Fantasy Agent Privacy Policy Back to Fantasy Agent

Privacy Policy

Last updated: September 24, 2026 · Effective: September 24, 2026

Scope and controller

This Privacy Policy explains how Niam LeStourgeon, doing business as Fantasy Agent ("Fantasy Agent," "we," "us," or "our"), collects, uses, discloses, and otherwise processes personal information when you use our websites, applications, emails, and related services (collectively, the "Service"). It does not govern information processed by third parties under their own privacy notices, including Sleeper and Stripe.

You can reach our privacy contact at legal@footballagent.tech.

Information we collect

Information you provide

Information from connected services and public league sources

When you ask us to use Sleeper or ESPN information, we retrieve and process the information that platform makes available to us for the selected account or league. For ESPN, we read leagues that the league manager has made viewable to the public; we do not ask for or store your ESPN password. If a user consents, we store ESPN sign-in cookies so that the service can use your private leagues. Depending on the league and the platform’s available data, this may include usernames, league membership, rosters, matchup and transaction activity, scoring settings, player selections, waiver and trade information, and publicly available league content. This information may concern other people in your league; use of the Service does not authorize you to provide us private information that you are not permitted to share.

Information collected automatically

We may collect device, browser, IP address, approximate location derived from IP address, pages viewed, interactions, timestamps, referring URLs, diagnostic logs, and similar usage information. Cloudflare, our security and content-delivery provider, may process request and browser information, including IP address, browser and device characteristics, request metadata, and security signals, to protect the Service from automated abuse, fraud, credential-stuffing attempts, malicious traffic, and other threats. Our Cloudflare client-side security tools may also monitor third-party scripts, browser connections, and cookies loaded on our pages for security risks. With your consent where required, Google Analytics may collect information through cookies or similar technologies. We do not knowingly use this information for targeted advertising or sell it for money.

How we use information

We use personal information to provide, secure, improve, and support the Service, including to:

We may create aggregated or de-identified information that no longer reasonably identifies you. We may use and disclose that information for lawful business purposes.

Where the GDPR, UK GDPR, or similar law applies, we process personal data to perform our contract with you; to comply with legal obligations; to pursue our legitimate interests in operating, securing, and improving the Service where those interests are not overridden by your rights; and, where required, with your consent. You may withdraw consent at any time, but doing so does not affect processing already performed lawfully before withdrawal.

How we share information

We may disclose personal information to the following categories of recipients, only as needed for the purposes above:

We do not sell personal information or share it for cross-context behavioral advertising as those terms are defined by applicable U.S. state privacy laws. If that practice changes, we will update this policy and provide any required notice or choice.

Cookies and analytics

We use strictly necessary technologies to operate the Service, such as technologies that maintain a session, protect against abuse, or remember a privacy choice. Cloudflare may use strictly necessary cookies or similar browser identifiers to distinguish automated traffic from legitimate visitors and to apply security protections. Where enabled and allowed by your consent, we use Google Analytics to understand aggregate use of our site. You can manage optional analytics through the Cookie settings link on our website and may also control cookies through your browser. Blocking cookies may affect some features or prevent security checks from completing.

Separately from Google Analytics, we keep our own basic measurement that uses no cookies and does not identify you. Each page view or action on the page is added to hourly totals along with the page address, a broad device type (mobile, tablet, or desktop), and the website that referred you. These totals are counted for every visitor, including visitors who decline analytics cookies, because they contain no identifiers, are never linked to your account, and cannot be traced back to an individual; where the GDPR or similar law applies, we rely on our legitimate interest in understanding whether the Service works and how people find it.

Our website also stores a single item in your browser's local storage, named fa_source, recording where you first arrived from, such as a directory listing or a search engine. Signing in uses a link sent to your email, so without it a sign-up finished after you return from your email would be credited to no source at all. It holds no identifier and nothing about you, only the name of the website or campaign you arrived from; it is readable only by our own site; and you can remove it at any time by clearing site data in your browser.

We honor legally required opt-out preference signals where applicable.

