Legal
Privacy Policy
Last updated August 28, 2026
This Privacy Policy explains what LeagueFrenzy — a product of Aspiretoachieve Studios LLC — collects, why, and what you can do about it. It covers the data we receive when you create an account, connect a fantasy-football league, and buy a Season Pass.
1. Information we collect
Account information
When you sign up we collect your email address and authentication details. Account sign-in is handled through Amazon Cognito; we do not store your password ourselves.
Launch list (waitlist)
If you join our launch list — for example from a marketing page or when downloading a free cheat sheet — we collect the email address you enter. No account is required. We store it so we can reach you about product launch and related updates. Joining is optional and separate from creating a LeagueFrenzy account.
If you ask us to email you a board from the free trial, we store the same email address plus which board you asked for, which league it was built from, and which fantasy platform that league is on. We use that to send you the link and to understand which leagues and platforms people try. You can have it erased at any time by leaving the launch list — see data deletion — and we delete that record automatically a year after the request in any case.
Support requests
When you contact us through the support form, we store the email address you give us, your name if you provide one, the category you pick, and the subject and message you write, so we can look into your request and reply. We also record the IP address the message came from and your browser’s user agent — we use these only to detect and block automated spam, not to profile you. Emailing us directly instead of using the form sends the same message content to the same inbox, without the IP and user-agent record.
League data from third-party platforms
When you connect a league, we ingest the league data made available by that third-party platform, including drafts, transactions, trades, waivers, rosters, standings, scoring settings, roster requirements, and related league configuration. Capture happens when you connect or refresh a league, plus a daily refresh of waiver activity for leagues you have already connected. We never crawl or enumerate leagues you have not connected. The platforms we actually connect are Sleeper, MyFantasyLeague, ESPN, Yahoo, and Fleaflicker — we are not affiliated with or endorsed by them. We use this data to build your league-adjusted rankings, boards, and projections.
How you use our tools
When you re-rank players, draw tiers, set lineup choices, make lists (do-not-draft / my-guys), or flag players, we store those ranking edits, tiers, lineup choices, lists, and flags so we can show them back to you. In aggregate and de-identified form we also use them to improve rankings and tools for all members.
Platform access tokens
For platforms that use OAuth or an equivalent authorization step, we store the access token that platform issues so we can sync your league on your behalf. These tokens are treated as credentials and are not shared with third parties except as needed to talk to the platform that issued them.
Payment information
Season Pass payments made on the web are processed by Stripe. Stripe handles your card details under its own privacy policy; we receive confirmation of the transaction and limited metadata, not your full card number.
If you subscribe inside the mobile app, Apple or Google processes the payment under their own privacy policies. We never see your payment details in that case either — we receive only a receipt confirming the subscription.
Product usage
While you are signed in, we keep a record of which parts of LeagueFrenzy your account uses — for example the draft board, the trade tools, or AI analysis — and on which days. We store this as a daily count per feature, not a log of individual actions: it tells us that your account used the board on a given day, not what you looked at, which players you viewed, or what you typed.
We use it to understand whether people come back and which features are worth continuing to build, and to answer support questions about your own account. This is our own record, kept on our servers and not shared with advertising or analytics vendors. Because it is part of running the service for a signed-in account rather than third-party analytics, it is recorded whether or not you accept the analytics cookies described in section 3 — those are a separate thing, and declining them still turns off everything section 3 covers.
Marketing attribution
To understand which campaigns bring people to LeagueFrenzy, when you first arrive we read any UTM parameters (utm_source, utm_medium, utm_campaign, utm_content, utm_term) from the page URL and your browser’s referrer. We keep this on a first-touch basis — the first visit that carries attribution wins and is never overwritten — and we reduce any referrer to its origin and path so query strings that might contain tokens are dropped.
This attribution is stored in your browser’s local storage (not in a cookie) under the key lf.attribution. When you connect a league, run a league check, or check out, we forward it to our own backend and include it as metadata on the Stripe checkout so we can attribute the connect, check or purchase to the campaign that referred you.
