Skip to main content

Legal

Privacy Policy

Effective

This Privacy Policy describes what information FF Beacon, operated by Michael Walsh ("we", "us"), collects when you visit the site, why we collect it, who we share it with, and the choices you have. We collect the minimum needed to make the product work.

The short version: most of FF Beacon works without an account and without you telling us anything. We do not sell your data, we do not use advertising cookies, and we never see your card number. Questions or requests go to michael@ffbeacon.com.

1. Information we collect

Account information

When you sign in we receive a unique identifier and email address from the authentication provider you choose (currently Google or Discord; an email-link option may also be available). We do not receive or store your password.

Profile information

With your consent we may receive your display name and avatar from the OAuth provider. From Google: name, email, profile picture (scopes openid email profile). From Discord: username, avatar, and the email associated with your Discord account (scopes identify email). We do not access your Google Drive, Gmail, calendar, contacts, or any Discord server or message content.

Preferences and product data

We store the choices you make inside the product: your default fantasy format, default data source, theme, optional Sleeper username (for league sync), favorite players, custom rankings order, vote history on matchups and in the games, and email digest opt-in.

Content you post

If you claim a Signal profile we store its handle, display name, avatar, and anything you post to it, including uploaded images (held in Supabase Storage). A Signal profile is public: its contents can be read by anyone and indexed by search engines. We also store questions you send through the guide and contact forms, along with any name or email address you choose to include with them.

Sleeper league data

When you enter a Sleeper username, we pull and cache the public data Sleeper exposes for those leagues: league metadata, rosters, matchups, transactions, drafts, traded picks, and the display names of users within those leagues. This data is already public on Sleeper and remains visible to other members of the same league inside our product. Note that entering someone else's Sleeper username in a tool causes us to fetch their public league data too; only do that where it is appropriate.

Assistant questions

When you ask BEAM a question, we log the question so we can see what the assistant could not answer and improve it. The text is scrubbed of things that look like contact details or long digit strings before it is stored, and it is linked to your account only if you were signed in. BEAM answers from our own data with our own code; your question is not sent to an external language model provider.

Donations

Donations are processed by Stripe, PayPal, or Venmo. Your card number, wallet token, and bank details go to that processor and never to us. We do not store any payment instrument. If you were signed in we pass Stripe your email address so it can prefill its own form.

When a donation through Stripe completes, Stripe notifies our server and we send you a receipt by email. To do that we keep one record per donation containing the amount, the Stripe identifiers for the payment, which page the donation started from, and whether the receipt was sent. That record deliberately does not include your email address, your name, your billing address, or anything about your card. Your email address is read from Stripe's notification, used to address the receipt, and then discarded. Stripe keeps the full record of the payment, including your details, under its own policy, and the same is true of PayPal and Venmo if you use those instead.

Cookies and similar storage

We use first-party cookies and similar browser storage to keep you signed in (Supabase auth cookies), to remember your format and source preferences across visits, to hold a guest identifier so a game can tell whether you have already voted, and to cache transient interface state.

We do not use third-party advertising cookies and we do not build cross-site profiles. If advertising is ever introduced on the site, this page will say what it collects before it starts. You can clear our cookies at any time from your browser settings; clearing them signs you out and resets your preferences.

Technical and abuse-prevention data

Our hosting provider (Vercel) automatically logs basic request information, including IP address, user agent, request path, and response status, for security and operational troubleshooting.

Some public endpoints are rate limited so one visitor cannot exhaust them. Where you are signed in, the limit is counted against your account identifier. Where you are not, we count it against a salted one-way hash of your IP address. We store the hash, not the address, and the hash cannot be reversed back to an IP.

Analytics

We use Vercel Analytics to count page views and see which pages are used. It sets no cookie and builds no profile of you across sites or visits.

Discord polls

If you vote on one of our polls in Discord, we record your Discord user identifier against that poll so that one person is counted once. We do not publish who voted, and we do not link Discord poll votes to your FF Beacon account.

2. Why we collect it, and our legal basis

  • To authenticate you and keep you signed in. Basis: performance of a contract with you.
  • To save the preferences that personalize the product. Basis: performance of a contract.
  • To power features that need league data (League Pulse, Power Pulse, the power-rankings table, the trade analyzer, Manager Pulse, the transaction feed). Basis: performance of a contract.
  • To pass a donation you choose to make to the payment processor that handles it. Basis: your consent, given by choosing to donate. A donation is a gift rather than a purchase, so there is no contract here to perform.
  • To prevent abuse, rate-limit expensive endpoints, and keep the service available. Basis: our legitimate interest in a service that stays up.
  • To understand which pages are used, in aggregate. Basis: our legitimate interest in improving the product.
  • To send email digests, if and only if you explicitly opted in. Basis: your consent, which you can withdraw at any time.

