Effective
Who we are
Leagology is operated by nineteen87 LLC. This policy covers leagology.app, every league site served from it, and any league running on its own custom domain.
A league site is published by its commissioner. We host it and keep it in sync; they decide what it says and who is in it. Where that distinction changes your rights, this policy says so.
What we store
Everything below lives in one Postgres database. Each entry names the tables it describes, so you can check this page against the schema rather than take its word.
- Your account (User, Account, Session)
- Your name, your email address, and the credentials you sign in with. Passwords are never stored — only a scrypt hash of one, which cannot be reversed into the password you chose.
- Your leagues (LeagueMember, LeagueInvite)
- Which leagues you belong to, whether you are a commissioner of them, when you joined, and any invitation that brought you in.
- Your manager profile (Manager, ManagerIdentity, ManagerAlias)
- The public identity your league's pages show: a display name, optionally a real name, where you play from, a short bio, and the platform handles that tie your seasons together across renames.
- What you wrote (Post, Poll, Vote, Feedback)
- Posts on a league's blog, votes you cast in league polls, and anything you send through the feedback button — which also records the page you were on, your browser and screen size, and a screenshot if you attached one.
- Your league's fantasy history (Team, LineupSlot, Transaction, DuesPayment)
- Rosters, lineups, scores, drafts, trades and waivers, read from Sleeper. Dues are a ledger your commissioner keeps by hand — we do not process payments and never see a card.
- If you joined the waitlist (WaitlistSignup)
- Your name, your email address, and which page you signed up from. Nothing else, and it is not combined with an account unless you make one.
What we don't do
- We don't sell or rent your personal data, and we don't share it with advertisers.
- We don't process payments. League dues are a ledger your commissioner keeps by hand — no card ever touches this system.
- We don't run third-party advertising or tracking pixels. Page analytics are aggregate and come from our host.
- We don't email you marketing you didn't ask for. Today we send no email at all; if that changes, anything promotional will be opt-in and will carry an unsubscribe link.
Why we store it
To run the product you asked for: to sign you in, to know which leagues you belong to and what you may do in them, to draw your league's pages, and to answer you when you send feedback. We keep a league's history indefinitely, because a permanent record is the thing the product is for — see deleting your account for what that means when you leave.
Who else touches it
These are the only companies that process data on our behalf. Entries marked optional are integrations that are switched off unless configured, and when they are off nothing is sent to them at all.
- Vercel — Hosting, edge routing and product analytics for the pages you load.
- Neon — The Postgres database that stores accounts, leagues and synced league history.
- Sleeper — The fantasy platform your league's rosters, matchups and drafts are read from.
- Vercel Blob (optional) — Storage for images you upload — league crests, post images and feedback screenshots.
- Upstash (optional) — Rate limiting for public forms, which reads the request's IP address and stores nothing else.
- Slack (optional) — Operator alerts when a league is created, imported or joined, so someone sees a broken import the day it breaks.
We may add a provider for authentication and for transactional email — the “reset your password” kind, not the marketing kind. When we do, this list is updated before the change ships.
What's public
A league site is public on the web by default. That means your manager profile — display name, bio, location, avatar — and your league's results, drafts and trades can be read by anyone with the link and indexed by search engines.
A commissioner can ask search engines to stay away from their league in its settings. That is a request search engines honor by convention; it is not a lock, and it does not make a page private. Don't put anything on a league site you wouldn't want found.
Your email address is never shown on a public page. It is visible to your league's commissioners in their member settings, which is how invitations and account recovery work today.
Cookies
We set one cookie: your session, so you stay signed in. It is httpOnly, same-site, and secure in production. There is no advertising cookie and no cross-site tracking, so there is no consent banner to dismiss.
Security
Passwords are stored only as a scrypt hash. Password reset links are stored only as a SHA-256 hash of the token, so a database leak yields no usable links. Traffic is served over HTTPS throughout.
Leagology is in beta and is built by a very small team. We think the above is a sensible baseline, but we are not going to claim a certification we don't have.
Your rights
Wherever you live, you can ask us for a copy of your data, ask us to correct it, or ask us to delete it. You can do the first two yourself from Settings → Account in the dashboard. If you are in the UK, EU, or a US state with a privacy statute, those requests are rights you hold rather than favours we grant, and we will not charge you or treat you differently for exercising them.
Deleting your account
You can delete your account from Settings → Account. It removes your login, your email address, your league memberships, your votes and your feedback.
It does noterase your league's history, and this is deliberate: a season your league played is a shared record, not solely yours, and unpicking one manager from a decade of results would damage everyone else's. Your manager profile is unlinked from your login and its optional real name is cleared — what remains is the display name your league knows you by, attached to games that happened. If you want that removed too, ask your commissioner, who can edit or merge the manager record, or write to us.
Children
Leagology isn't for children. You must be at least 13 to hold an account, and 16 where local law sets a higher age for consenting to this kind of processing. If we learn we hold a child's account we delete it.
Changes to this policy
When the substance changes we update the effective date at the top of this page, and material changes are noted in the changelog.
Contact
Privacy questions, data requests and anything else on this page: privacy@leagology.app. We aim to answer within 30 days, which is the deadline the strictest of the laws above sets.