Privacy

Privacy and league data handling

Last updated: July 2026. LeagueGazette uses connected league data to generate fantasy football rankings, playoff odds, lineup efficiency, trophies, and weekly recap content. This page explains what the product collects, how it is used, and how to request deletion.

Data LeagueGazette collects

When you connect or preview a league, LeagueGazette may process league IDs, platform, season, league names, team names, manager names, rosters, lineups, matchup scores, schedules, standings, scoring settings, league configuration, transaction or FAAB data when available, player details, team logos, and similar league assets.

ESPN credentials

For ESPN private leagues, you may provide ESPN cookies such as espn_s2 and SWID so LeagueGazette can validate access and refresh your league dashboard. These credentials are stored encrypted at rest and should only be submitted by someone authorized to access that league.

Generated outputs

LeagueGazette stores or serves generated outputs such as power rankings, playoff odds, lineup grades, trophies, AI-assisted columns, weekly recaps, and JSON payloads used by the dashboard. These outputs are derived from the connected league data and may include team, manager, player, matchup, or league references.

Payment and entitlement records

Paid unlocks may include buyer email, Stripe checkout or session identifiers, platform, league ID, season, paid-through season, entitlement status, and related support records needed to provide access and handle refunds.

Technical and analytics data

This policy covers League Gazette at leaguegazette.com and Draft Room by League Gazette at draft.leaguegazette.com. Cloudflare Web Analytics provides aggregate traffic and performance measurement on both products. Query strings are suppressed before transmission so league identifiers, payment-return flags, Draft Room configurations, and campaign parameters are not included.

Optional product analytics

PostHog product analytics is optional and starts only after explicit opt-in. It uses memory-only SDK persistence, no session replay, no autocapture, no automatic page views, no person profiles, and no IP or geolocation enrichment. We retain PostHog events for 30 days maximum.

If you opt in, we create a pseudonymous random identifier in the lg_analytics_id cookie and store your choice in the lg_analytics_consent cookie. Both cookies use the .leaguegazette.com domain and expire after one year so the same choice applies to both products. The identifier is not derived from your identity, league, payment, device fingerprint, or product data.

Optional analytics is limited to allowlisted product views, cross-product clicks, connection starts and completions, checkout starts, purchase completions, Draft Room funnel actions, and sanitized exceptions. Sanitized exceptions use enumerated error codes and query-free allowlisted paths; they never include raw messages, stacks, request bodies, or free text.

PostHog receives no personal or league data: no names, email addresses, league or team identifiers, manager or player data, imported labels, draft configurations or picks, Stripe identifiers, full URLs, queries, hashes, referrers, user agents, or IP-derived properties.

You can decline optional analytics or later opt out through Privacy & analytics choices. Opting out stops PostHog, deletes the shared pseudonymous identifier and PostHog cookies, and leaves only the denied consent choice. It does not delete essential storage such as recent leagues, saved Draft Room configurations, or draft progress.

Operational records and processors

Operational league, connection, payment, entitlement, support, security, and accounting data is separate from optional product analytics. Stripe, Supabase, Cloudflare, Google Cloud, and our storage providers process the operational data needed to connect leagues, take the one-time payment, provide seasonal access, generate results, prevent abuse, and administer the 30-day refund process. Analytics opt-out does not erase records that must be retained to provide access, refunds, security, or accounting.

Questions, privacy requests, and analytics opt-out assistance are available at leaguegazette.support@gmail.com.

How data is used

Data is used to validate ESPN or Sleeper league connections, compute and render dashboards, process paid access, provide support, debug failures, improve the product in aggregate, protect against abuse, and generate league analytics or recap content.

Service providers

LeagueGazette uses infrastructure and processors that may include Stripe for payment, Supabase for database and entitlement records, Cloudflare Pages, Workers, and R2 for hosting and storage, Google Cloud Run for compute, analytics providers, and AI providers for generated recap or insight content. ESPN and Sleeper are data sources; LeagueGazette is not affiliated with or endorsed by them.

Dashboard visibility

Public marketing pages are crawlable and included in the sitemap. Connected league dashboards are not intended to be the public discovery surface or intentionally listed in the sitemap, but league dashboards or data payloads may be accessible to anyone with a valid league link or identifier depending on the platform and route. Do not share league links if you do not want others to view them.

Retention and deletion

LeagueGazette retains league payloads, generated outputs, payment records, entitlement records, logs, and support records as needed to operate the product, provide access, debug issues, comply with payment records, and prevent abuse. You can request removal of stored ESPN credentials, league payloads, or associated records. Backups, logs, and payment records may take longer to expire or may be retained where needed for legal, security, or accounting reasons.