Privacy Policy

Last updated: July 11, 2026

Information We Collect

When you create an account, we store your email address, display name, profile fields, and access entitlement. If checkout is available and you choose a paid plan, payment processing is handled by Stripe; ScrimmageLab does not receive your full card number.

Our application and hosting layers may create routine security and reliability logs, such as an IP address, request path, timestamp, response status, and user agent.

How We Use Your Data

We use account data to authenticate you, apply your access level, save the profile fields you submit, operate the service, and respond to support or security issues. We do not sell your personal information.

League Data

The current import tools retrieve or parse a roster and match player names to ScrimmageLab player records for a one-session review. The current import endpoints return that match result but do not save it to your ScrimmageLab account or feed it into other tools.

When you choose a provider lookup, the identifier needed for that request—such as a league ID, username, email address, or ESPN access cookies—is sent to the selected fantasy provider. Private ESPN cookies are sent in the request body, not in the URL. Manual roster text is parsed by ScrimmageLab and is not sent to a fantasy provider.

Browser Storage

The current website stores authentication tokens and device-local preferences such as theme and scoring format in your browser's local storage. The current import forms keep their result and any provider credentials in page state; they are not intentionally added to local storage by those forms.

When you use Draft Monkeys sign-in or account linking, your browser submits the email and password directly to Draft Monkeys' authentication provider. ScrimmageLab's backend receives the resulting token, not the password, and stores the linked Draft Monkeys user identifier. A first Draft Monkeys sign-in creates a reserved, non-routable local identity and may store the provider display name. The unverified provider email is used only to detect whether an existing native account must be linked; it is not stored as the new local account's email identity.

AI Assistant Questions

ScrimmageChat's optional web-research mode is disabled unless the deployment explicitly enables it. When enabled, the question you submit is transferred to a separately hosted Hermes agent machine over an encrypted administrative connection. That agent may send the question to its configured AI and web-search services to prepare an answer and source links. Do not include passwords, access cookies, payment information, or private league data in an assistant question.

ScrimmageLab does not intentionally write assistant question text to application logs. The current integration uses temporary files on the application and agent machines and attempts to delete them after each request; cleanup is best-effort. External AI, search, and source websites may process requests under their own terms and retention practices.

Data Security

Production traffic uses HTTPS/TLS in transit, and access to account data is limited by application authentication and authorization controls. No internet service can guarantee absolute security.

Your Choices

You can clear device-local data using your browser controls. To request deletion of your ScrimmageLab account data, email the privacy address below; automated account deletion is not currently available in the website.

Contact

If you have questions about this privacy policy, contact us at [email protected].