Hosted or self-hosted deployment
Privacy policy
Effective August 5, 2026What this deployment stores
- Your display name, normalized email address, password hash, and revocable sessions.
- Notification-device labels and push-service delivery credentials when you explicitly enable alerts. Notification permission is never requested merely by signing in.
- If the operator enables account email, hashed confirmation and password-reset tokens and a send-once record of the one league-setup reminder — never message content. The account also records when its email was confirmed. Optional email honors the Settings toggle; confirmation and password-reset email exist only in response to your own action.
- Fantasy league settings, teams, rosters, standings, matchups, draft events, and the team associated with your account in each league.
- Your rankings, auction values, notes, shares, and recommendation inputs or feedback.
- Operational records such as sync time, artifact freshness, refresh intent and attempt states, bounded error codes, request correlation IDs, and security audit events. Provider response bodies and device bearer tokens are not stored in refresh history, and application logs are configured to redact credentials.
- Encrypted Yahoo authorization and, only when you explicitly enable always-on ESPN sync, encrypted ESPN session authorization. Provider passwords are never collected.
- Film room provider, model, request status, token counts, and timing. If you add a personal model-provider API key, it is encrypted. Laces Out does not retain the question or answer.
- Weekly Reckoning recaps your league generates, and the League Intel notes that personalize them. Both are league data, visible to league members. A recap keeps the provider, model, requester, time, and tone level it was written with, and a reroll replaces it. Mild recaps stay clean; Medium and Scorched deliberately allow uncensored profanity and NSFW adult humor. A failed generation is not stored.
Provider connections
Yahoo authorization happens on Yahoo. The server stores Yahoo tokens in an encrypted, versioned credential envelope and uses them only for read-only fantasy sync initiated through this deployment. The current release shows the last successful sync and supports automatic, server-side read-only Yahoo league refreshes in addition to member-initiated refreshes. Refresh timing is best effort and is not guaranteed.
ESPN does not provide this app with a supported consumer Fantasy OAuth flow. The Chrome companion uses the ESPN session already present on that device and sends bounded league data to Laces Out. If both the deployment operator and member enable always-on ESPN sync, an authorized paired client sends ESPN's session authorization once over HTTPS. A compatible native app keeps credential entry on an ESPN-hosted page. Laces Out encrypts the resulting authorization at rest and uses it only for fixed, read-only fantasy endpoints; the ESPN password is never collected. The member can revoke that connection from League Sync, and expiration requires an explicit renewal. A separately enabled public-direct path sends no member credential and can refresh only an already-known, exactly matching public league season.
How data is used and shared
Data is used to synchronize leagues, run deterministic draft and in-season analysis, show league-wide statistics to authorized league members, and operate or secure this deployment. Private rankings, notes, provider credentials, and personal recommendation settings are not exposed to another member unless you explicitly create a permitted share.
Laces Out does not sell data or run behavioral advertising.
The native iOS app communicates with the Laces Out server you select. It stores the selected server address and app preferences on your device, keeps the authenticated server cookie in system-managed website storage, and uses the system share sheet only when you choose to share. Its bundled demo uses local sample data and does not require an account.
Provider and football-data services receive only the requests required to retrieve their data. Film room sends your question and a bounded snapshot of your authorized league, recommendations, and analytics to Google Gemini by default using the operator's Google AI Studio project. This included Film Room access uses Gemini 3.6 Flash and requires no personal key. When the operator has enabled it, included Medium and Scorched Weekly Reckoning recaps send the same bounded league context and the league's League Intel notes to Grok 4.3 through OpenRouter; Mild recaps use Gemini. Google states that free-tier submitted content may be used to improve its products. You may instead add a separately billed OpenAI, Anthropic, Gemini, DeepSeek, Grok, or OpenRouter API key and choose the model; that key is encrypted, is not shown again after save, and can be removed at any time. Provider processing is governed by that provider's account terms and privacy choices.
Retention, export, and deletion
A signed-in member can go directly to Settings → Your data to download a portable JSON export or permanently delete the account. The export includes identity, preferences, memberships, removed-league sync choices, private rankings and projections, activity, connection metadata, notification history, user-owned ESPN refresh and attempt history, and AI usage. It deliberately excludes password hashes, session or invitation tokens, OAuth and ESPN sync-device credentials, another member's device provenance, push endpoints and keys, browser-handoff tokens, encrypted fantasy-provider or AI keys, provider request hashes, and share-link tokens.
When the native app opens an authenticated web tool, the server stores only a digest of a random, single-use handoff lasting at most two minutes. Its bearer is carried in a URL fragment that is not sent in HTTP requests or referrers, removed from browser history, atomically rotated into a one-minute HttpOnly cookie, then deleted when the ordinary revocable browser session is created.
Removing one synced league in Settings detaches your membership, provider links, and ESPN device scope for that league. Other members keep shared data and ownership moves automatically when needed; a sole-member league is deleted. Background sync will not silently add the removed provider season again, but an explicit new provider pairing can restore it.
Account deletion requires the current password and an explicit destructive confirmation. It immediately revokes all sessions, provider and AI credentials, bridge devices, push subscriptions, invitations, preferences, private rankings/imports/shares, private projections, activity receipts, and league memberships from the live database. A league with surviving members is preserved and ownership moves to a surviving commissioner or member in that order. A league with no other member is deleted. Shared synced facts, league-visible numeric projections, immutable change events, and bounded usage/audit records remain only where other members or security accounting still require them; direct account attribution is removed, including user identifiers embedded in surviving projection and cloned-ranking provenance. League Intel text last written by the member and Weekly Reckoning recap text generated by that member are deleted.
Encrypted backups may retain deleted records until the deployment operator's documented backup rotation completes. Contact the operator if you cannot sign in or need help with an exceptional access request.
Security and your choices
Passwords are protected with Argon2id, browser sessions are HTTP-only, production traffic is intended to use HTTPS, and provider credentials are encrypted at rest. No internet service can promise absolute security. Use a unique password, revoke provider access if a device or server is compromised, and report unexpected league or account activity to the operator promptly.
Policy changes and contact
Material policy changes should be announced to members before new processing begins. The operator of the server you selected is responsible for access, backup retention, security, and policy questions for that deployment. The official hosted service and a self-hosted instance may have different operators.
Provider reviewers, members, and security researchers may contact the deployment operator at [email protected].