Privacy
Last updated August 29, 2026. This page describes what cfbfantasy.net stores when you visit or use the product.
Accounts
Sign-in is handled by Supabase Auth. We store your account email and user id there. League membership in our database uses your user id, not a copy of your email, except on pending invite rows (so we can send the invite).
League data
Rosters, drafts, waivers, trades, and settings live in our application database so the product can run. Draft chat (“banter”) is kept in memory for the room and is not written to disk.
Marketing analytics
The marketing page and sign-in card send first-party events (page view, button click, signup). Those rows store an anonymous session id, optional campaign tags (UTM), the referring site’s origin only (scheme and host — no path or query), and your browser’s User-Agent. We do not store your IP address on those events.
Creating or joining a league records a separate activation event with your user id so we can see whether sign-up led to a league. Anonymous session traffic is never attached to your account on the server.
Your rights
- Signed-in users can export their product data from account settings.
- Signed-in users can delete their account from account settings. Auth deletion in Supabase may still need operator help.
- Backups may retain deleted rows until that copy is rotated.
Questions: email the operator who invited you, or the address on your league invite.