Unique visitor measurement

We count unique visitors to our website using a privacy-preserving method: we compute a daily rotating hash of your IP address and browser user-agent string. This hash cannot be reversed to identify you, is not linked to your account, and is discarded when the daily salt rotates. Like the totals described above, it is counted for every visitor rather than only those who allow analytics cookies, and we use it only to understand aggregate traffic patterns (for example, how many distinct people visited on a given day). We do not use it for profiling, advertising, or cross-site tracking.

Retention and security

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, including to provide the Service, comply with legal and accounting obligations, resolve disputes, and enforce agreements. The appropriate period depends on the type of information, your relationship with us, legal requirements, and our operational needs. We keep all logs, regardless of the content for 1 year, because we only collect data needed to make our service work as best we can. Inactivity after 1 year will result in us deleting all data associated with your account.

We use reasonable administrative, technical, and organizational safeguards designed to protect personal information. These measures include traffic filtering and bot-mitigation tools provided through Cloudflare, as well as client-side monitoring designed to identify potentially risky third-party scripts, connections, and cookies. No system or transmission is completely secure, however, and we cannot guarantee absolute security. You are responsible for maintaining the security of your email account and should promptly notify us of suspected unauthorized account use.

Your choices and privacy rights

Account, communications, and connected data

You may update certain account information, retake the GM philosophy questionnaire, change your email schedule, download your philosophy document, disconnect or stop using the Service, and unsubscribe from non-essential marketing communications through the link in those messages. We may still send transactional, billing, security, and other non-marketing communications. You can view and revoke trusted devices from your account settings at any time; revoking a device immediately invalidates its token and signs you out on that device. To request account deletion or deletion of connected league data, contact support@footballagent.tech. Deletion may be subject to lawful retention requirements and backup cycles.

Regional rights

Depending on where you live, you may have rights to request access, correction, deletion, portability, restriction, or objection to certain processing; to withdraw consent; and to appeal a privacy-rights decision. California residents may have rights to know, correct, delete, and limit certain uses of sensitive personal information. We do not discriminate against individuals for exercising applicable privacy rights.

To make a request, email support@footballagent.tech with "Privacy Request" in the subject line. We may need to verify your identity and authority before acting. An authorized agent may submit a request where permitted by law, subject to verification. If we deny an appealable request, you may appeal by replying to our decision with "Privacy Appeal." You may also complain to your local data-protection authority where applicable.

International transfers

We may process and store information in the United States and other countries that may have different data-protection laws than your country of residence. Where required, we use appropriate safeguards for restricted international transfers, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another valid transfer mechanism. You may request information about applicable safeguards at support@footballagent.tech.

Children’s privacy

The Service is not directed to children, and we do not knowingly collect personal information from children under the age at which parental consent is required under applicable law. If you believe a child has provided personal information to us, contact us so that we can investigate and take appropriate action.

Changes to this policy and contact

We may update this Privacy Policy from time to time. We will post the updated version here and revise the "Last updated" date. If a change materially affects your rights, we will provide additional notice when required by law. Your continued use of the Service after an update becomes effective is subject to the updated policy, to the extent permitted by law.

Questions or requests about this policy may be sent to Niam LeStourgeon, legal@footballagent.tech.

Internal aggregate operations reporting

When configured by the operator, a private dashboard called Jarvis receives aggregate product activity, service status, sanitized failure counts, and financial totals for internal operations. Exported records do not include customer names, contact details, document text, call recordings, message content, league identifiers, or generated report bodies. Existing analytics consent choices continue to apply.

Model accounting records provider, model, token counts when available, elapsed time, outcome, and estimated cost without prompts or responses. Detailed dashboard snapshots and sanitized events are retained for 30 days; daily aggregate history is retained for 13 months. The latest observation is retained while a connector is offline. Access is restricted to the owner. Where cloud hosting is enabled, these aggregates and encrypted backups are processed by AWS.

The owner can optionally discuss these aggregates with an OpenAI voice assistant. That assistant receives retrieved aggregates and the owner's conversation, and has no project-changing tools. Jarvis does not record raw audio or persist conversation transcripts unless the owner explicitly saves them. OpenAI processes voice, text, and tool results under its own data controls, including applicable abuse-monitoring retention; this is separate from Jarvis storage. Please avoid including customer content in an owner conversation.

Reporting update: September 16, 2026. Existing contact and rights-request procedures in this policy continue to apply.