Skip to content
Z30 Labs
  • What we do
  • Products
  • News
  • Contact
  • Sign in

Privacy

What we collect, and what we do with it

This describes what the software actually does rather than what a template says it might. Where something is not collected, it says so; where a third party sees your data, it names them and says exactly what they see.

Last updated 3 September 2026.

Who we are

Z30 Labs is a division of ZanCo Technologies, the data controller for the personal data described here. Questions, requests and complaints: zancoholdings@gmail.com.

Two different sites

This site, z30labs.com, is a public marketing page. It has no accounts and sets no cookies of its own. There is no analytics script, no tag manager and no advertising or tracking pixel of any kind. It makes one request to the app, for the current prices, and that request is anonymous — it carries no cookie and identifies nobody.

The app, app.z30labs.com, is behind a sign-in and is where personal data is actually handled. Everything below applies to the app unless it says otherwise.

What the app holds about you

WhatWhere it comes fromWhy
Your GitHub numeric id, username, display name, email address and avatar URL GitHub, when you sign in To identify your account and show who is signed in
A session Created when you sign in To keep you signed in. Stored only as a hash — see below
Your settings: a Fantasy Premier League team id, and your planning preferences You, when you enter them So the recommendations are about your team
Saved views: the title and note you give them, the search itself, and optionally a copy of the results as they stood You, when you save one So you can reopen your own work
An activity log: sign-ins and sign-outs, plan changes, queries you run in the Advanced console and questions you type into Ask Recorded as you use the app Security, abuse investigation, and showing you your own recent queries

We never receive your GitHub password, and we never receive your card details.

The one cookie

The app sets a single cookie, z30_session. It holds a random token and nothing else — no name, no email, no identifier that means anything on its own. It is marked HttpOnly (so no script can read it), Secure (so it only travels over HTTPS) and SameSite=Lax (so it is not sent from other sites).

On our side the token is stored only as a SHA-256 hash. That is a deliberate choice over the more common signed cookie: a signed cookie is valid until it expires and cannot be withdrawn, whereas deleting our row ends the session immediately, and a stolen copy of our database yields no usable tokens.

This cookie is strictly necessary to sign you in, so there is no consent banner. There is nothing else to consent to: no analytics, no advertising, no third-party cookies, and nothing that follows you anywhere.

Who else sees it

We use four external services, and no others.

  • GitHub — signs you in and tells us who you are. What they see is that you authorised this application.
  • Stripe — takes payment, when payment is switched on. Card details go to Stripe and never reach our servers; we store only the customer reference they give us.
  • Anthropic — only if you use the Ask box. What is sent is the question you typed and a generated list of the statistics the console understands. Your name, your email, your account id and everything else about you are not sent, and there is no way for the model to reach your saved work. If Ask is switched off on the server, nothing is sent at all.
  • Fly.io — hosts the app, in London.

We do not sell personal data, and we do not share it for advertising.

Where it is kept, and for how long

  • Your account and settings — until you ask us to delete them.
  • Saved views — until you delete them, or your account goes.
  • Sessions — until they expire or you sign out, then removed automatically.
  • The activity log — 180 days, then deleted automatically. This is the table that holds the queries you have run, which is why it has the shortest life of anything here.

Everything sits on one encrypted-at-rest volume in London, alongside the statistics warehouse.

What you can ask us to do

Under UK and EU data protection law you can ask for a copy of your data, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use, and ask for it in a portable form. Email zancoholdings@gmail.com and we will act within one month.

Deletion is real, not a flag: it removes your account, your settings, your saved views and your sessions. The activity log keeps its lines with your identity stripped out, because a security log that can be emptied by the person it is about is not a security log.

You can also complain to the Information Commissioner's Office at ico.org.uk.

Why we are allowed to hold it

  • To provide the service you asked for — your account, your settings, your saved work.
  • Our legitimate interest in keeping the service safe — the activity log, and the rate limits it feeds.
  • To meet a legal obligation — records relating to payment.

Children

This is not directed at children and we do not knowingly hold data about anyone under 16. Tell us if you think we do and we will remove it.

Changes

If this changes in a way that matters, the date at the top changes and anyone with an account is told. Older versions are in the public history of this site's repository, so a change is always visible as a change.

Z30 Labs

  • What we do
  • Products
  • Research
  • Contact

Reading

  • News and analysis

Product

  • Sign in
  • Pricing

Legal

  • Privacy
  • Terms of use

Z30 Labs, a division of ZanCo Technologies.

Premier League club badges and marks are licensed and are not used here.