan limits;
  • Enforce daily usage limits, including for visitors who are not signed in;
  • Detect, investigate, and prevent fraud, abuse, and violations of our Terms;
  • Monitor reliability, diagnose errors, and improve performance and answer quality;
  • Understand which channels bring people to the Service, in aggregate;
  • Send you service messages, and marketing email if you have opted in;
  • Complete a TikTok share that you have explicitly initiated;
  • Comply with legal obligations and enforce our agreements.

5. AI Processing of Your Questions

Answers on this Service are generated by a large language model. This means that the questions you type are transmitted to third-party providers in order to produce a response. You should know this before you type anything into the Service.

  • Anthropic receives your question and the sports data context needed to answer it, and returns the response. Anthropic processes this as a service provider on our behalf.
  • Helicone sits in front of that connection and records the request for monitoring and cost tracking. It receives the question, the response, and an identifier for your account and plan.
  • Langfuse records a trace of the interaction, including the text of your question, so we can debug quality problems.
  • Upstash provides the cache described in section 6.

PLEASE DO NOT SUBMIT SENSITIVE INFORMATION

Because your questions leave our systems to be answered and are retained for quality and debugging, do not include financial account details, government identifiers, health information, or other sensitive personal information in what you type.

6. Cookies & Local Storage

We use a small number of cookies and browser storage entries, all of them functional:

  • Authentication. Session cookies and browser storage that keep you signed in. Without these you would be signed out on every page load.
  • Preferences. Your current plan and interface preferences, stored so the interface renders correctly.
  • First-touch channel. The referral channel described in section 2.5, stored in your browser.
  • Response cache. Common questions and their answers are cached on our servers for a short period so that repeated questions are faster and cheaper to serve. The cache is keyed on the text of the question, not on who asked it.

We do not use advertising cookies, and we do not run third-party advertising or cross-site tracking pixels on the Service. Our analytics provider, described next, does not use cookies at all. You can clear cookies and browser storage at any time through your browser settings, though doing so will sign you out.

7. Analytics

We use Plausible Analytics to understand how the site is used. Plausible is a privacy-focused, cookieless analytics service. It does not set cookies, does not track you across other websites, and does not build an advertising profile of you. It reports aggregate figures such as page views, referring sites, and country.

We also use Google Search Console, which reports aggregate search performance for our own pages. It does not identify individual visitors to us.

IP geolocation. When we review usage internally, we may look up the approximate geographic location of an IP address using a third-party lookup service (ip-api.com) in order to understand where our audience is. This returns an approximate city, region, and country. It is not used to identify you personally or to target you.

8. Third-Party Service Providers

We rely on the following providers to operate the Service. Each receives only what it needs to perform its function, and each is bound to use that information solely to provide the service to us.

  • Supabase - authentication and our primary database. Stores your account, your conversation history, usage records, and subscription status.
  • Stripe - payment processing and subscription billing. Receives your payment details directly; we do not handle your card number.
  • Anthropic - the AI provider that generates answers. Receives your questions.
  • Helicone - monitoring for AI requests. Receives your questions, the responses, and an account identifier.
  • Langfuse - quality tracing for AI requests. Receives the text of your questions.
  • Sentry - error monitoring. Receives technical error reports, which can include the context of the request that failed.
  • Upstash - hosted cache for question and answer pairs.
  • Vercel - hosting for the website. Processes request logs, including IP addresses.
  • Railway - hosting for our backend. Processes request logs, including IP addresses.
  • Plausible - cookieless website analytics, as described in section 7.
  • Resend - delivery of account and marketing email. Receives your email address. See section 8.1.
  • AgentMail - internal operational alerts and reports sent to our own team. These reports can include account data such as email addresses.
  • TikTok - only if you connect a TikTok account, as described in section 3.

8.1 Email Tracking

Email we send through Resend includes open and click tracking. This tells us whether a message was opened and which links were clicked, using a tracking image and rewritten links on our own tracking subdomain. If you would rather not be tracked this way, you can disable remote image loading in your email client, and you can unsubscribe from marketing email using the link at the bottom of any such message.

9. Data Sharing & No Sale

WE DO NOT SELL YOUR PERSONAL INFORMATION

We have never sold personal information, and we do not share it with third parties for their own advertising or marketing purposes.

We share information only in these situations:

  • With the service providers listed in section 8, strictly so they can perform their function for us;
  • When you direct us to, such as sending a video to your own TikTok account;
  • For legal reasons, when we are required by law, subpoena, or other valid legal process, or where we believe disclosure is necessary to protect our rights, your safety, or the safety of others;
  • In a business transfer, such as a merger or acquisition, in which case we will notify you and this policy will continue to apply until replaced.

10. Data Retention

  • Account information is kept while your account is active.
  • Conversation history, usage records, and associated IP addresses are retained while your account is active and until you ask us to delete them. We do not currently purge this data on a fixed schedule. You can request deletion at any time, as described in section 12.
  • TikTok tokens and profile details follow the shorter schedule in section 3.5: deleted when you disconnect, and after 12 months of inactivity.
  • Cached question and answer pairs expire automatically after a short period.
  • Payment and billing records are retained as long as required for tax, accounting, and legal obligations, even after account deletion.

When you delete your account, we remove your account information, conversation history, and any connected account credentials, other than records we are legally required to keep.

11. Age Requirement

21+

Adults Only

You must be 21 years of age or older to use this Service.

The Service is intended solely for adults aged 21 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 21.

If we learn that we have collected personal information from someone under 21, we will delete that information and terminate the account. If you believe a minor has provided us with personal information, contact us at hoynelabs@gmail.com and we will act promptly.

12. Your Privacy Rights

Whatever jurisdiction you are in, you may ask us to:

  • Access the personal information we hold about you;
  • Correct information that is inaccurate or incomplete;
  • Delete your account and the personal information associated with it;
  • Export a copy of your information in a portable format;
  • Object to or restrict certain processing;
  • Withdraw consent you previously gave, such as disconnecting a TikTok account or unsubscribing from marketing email;
  • Opt out of sale or sharing of personal information. As stated in section 9, we do not sell or share personal information for advertising, so there is nothing to opt out of.

To make a request, email hoynelabs@gmail.com from the address on your account. We will respond within 30 days. We will not discriminate against you for exercising any of these rights.

We operate from the United States, and information we collect is processed and stored in the United States and other countries where our providers operate. If you use the Service from outside the United States, you understand that your information will be transferred to and processed in the United States, where privacy laws may differ from those in your country.

13. Data Security

We use industry-standard measures to protect your information, including encryption in transit, encryption at rest for credentials such as third-party access tokens, hashed passwords, restricted administrative access, and reputable infrastructure providers.

However, no method of transmission over the Internet or method of electronic storage is completely secure. While we work to protect your information, we cannot guarantee absolute security. You are responsible for keeping your account credentials confidential and for notifying us promptly of any unauthorized use of your account.

14. Changes & Contact

14.1 Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will post the revised policy on this page and update the "Last Updated" date at the top. If we make a material change to how we handle your information, we will provide a more prominent notice, such as an email to the address on your account. Your continued use of the Service after an update means you accept the revised policy.

14.2 Contact Us

For any privacy question, to exercise the rights in section 12, or to report a concern, contact us at:

Hoyne Labs LLC

Email: hoynelabs@gmail.com

State of Organization: Illinois