Privacy Policy
Version: 2026-08-26
Last updated: 2026-08-26
This policy explains what PG Three Industries LLC ("ReadOption," "we," "us") collects when you use ReadOption, and how we use, store, and delete it. It describes what the product does today, during its free early-access (alpha) phase — when the product changes in a way that affects your data, we update this policy first. Please read it alongside our Terms of Use.
1. The Short Version
- You sign in with Google and give us your Sleeper username. At your direction, we fetch your league’s public Sleeper data and analyze it.
- We store our own analysis — never raw copies of Sleeper’s data.
- Your league-mates who never signed up are processed as display names only: no real names, no emails, no contact details, ever.
- Profiles are visible only to members of your league who imported it — never public, never cross-league.
- We don’t sell personal data, and we don’t run ads. There are no analytics or advertising trackers in the product today.
- The public demo at /demo uses an anonymized league — real historical patterns with fictional identities — and needs no sign-in.
- ReadOption is for adults: you must be 18 or older to use it.
2. What We Collect
2.1 From you
- Google sign-in basics. When you sign in with Google we receive and store your email address, your name as it appears on your Google profile, a profile-picture URL (we store the link, not the image), your Google account identifier, and whether Google has verified your email. We never see or store a password.
- Your Sleeper username. You provide it so we can look up your public leagues. Sleeper’s API is public and read-only — we never ask for your Sleeper password.
- Your league choices. Which leagues you import.
- Things you create in the app. Draft watchlists, profile corrections, keeper confirmations, and thumbs-up/down feedback on recommendations. All of it is scoped to your account.
2.2 From Sleeper’s public API (at your direction)
When you import a league, we read the same public data anyone can request from Sleeper: league settings, rosters, draft history, trades, and waiver/FAAB activity across seasons, plus the public profile basics (user ID, display name, avatar identifier) of the league’s members. We import a league only after confirming your linked Sleeper account is a member of it.
We keep only what we compute from this data — the raw Sleeper responses are processed in-session and never stored (Section 4).
2.3 Automatically — and deliberately little
- Session records. To keep you signed in, our auth layer (Better Auth) stores a session token, its expiry, and basic request metadata (IP address, browser user-agent). Sessions last 30 days, refreshed as you use the app, and the session cookie is HTTP-only (not readable by page scripts).
- Terms acceptance log. When you accept the Terms, we record the version, a timestamp, and your IP address.
That’s it. No advertising trackers, no analytics scripts, no fingerprinting.
3. Your League-Mates (People Who Never Signed Up)
This is the heart of the product, so it gets its own section.
ReadOption’s core feature is behavioral profiles of the other owners in your league, computed from their public Sleeper activity — when they draft each position, how they spend FAAB, whether they handcuff their running backs. For each owner we process only what Sleeper’s public API already exposes: an opaque Sleeper user ID, their public username and display name, their avatar identifier, and their team name.
What we deliberately never collect or store about league-mates:
- Real names beyond whatever display name they chose on Sleeper
- Email addresses, phone numbers, physical addresses, or any off-platform identity
- League chat or messages — we never fetch them
- Copies of their avatars — images are served from Sleeper by identifier, not stored by us
Profiles are strictly fantasy-football-scoped (draft and roster behavior, nothing personal) and are visible only to members of that same league who have imported it — never to other leagues, never publicly, never shareable. If you correct a profile, your correction is private to you and never changes what anyone else sees.
If you’re a league member (user or not) and want to understand, correct, or object to how your public Sleeper activity is used, email privacy@readoption.football and we’ll help.
4. Derivatives, Not Raw Data
We are not building a copy of Sleeper’s database. We fetch public data, compute our analysis in-session, and store only the analysis: per-dimension behavioral stats, prose summaries written from those stats, keeper facts, and your recommendations, corrections, watchlists, and feedback. Raw Sleeper API responses are never persisted.
5. How We Use Information
- To run the product — import your leagues, compute owner profiles, and generate draft and keeper recommendations.
- To personalize — apply your corrections, confirmations, and watchlist to your own recommendations.
- To improve the product — learn from your feedback on recommendations.
- To keep you signed in and the service healthy — sessions, rate limiting, and abuse prevention.
About AI: prose summaries and recommendations are written by a language model (Anthropic’s Claude). The model receives only the derived facts we computed — profile dimensions, roster context, pick state — never raw Sleeper data, and never your email or Google identity. A validation gate checks generated prose against the computed facts before anything is stored.
We do not sell personal information. We do not use it for advertising. And we do not train AI models on your personal data — including the things you add in the app (corrections, keeper confirmations, watchlists, feedback). We do tune the Service’s own recommendation logic using aggregated, de-identified feedback (e.g., "users disliked this kind of pick"); that never involves training a model on your personal data or your content. If we ever want to use your content for model training, we will update this policy first and ask for your explicit consent before your content is included.
