Privacy Policy

Effective EFFECTIVE_DATE · Applies to the Draft Copilot web service at YOUR_DOMAIN and the Draft Copilot Chrome extension.

The short version

The Chrome extension

The extension does one job: it docks the Draft Copilot web app in a panel beside your draft room. Specifically:

The hosted service

Website analytics. Our marketing pages (the landing page, this policy, the install guide) use Vercel Web Analytics to count visits. It is cookieless: it records aggregate page views and rough device/region categories, sets no cookies, does not identify you, and does not follow you across other sites. It does not run inside the copilot app itself or the extension.

When you connect a draft, here is everything the service receives:

What Why
The draft URL or draft ID you paste in or connect To find your draft on the fantasy platform
The picks of that draft, fetched from the platform's public API To mirror the board and compute recommendations. This is the same public data anyone with the draft link can see.
Your chat messages to the assistant To answer them

Sessions are anonymous. When you start using the app we issue a random session token so your strategy settings and chat history follow you during the draft. It is not linked to an account, an email, or your identity — we don't have accounts and we don't collect email addresses.

Sessions expire. A session and everything attached to it — including its chat history — is deleted after SESSION_TTL_HOURS hours of inactivity. We do not keep chat archives.

Server logs. Like nearly every web service, our servers keep short-lived request logs: IP address, request path, and response status. We use them only to spot abuse and keep the service up, and they are deleted after LOG_RETENTION_DAYS days.

Yahoo Fantasy (beta)

Connecting a Yahoo draft uses Yahoo's standard OAuth flow:

Chat and language models

When the operator of a Draft Copilot deployment enables it, chat messages are processed by a third-party large-language-model API to generate answers. What gets sent is exactly two things:

The assistant never asks for personal information, and none is required to use it. Don't paste anything into the chat you wouldn't want processed by such an API. If LLM processing is not enabled on a deployment, chat messages stay within the service.

What we don't do

Changes to this policy

If this policy changes, the new version will be posted here with a new effective date. Since we have no way to contact you (by design), checking this page is the way to see updates.

Contact

Questions about any of this: CONTACT_EMAIL.