Fantasy Lair · Legal
Privacy Policy
Last updated 2026-08-21
The short version: we collect your Google identity, the ESPN league data you ask us to fetch, and everything you say to Dr. Vorp. We send your questions and the relevant league data to Anthropic to generate answers. We do not sell any of it, we run no trackers and no analytics, and you can have all of it deleted by asking.
The detail below matters more than the summary, particularly Section 3, which covers the information we hold about other people in your leagues. The numbered sections govern.
Who this covers
This policy describes how Samwisette Software Holdings LLC, operating Fantasy Lair at fantasylair.app (the “Service”), handles personal information. It applies to the website, the application, and the background jobs that fetch your league data.
Samwisette Software Holdings LLC is a small company run by one person, not an enterprise with a privacy department. This policy is written to tell you accurately what happens to your data, including the parts that are less flattering. For readers to whom the GDPR or a similar law applies: Samwisette Software Holdings LLC is the data controller for the personal information described here. Where a lawful basis is required, we rely on performance of our contract with you (operating the Service you signed up for), our legitimate interests (securing, debugging, and improving the Service), and your consent (the optional connections and uploads you choose to make, which you can withdraw by disconnecting or deleting them).
What we collect
- Google account information
- When you sign in, Google gives us your email address, your display name, and the URL of your profile image. We store all three. We never receive your Google password.
- ESPN credentials
- To fetch your league history we need to sign in to ESPN as you. Your ESPN email and password are submitted from your browser, passed through an encrypted internal queue to a background worker, and used to complete the sign-in. Your ESPN password is never written to our database. It exists in memory during the sign-in and in the queue message until that message is consumed.
- ESPN session cookies
- The sign-in produces two session cookies (SWID and espn_s2). We store them so we can keep fetching your data without asking you to sign in repeatedly. They are encrypted with AES-256-GCM before they are written; the key is held in AWS Systems Manager Parameter Store and never stored alongside them.
- Two-factor challenge data
- If ESPN presents a two-factor prompt, the worker captures a screenshot of that screen so you can see what is being asked. The screenshot may show your ESPN email address and the challenge text. It goes to a private, encrypted storage bucket and is automatically deleted 24 hours later. The code you type is stored only until the worker uses it, then immediately erased.
- Fantasy league data
- Matchups, scores, standings, draft results, rosters, transactions, keeper rules, and league settings, for the leagues and seasons you connect.
- Information about other people in your leagues
- League data necessarily includes your leaguemates — their team names, display names, ESPN identifiers, and their transaction and draft history. We collect this because it is part of the league record you asked us to retrieve. See Section 3.
- Chat history
- The questions you ask, any images you attach to them, the answers generated, the database queries run to produce them and their results, any charts or tables produced, token counts, and any thumbs-up or thumbs-down you leave.
- Images you attach to a question
- If you attach an image to a chat message — a screenshot, a photo of a draft board, a picture of a hand-written list — we store the image itself in a private, encrypted storage bucket, along with its type, size, and the message it belongs to. It is sent to Anthropic to answer the question it was attached to. Unlike the two-factor screenshot above, it is not on a deletion timer: it stays as long as the conversation does, because a chat that renders a broken image is a broken transcript. Deleting the conversation, or your account, deletes it — see Section 7.
- Memory notes
- Facts the assistant records about your league so it does not have to relearn them — for example a house rule, or which team is yours.
- Technical logs
- Our servers record ordinary operational data: request paths, timestamps, error messages, and job outcomes. These logs are kept to run and debug the Service.
We never see or store your full payment card details — if you subscribe, your card goes directly to Stripe, our payment processor. We do not ask for your address, phone number, or date of birth. We do not buy personal information about you from anyone.
Data about your leaguemates
This deserves its own section because it is the part people do not expect. When you connect a league, we store the league’s full record — which includes personal information about the other people in it, none of whom signed up for Fantasy Lair.
We only ever collect what your own ESPN account can already see, and we use it for one purpose: answering your questions about your league. We do not build profiles of your leaguemates for any other use, do not contact them, and do not sell or share their information.
Images you upload extend this in a way worth stating plainly: a screenshot of a group chat, a trade offer, or another platform’s message thread carries whatever is in the picture — names, handles, and anything else visible — and it is sent to Anthropic along with your question. The Terms ask you not to upload other people’s personal information without their consent, and this is why.
You are responsible for whether connecting a league is appropriate given your relationship with the people in it. If someone in your league wants their information removed from our copy of the league record, they can write to hello@spokenalpha.com and we will handle it — noting that removing a leaguemate from a league’s history may make parts of that history unanswerable.
How we use it
We use the information above to:
- Authenticate you and keep you signed in.
- Fetch and refresh your league history from ESPN.
- Answer your questions, which means sending the relevant data to an AI model.
- Show you your leagues, chats, and past answers.
- Operate, debug, secure, and improve the Service.
- Communicate with you about your account or a material change to these documents.
- Comply with the law and enforce our Terms.
Where it is stored and how it is protected
Data is stored in the United States, in AWS’s US East (Ohio) region. The database is PostgreSQL on Amazon RDS, running in a private network with no public address.
The specific protections in place today:
- ESPN session cookies are encrypted with AES-256-GCM before being stored.
