Privacy policy
Summary
Fantasy Insights is a league-history platform for fantasy football. We collect the data needed to run the service: your Google or email identity for sign-in, your Sleeper handle and the league data you import, and a small set of preferences. We display advertising and may share certain personal information with advertising partners. A paid subscription removes ads and the advertising-related data sharing that comes with them. We also record diagnostic information when something goes wrong, including a masked replay of the page you were on. We do not send marketing emails. You can opt out of sale or sharing for advertising in one step on Your Privacy Choices, and export your data or delete your account at any time from Settings.
What we collect
- Account identity. You sign in through our authentication provider, Clerk, using either Google or an email address. We receive your email address and a stable account identifier, plus your name and profile picture if you use Google. The identifier is what ties your sessions together; your email and name are stored to identify your account. A league you add is private to you, so no other user of the app sees them.
- Sleeper handle and imported league data. When you link a Sleeper account we store the handle you provide. When you import leagues, we store the roster, schedule, scoring, draft, trade, and waiver history we read from Sleeper for those leagues. Custom (non-Sleeper) league data you enter directly is stored the same way.
- Preferences. Theme, dashboard layout, last-visited league, and your “Do not sell or share” choice.
- Session cookies. A signed cookie carries your sign-in state. We also use cookies and similar technologies to enable advertising. See "Advertising" below.
- Technical signals. Approximate location (from IP), device and browser identifiers, and standard server-log fields (request path, status, user agent, timing).
- Diagnostic data. When the app errors, and on a small sample of ordinary sessions, we record the failure, the page you were on, your browser version, and a masked replay of that page. Identified by an internal account identifier, never your email or name. See Diagnostics and session replay.
How we use it
- To authenticate you and keep you signed in across visits.
- To render the league pages, standings, dashboards, and other views that make up the product.
- To select and display advertising, and to measure its performance, subject to your "Do not sell or share" preference.
- To debug and operate the service (server logs, never the contents of your session cookie).
- To diagnose crashes and performance problems, through our error-monitoring provider.
Advertising
Fantasy Insights is supported by advertising served through Google AdSense. We display a banner ad beneath the navigation on league pages. To select, deliver, and measure those ads, Google sets cookies and processes personal information, including device and browser identifiers, IP address, approximate location, and your interaction with the ad. When ads are personalized, this involves "sharing" personal information for cross-context behavioral advertising under the California Privacy Rights Act (CPRA), and may constitute "selling" personal information under CCPA. You can review how Google uses this data in “How Google uses information from sites or apps that use our services” and manage Google’s ad personalization at My Ad Center.
Paid subscribers do not see ads. If you subscribe to a paid plan, the banner ad is removed and no ad-related personal information is shared for advertising. The Google ad code is not loaded at all. The same applies to Fantasy Insights staff accounts.
You can opt out in one step. Press Opt out of sale/sharing on Your Privacy Choices (linked in every page’s footer), or Opt out on the cookie notice. It opts out this browser and, when you are signed in, your account, so the choice follows you to other devices. The Do not sell or share my personal information toggle in Settings → Privacy does the same. We also honor the Global Privacy Control (Sec-GPC: 1) browser signal as an opt-out for the requesting session, whether or not you are signed in. When you have opted out by either means, we instruct Google to serve non-personalized ads, chosen from the page’s content and coarse context rather than a profile of your activity.
Visitors in the European Economic Area, the UK and Switzerland. Before ads load, Google shows a consent message, provided by Google’s consent management platform, which is certified under the IAB Europe Transparency and Consent Framework. It asks whether Google and its ad partners may store and read information on your device and use your personal data for purposes such as personalized ads and measurement. Ads are personalized only if you agree; we do not turn personalization on for you. You can change your answer at any time from the privacy and cookie settings link on pages that carry ads. If you have also opted out of sale or sharing, or your browser sends Global Privacy Control, we still request non-personalized ads.
We do not knowingly share personal information of users we know to be under 16 without affirmative authorization, as CPRA requires.
Diagnostics and session replay
To find and fix crashes we use Sentry, an error-monitoring service, as our service provider. When the app fails, or on a small sample of sessions while it is working normally, your browser sends Sentry a diagnostic record.
