Privacy Policy
Last Updated: 2025-09-29
Dynasty DataForge (the "Platform") provides deterministic dynasty league intelligence, projections, simulations, and narrative tooling. This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices you have.
1. Information We Collect
1.1 League & Roster Data
We ingest publicly available or league‑authorized data from Sleeper and enrichment sources (e.g. projections, market baselines) to compute value, VORP, simulated matchups, and trade impacts.
1.2 Account & Access Data
If you request access or claim a manager slot we may store: email, display name, claimed roster identifiers, and access timestamps. For email magic link authentication we store a short‑lived token hash with a 15‑minute TTL (single use).
1.3 Usage & Event Metadata
We log deterministic usage events (e.g. newsletter context build, advice fetch, trade sim run) to enforce quotas and measure feature reliability—not to build behavioral ad profiles.
1.4 Optional Inputs
Manual overrides (e.g. custom projections, calibration inputs) are stored only to support reproducibility and auditing.
2. How We Use Information
- Generate deterministic analytics (projections, VORP, lineup & trade sims).
- Produce stable hashed newsletter payloads and matchup capsules.
- Enforce fair‑use and plan quotas (free vs pro vs enterprise tiers).
- Detect abuse, operational errors, or data ingestion failures.
- Improve calibration artifacts (e.g. SLOT_SIGMA) using aggregated historical performance.
3. Legal Bases (GDPR / Similar Regimes)
- Legitimate Interests: Operating a reproducible analytics platform for participating leagues.
- Consent: When you explicitly request access, subscribe to updates, or enable experimental features.
- Contract: Providing paid or premium tiers (if applicable) to league commissioners.
4. Data Retention
Operational events and calibration artifacts are retained to preserve longitudinal comparability. Access request logs and magic link token hashes are minimized or purged after they expire or are no longer required for audit/security.
5. Data Sharing
- No sale of personal data.
- No third‑party advertising networks.
- Vendors limited to infrastructure (hosting, email delivery, Supabase) under data processing terms.
- Aggregated, non‑personal metrics may be published for product transparency.
6. Security
We apply principle of least privilege, environment‑scoped secrets, and deterministic hashing for newsletter payloads to reduce tampering risk. Tokens and secrets are never embedded into hashed artifacts.
7. Your Rights
Depending on jurisdiction you may request: access, correction, deletion, restriction, or export of your personal data. Contact us at privacy@dynastydataforge.com.
8. International Transfers
Data may be processed in the United States. Where required, standard contractual clauses (SCCs) or equivalent safeguards are applied.
9. Children
The Platform is not directed to children under 13 (or the applicable minimum age). We do not knowingly collect their data.
10. Changes
We may update this policy when systems, data flow, or regulatory requirements change. Material changes will be versioned and dated.
11. Contact
Questions? privacy@dynastydataforge.com