Legal
Privacy Policy
Last updated: May 11, 2026
This policy explains what data Unfair Judge collects, how it is used, and the choices you have. Questions? Email support@thebandindex.com.
Who we are
Unfair Judge is a fan-run web app for rating NBA referees. The site is operated by the publisher reachable at support@thebandindex.com. Unfair Judge is not affiliated with, endorsed by, or sponsored by the National Basketball Association.
Information we collect
From Google when you sign in
We use Google as our sign-in provider via Supabase Auth. When you sign in, Google sends us only the following information from your Google account:
- Your Google account identifier (the OAuth
subvalue) - Your email address
- Your display name
- Your profile picture URL
We request the standard OAuth scopes openid, email, and profile only. We do not request or receive access to your Gmail, Google Drive, Google Calendar, Contacts, Photos, or any other Google service.
From your activity on the site
- Star ratings (1–5) you submit for referees in a given game
- Comments you post and upvotes you cast
- The games and referees you rate, with timestamps
- IP address and request metadata (user agent, timestamp) recorded by our hosting provider for abuse prevention and standard server logs
Cookies and local storage
We use essential cookies set by Supabase Auth to keep you signed in. We use browser localStorage to remember your theme preference (light/dark). We do not use advertising or cross-site tracking cookies.
How we use information
- To authenticate you and maintain your session
- To attribute your ratings and comments to your account
- To compute aggregate referee scores shown publicly on the site
- To moderate user-submitted comments for hate speech, threats, and spam
- To prevent abuse and respond to security issues
- To send rare, service-critical notices if necessary
Legal basis for processing
We rely on your consent when you choose to sign in and submit ratings or comments, and on our legitimate interest in operating the site, preventing abuse, and producing aggregate analytics about officiating.
How we share information
We do not sell personal data and we do not use advertising networks. We share data only with the service providers that make the product work:
- Supabase — authentication and database hosting (your account record, ratings, and comments are stored here)
- Google — OAuth identity provider (handles sign-in)
- Vercel — application hosting and request logging
- Google Gemini API — comment moderation. When you post a comment, the comment text is sent to the Gemini API to check for disallowed content before publication. No account identifiers are sent with the comment text.
- balldontlie API — public NBA game and box score data. This is a one-way pull: we read game data from them; no user data is sent.
We may also disclose information if required by law or to protect the rights, property, or safety of users or the public.
Data retention
- Account data is kept while your account is active.
- When you delete your account, your account record is removed and your ratings and comments are detached from your user ID (anonymized) so aggregate referee scores remain accurate.
- Server logs are retained by our hosting provider for approximately 30 days.
Your rights and choices
You have the right to access, correct, export, or delete your personal data. To delete your account, visit your account deletion page. For any other request, email support@thebandindex.com. If you reside in the EU, UK, California, or another jurisdiction with additional privacy rights (GDPR, UK GDPR, CCPA/CPRA), you may have further rights under local law, including the right to lodge a complaint with your data protection authority.
Account deletion details
When you delete your account, the user row tying your Google identity to the site is removed. Your individual ratings and comments remain visible on referee and game pages but are no longer linked to your user account or profile. This keeps the aggregate referee scores honest while removing your personal identifier from the public record.
Children
Unfair Judge is not directed to children under 13 (or under 16 in the EEA), and we do not knowingly collect personal data from them. If you believe a child has provided us with personal information, please contact us and we will delete it.
Security
Data is transmitted over TLS. Database access is gated by Supabase row-level security policies. We do not collect or store payment information. No system is perfectly secure, and we cannot guarantee absolute security.
International transfers
Our service providers may process data in the United States and other countries. By using Unfair Judge you consent to your data being processed in those locations.
Changes to this policy
We may update this policy from time to time. When we do, we will update the “Last updated” date above. Material changes will be announced via an in-app notice or by email where appropriate.
Contact
For privacy questions or requests, email support@thebandindex.com.