Privacy Policy
Introduction
Signals Fantasy ("Signals," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, retain, and safeguard information about you when you use our website at SignalsFantasy.com, our fantasy football application, and our Signals Draft Overlay browser extension (collectively, the "Service"). It also explains the choices and rights that may be available to you under applicable law. This Privacy Policy does not govern the privacy practices of third-party fantasy platforms, payment processors, analytics providers, or other third parties except as described here. If you do not agree with these practices, please do not access or use the Service.
1. Information We Collect
We collect several categories of information in connection with your use of our Service:
a. Account Information When you register for an account or communicate with us about your account, we may collect: - Name and display username - Email address - Authentication credentials (e.g., one-time passcodes delivered to your registered email or phone number, or session tokens issued at login). Signals does not store persistent passwords. - Profile preferences and notification settings
b. Fantasy League & Roster Data To provide our core features, we access and process fantasy football data through third-party platforms you connect to Signals, including: - League configurations, rosters, and standings from Sleeper, ESPN, MyFantasyLeague (MFL), Yahoo, CBS Sports, and other connected platforms - Platform connection credentials used to link private leagues (e.g., ESPN browser session cookies, an MFL session credential, or a league-scoped CBS API token; MFL and CBS passwords are used once to establish a session or mint a league token and are not stored). You may provide these credentials by entering them yourself, or — for ESPN and CBS only, and only if you install our browser extension and grant it permission — by having the extension read your own ESPN session cookies, or the API token CBS writes into your own league page, at your request and pass them to your Signals account. See Section 4 (Browser Extension) for details. - Draft history, trade history, and waiver activity associated with your leagues We access this data only with your authorization and use it solely to provide and improve the Service.
c. Payment & Billing Information If you subscribe to a paid plan, we collect billing and transaction information reasonably necessary to process your payment, manage your subscription, calculate taxes where applicable, prevent fraud, and maintain related records. Payment transactions are handled by a PCI-DSS-compliant third-party payment processor (for example, Stripe). We do not store your full payment card number or CVV on our servers. We may retain limited payment-related details such as billing name, billing address, billing ZIP or postal code, payment status, card brand, the last four digits of your payment method, and subscription history.
d. Usage Analytics & Cookies We and our service providers automatically collect certain information when you use the Service, including: - Log data: IP address, browser type, operating system, referring URLs, pages viewed, and time spent - Device information: hardware model, unique device identifiers - Cookies and similar technologies used for authentication, security, preferences, analytics, and, if enabled, advertising or campaign measurement
We use Google Ads conversion measurement to understand which advertisements lead to account sign-ups and purchases. When you sign up or make a purchase, we send Google a securely hashed (irreversible) form of your email address. We send it whether or not you arrived from one of our advertisements; Google uses it only to match that conversion to an earlier ad interaction where one exists. Your plaintext email address is not shared with advertising partners for this purpose.
You may control cookies through your browser settings. Disabling certain cookies may affect the availability or functionality of the Service. If our use of cookies or similar technologies ever triggers an opt-out right for targeted advertising, sale, or sharing under applicable law, we will provide the required notice and opt-out method, including honoring browser-based signals such as Global Privacy Control where required.
2. How We Use Your Information
We use the information we collect for the following purposes: - To create and manage your account and provide the core features of the Service - To process transactions and manage your paid subscription - To personalize your experience, including league-aware rankings and recommendations - To analyze usage trends and improve the performance, reliability, and features of the Service - To send you transactional emails (account confirmation, password reset, subscription receipts) - To send you product updates, newsletters, or promotional content, where you have opted in - To detect, investigate, and prevent fraudulent or unauthorized use of the Service - To comply with applicable laws and legal obligations - To train, evaluate, or improve AI models and features used within the Service, using aggregated or de-identified data where possible. We will not use your personally identifiable fantasy data or account information to train AI models without your separate consent - To produce aggregated, de-identified, or anonymized analytics and research insights that cannot reasonably be used to identify you
3. How We Share Your Information
We do not sell personal information for monetary consideration. We may disclose personal information in the following circumstances, and if our use of analytics, advertising, or similar technologies ever constitutes a "sale," "sharing," or targeted advertising under applicable law, we will provide any required notice and opt-out rights:
a. Service Providers We engage trusted third-party vendors to assist in operating the Service (e.g., cloud hosting, analytics, payment processing, email delivery). These providers are contractually obligated to use your data only as directed by us and in accordance with this Privacy Policy.
b. Third-Party Fantasy Platforms When you connect a third-party platform (such as Sleeper, ESPN, MFL, Yahoo, or CBS Sports) to Signals, data is exchanged with that platform pursuant to their terms of service and your authorization. We are not responsible for the privacy practices of third-party platforms.