If you arrive by clicking one of our Google ads, that click also carries an advertising click id (gclid, or wbraid / gbraid on some Apple devices), which we read from the page URL in the same way. It is stored separately, in local storage under the key lf.click-id, and is sent with the same connect, league check and checkout requests. Unlike the UTM record above this one is last touch — a newer ad click replaces an older one, because it answers a different question (which ad you bought through, rather than which campaign first found you), so the two can legitimately disagree. It also expires: we discard it once it is older than 90 days, the window Google will accept it in. It identifies an ad click, not you, and we do not use it to build a profile.
Our server later sends that click id to Google Ads as an offline conversion, to report that an ad click led to a league being connected. This is how Google can tell us what a connect costs. What we upload is the click id itself, the time the connect happened, and the name of the conversion we are reporting: we do not send your name, email address, account id, or anything about your league or its rosters. Your browser still plays no part in this. It happens server to server, after the fact, whether or not you accepted cookies, because the click id was collected to measure our advertising and the upload is that measurement rather than a separate use of it.
2. How we use your information
- to provide the service — building and syncing your boards;
- in aggregate and de-identified form, to improve rankings, boards, and tools for all members;
- to process Season Pass purchases and support refunds;
- to contact you about product launch and related updates if you joined the launch list;
- to understand, on an aggregate basis, which marketing channels are effective; and
- to secure the service and respond to support requests.
3. Cookies, local storage, and analytics
We use your browser’s local storage for functional purposes that are always on: keeping you signed in, remembering your first-touch marketing attribution (described above), and recording your cookie-consent choice (stored under the key lf.cookie-consent), and — if you arrived from one of our Google ads — the advertising click id described above, under lf.click-id. That last one is read from the landing URL before the consent banner is answered, because it is only available on that first page load. It is stored in local storage, never in a cookie, and your browser never sends it to Google— the advertising tags do not read it. Our server does send it to Google Ads afterwards, as the offline conversion described above. Like the attribution record above, it is sent to our own backend when you connect a league, run a league check, or check out — whether or not you accept cookies — because it is how we tell which ad brought you, not something the advertising tags read. We do not sell advertising space on LeagueFrenzy. We do run advertising measurement cookies — described under Google Ads below — and only after you accept.
Analytics. We use Google Analytics 4 and Microsoft Clarity to understand how visitors use the site (pages viewed, general location, device and referral source) so we can improve it. If you are signed in, Microsoft Clarity also receives your account id so we can tell how the product is used by account rather than by anonymous session, and can find your own activity when you write to us about a problem. The account id we send is a pseudonymous identifier that only we can link back to you — it is not your email address, and neither tool receives your email address or your plan. Microsoft Clarity loads only after you accept — if you decline, or haven’t chosen, it never loads at all. Google Analytics works differently, and we would rather be exact about it than reassuring: the Google tag loads for every visitor, but until you accept it runs with advertising and analytics storage switched off. In that state it sets no cookie and cannot identify you or follow you between visits, but it does tell Google which pages you view and what you do on them — starting a checkout, filtering the rankings — along with the ordinary things any web request carries: your approximate location from your IP address, and your browser and device type. Google calls this Consent Mode; it lets them estimate totals without tracking individuals. Accepting turns storage on; declining leaves it off permanently. Google and Microsoft act as our service providers and process this data on our behalf. You can change your mind at any time by clearing the lf.cookie-consent value in your browser’s storage.
Google Ads. We advertise LeagueFrenzy on Google Search, and we measure which ads actually lead to a purchase so we are not paying for advertising that does not work. When you buy a Season Pass, we report the sale to Google Ads — the amount, the currency, and the order id, so the same purchase is not counted twice. We do not send your name, email address or card details. We do not run remarketing or retargeting campaigns, and we switch off Google’s advertising-personalisation signal outright — before you accept and after. Our Google Ads account does contain a remarketing audience that the advertising tag would otherwise add visitors to, and which no campaign currently targets; with that signal off, accepting does not put you in it. Accepting does set Google’s _gcl_* cookies on our own domain, which exist to link an ad click to a later purchase. The Google Ads tag rides on the same Google tag described above, so it too is present from the first page load with storage switched off. We would rather be exact here too: if you decline, we set no cookie and nothing ties the purchase to you or to an ad click — but the sale is still reported to Google, with the amount, the currency and the order id, so that declined purchases are counted in totals only. Note that clearing lf.cookie-consent stops us loading these tags again, but it does not delete _gcl_* cookies already set on this domain, or the lf.click-id value — clear your site data for leaguefrenzy.com to remove those.
