Privacy Policy

Dynasty DataForge (the "Platform") provides deterministic dynasty league intelligence, projections, simulations, and narrative tooling. This Privacy Policy explains what information we collect, why we collect it, how we use it, and the choices you have.

1. Information We Collect

1.1 League & Roster Data

We ingest publicly available or league‑authorized data from Sleeper and enrichment sources (e.g. projections, market baselines) to compute value, VORP, simulated matchups, and trade impacts.

1.2 Account & Access Data

If you request access or claim a manager slot we may store: email, display name, claimed roster identifiers, and access timestamps. For email magic link authentication we store a short‑lived token hash with a 15‑minute TTL (single use).

1.3 Usage & Event Metadata

We log deterministic usage events (e.g. newsletter context build, advice fetch, trade sim run) to enforce quotas and measure feature reliability—not to build behavioral ad profiles.

1.4 Optional Inputs

Manual overrides (e.g. custom projections, calibration inputs) are stored only to support reproducibility and auditing.

2. How We Use Information

  • Generate deterministic analytics (projections, VORP, lineup & trade sims).
  • Produce stable hashed newsletter payloads and matchup capsules.
  • Enforce fair‑use and plan quotas (free vs pro vs enterprise tiers).
  • Detect abuse, operational errors, or data ingestion failures.
  • Improve calibration artifacts (e.g. SLOT_SIGMA) using aggregated historical performance.

3. Legal Bases (GDPR / Similar Regimes)

  • Legitimate Interests: Operating a reproducible analytics platform for participating leagues.
  • Consent: When you explicitly request access, subscribe to updates, or enable experimental features.
  • Contract: Providing paid or premium tiers (if applicable) to league commissioners.

4. Data Retention

Operational events and calibration artifacts are retained to preserve longitudinal comparability. Access request logs and magic link token hashes are minimized or purged after they expire or are no longer required for audit/security.

5. Data Sharing

  • No sale of personal data.
  • No third‑party advertising networks.
  • Vendors limited to infrastructure (hosting, email delivery, Supabase) under data processing terms.
  • Aggregated, non‑personal metrics may be published for product transparency.

6. Security

We apply principle of least privilege, environment‑scoped secrets, and deterministic hashing for newsletter payloads to reduce tampering risk. Tokens and secrets are never embedded into hashed artifacts.

7. Your Rights

Depending on jurisdiction you may request: access, correction, deletion, restriction, or export of your personal data. Contact us at privacy@dynastydataforge.com.

8. International Transfers

Data may be processed in the United States. Where required, standard contractual clauses (SCCs) or equivalent safeguards are applied.

9. Children

The Platform is not directed to children under 13 (or the applicable minimum age). We do not knowingly collect their data.

10. Changes

We may update this policy when systems, data flow, or regulatory requirements change. Material changes will be versioned and dated.

11. Contact

Questions? privacy@dynastydataforge.com