Who we are
League Loom ("League Loom", "we", "us", or "our") is operated by an individual developer based in the United States. It is not a registered company. This policy covers the website at leagueloom.com and the League Loom connector service. Questions: support@leagueloom.com.
How the service works
Understanding the flow makes the rest of this policy concrete:
- During setup you provide your own provider credentials (your ESPN espn_s2 and SWID cookies, your Sleeper username, or your Fantrax Secret ID).
- Those credentials are encrypted with AES-256-GCM and sealed into a connector token that you hold. By default, we do not save them. If you enable email recovery, we store an encrypted backup of that token.
- Each time your connected AI requests league data, the server decrypts your token in memory for that single request, reads only the data the AI asked for from the provider, returns it, and keeps nothing afterward.
- Every tool registered today retrieves or analyzes data. No write-action tools are available, so League Loom cannot write to, modify, post to, or delete anything in your leagues or provider accounts.
Information we collect
- Provider credentials you give us. Your ESPN espn_s2 and SWID cookies, Sleeper username, or Fantrax Secret ID. These are placed into your own encrypted connector token. We use them only to read your leagues when your AI asks.
- Fantasy league data, on demand. When your connected AI requests it, we read rosters, standings, matchups, drafts, and player data from the provider and return it. We do not keep a copy afterward.
- Setup preferences. If you choose an assistant, fantasy platform or first question, we remember those choices in this browser for up to seven days to help you finish setup. You can clear them in the setup chooser. These preferences contain no credentials or league details.
- Website analytics. When you visit leagueloom.com we use Google Analytics (GA4) to measure aggregate usage. The custom events we send are deliberately coarse: only allowlisted values such as the page, a link or button name, a provider name, the name of the AI assistant you connect through, an approximate country and region recorded once when you connect, and counts. Our hosting provider supplies approximate location. For abuse prevention, we also process request IP addresses into short-lived hashed rate-limit keys; we do not save raw IP addresses in our recovery store or custom analytics. Google Analytics may also collect standard technical data such as approximate location derived from your IP address, device and browser type, and a cookie identifier. We also send the same coarse, server-side usage events to Mixpanel, keyed by a pseudonymous connection identifier, to understand how the connector is used over time. These events carry no credentials, no league or team identifiers, and no names.
- Optional email recovery. If you opt in, we temporarily store your encrypted email address while you verify it. After verification and saving, we store your email and connection token together in an encrypted backup. The token includes your league settings and provider credentials. A keyed hash of your email locates the backup. We record verification state and expiry times to operate recovery. Authorized administrators can view saved recovery addresses and associated connection activity for support and service monitoring. Recovery emails do not subscribe you to marketing.
- Messages you send us. If you email us, we receive your message and address.
What we do not collect or store
- We never store plaintext provider credentials. Without optional email recovery, your encrypted connector token is not saved in our database.
- There is no League Loom password. You can optionally verify an email address to recover your saved setup.
- Our analytics never send your credentials, your league or team identifiers, your name, email, sign-in links, or any values you copy. Our custom events carry no personal information.
- Because the service is stateless, the league data we read for your AI is not saved after the request finishes.
- Honest caveat: like any internet service, requests pass through our hosting provider, and brief operational logs may exist for security and reliability before they expire. We design the service to avoid capturing your token or credentials in those logs.
How we use information
- Credentials are used to authenticate data requests to ESPN, Sleeper, or Fantrax on your behalf. Setup asks only for the credentials needed to read your leagues.
- League data is used only to answer your AI's specific request, then returned to you and discarded.
- Analytics are used only to understand aggregate usage and improve the service.
We do not sell your personal information for money, we do not use it for advertising, and we do not use your league data or credentials to train any AI model.
How your credentials are protected
Your credentials are sealed into your own bearer token using AES-256-GCM encryption, decrypted only in memory per request, and sent over encrypted connections (HTTPS/TLS). Your token is the key to your league data, so keep it private: anyone who has your token can read your connected leagues. No write-action tools are registered today. Running setup again creates a new token and updates the connection used by your AI tool, but it does not revoke an older stateless token. Remove old connector copies, and rotate the provider credential if an older token may have been exposed. No method of transmission or storage is completely secure, so we cannot guarantee absolute security, but we aim to minimize what is stored and exposed.
Optional email recovery
Email recovery is optional. Verify your email and save your setup to enable it; simply typing an address does not create a backup. There is one saved setup per email address on each environment. Saving a newly verified setup replaces that address's previous backup. Saving edits to an existing recovered setup updates its backup.
Anyone with access to your recovery inbox or a sign-in link can obtain a connection key and access your connected leagues. Use an inbox you control and protect it with multifactor authentication. Links expire after 15 minutes and work once. We do not include provider credentials or your connection key in emails. Expired or revoked connections cannot be restored, and recovery cannot refresh expired provider credentials.
You can turn off recovery and delete its email and backup from the setup edit screen after signing in with a link or a current connection key. This also prevents outstanding sign-in links from opening that backup. It does not revoke keys already issued or delete copies of emails in your mailbox. If you no longer have access, contact support@leagueloom.com; we may need to verify your request.
