Privacy Policy

Last updated August 31, 2026

DraftHQ is a fantasy draft and league management service operated from the United States. This policy explains what we collect, why we use it, who receives it, and the choices you have. It applies to DraftHQ websites and apps, including drafthq.net.

Information We Collect

Account information. We collect your email address, authentication identifiers, and account status. Passwords are handled by our authentication provider and are not stored by DraftHQ in readable form.

Profile and league information. We store the display name, avatar, nickname, bio, leagues, memberships, roles, invitations, teams, logos, owner photos, team names, short names, text-to-speech names, draft settings, draft order, picks, chat messages, and walk-up songs you or your commissioner add.

Imported fantasy league data. If a commissioner imports a league, we may retrieve team names, owner names, roster slots, draft settings, prior-season records, standings, and related league metadata from providers such as Sleeper, ESPN, or Yahoo. Imported owner names may describe people who have not created DraftHQ accounts.

Provider credentials and cookies. Private ESPN imports may require ESPN cookies that are sent to DraftHQ only to fetch that import preview. Yahoo imports use an OAuth flow and store Yahoo tokens in a short-lived, http-only browser cookie. Spotify playback tokens are stored in your browser local storage, not in DraftHQ database tables.

AI announcer information. If AI announcer features are enabled, we may process announcement text, draft event details, league names, team names, player names, text-to-speech names, selected voices, and related draft-room context to generate draft-night commentary or audio. Optional custom voice provider API keys may be sent with a request to generate or preview audio, but DraftHQ does not store those keys in database tables unless we clearly say so in the feature.

Technical and security data. We and our service providers may process IP addresses, device and browser information, request logs, authentication events, CAPTCHA signals, and error logs to keep the service reliable and secure.

We do not collect payment card information today, and we do not sell personal information or share it for cross-context behavioral advertising.

How We Use Information

We use information to create and secure accounts, run leagues and drafts, synchronize draft rooms in real time, import league setup data, send invitations and account emails, play or preview walk-up music, provide support, prevent abuse, diagnose errors, and improve DraftHQ.

Who Can See League Information

DraftHQ is built around shared league spaces. League members can see league names, member profiles, team identities, draft order, picks, chat messages, walk-up songs, and draft results for leagues they are part of. Commissioners can also see and manage invitations and owner assignments. People outside a league should not be able to view that league through DraftHQ.

Service Providers

We use vendors that process information for us only as needed to operate DraftHQ:

  • Supabase for database, authentication, storage, and realtime features.
  • Vercel for hosting and application delivery.
  • Cloudflare for DNS, security, and Turnstile bot protection.
  • Resend or another email provider for transactional email.
  • OpenAI and ElevenLabs when AI announcer features generate commentary or synthetic audio.
  • Spotify and YouTube when you search for, preview, or play walk-up music.
  • Sleeper, ESPN, and Yahoo when you choose to import or connect fantasy league data.

Provider Connections

Provider connections are optional. We use imported fantasy data to set up DraftHQ leagues and drafts, not to sell profiles or target ads. Disconnecting or deleting a league removes the active provider connection from DraftHQ, but it does not delete your account or data at the provider.

You can disconnect Spotify in DraftHQ by clearing the connection in the app or by removing DraftHQ access from your Spotify account. After disconnecting, DraftHQ will no longer request Spotify playback tokens from that browser unless you connect again.

AI Features

AI announcer features are optional draft presentation tools. When used, DraftHQ may send the minimum draft-room context needed to generate the requested script or audio to AI service providers such as OpenAI or ElevenLabs. Generated audio may be cached so the same announcement does not need to be regenerated.

AI-generated commentary is not the authoritative draft record. Draft settings, picks, owner assignments, and league records remain stored in DraftHQ and Supabase.

Cookies and Local Storage

DraftHQ uses cookies and browser storage for authentication, provider OAuth flows, bot protection, lobby audio preferences, and optional Spotify playback. We do not use advertising cookies.

How Long We Keep Information

We keep account information while your account exists. League and draft content is kept while the league exists because it is a shared record for league members. If you leave a league, your membership and owner assignment can be removed, but completed draft picks and league history may remain as part of the league record.

Pending invitations may be kept until accepted, revoked, expired, or deleted. Provider cookies and OAuth state are short-lived. Security logs are kept only as long as reasonably needed for abuse prevention, debugging, compliance, and reliability.

Your Choices

You can update profile and team information in the app, leave leagues where that option is available, revoke provider access through the provider, and request deletion of your DraftHQ account. Depending on where you live, you may also have rights to access, correct, delete, export, or object to certain uses of your personal information.

To make a privacy request, email privacy@drafthq.net.

Children

DraftHQ is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child provided personal information to DraftHQ, contact us and we will take appropriate steps to delete it.

Security

We use authentication, database-level access controls, storage rules, bot protection, and operational monitoring to protect DraftHQ. No online service can guarantee perfect security. If we learn of a security incident that requires notice, we will provide notice as required by applicable law.

Changes

We may update this policy as DraftHQ changes. If we make material changes, we will update the date above and provide additional notice when appropriate.

Contact

Privacy questions or requests: privacy@drafthq.net