Privacy Policy

Effective 29 July 2026. FAABFAX is operated by an individual, not a company. Contact: dfinn0@gmail.com

This is a beta. It is small, it is run by one person, and this policy describes what actually happens rather than what a lawyer would like to reserve the right to do.

The short version

What we collect about you

A random token. When you first add a league we generate a random identifier (a UUID) and put it in your dashboard URL. That token is the whole account. We store it, and it is stored in your browser's localStorage so you can find your way back.

Your Sleeper username, if you typed one. If you looked up your leagues by username rather than by league ID, we keep that username so the dashboard can show you the right leagues.

Which leagues you added. League ID, league name, platform, and when it was last synced.

Job records. Each time we build or rebuild a league, we record that it happened, what step it reached, and any error text, so the status page can tell you what went wrong.

Waitlist entries. If you enter a private ESPN league, we record your token and that league ID so we know there is demand for private-league support. We do not collect, request, or store ESPN cookies or credentials of any kind.

Your IP address, briefly. We count requests per IP address to stop one person from overwhelming the service. Those counters live in memory only, are discarded as they age out, and are never written to our database. Our hosting provider keeps its own server logs, which typically include IP addresses, under its own policies and retention periods.

We do not use cookies. We do not run third-party analytics, tracking pixels, advertising scripts, or session recording.

What we collect about other people in your league

Read this part. It is the part most services bury.

When you add a league, we download that league's history and store it. A fantasy league is a group activity, so that history is about ten to fourteen people, not just you. For each of them we store:

We only read leagues that Sleeper or ESPN already serves publicly to anyone who asks, with no login and no credentials. We do not access private leagues. If a league is private, we stop and offer a waitlist entry instead.

That said, "publicly available" is not the same as "everyone in your league expected this." The people in your league did not agree to this policy and most likely do not know this tool exists. If that matters to you, tell them. If you or another member of a league has questions or a request about data we hold, write to dfinn0@gmail.com.

Where the data comes from

The public Sleeper API and the public ESPN fantasy API. We read them anonymously. We do not scrape logged-in pages, and we hold no credentials for either platform.

How we use it

To build your league's analysis and show it to you. That is the entire purpose. We do not profile you for advertising, we do not train models on your league data, and we do not sell or rent it.

Who we share it with

Nobody, with two unavoidable exceptions:

Anyone with your link can see your leagues

This is a design decision and you should understand it before you share anything.

Your dashboard URL contains your token, and the token is the credential. There is no password on top of it. If you post that link, forward it, or paste it somewhere public, whoever reads it can see every league on your account. They cannot delete your data, and re-syncing is throttled, but they can see it.

Because we hold no email address for you, there is also no account recovery. Lose the link and clear your browser storage, and the account is gone. We cannot look it up for you, and we cannot email you if something goes wrong.

Retention

There are two different things stored, kept for different lengths of time.

The raw Sleeper/ESPN API responses captured while your league is ingested or re-synced are kept on the server for up to 30 days (currently the production setting), then deleted automatically. They exist only to make re-syncing fast and reliable — not as a permanent copy — so once they age out, they're gone.

What actually powers your dashboard is a separate, derived database (rosters, draft picks, waiver claims, FAAB bids, and the analysis built from them). We keep that data indefinitely while the beta runs, because deleting it would break the dashboard you're using. There is no automatic deletion schedule for it yet, and saying otherwise would be inventing a process that does not exist.

If you want your account and its leagues removed, send your token to dfinn0@gmail.com and we will action it manually. Sending the token is what lets us identify the account — it is the only identifier we have.

Security

The honest limits: the token travels in a URL, which means it can end up in browser history, in a shared screenshot, or in the logs of any site you navigate to from a dashboard page. We set Referrer-Policy: no-referrer specifically to stop that last one. This is a beta run by one person and has not been penetration tested by a third party.

Because we hold no contact details, we have no way to notify you of a security incident. If one occurs we will post a notice on the site.

Children

This service is not directed at children under 13 and we do not knowingly collect their data.

Where this is run from

The service is operated from the United States and data is stored there. If you use it from elsewhere, your data is processed in the US.

Depending on where you live, local law may give you rights over your personal data that go beyond what this policy describes. If you believe that applies to you, write to dfinn0@gmail.com.

Changes

If this policy changes materially, the effective date at the top changes and a notice goes on the site. We have no way to email you about it.

Contact

dfinn0@gmail.com

← Back