3. Who we share it with

We do not sell, rent, or trade your personal information, and we do not share it for cross-context behavioral advertising. The list below is every third party involved in running the product, and they are not all the same kind of party. Some process data on our instructions. Some are independent of us and decide for themselves what they do with what you give them. Some receive nothing about you at all. Each entry says which:

  • Supabase, managed PostgreSQL, authentication, and file storage. Processes on our instructions. Stores your account, preferences, posted content, and synced league data.
  • Vercel, hosting, edge network, and the cookie-free analytics described above.
  • Stripe, card and digital wallet payments for donations. Stripe acts as an independent controller of the payment data you give it directly, not on our instructions, and uses it for payment processing and fraud prevention under its own policy.
  • PayPal and Venmo, only if you choose one of those donation buttons. You leave our site to complete the payment on theirs, and they receive whatever their own flow collects.
  • Resend, transactional and digest email delivery, including donation receipts. Processes on our instructions, and receives the recipient address and the message.
  • Google and Discord, only when you choose to sign in with one of them. They receive the fact that you authenticated against the FF Beacon app; we receive the profile fields listed above. Discord additionally receives poll interactions you make in our server.
  • Anthropic, whose language models help draft parts of the Beacon Brief and some analytical commentary from public NFL news and our own data. No personal information about you is sent to it.
  • Sleeper, KeepTradeCut, FantasyCalc, DynastyProcess, odds providers, and GIPHY. We read from their public interfaces from our own servers. We do not send them anything about you, your browser does not contact them directly for this content, and they do not know who is browsing our site.

We may disclose information if compelled by lawful process, or where necessary to protect the rights, property, or safety of FF Beacon, our users, or the public. If the Service is ever transferred to a new owner, account data may transfer with it, and we will say so on this page before it takes effect.

4. Where your data is processed

FF Beacon is operated from the United States and our providers process data in the United States and, for edge delivery, in other regions. If you are in the European Economic Area, the United Kingdom, or Switzerland, this means your information is transferred outside your home country. Our providers rely on the European Commission's Standard Contractual Clauses or an equivalent transfer mechanism for those transfers.

5. Google API Services User Data Policy

FF Beacon's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (opens in a new tab), including the Limited Use requirements. We use the data we receive solely to authenticate you and to populate your profile (name, email, avatar). We do not transfer this data to third parties for any purpose other than the providers named above, do not use it for advertising, do not use it to train machine learning models, and do not allow humans to read it unless we have your explicit consent or it is necessary for security or to comply with applicable law.

6. How long we keep it

  • Account and preference data: while your account is active, and deleted when you ask us to delete the account.
  • Public Signal profile content: until you delete it or the account, allowing for backup copies to age out.
  • Synced public Sleeper league data: while the league remains in use, or until you request removal of the leagues you brought in.
  • Donation records: kept indefinitely as a financial record, but they identify nobody. A row holds an amount, Stripe's identifiers, and whether we managed to email a receipt. It contains no name, no email address, and no payment details.
  • The payment itself, including your name, email address, and billing details, lives with the payment processor for as long as its own legal obligations require. We can neither delete nor amend that copy on your behalf; to have it removed you would need to ask the processor directly.
  • Rate-limit hashes: short-lived, and expire with their window.
  • Hosting request logs: retained by our hosting provider on a rolling short-term basis, typically 30 days.

7. Your rights and choices

Whoever and wherever you are, you can:

  • View and change your preferences (format, source, Sleeper username, theme, email opt-in) from your dashboard.
  • Disconnect Sleeper sync by clearing your Sleeper username.
  • Delete your Signal profile and anything posted to it.
  • Unsubscribe from the email digest using the link in any message it sends.
  • Request a copy of the personal data we hold about you, ask us to correct it, or ask us to delete your account, by emailing michael@ffbeacon.com. We will respond within 30 days and will not charge you or treat you differently for asking.
  • Revoke OAuth access to FF Beacon from your Google account settings or your Discord authorized-apps page at any time.

If you are in the EEA, the UK, or Switzerland, you also have the rights to object to processing based on legitimate interests, to restrict processing, to data portability, to withdraw consent at any time without affecting prior processing, and to complain to your local supervisory authority.

If you are in California, you have the rights to know, delete, and correct, and the right to opt out of sale or sharing. We do not sell or share personal information as those terms are defined by the CCPA, and we have not done so in the preceding twelve months. We do not knowingly sell or share the personal information of anyone under 16. Because there is no sale or sharing to opt out of, we do not operate an opt-out mechanism and we do not currently act on the Global Privacy Control browser signal; there is nothing for it to switch off. If that ever changes, this page changes with it.

8. Security

We protect data with HTTPS in transit, encryption at rest via Supabase, row-level security so an account can only read and write its own records, server-side authorization checks on the endpoints that change data, hashed identifiers in the abuse-prevention ledger, and rate limits on public and admin endpoints. Card data never reaches our servers at all.

No system is perfectly secure. Use a strong, unique passphrase on whichever provider you sign in with, and turn on its two-factor authentication. If we become aware of a breach affecting your personal data, we will notify you and any required regulator without undue delay. If you think you have found a vulnerability, email michael@ffbeacon.com rather than posting it publicly.

9. Children

FF Beacon is not directed to children under 13 and we do not knowingly collect personal information from them. If you are a parent or guardian and believe a child has given us personal data, email michael@ffbeacon.com and we will delete it.

10. Changes to this Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Effective" date at the top of this page. Material changes will be highlighted on the homepage or through an in-app notice before they take effect.

11. Contact

Questions, requests, or complaints go to michael@ffbeacon.com. You can also reach us through the contact form on the About page. The data controller is Michael Walsh, operating FF Beacon in the United States.