Laces OutPrivacy & data use Back to Laces Out

Private, self-hosted deployment

Privacy policy

Effective July 17, 2026

What this deployment stores

  • Your display name, normalized email address, password hash, and revocable sessions.
  • Fantasy league settings, teams, rosters, standings, matchups, draft events, and the team you claim in each league.
  • Your rankings, auction values, notes, shares, and recommendation inputs or feedback.
  • Operational records such as sync time, source freshness, request correlation IDs, and security audit events. Application logs are configured to redact credentials.
  • Film room provider, model, request status, token counts, and timing. If you add a personal model-provider API key, it is encrypted. Laces Out does not retain the question or answer.

Provider connections

Yahoo authorization happens on Yahoo. The server stores Yahoo tokens in an encrypted, versioned credential envelope and uses them only for read-only fantasy sync initiated through this deployment. The current release shows the last successful sync and keeps unattended Yahoo league refreshes disabled until that scheduler is separately validated.

ESPN does not provide this app with a supported consumer Fantasy OAuth flow. The one-click sync bookmark and optional browser companion use the ESPN session already present in your browser. They send bounded league data to Laces Out, but never send your ESPN password or the values of ESPN cookies. Every scoped sync credential can be revoked from the League Sync screen.

How data is used and shared

Data is used to synchronize leagues, run deterministic draft and in-season analysis, show league-wide statistics to authorized league members, and operate or secure this deployment. Private rankings, notes, provider credentials, and personal recommendation settings are not exposed to another member unless you explicitly create a permitted share.

Laces Out does not sell data or run behavioral advertising.

This deployment uses Cloudflare Web Analytics so the operator can see aggregate traffic levels. It reports page views through a script loaded from Cloudflare; it is not used to build a profile of you, and it plays no part in any recommendation. Cloudflare states that it does not log query strings, so the contents of a search or filter are not sent. What Cloudflare records and retains is described in its own documentation and governed by its terms, not by this policy.

Provider and football-data services receive only the requests required to retrieve their data. Film room sends your question and a bounded snapshot of your authorized league, recommendations, and analytics to Google Gemini by default using the operator's Google AI Studio project. This included access currently uses Gemini 3.6 Flash and requires no personal key. Google states that free-tier submitted content may be used to improve its products. You may instead add a separately billed OpenAI, Anthropic, Gemini, or OpenRouter API key and choose the model; that key is encrypted, is not shown again after save, and can be removed at any time. Provider processing is governed by that provider's account terms and privacy choices.

Retention, export, and deletion

The live database retains an account and its authorized artifacts until they are deleted by the deployment operator or required for an active shared league. Encrypted backups may retain deleted records until that operator’s documented backup rotation completes. Ask the person who invited you to export your data, revoke a connection, delete a share, or delete your account and associated private data.

Security and your choices

Passwords are protected with Argon2id, browser sessions are HTTP-only, production traffic is intended to use HTTPS, and provider credentials are encrypted at rest. No small self-hosted service can promise absolute security. Use a unique password, revoke provider access if a device or server is compromised, and report unexpected league or account activity to the operator promptly.

Policy changes and contact

Material policy changes should be announced to members before new processing begins. This is a private deployment rather than a centrally operated Laces Out service; the person who issued your invite operates it and is responsible for access, deletion, security, and policy questions.

Members should contact the operator through the channel used to share their invite.

Read-only provider access by default. No hidden transactions.