We do not sell, rent, or disclose platform session credentials — including ESPN espn_s2 and SWID cookies and CBS league API tokens — to any third party, and we do not use them for advertising, analytics, or AI model training. They are sent only to the platform that issued them, and only to carry out the actions you authorized.
c. Legal Requirements We may disclose your information if required to do so by law, regulation, court order, or governmental authority, or if we believe in good faith that such disclosure is necessary to protect the rights, safety, or property of Signals, our users, or the public.
d. Business Transfers In the event of a merger, acquisition, sale of assets, or bankruptcy, your information may be transferred to a successor entity. We will notify you via email or prominent notice on the Service before your information becomes subject to a different Privacy Policy.
e. Aggregated and De-identified Data We may use and share aggregated, de-identified, or anonymized information derived from your use of the Service that cannot reasonably be used to identify you. We may use such data for any lawful business purpose, including product analytics, industry research, benchmarking, and improving the Service.
4. Browser Extension (Signals Draft Overlay)
We publish a browser extension called Signals Draft Overlay. Installing it is optional and it is not required to use the Service. The extension displays your Signals draft board inside supported fantasy draft rooms (Sleeper, ESPN, and CBS Sports) and marks players as taken during a live draft. Your draft board, your interface preferences, and the draft picks it observes in a draft room you have open are held in local browser storage on your device; the extension does not upload them to us.
How it learns which players are taken differs by platform, and in every case it reads only the draft room you already have open: on Sleeper it reads Sleeper's public, unauthenticated draft API; on ESPN it reads the draft state the ESPN page already holds in memory; on CBS it reads the league API token that CBS itself writes into your league page and calls CBS's own draft endpoints with it. It does not read any other page, tab, or site.
The extension includes two optional features that handle credentials, described here in full:
a. ESPN Cookie Connection (optional, off by default) ESPN publishes no OAuth or login API, and reading your private ESPN leagues requires two of your own ESPN session cookies: espn_s2 and SWID. The espn_s2 cookie is marked HttpOnly, which means no website script can read it and only a browser extension can. If you choose to use this feature, the extension reads exactly those two cookies — espn_s2 and SWID, each requested by exact name — and no other cookie or browsing data.
b. How the read is authorized The read is user-initiated and permission-gated at every step. The extension asks for the browser permissions it needs (access to cookies, scoped to espn.com) only after you click "Connect my ESPN leagues" in the extension popup, having first read the notice displayed above that button; your browser then presents its own permission prompt, which you may decline. Clicking that button also opens a single-use window of two minutes. Outside that window, or if the request does not come from the Signals web app running in your own browser, the extension refuses to read the cookies.
c. Where the values go On a successful read, the extension hands the two values to the Signals web app open in your browser, which transmits them over an encrypted (HTTPS) connection to your own signed-in Signals account, and nowhere else. This is the same destination as the manual copy-and-paste method the Service has always offered; the extension only saves you the copying. We use the values to read your ESPN leagues on your behalf. Because Signals keeps your leagues current in the background, this reading also happens on a recurring schedule while you are not signed in, for as long as the credentials remain stored and valid. If you turn on Auto Lineups — an optional feature on paid plans — we also use the credentials to submit the specific lineup change you confirm in the app; apart from that, we make no changes to your ESPN account, and we never post, chat, trade, or add or drop players on your behalf. They are stored in your Signals account server-side under access controls, are not returned to your browser, and are not sold, shared with, or disclosed to any third party. The extension itself never writes the values to its own storage, never caches them, and never logs them.
d. CBS League Token Connection (optional, off by default) CBS Sports publishes no OAuth or login API, and reading your private CBS league requires a league-scoped CBS API token. CBS writes that token into the HTML of your own league page when you are signed in. If you choose to use this feature, the extension fetches your own CBS league page — and, to list the leagues you belong to, the "My Teams" page on cbssports.com — using the CBS session already in your browser, and takes from the response only the league API token and the league's name. It reads no cookie, no password, and no other page or browsing data, and it needs no cookie permission to do so.
The read is user-initiated and permission-gated at every step, in the same way as the ESPN feature above. The extension asks for the browser permissions it needs (access to your CBS league pages on football.cbssports.com, and to cbssports.com) only after you click "Connect my CBS league" in the extension popup, having first read the notice displayed above that button; your browser then presents its own permission prompt, which you may decline. Clicking that button also opens a single-use window of two minutes. Outside that window, or if the request does not come from the Signals web app running in your own browser, the extension refuses to read.
On a successful read, the extension hands the league token to the Signals web app open in your browser, which transmits it over an encrypted (HTTPS) connection to your own signed-in Signals account, and nowhere else. We use it to read that CBS league on your behalf. Because Signals keeps your leagues current in the background, this reading also happens on a recurring schedule while you are not signed in, for as long as the token remains stored and valid. We make no changes to your CBS account: we never post, chat, trade, set lineups, or add or drop players on your behalf. The token is stored in your Signals account server-side under access controls, is not returned to your browser, and is not sold, shared with, or disclosed to any third party. The extension itself never writes it to its own storage, never caches it, and never logs it.
