Privacy policy
Last updated · May 22, 2026
1. Data we collect
We collect the minimum data necessary to provide the service:
| Data | Source | Purpose |
|---|---|---|
| Email address | Google Sign-In | Account identification |
| Display name | Google Sign-In | Personalization |
| Google account ID | Google Sign-In | Authentication |
| Login timestamps | Automatic | Security and diagnostics |
| Draft configurations | Your input | Saving your draft sessions |
| Draft picks | Your input | Draft history and analysis |
| Sleeper username + league IDs | You, when connecting Sleeper | Pulling your league's draft + rosters |
| Yahoo refresh token (encrypted) | Yahoo OAuth, when you connect Yahoo | Pulling your Yahoo league's draft + rosters |
| League rosters (player names, positions, slots) | Sleeper / Yahoo, when you sync a league | Showing your team and projections on My Team |
2. Local browser storage
Some tools store preferences in your browser's localStorage to persist settings between visits:
- Drafted player selections (draft board)
- League configuration preferences
- Your "Keep me signed in" choice from the sign-in panel
This data stays on your device and is never transmitted to our servers. You can clear it at any time through your browser settings. Sign-in session tokens are covered in Section 8.
3. How we use your data
- To authenticate you and maintain your session
- To save and restore your draft sessions
- To improve the service based on aggregate usage patterns
We do not sell, rent, or share your personal data with third parties.
4. External services
The following third-party services may receive limited information when you use the site:
- Google Fonts: loads fonts from fonts.googleapis.com. Google may receive your IP address. See Google's Privacy Policy.
- Google OAuth: used for sign-in. We verify your identity token with Google's servers. See Google's Privacy Policy.
- Sleeper: when you connect a Sleeper league, we call sleeper.com's public Fantasy API to fetch your league's draft picks and rosters. Sleeper sees the request and your league ID. No Sleeper authentication is required; you just paste a username. See Sleeper's Privacy Policy.
- Yahoo Fantasy Sports: when you connect Yahoo, you authorize our app to read your fantasy leagues via Yahoo OAuth. We receive (and store, encrypted) a refresh token that lets us pull your league data on your behalf. Disconnecting on /my-drafts revokes our copy locally; to revoke server-side, manage app access at developer.yahoo.com/apps. See Yahoo's Privacy Policy.
- Sentry: when an unexpected error happens server-side, the exception type, message, and stack trace are sent to Sentry for debugging. We do not enable Sentry's default PII capture, so emails / IPs / cookies are not transmitted. See Sentry's Privacy Policy.
- Cloudflare: fronts the site as a CDN and proxy. Cloudflare logs request metadata (IP, timing, user agent) per their standard policy.
- jsDelivr CDN: serves the Chart.js library on the accuracy page.
5. Data storage and security
Account data is stored in a server-side Postgres database. We use industry-standard security measures including HTTPS in production, signed and rotating JWT session tokens, and AES-256-GCM encryption at rest for any external-platform refresh tokens (Yahoo, future platforms). The encryption key lives only in the application's runtime environment, never in the database. No payment information is collected or stored.
6. Data retention and deletion
Your account data is retained for as long as your account is active. You can delete your account at any time from the user menu in the top-right corner of the site (Sign in → Delete account). This action cascades: your user record, all saved drafts, all picks, all mock-draft results, all synced rosters, all platform credentials (including encrypted Yahoo refresh tokens), and all DraftAI refresh tokens are removed from our database immediately.
If you cannot access the site to delete your account, email the address in the Contact section below; verified requests are honored within 30 days.
DraftAI sign-in refresh tokens expire automatically after 30 days, or sooner if you sign out. Revoked refresh-token rows are kept for up to 90 days for fraud-detection audit purposes, then purged. Yahoo refresh tokens are deleted immediately when you disconnect Yahoo, or when your account is deleted.
7. Your rights (GDPR / CCPA)
Depending on where you live you may have the right to (a) access the personal data we hold about you, (b) correct inaccuracies, (c) delete your data (see Section 6), and (d) object to processing. To exercise any of these rights, contact us via Section 11.
We do not sell personal information. We do not share data with advertisers or data brokers.
8. Cookies
This site does not use tracking cookies. Authentication is handled via JWT tokens: the short-lived access token is held in browser memory, and the longer-lived refresh token is stored in sessionStorage, which the browser clears when you close the tab. If you check "Keep me signed in" when signing in, the refresh token is stored in localStorage instead, so your session survives closing the browser on that device. Signing out removes the token from your browser and revokes it on our servers either way.
9. Children's privacy
This service is not directed at children under 13 (or under 16 in the EEA/UK). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will delete it.
10. Changes to this policy
We may update this policy from time to time. Material changes will be reflected in the "Last updated" date at the top of this page. Continued use of the service after a change constitutes acceptance.
11. Contact
For privacy questions, deletion requests, or to exercise GDPR / CCPA rights, email [email protected].