- The encryption key is held in AWS Systems Manager Parameter Store as an encrypted parameter, separate from the database.
- The database is not reachable from the public internet.
- Traffic between your browser and the Service is encrypted with HTTPS.
- Two-factor screenshots go to a storage bucket that blocks all public access, encrypts objects at rest, and automatically deletes them after 24 hours.
- Access to the Service is limited to accounts we have approved.
How long we keep it
- Account information
- Kept while your account exists. You can delete your account yourself, immediately, from Settings → Account — see the Deletion row below.
- ESPN session cookies
- Kept while your ESPN connection is active. Deleted when you disconnect ESPN or delete your account. Expired cookies are replaced when you reconnect.
- ESPN password
- Not retained. See Section 2.
- Two-factor screenshots
- Automatically deleted 24 hours after capture.
- League data
- Kept while your account exists, so that historical questions stay answerable. It is not automatically purged when you disconnect ESPN — disconnecting stops future fetching, it does not erase what was already fetched. Deleting your account erases it immediately.
- Chat history and memory notes
- Kept indefinitely unless you delete them or delete your account. You can delete an individual chat at any time from the Service, or erase all of it immediately by deleting your account.
- Images you attached to a question
- Kept for as long as the conversation they belong to. There is no expiry clock on them — an image that vanished on a timer would leave a hole in an old transcript. Deleting the chat deletes its images from storage, and deleting your account deletes every one of them, in both cases as an actual erasure of the file rather than only of the record pointing at it.
- Technical logs
- Kept on a rolling basis for operations and debugging, and not used to build a profile of you.
- Backups
- Database backups may retain deleted data for a limited period before they age out.
Your choices and rights
Whether or not any particular privacy law applies to us, we will honor the following requests from any user:
- Access
- Ask what personal information we hold about you, and get a copy of it.
- Correction
- Ask us to correct information that is wrong.
- Deletion
- Delete your account and the data associated with it yourself, immediately, from Settings → Account in the Service — no waiting period, and it cannot be undone. If you would rather ask us to do it for you, email us and we will do so within 30 days. Either way, this is subject to anything we must keep by law and copies in backups that have not yet aged out.
- Portability
- Ask for your chat history and league data in a machine-readable format.
- Disconnect ESPN
- Stop future data retrieval at any time without deleting your account.
- No retaliation
- We will not degrade the Service or charge you differently for exercising any of these.
To make a request, email hello@spokenalpha.com from the address on your account. We will acknowledge within 10 business days and respond within 30 days. If we cannot verify that a request comes from you, we will decline it — that protects you.
California and other state privacy laws
The California Consumer Privacy Act applies to businesses that meet certain thresholds — broadly, more than roughly $26.6 million in annual revenue, personal information about 100,000 or more consumers or households, or half or more of revenue from selling personal information. Fantasy Lair meets none of them and is not currently a covered “business” under that law. Several other state privacy laws have comparable thresholds we also do not meet.
We say that plainly rather than claiming compliance we have not been assessed for. It changes nothing about what you can ask for: the rights in Section 8 — including access, deletion, correction, portability, the right to know what is shared and with whom, and the right not to be retaliated against — are offered to every user regardless.
For the avoidance of doubt: we do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in the CCPA. We do not process sensitive personal information to infer characteristics about you.
Users outside the United States
The Service is intended for users in the United States, is hosted there, and is not directed to the European Economic Area, the United Kingdom, or Switzerland. We do not offer the Service to users in those regions and have not implemented the transfer mechanisms, records, or representative arrangements the GDPR requires of businesses that do.
If you use the Service from outside the United States, you are transferring your information to the United States, where privacy laws differ from those in your country. If you are in the EEA or the UK and want your data deleted, email us and we will delete it.
Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from them. If we learn that we have, we will delete it promptly. A parent or guardian who believes their child under 13 has given us information should email hello@spokenalpha.com. Users aged 13 to 17 may use the Service only with a parent or guardian’s consent, as described in the Terms of Service.
If there is a data breach
If we determine that unauthorized access to personal information has occurred, we will:
- Work to contain it and stop ongoing access.
- Notify affected users by email without unreasonable delay, and in any case within 72 hours of confirming a breach that is likely to affect them, unless law enforcement asks us in writing to delay.
- Describe what happened, what categories of information were involved, what we have done, and what you should do — such as changing your ESPN password.
- Notify state regulators where the breach notification laws that apply to us require it.
- Revoke and rotate affected credentials, including stored ESPN session cookies.
If you find a security problem in the Service, please report it to hello@spokenalpha.com rather than disclosing it publicly. We will not pursue legal action against anyone who reports a vulnerability in good faith, without accessing other users’ data, and gives us a reasonable chance to fix it.
Changes to this policy
We may update this policy. The “last updated” date at the top changes when we do. If a change materially affects how we handle information already collected — a new category of sharing, a new analytics provider, a materially longer retention period — we will notify you by email or in the Service before it takes effect, and where the change requires your consent, we will ask for it.
Contact
Privacy questions, requests, and complaints go to hello@spokenalpha.com. The Service is operated by Samwisette Software Holdings LLC, a Delaware limited liability company, which is the data controller for the personal information this policy describes.