Rosterline Policies

Privacy Policy

Effective: September 2026

This Privacy Policy explains how Rosterline handles information when you use its fantasy-sports editorial service. It is an early-stage policy for the 2026 Founding 100 beta and should be reviewed by legal counsel before broader launch.

01

Information you provide

When you create or access an account, you may provide an email address or use Google sign-in. Authentication is handled through Supabase Auth. Depending on the sign-in method, authentication records may include your email address, provider identity, and provider-supplied account metadata.

Rosterline's profile record is limited to your account identifier, optional display name and avatar URL, and record timestamps. Rosterline does not currently collect payment-card information.

02

Fantasy league information

The Sleeper username lookup requests your public Sleeper user identifier and 2026 NFL league list. That search is used to display results and is not saved as a Rosterline profile field.

When you save a league, Rosterline stores the Sleeper league identifier, league name, season, platform, the Rosterline account that saved it, and membership role. To display and prepare coverage, Rosterline may fetch public league settings, scoring rules, managers and display names, team names, rosters, players, standings, and records from Sleeper. Most source league detail is fetched when needed rather than copied into separate database tables, though facts reflected in a saved publication remain part of that publication.

03

Publications and generation records

Rosterline stores generated editions and immutable edition versions, including structured publication content. Operational records may include publication status, generation attempts, timing and lease state, sanitized failure codes, model and prompt versions, provider response identifiers, and token-usage counts.

Founding 100 records identify the eligible league, season, entitlement status, and founding position. These records support access and generation limits.

04

How information is used

Rosterline uses information to:

  • authenticate accounts and maintain sessions;
  • find, save, and display fantasy leagues;
  • generate, validate, store, and deliver editorial coverage;
  • manage beta eligibility, generation limits, and public sharing;
  • operate, secure, troubleshoot, and improve the service; and
  • enforce these policies and prevent misuse.

05

AI processing

Rosterline uses a third-party AI service, currently OpenAI, to generate some editorial fantasy-league coverage. The generation request includes normalized league facts needed for the edition, such as league identity and format, manager display identities, team and roster information, player information, and competitive records when available. Rosterline account email addresses are not included in the League Preview generation payload.

Information processed by service providers is subject to their applicable terms and privacy practices. Rosterline does not make broader promises here about provider retention or model training that are not established by the current implementation and applicable provider terms.

06

Service providers and third parties

Rosterline relies on providers that may process information to perform their services: Supabase for authentication and database services, Vercel for application hosting and delivery, OpenAI for AI-assisted generation, Google when you choose Google authentication, and Sleeper as the source of public fantasy-league data. Their handling of information is governed by their own terms and privacy practices.

07

Public sharing

League Previews are private and restricted to authorized league members by default. An authorized member may intentionally enable a public share link for a specific, immutable edition version. Anyone who possesses that link may be able to view and forward the shared edition while the link is active, without signing in.

Disabling a public link prevents further access through that URL, and that URL is not reused. Rosterline may retain the revoked link record to enforce revocation. Consider the publication's team names, manager display names, and editorial contents before enabling public access.

08

Cookies and technical information

Rosterline uses cookies and similar browser storage needed for Supabase authentication, session continuity, and security. Rosterline also uses Vercel Web Analytics to understand page visits and a limited set of product actions. Rosterline removes query strings and redacts dynamic league and public-share paths before analytics are sent. It does not include account, league, share-link, or generated-publication identifiers in custom event properties.

Vercel states that its Web Analytics does not use cookies and uses a daily rotating hash derived from request information to produce anonymous visit counts. Rosterline does not add advertising trackers, session replay, or persistent cross-service identity tracking. Hosting, authentication, and security providers may still receive ordinary technical information such as IP address, browser or device details, request information, timestamps, and diagnostic logs as part of operating their services.

09

Retention and security

Rosterline retains account, saved-league, entitlement, publication, and operational records for as long as reasonably needed to provide the beta, maintain stable published editions, enforce limits and revocations, address security or support issues, and meet applicable obligations. Retention periods have not yet been formalized for every record category.

Rosterline uses access controls, member-scoped database policies, server-only privileged operations, and other safeguards intended to protect information. No online service can promise absolute security.

10

Your choices

You may choose not to connect a league, sign out, stop using Rosterline, or disable a public share link you are authorized to manage. Rosterline does not yet provide a self-service account deletion or data-export interface. During the closed beta, account or data questions should be raised through the beta support channel.

11

Children

Rosterline is not intended for children under 13 and does not knowingly seek their personal information. The beta Terms require users to be at least 18. The relationship between these age statements should receive professional legal review before broader launch.

12

Changes and contact

Rosterline may update this policy as the service develops. The effective date above will be updated when a revised policy takes effect. Material changes may also be communicated through the service when appropriate.

During the closed beta, use the Rosterline support channel through which you received access. A dedicated public legal contact address will be published before broader launch.