HuddleWatch
Privacy policy
Last updated September 7, 2026
The short version. We collect what we need to run your call sheet and nothing else. We do not sell your data, we do not run ads, and there are no analytics or tracking scripts anywhere on this site. Deleting your account erases everything we hold about you.
What we collect
What you give us when you sign up
- Your first and last name.
- Your email address, which is also how you sign in and how we reach you.
- Your password, which is stored only as a salted hash. We cannot read it, recover it, or tell you what it is.
- Your date of birth, only if you choose to add it in settings. It is optional and you can leave it blank.
What you give us when you connect a fantasy platform
HuddleWatch is only useful once it can read your leagues, so connecting a platform means handing us something that lets us act as you on that platform. This is the most sensitive thing we hold, so here is exactly what it is:
- ESPN. Two sign-in cookies from your browser, called espn_s2 and SWID. We never receive or ask for your ESPN password. These cookies let us read your leagues and, when you confirm a move, send it to ESPN.
- Yahoo. An access token and refresh token issued by Yahoo after you approve HuddleWatch on Yahoo's own sign-in page. We never see your Yahoo password.
- Sleeper. Only your public Sleeper username. Sleeper does not allow outside apps to make changes, so these leagues are read only.
- Public league links. If you link a league by its public URL, we store only the league id and which team is yours. No credentials are involved.
We use these credentials for one purpose: reading your leagues and making the changes you explicitly confirm. We never make a roster move you did not ask for. You can disconnect any platform at any time from the Leagues screen, which deletes the stored credential immediately.
What we pull from those platforms
Your leagues, teams, rosters, matchups, projections, scores, and the transactions you make through HuddleWatch. We also keep a snapshot of your lineup before each week's games begin so the optimization history can show honestly whether your lineup was set before kickoff.
Payment information
Payments run through Stripe. Your card number never reaches HuddleWatch and we could not store it if we wanted to. We keep only the fact that a season was paid for, and the identifier Stripe gives us for the transaction.
What we do not collect
No advertising identifiers, no third party analytics, no tracking pixels, no session recording, no cross site tracking, and no location data. There are no such scripts on this site. We do not buy data about you from anyone.
Cookies
HuddleWatch sets one cookie, called hw_session, which is what keeps you signed in. It is marked HttpOnly and Secure so it cannot be read by scripts, and it expires after 30 days or when you sign out. That is the only cookie we set, and we do not use it to follow you anywhere else.
Where it is stored
Account records live in Cloudflare's key value storage, and the site itself runs on Cloudflare's network. Access is restricted to the site's own code and to the account owner.
Who we share it with
We do not sell your personal information, and we do not share it for advertising. We do not disclose it to anyone except the following service providers, each of which only receives what it needs to do its job:
- Cloudflare, which hosts the site and stores account data.
- Stripe, which processes payments and receives your email address to attach to the transaction.
- Resend, which delivers our email, and therefore receives your email address and the contents of messages such as verification and password resets.
- The fantasy platforms you connect, which receive requests made on your behalf using the credential you gave us.
We may also disclose information if the law requires it, or where it is necessary to investigate fraud or protect someone's safety.
How long we keep it
Account data is kept for as long as your account exists. Cached league data expires on its own within 30 days. Sign-in sessions expire after 30 days. Records we are required to keep for tax or accounting reasons, such as the fact that a payment occurred, are retained as long as the law requires.
Deleting your account
Open Settings and choose to delete your account. This removes your profile, your password hash, every stored platform credential, your leagues, and your saved snapshots. It takes effect immediately and cannot be undone. If you would rather we did it for you, email us from the address on your account.
Your rights
Wherever you live, you can ask us what we hold about you, ask us to correct it, or ask us to delete it. Email us and we will respond. We will not charge you for it and we will not treat you differently for asking.
If you live in California, you additionally have the right to know what personal information we collect and how it is used, the right to request deletion, and the right to opt out of the sale or sharing of personal information. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, but the right to ask still stands.
Children
HuddleWatch is not intended for children under 13 and we do not knowingly collect information from them. If you believe a child has created an account, tell us and we will remove it.
Security
Passwords are hashed, never stored in readable form. Traffic is encrypted in transit. Session cookies cannot be read by page scripts. No system is perfect, and we will tell affected users promptly if we ever discover a breach involving personal data.
Changes
If we change this policy in a way that materially affects you, we will update the date at the top and email account holders. Continuing to use HuddleWatch after a change means you accept the updated policy.
Contact
Questions about privacy, or a request about your data, go to [email protected].