Privacy Policy

Last updated: February 3, 2026

Spicy Sports ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our fantasy sports analytics platform.

By using Spicy Sports, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not use our service.

1. Information We Collect

1.1 Information from OAuth Providers

When you sign in using a third-party authentication provider, we receive and store certain information from that provider:

Discord

  • User ID and display name
  • Email address
  • Profile avatar
  • List of Discord servers you belong to (to verify community membership)
  • Authentication tokens for maintaining your session

Yahoo

  • Yahoo account ID
  • Email address
  • Profile information
  • Authentication tokens for accessing Yahoo Fantasy Sports data

X (Twitter)

  • User ID
  • Profile information
  • Authentication tokens for maintaining your session

1.2 Sleeper Fantasy Accounts

Sleeper integration works differently from OAuth providers. When you add a Sleeper account, you provide your Sleeper username. We store only:

  • Your Sleeper username
  • Your Sleeper user ID (a public identifier)

All Sleeper fantasy data (leagues, rosters, matchups, drafts) is fetched from Sleeper's public API. This data is not stored in our database—it is retrieved in real-time when you view your leagues. The Sleeper API is publicly accessible and does not require authentication, meaning any user's public fantasy data can be viewed by anyone who knows their username.

We do not have access to your Sleeper account credentials, and we cannot make changes to your Sleeper leagues or rosters.

1.4 Yahoo Fantasy Sports Data

When you connect your Yahoo account, we access your Yahoo Fantasy Sports data to provide our analytics services. This includes:

  • Your fantasy leagues and teams
  • League standings, matchups, and scores
  • Roster information and player statistics
  • Transaction history (trades, waiver claims, drops)
  • Draft information

This data is accessed in read-only mode. We do not make changes to your Yahoo Fantasy teams or leagues.

1.5 Session Information

When you use our service, we automatically collect:

  • IP address
  • Browser type and version (user agent)
  • Session timestamps

1.6 User Preferences

We store your preferences to personalize your experience:

  • Favorite sports (NFL, NBA, MLB, NHL)
  • Favorite leagues and managers
  • Display preferences

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Authentication: To verify your identity and maintain your session
  • Community Access: To verify your membership in the Spicy Sports Discord community for access to certain features
  • Fantasy Analytics: To display your fantasy sports data and provide personalized analytics and insights
  • Service Improvement: To understand how our service is used and to improve functionality
  • Security: To protect against unauthorized access and maintain the security of our platform

3. Information Sharing and Disclosure

We do not sell, trade, or rent your personal information to third parties. We may share your information only in the following circumstances:

3.1 Service Providers

We use trusted third-party services to operate our platform:

  • Neon: Database hosting (data stored on AWS infrastructure in the United States)
  • Appwrite: Application hosting
  • Discord, Yahoo, X: Authentication providers (we send authentication requests to these services)
  • Sleeper: Fantasy sports data provider (we fetch publicly available data from their API)

3.2 Legal Requirements

We may disclose your information if required by law, court order, or governmental regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.

4. Data Security

We implement appropriate security measures to protect your information:

  • All database connections use SSL/TLS encryption
  • OAuth tokens are stored securely and never exposed to client-side code
  • Session tokens use secure, HTTP-only cookies
  • Sensitive credentials are stored as environment variables, not in code

While we strive to protect your information, no method of electronic storage or transmission is 100% secure. We cannot guarantee absolute security.

5. Data Retention

We retain your information for as long as your account is active or as needed to provide our services:

  • Session data: Sessions expire after 30 days of inactivity
  • Account data: Retained until you request account deletion
  • OAuth tokens: Refreshed periodically and revoked upon sign-out or account deletion

6. Your Rights and Choices

You have the following rights regarding your personal information:

  • Access: You can view your account information and connected services in your Settings
  • Correction: You can update your display name and preferences in Settings
  • Revocation: You can disconnect OAuth providers through your Settings or directly through the provider's application settings
  • Deletion: You can request complete deletion of your account and associated data by contacting us
  • Sign Out: You can sign out at any time to end your active session

7. Cookies and Tracking

We use essential cookies to maintain your authentication session. These cookies are strictly necessary for the service to function and cannot be disabled.

We do not use analytics cookies, advertising cookies, or third-party tracking technologies.

8. Third-Party Links

Our service may contain links to third-party websites (such as Yahoo Fantasy Sports). We are not responsible for the privacy practices of these external sites. We encourage you to review the privacy policies of any third-party services you access through our platform.

9. Children's Privacy

Spicy Sports is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected personal information from a child under 13, we will take steps to delete that information.

10. International Users

Our services are hosted in the United States. If you are accessing our service from outside the United States, please be aware that your information may be transferred to, stored, and processed in the United States, where data protection laws may differ from those in your jurisdiction.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by updating the "Last updated" date at the top of this page. Your continued use of the service after any changes indicates your acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, you can reach us through our Discord community or by contacting the platform administrators.

For data deletion requests or privacy concerns, please contact us directly through the Spicy Sports Discord server.