Session recordings and heatmaps. Microsoft Clarity additionally records how pages are interacted with — where you click and scroll, and where a page appears to frustrate people — and replays it as a session recording. If you are signed in, that recording carries the pseudonymous account id described above, so that when you report a problem we can look at what actually happened on your screen instead of guessing. Fields that carry personal information are masked in our own code — your password, your email address wherever you enter one, the support form, and the ESPN cookies on the connect screen are excluded from recording, and that exclusion is written into the site itself rather than left to a setting we could change later. Fields that carry no personal information — a league URL, a player search — may be recorded, because seeing what people type there is how we find out why a step is not working. Card details are never in scope at all: they are entered inside Stripe’s own frame, which we cannot read. Clarity is subject to the same consent gate as the rest of this section, and Microsoft documents its own data handling.
4. How we share information
We do not sell your personal information. We share it only with service providers that make the product work, each acting on our behalf: Amazon Web Services and Amazon Cognito (hosting and authentication), Stripe (payments), Google Analytics, Google Ads and Microsoft Clarity (usage analytics, advertising measurement, session recordings and heatmaps, only if you accept cookies), Sentry / Functional Software, Inc. (error and performance monitoring), and the third-party fantasy platform you choose to connect. Player statistics may be sourced from third-party data providers. We may also disclose information if required by law or to protect our rights and users.
5. Data retention
We keep account information, league configuration, and platform tokens for as long as your account is active or as needed to provide the service, and then for a reasonable period afterward as required for legal, accounting, or security purposes. You can ask us to delete your account data.
Your ranking edits, tiers, lineup choices, lists, and flags are tied to your account. We keep them while the account is active, and they are deleted when you delete the account.
Records that belong to a league rather than to you — the drafts, transactions, trades, waivers, rosters, and standings we read from a league you connected — are kept while that league is connected by any member, so they can outlive any one account. They are deleted with the league when it is removed. Once no account still holds the league and nobody has opened it for 30 days, we delete its waiver history.
De-identified aggregates already computed from that data are retained. They cannot be unwound to a person and are not deleted when you delete your account.
The product usage record described above is tied to your account and is deleted with it — when the account goes, so does its usage history, in the same operation.
Support requests are kept while we work on them and afterward as a record of the request and its resolution — for example to honour a deletion request or to handle a billing dispute. You can ask us to delete a support request once it is resolved.
If you leave the launch list, we keep a record of that opt-out — the email address and the date you left — so we can honour it and not add the address back from a later signup or an imported list. We use that record only to stop contacting you, never to email you or to build a profile. If you would rather we erase the address altogether, ask us and we will.
If you asked us to email you a board from the free trial, we keep the record of that request — the email address, the board, the league, and the platform — for up to one year, and then delete it. Leaving the launch list erases those records immediately, and a request from an address that has already left creates no new record. The opt-out itself is kept, as described above, so we can keep honouring it.
6. Your choices and rights
You can delete your account and its data yourself at any time from your account settings, or follow the account & data deletion instructions. Deleting the account erases the identifiable harvest rows tied to your account. It does not unwind aggregates already computed.
If you joined the launch list without an account, you can leave it anytime using the self-serve form on the data deletion page, or via the support form.
You can also request access to, correction of, or deletion of your personal data using the support form. You can disconnect a connected league at any time, and you can clear the locally stored attribution and consent values by clearing your browser’s site data. Depending on where you live, you may have additional rights under applicable privacy law.
7. Security
We use industry-standard measures to protect your information, including encrypted transport and access controls around stored tokens. No method of transmission or storage is perfectly secure, so we cannot guarantee absolute security.
8. Children
LeagueFrenzy is not directed to children under 13, and we do not knowingly collect personal information from them.
9. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be reflected in the “Last updated” date above and, where appropriate, accompanied by additional notice.
10. Contact
Questions about your privacy? Use our support form. See also our Terms of Service and Refund Policy.
This page is a drafted template grounded in how LeagueFrenzy handles your data. It is not legal advice and has not yet been reviewed by counsel.