6. Who Touches the Data (Processors)
These are the services that actually run ReadOption today. Each receives only what its job requires.
| Service | Job | What it handles |
|---|---|---|
| Google (OAuth) | Sign-in | Exchanges your Google identifier, email, name, and picture URL with us during sign-in. |
| Vercel | Hosts the web app | Serves pages; your session cookie stays in your browser. |
| Railway | Hosts the API | Processes your requests (session identity, league IDs) and runs the profile and recommendation logic. |
| Neon | Postgres database | Stores everything in Section 2 that we keep: account basics, sessions, league derivatives, profiles, watchlists, corrections, feedback. Encrypted in transit and at rest per Neon’s managed service. |
| Anthropic | AI summaries and recommendations | Receives derived facts only (computed profile dimensions, roster/pick context) as prompt text — no raw Sleeper data, no account identity. |
| Upstash (Redis) | Rate limiting | IP-based request counters. Not a store of personal content. |
| Sentry | Error tracking | Receives error reports from the API when something breaks — the failing route and the user and league IDs involved, so we can fix what you actually hit. No session replay, no page recording. |
| Axiom | Server logs | Receives one structured event per API request — the route, timing, outcome, and the user and league IDs involved. Operational logs, not content. |
| PostHog | Product analytics | Receives a small set of product events (for example, "league imported") tagged with your user ID, counted server-side. No browser tracker, no advertising, no session replay. |
Sleeper, Fantasy Football Calculator, and nflverse are data sources, not recipients — we send them no personal information. (During a live draft, your own browser polls Sleeper directly, the same as having the Sleeper app open.) All three are credited at /credits.
Future providers. Error tracking, server logging, and product analytics went live on 2026-08-07 — they are the Sentry, Axiom, and PostHog rows above, and this policy revision is the update we promised before naming them. Post-launch we expect to add payment and email providers. Before any new provider handles personal data, we will update this policy and its version.
7. How Long We Keep Things, and How Deletion Works
The rule of thumb: your things live and die with your account; league derivatives live and die with the league’s last remaining user.
| Data | Kept | Deleted |
|---|---|---|
| Account basics (Google info, Sleeper username) | Life of your account | When your account is deleted |
| Sessions | 30 days, rolling | On expiry or sign-out |
| Terms-acceptance log | Life of your account | With your account |
| Watchlists, corrections, feedback, keeper confirmations | Life of your account | With your account (watchlist entries and corrections can also be removed in-app anytime) |
| League identity + settings summary | While any member keeps the league linked | When the last linking user deletes their account or unlinks the league |
| Owner behavioral profiles and draft derivatives (tendency stats, prose summaries, keeper facts) | Live with the league link; recomputed on re-import | Deleted with the league |
| Raw Sleeper API responses; league-mates’ real names/emails/phones; league chat; avatar images | Never stored | — |
To delete your account and data: email privacy@readoption.football from your account email. Self-service deletion isn’t built yet, so we handle requests manually — deleting your account removes all user-scoped data above, and any league where you were the last linked user has its derivatives removed too. Our database provider (Neon) keeps standard short-term backups for disaster recovery; data you delete leaves those backups automatically as they age out — within 30 days at the longest.
8. Cookies
We use one session cookie to keep you signed in (HTTP-only, 30-day expiry). The app may use local browser storage for interface state. There are no analytics cookies, advertising cookies, or cross-site trackers.
9. Security
Honest summary rather than boilerplate: sign-in is delegated to Google (we store no passwords); data moves over TLS and rests encrypted under Neon’s managed service; access is scoped per user (you see only leagues you imported; your corrections are private to you); and the AI provider receives derived facts, not identities. We do not layer our own end-to-end encryption on top of the database. No internet service can promise perfect security — if we learn of a breach affecting your data, we will notify you as required by law.
10. Age Requirement
ReadOption is for adults. You must be 18 or older to use the Service (see the Terms), and we do not knowingly collect personal information from anyone under 18. If we learn we have, we will delete it.
11. Your Choices and Rights
- Import or don’t. Leagues are only analyzed because you imported them.
- Fix what’s wrong. Correct any profile — corrections stay private to you. Watchlist entries and corrections can be removed in-app.
- Ask us anything. Email privacy@readoption.football to access a copy of your data, correct it, or delete your account — whether or not a specific law entitles you to it, we honor reasonable requests. We aim to respond within 30 days.
We do not sell or share personal information for advertising, so there is nothing to opt out of on that front.
12. Visitors Outside the United States
ReadOption is directed to users in the United States, and data is processed and stored in the U.S. We don’t market the Service elsewhere, and we don’t claim to satisfy the formal machinery of non-U.S. privacy regimes (such as the GDPR) during this phase. If you use the Service from outside the U.S. anyway, the same promises in this policy apply to you, and you can make any data request through the contact below.
13. Changes to This Policy
When the product changes in a way that affects your data — new features, new providers, or (post-launch) payments — we update this policy before the change takes effect, bump the version date at the top, and, for material changes, ask you to accept the new version in-app before continuing.
14. Contact
privacy@readoption.football
PG Three Industries LLC