Cookies and analytics
We use Google Analytics (GA4), provided by Google LLC, which sets cookies or similar identifiers to measure usage. Mixpanel receives only server-side events and sets no cookies in your browser. You can opt out using your browser's cookie controls, the Google Analytics opt-out browser add-on, or your browser's privacy settings. Our website does not currently respond to browser "Do Not Track" or Global Privacy Control signals, because there is no single industry standard for them; you can still opt out of analytics using the controls above. If you are in a region that requires consent before non-essential cookies load, please use your browser controls to block them.
Third-party services
- Fantasy providers: ESPN (The Walt Disney Company), Sleeper, and Fantrax. Current tools use the credentials you provide to retrieve league data, and no write-action tools are registered. Their own privacy policies govern your account with them. League Loom is not affiliated with, endorsed by, or sponsored by any of them.
- The AI tool you connect: when you use League Loom through Claude (Anthropic), ChatGPT (OpenAI), or another AI tool, the data we return flows to that tool, and that provider's own terms and privacy policy govern what it does with the data. We do not control the AI tool.
- Analytics: Google Analytics (Google LLC) and Mixpanel (Mixpanel, Inc.).
- Recovery storage: Upstash, through our Redis storage service, stores the encrypted backup, keyed email lookup, verification records and short-lived abuse-prevention counters.
- Transactional email: Resend receives your email address and verification or sign-in message to deliver the requested link. Resend and your email provider process and may retain message content and delivery records under their own policies and configured retention periods. Your provider credentials and connection key are not sent to Resend.
- Hosting: Vercel, which serves the site and processes requests.
Data retention
- Recovery: verification records and sign-in links expire within 15 minutes. Verified email and encrypted token backups expire 400 days after their last save, or are deleted when you turn recovery off or replace the backup. This includes any credentials sealed inside the token. Abuse-prevention counters expire within 24 hours. Aggregate email-operation counts expire after 100 days; per-backup activity counts and timestamps expire after 100 days without recorded activity. These counters contain no email addresses, credentials or sign-in links. Without recovery, we do not retain your token.
- League data: processed per request and not stored afterward.
- Analytics: Google Analytics and Mixpanel retain usage data for their configured periods. Our own usage history stores daily activity against a pseudonymous connection identifier for up to 180 days, with first-use markers retained until 400 days of inactivity. This history contains usage counts, timestamps, and coarse configuration counts, never credentials, league or team identifiers, or prompt text.
- Operational events: our own detailed event history uses separate, size-limited daily buckets for tool calls, initialization requests, and connection events. The console shows the latest 14 calendar days; these buckets expire within 15 days of their last write. They contain timestamps, pseudonymous connection identifiers, tool names, and coarse outcomes, never tool arguments or prompt text. Older shared event buffers expire within 30 days of their last expiry refresh. Hosting logs may also be retained briefly for security and reliability.
Children's privacy
League Loom is intended for adults managing their own fantasy leagues and is not directed to children. We do not knowingly collect personal information from anyone under 13, and we do not ask your age. If you believe a child has provided personal information, contact us at support@leagueloom.com and we will address it.
Your choices and rights
- Stop and disconnect: remove the League Loom connector from your AI tool and stop using your token at any time.
- Rotate your token: run setup again to mint a new token and discard the old one.
- Delete email recovery: open your setup using a current key or an emailed sign-in link, then choose Turn off email recovery. You can verify a different address afterward.
- Opt out of analytics: see "Cookies and analytics" above.
Depending on where you live, you may have rights to access, correct, or delete personal information, or to opt out of the sale or sharing of it. The personal data we hold may include your optional recovery email and encrypted backup as well as usage information. To make a request, email support@leagueloom.com. We do not sell or share your personal information for cross-context behavioral advertising for money; note that some privacy laws treat standard analytics cookies as a "sale" or "share", which you can opt out of using the browser and Google controls above. We will not treat you differently for exercising your rights.
California and other US state residents
If you are a California resident, you may have rights under the CCPA and CPRA, including to know, delete, and opt out of the sale or sharing of personal information. We do not sell your personal information for money. To exercise any right, contact support@leagueloom.com. Residents of other US states with privacy laws may have similar rights and can use the same contact.
EU, EEA, and UK visitors
If you visit from the EU, EEA, or UK, our lawful basis for reading your leagues, handling your token, and providing email recovery when you choose it is performance of the service you requested, and our basis for coarse analytics is our legitimate interest in understanding aggregate usage. You may have rights to access, correct, delete, restrict, or object to processing, and to complain to your local supervisory authority. Contact support@leagueloom.com. Our operator and hosting are in the United States, so your data is processed in the United States; by using the service from outside the US you understand and accept this.
Changes to this policy
We may update this policy. We will post changes here, update the "Policy last revised" date above, and highlight material changes where reasonable. Continued use after an update means you accept the revised policy.