Separately, and only while you have a CBS draft room open, the extension reads that same token from the draft-room page and uses it to ask CBS which players have been drafted, so it can mark them taken on your board. That use stays entirely on your device and involves no permission prompt, because displaying your board in the CBS draft room is the extension's core purpose and it already runs there.
You can also connect a CBS league without installing the extension, by entering your CBS email and password in the Signals app. In that case we use them once, server-side, to complete CBS's own sign-in and obtain the same league token. We store the league token; we do not store your CBS password.
e. Revoking access You can revoke the extension's ESPN or CBS access at any time by opening the extension popup and clicking "Disconnect ESPN access" or "Disconnect CBS access," or by removing the permission from your browser's extension settings, or by uninstalling the extension. Revoking stops any further reads. To delete ESPN cookies or CBS league tokens already saved to your Signals account, open Settings, go to Leagues, and click "Disconnect" on that account — this deletes the stored values immediately. Deleting your Signals account deletes them automatically as well, as part of that process. You can also email support@signalsfantasy.com.
f. No analytics, no tracking, no remote code The extension contains no analytics, advertising, telemetry, or third-party tracking code, and loads no code from outside its published package.
5. Data Retention
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy, including to maintain your account, provide subscriptions and integrations, keep required business, tax, and accounting records, resolve disputes, enforce our agreements, and prevent fraud or abuse. Retention periods vary based on the type of data and our legal obligations. When we no longer need personal information, we will delete it, deidentify it, or securely anonymize it unless applicable law requires longer retention.
Platform session credentials, such as ESPN cookies, are a special case. We keep them until you disconnect the integration, replace them, or delete your Signals account, so that your leagues can keep syncing in the meantime. We do not impose a fixed expiry of our own, which means a credential that has stopped working at the platform stays stored until one of those things happens. Deleting your Signals account deletes your stored ESPN credentials automatically, as part of that deletion — you do not need to disconnect first. Disconnecting or deleting your account removes the credential from our live systems right away; routine encrypted backups may retain a copy for a limited period before they age out.
6. Security
We implement industry-standard technical and organizational measures to protect your information against unauthorized access, disclosure, alteration, or destruction. These measures include encrypted data transmission (HTTPS/TLS), encryption at rest for data held on our infrastructure, and access controls. Because Signals uses passwordless sign-in, there is no password of yours for us to store or lose.
Platform session credentials, such as your ESPN cookies, receive specific handling: they are held server-side under access controls that do not permit them to be read back by any browser, including your own, and are used only by the Signals systems that carry out the features you enabled. However, no method of transmission or storage is 100% secure. You are responsible for maintaining the confidentiality of your account credentials.
In the event of a security incident that we reasonably believe has resulted in unauthorized access to or disclosure of your personal information, we will notify you as required by applicable law. Such notice may be provided by email to your registered address, by prominent notice on the Service, or by such other means as required by law. We will also make any mandatory reports to applicable regulatory authorities. You can help protect your account by promptly notifying us at support@signalsfantasy.com if you suspect any unauthorized activity.
7. Your Rights & Choices
Depending on where you live, you may have privacy rights under applicable law, which can include the following: - Know/Access: Request confirmation of whether we process your personal information and request access to the categories of personal information we hold about you - Correction: Request that we correct inaccurate personal information, taking into account the nature of the information and the purposes of processing - Deletion: Request deletion of personal information we collected from you or obtained about you, subject to legal exceptions - Portability: Request that we provide a portable copy of certain personal information in a structured, commonly used, and machine-readable format where required by law - Opt-out: Unsubscribe from marketing emails at any time and, where applicable, opt out of targeted advertising, the sale or sharing of personal information, or certain profiling activities
To exercise privacy rights, contact us at support@signalsfantasy.com or use any privacy-request tools we make available within the Service. We may take reasonable steps to verify your identity before responding. We will respond within the time required by applicable law.
Do Not Track. Our Service does not currently respond to browser Do Not Track (DNT) signals. If we change this practice in the future, we will update this Privacy Policy accordingly.
8. Children's Privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13 without any consent required by applicable law. If we learn that we collected personal information from a child under 13 in a manner that requires parental consent and did not obtain it, we will delete that information. If you believe that a child under 13 has provided us personal information, please contact us at support@signalsfantasy.com.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, or legal requirements. We will notify you of material changes by posting the updated policy on our website with a new effective date, and where appropriate, by sending an email notification. Your continued use of the Service after any changes constitutes your acceptance of the updated policy.
10. Contact Us
If you have questions or concerns about this Privacy Policy, our data practices, or a privacy request, please contact us at:
Signals Fantasy Intelligence Email: support@signalsfantasy.com Website: SignalsFantasy.com