Sign in Get started

Privacy and data use

Account and access data

League Read stores your account identifier, display name, email, password hash when you create a password, Google external-login identifier when connected, approval state, 2FA state and recovery-code hashes, last login time, system roles, the internal partition for your account data, and named capabilities. It never stores your password, authenticator secret in readable page output after setup, or Google password. Personal API-token secrets are stored only as hashes; a newly issued secret is displayed once.

Fantasy-football evidence

Your account can contain independent copies of league settings, owners, teams, rosters, players, drafts, transactions, standings, matchups, projections, injuries, news, models, and analysis results. Another account may connect the same external league without receiving your credentials, custom settings, or saved work. Public provider evidence and content-identical calculations may be reused by fingerprint.

Operational records

Durable jobs retain parameters, seeds, evidence fingerprints, progress, results, and bounded failure messages. Audit events record material access and authority changes with the acting account, account data partition, time, resource, detail, and request IP address when available. Health checks expose installation status and aggregate operational counts, not private league records.

Retention and deletion

Data & privacy shows the league data stored for your account. You can reset one league to its imported settings, disconnect only its provider sign-in, or remove that league copy and its private data without affecting another account or the external league. Installation-wide public provider evidence and trial-abuse markers follow separate retention rules and are not presented as private league rows.

External sources

Opening a preserved news, injury, or evidence link sends your browser to that publisher, whose privacy terms then apply. League Read does not treat a summary as a replacement for its source and does not make source authority depend on optional model enrichment.

Public pages

The landing page, this notice, and the free tier chart do not require an account. The tier chart can display current provider-derived rankings, attribution, source links, freshness, and League Read's calculated tier boundaries, but it never exposes a private account or league copy. The operator is responsible for confirming that public display is permitted by each configured provider agreement.

Operator responsibility

The person operating this installation chooses its host, backups, Google OAuth configuration, provider credentials, retention periods, account approvals, and authorized users. Do not import or publish data you are not permitted to use, and protect the data directory, backup directory, Data Protection keys, and service account as sensitive application state.