- What is in a diagnostic record. The error and its technical stack trace, the page path, your browser and operating system version, the app version, and a randomly generated identifier that lets us group related records together.
- How you are identified. By an internal account identifier only. We deliberately do not send your email address, your name, your Sleeper handle, or your IP address to Sentry, and we strip credentials (session tokens, passwords, authorization headers) out of every record before it leaves your browser.
- Session replay. Sentry reconstructs what happened in the browser leading up to an error, which is closer to a recording of the page than to a log file. It is masked before it is recorded: all text is replaced with placeholder shapes, all images, video, and avatars are blocked, and everything you type into a form field is hidden. The result shows the layout you saw and where you clicked, not the names, scores, emails, or values on the screen. We capture replays for a small percentage of ordinary sessions and for sessions where an error occurred.
- We do not use any of this for advertising or analytics. Diagnostic data is used to fix defects and keep the service running. It is not sold, not shared with advertising partners, and not used to build a profile of you or to measure product usage.
Sentry processes this data on our behalf as a service provider, under a contract that limits them to that purpose, and we keep it only as long as it is useful for debugging. Diagnostic records are keyed to an internal account identifier rather than to your name or email, so they are not part of the data export in Settings; deleting your account removes the link between that identifier and you.
What we do not do
- We do not send marketing emails.
- We do not use session replay for advertising, analytics, or measuring product usage. We do run it, masked, for crash diagnostics. See Diagnostics and session replay.
- We do not use sensitive personal information (as defined by CPRA) for purposes other than those CPRA exempts.
Your rights
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), gives you the following rights. We extend these to all users regardless of residency:
- Right to know. Use Settings → Privacy → Download my data to receive a copy of the personal information we hold about you.
- Right to delete. Use Settings → Danger zone → Delete account to permanently delete your account and the personal data tied to it.
- Right to correct. Profile fields cannot be edited in the app yet. Email us at the address below to correct data we hold about you.
- Right to opt out of sale or sharing. One step on Your Privacy Choices, signed in or not; the cookie notice and Settings → Privacy offer the same opt-out.
- Right to non-discrimination. Exercising any of these rights does not change the level of service you receive.
How long we keep records of your privacy requests. When you accept this policy, change your privacy settings, download your data, or deactivate, reactivate, or delete your account, we keep a record of that request and how we handled it for 24 months, as California privacy regulations require. This record is kept separately from your account, so it survives account deletion. It stores an internal account identifier, the date and time, the action, whether your browser sent a Global Privacy Control signal, and a one-way cryptographic fingerprint of your IP address rather than the address itself. After 24 months it is deleted.
Cookies and similar technologies
Strictly necessary. First-party session cookies set by our authentication provider, Clerk, to keep you signed in across pages: a __session token (HttpOnly, Secure, SameSite=Lax) and a companion __client_uat timestamp that lets a page render your signed-in state.
Advertising. Google AdSense sets cookies and reads device identifiers to select, deliver, and measure ads, including Google’s first-party __gads / __gpi cookies and cookies from Google’s doubleclick.net ad domains. These load only for viewers who see ads (never for paid subscribers or staff). When you opt out of "Sell or Share", on Your Privacy Choices, the cookie notice, the Settings toggle or through a Global Privacy Control signal, Google serves a non-personalized ad and does not use the data to build a cross-context profile. In the European Economic Area, the UK and Switzerland, Google’s consent message asks first, and stores your answer in a cookie so it is not asked again on every page.
We also use the browser's localStorage to remember your theme, the order of your dashboard widgets, the last league you visited, and this browser’s sale/sharing opt-out. None of this localStorage data leaves your browser.
Children
Fantasy Insights is not directed at children under 13 and we do not knowingly collect personal information from anyone under 13. If you believe a child has provided us with personal information, contact us at the address below and we will delete it.
Changes to this policy
When we make a material change to this policy, we increment the version number at the top of this page and update the "Last updated" date. Signed-in users are prompted to review and accept the new version before continuing to use the service.
Contact
Questions about this policy, or to exercise any of your rights, write to privacy@curtislabs.com.