Privacy
Fader is a fantasy football tool at faderfantasy.com, run by one person. This page says what it stores, why, for how long, and how to have it removed. Questions and requests go to privacy@faderfantasy.com.
If you have an account
- Your email address, to send you sign-in links. There are no passwords.
- The leagues you connect: the platform, the league's ID and season, which team is yours, and the league's name.
- Which paid features you have used, to apply plan limits.
- Sign-in links, stored as a one-way hash together with the address they were sent to, and deleted a day after they are used or expire.
- One cookie, which keeps you signed in for 14 days. There are no tracking or advertising cookies.
If you join the paid waitlist
Your email address and when you joined. It is not an account. It is used once, to tell you paid plans are open, and the list is then deleted. To come off it sooner, email privacy@faderfantasy.com.
If you are in a league someone else connected
When a member connects a league, Fader reads the league's public data from the platform. From ESPN it stores the league's name, each team's name, and ESPN's own ID numbers for team owners. ESPN's public data does not include managers' names, and Fader stores none. On Sleeper, members' display names are read while a league is being connected, to help the member find their team, and are not stored.
If your team name or league name identifies you and you want it removed, email privacy@faderfantasy.com. It is removed by hand within 30 days, and the removal is recorded in the audit log described below.
The public record
Fader writes down every recommendation before kickoff and grades it afterwards, in public. That record keeps a recommendation after the account or league it was made for has gone, because a record that lost its calls whenever someone left would look better than it is. Each recommendation is stored under a random key rather than the league's ID, and that key stops pointing to the league when the league is released.
Deleting your data
- Delete your account from your leagues page after signing in. Your email address, leagues, usage records and sign-in links are deleted at once, and you are signed out.
- A league that no remaining account holds is released. It stops being shown at once, and within 24 hours Fader deletes the data it fetched for it and removes its name from the recommendations made for it.
- Every deletion is recorded in an audit log, which notes what kind of data was removed and when, without naming the league.
Logs
The web server logs each request's IP address, the address of the page, and what your browser sends about itself: its name, its language, and the page you came from. Fader's refresh logs record which leagues it fetched. Both are kept for 30 days, then deleted. The application itself does not log requests.
Where it is kept, and who else handles it
- Everything is stored on one server in Germany, rented from Hetzner.
- Sign-in emails are sent through Resend, which receives your email address and the message.
- Cloudflare provides the domain and its DNS, and forwards mail sent to privacy@faderfantasy.com. Visits to the site do not pass through Cloudflare.
- Backups are stored with Cloudflare R2, encrypted before they leave the server, with a key Cloudflare does not have.
- No page loads analytics, advertising or anything else from a third party.
Backups
Once a day Fader backs up its data, including accounts and league data, so that a failed server does not lose them. The server logs are not included. A backup cannot be edited after it is made, so something you delete stays in the older backups until they expire. Each backup is deleted after 30 days, so anything deleted from Fader is gone from the backups within 30 days of the deletion.
Payments
Fader does not take payments yet and holds no payment details.