This Privacy Policy describes how dfsforge ("dfsforge", "we", "us", or "our") collects, uses, stores, and discloses information about you when you create an account on or otherwise use the website at dfsforge.com and any related services (collectively, the "Service"). By using the Service you agree to the practices described here.
1. Who we are
dfsforge is a season-long fantasy sports and daily-fantasy assistant operated by Justin Seib as the sole member of an existing United States limited liability company. We are the data controller for the personal information described in this policy. Our postal address is available on request via the contact channel in Section 12.
2. What information we collect
2.1 Account data
- Email address (required for account creation, password reset, and service notices).
- Password, stored only as an argon2 hash — we never store or have access to the plaintext.
- An optional display name you choose.
2.2 Platform-sync data
To deliver the core product, you connect one or more third-party fantasy platforms. Depending on the platform you connect, we collect and store:
- Sleeper, ESPN, MyFantasyLeague: your public username on that platform, plus the leagues, rosters, matchups, drafts, transactions, and waiver activity that the platform exposes for the leagues you join.
- Yahoo Fantasy, ESPN: OAuth access and refresh tokens (Yahoo) or session cookies (ESPN) that authorize us to call the platform's API on your behalf. These credentials are encrypted at rest in our database and are never displayed back to you in plaintext after they are stored.
We do not receive or store your Yahoo, ESPN, Sleeper, or MyFantasyLeague password.
2.3 Usage and device data
- IP address and user-agent string for each authenticated session, retained for security, abuse detection, and rate limiting.
- Timestamps of significant account actions (sign-up, sign-in, password change, platform connect, account deletion).
- Server-side logs of API requests, including the route called and response status, which are retained on a short rolling window.
2.4 Payment data
When paid subscriptions launch, billing will be processed by Stripe, Inc. We will store the Stripe customer identifier and the subscription status returned to us by Stripe. We do not and will not store your full payment card number, CVV, or bank account number — that data is collected and held directly by Stripe under Stripe's own privacy policy and PCI obligations.
3. How we use your information
We use the information described above only to:
- Provide, maintain, and improve the Service, including computing projections, sleeper scores, trade analysis, waiver rankings, and other analytical outputs against your league data.
- Authenticate you and keep your account secure, including detecting and blocking abuse.
- Communicate with you about the Service — account confirmation, password resets, billing receipts (when applicable), and material changes to this policy.
- Comply with legal obligations and enforce our Terms of Service.
We do not sell your personal information. We do not use your personal information to train third-party machine-learning models. We do not run advertising on the Service and do not share your data with ad networks.
4. Who we share information with
We share personal information only with the following categories of recipients, and only as needed to operate the Service:
- Supabase, Inc. — our managed PostgreSQL and authentication infrastructure provider. All account data, platform tokens, and league data are stored in a Supabase-hosted Postgres database in the
us-east-1region with row-level security enforced. - Stripe, Inc. (planned, when paid subscriptions launch) — for payment processing, fraud prevention, and tax handling.
- Sentry (planned, when enabled) — for server-side error and performance telemetry. Reports will be scrubbed of email addresses, tokens, and other directly identifying data before transmission.
- The fantasy platforms whose APIs we call on your behalf — Sleeper, Yahoo Fantasy, ESPN, and MyFantasyLeague — necessarily receive the API requests we make using your credentials. Their use of that information is governed by their own privacy policies.
- Law enforcement, courts, or regulators when we are required to do so by valid legal process, or where we believe disclosure is necessary to protect the rights, property, or safety of dfsforge, our users, or the public.
- A successor entity in connection with a merger, acquisition, financing, or sale of all or substantially all of our assets. We will notify you before your information becomes subject to a different privacy policy.
5. How long we keep your information
We retain account data, platform credentials, and synced league data for as long as your account is active. If you delete your account, we will permanently delete or irreversibly anonymize your personal information within 30 days of the deletion request, except where retention is required to comply with a legal obligation, resolve a dispute, or enforce our agreements. Server logs containing IP addresses are retained on a short rolling window (typically 30 days) and then discarded. Encrypted database backups are retained for 90 days and then destroyed.
6. Your rights
Regardless of where you live, you can:
- Access the personal information we hold about you.
- Correct any information that is inaccurate.
- Delete your account and the personal information associated with it.
- Export a machine-readable copy of your account data and synced league data.
- Disconnect any connected fantasy platform at any time, which revokes our stored credentials for that platform.
- Opt out of non-essential email. We currently send only transactional and security email, so there is no marketing list to leave.
Account deletion and platform disconnection are available from your in-app settings. For everything else, email us at the address in Section 12 and we will respond within 30 days.
If you are a California resident, you have the additional rights granted by the California Consumer Privacy Act, including the right to know the categories of personal information we have collected and the right not to be discriminated against for exercising your rights. We do not sell or "share" personal information for cross-context behavioral advertising as those terms are defined under California law.
7. Security practices
- All traffic to and from the Service is encrypted in transit using TLS 1.2 or later.
- Passwords are hashed with argon2id. We do not log, store, or transmit plaintext passwords at any point.
- OAuth tokens and platform session cookies are encrypted at rest using authenticated symmetric encryption with keys held outside the database.
- Our database enforces PostgreSQL row-level security so that, by design, one user's queries cannot read another user's rows.
- API authentication uses bearer tokens scoped to a single account, with session metadata available for review and revocation.
- Administrative access to production data is restricted, logged, and protected with multi-factor authentication.
- We do not store fantasy-platform credentials in plaintext anywhere — in code, in logs, in support tools, or in backups.
No system is perfectly secure. If you believe your account has been compromised, change your password immediately and email us at the address in Section 12.
8. Cookies and local storage
The Service does not set third-party tracking cookies. The web application stores your authentication token in your browser's localStorage so you stay signed in between visits; clearing your browser's site data signs you out. We use a small number of strictly necessary first-party cookies for session continuity and OAuth round-trips when connecting a fantasy platform. We do not run third-party analytics or advertising trackers at this time. If we add product analytics in the future, we will update this policy and, where required, request your consent.
9. Children's privacy
The Service is not directed to children under the age of 13, and we do not knowingly collect personal information from children under 13. If you believe a child under 13 has provided us with personal information, please contact us at the address in Section 12 and we will delete it.
10. International transfers
The Service is operated from the United States and all personal information is stored in the United States (Supabase us-east-1). We do not currently offer data residency in any other region. If you access the Service from outside the United States, you understand that your information will be transferred to, stored in, and processed in the United States, which may have different data-protection rules than your home jurisdiction.
11. Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. If the changes are material — a new processor, a new category of collected data, or anything that meaningfully affects your rights — we will notify you by email or by a prominent in-app notice before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
12. Contact
If you have any questions, requests, or complaints about this Privacy Policy or our handling of your personal information, contact us at support@dfsforge.com. A postal address is available on request.
