League Ledger ("we", "us") helps you aggregate your fantasy football leagues across platforms into a single portfolio view. This document describes what we collect, what we store, and what we do not.
What we collect
To sync your leagues, you provide the following in the iPhone app. The website only displays data you have already synced; it does not collect league credentials.
- Sleeper — your public username.
- ESPN — in the iPhone app, you sign in to ESPN inside an in-app web view and the app captures your team page URL plus the
SWIDandESPN_S2cookies ESPN sets. The app never asks for or receives your ESPN password. - Fleaflicker — your account email (used as a public lookup; Fleaflicker does not require a password for league reads).
- MyFantasyLeague — your league ID and team name (we match you to your franchise by name).
- Yahoo (planned; not yet available) — when Yahoo support launches, you will approve read-only access in Yahoo's secure OAuth window. We never see your Yahoo password.
- Account email + password — for your League Ledger account itself, managed by Supabase Auth and stored encrypted at rest.
Where credentials live
ESPN session cookies are kept in two places, and one of them is our server. On iOS they are held in the iOS Keychain, encrypted at rest, scoped to the app, and erased when you sign out. In addition, while Keep my leagues fresh when the app is closed is on in Settings — it is on by default — your SWID and ESPN_S2 pair is sent to us and held as a single AES-256-GCM encrypted envelope in a server-only table, so a scheduled job can refresh your leagues while the app is shut. The encryption key never leaves our server, and your own account cannot read the envelope: the only columns your account may read are whether the connection needs re-authorising and when it was last used. Turn that setting off, sign out, or delete your account and the stored copy is removed.
The website does not collect league credentials. Adding leagues, syncing, reconnecting and manual leagues all happen in the iPhone app. When the app imports a league it sends your SWID and ESPN_S2 to our Supabase Edge Function with the import request. The function uses them strictly as an ESPN Cookie: header for that read. With background refresh off, the ESPN_S2 session secret is discarded after the request and the app asks you to sign in again when ESPN expires it; with it on, the same encrypted envelope described above is stored so scheduled refreshes can run without you.
The identifiers needed to refresh each platform are also stored while background refresh is on. That means your Sleeper username, your Fleaflicker account email, your MyFantasyLeague and Fantrax league ids and team names, and your ESPN league and team ids. They are what a scheduled job needs to ask each platform for your leagues without you present. They are deleted when you turn the setting off, sign out, or delete your account. Older ESPN league records may still carry a plain SWID identifier written by versions before September 2026; it is not usable to sign in on its own and is deleted with those leagues.
When an iOS sync runs, the app forwards its Keychain credentials to the same Edge Function. Credentials are used only to read your league from the source platform and are dropped from function memory after the read.
Yahoo OAuth tokens are handled differently. Yahoo access and refresh tokens are AES-256-GCM encrypted in a server-only database table, cryptographically bound to your League Ledger user ID, and decrypted only inside our Edge Function for read-only sync and token refresh. The Yahoo client secret and encryption key are stored as deployment secrets and never enter the web or iOS app. Client accounts have no database access to the token table.
Sign out from iOS Settings to wipe credentials held in iOS Keychain. The website does not collect or retain ESPN_S2 values. Use Disconnect Yahoo in Settings to delete the encrypted Yahoo token envelope. Deleting your League Ledger account also deletes it automatically.
What we DO store on our servers
We store the following data:
- Your leagues, weekly rosters, team names, scores, and matchup history.
- Cross-league derived data — player weights, rooting board calculations.
- Your account email + Supabase auth row.
- Purchase transaction identifiers and subscription status, used to grant Premium access. We do not receive payment card details.
- The encrypted ESPN session-cookie envelope and the platform identifiers described above, while background refresh is on.
- For Yahoo, the encrypted OAuth token envelope described above.
- Application error and crash reports, linked to your account ID so we can investigate problems you report. They contain the error message, app version, and device model identifier (like "iPhone17,1") — never your credentials or league financial details — are used only for debugging, and are deleted with your account.
- If you allow notifications: an APNs device token + a stable per-install device ID, used only to send you a single notification when one of your leagues enters a live game window. The token is deactivated when you turn the toggle off or sign out, deleted when you delete your account, and automatically purged server-side if the device hasn't checked in for 180 days.
All user data is scoped by your user ID through Supabase Row-Level Security policies. You cannot read anyone else's data; nobody else can read yours.
Purchases
Apple processes League Ledger Premium purchases through your Apple ID account. We receive transaction identifiers and subscription status to grant access to Premium. We do not receive your payment card details. Apple's privacy practices apply to payment processing.
Third parties
We do not sell, share, or rent your data. We do not run third-party analytics SDKs that fingerprint you. The platforms we sync from (Sleeper, ESPN, Yahoo, Fleaflicker, MFL) see the requests our edge function makes on your behalf — those go through their own privacy practices.
Hosting: Supabase (database + auth) and Vercel (web companion). Crash reporting: Sentry, when configured. Apple TestFlight + App Store handle iOS distribution and the standard Apple privacy disclosures apply there.
Children
League Ledger is not directed at children under 13. We do not knowingly collect data from anyone under 13.
Your rights
You can:
- Delete any league in the iPhone app (soft delete; row is marked inactive).
- Sign out on iOS — wipes credentials held in iOS Keychain. The website does not collect or retain
ESPN_S2values. - Disconnect Yahoo — permanently deletes the encrypted Yahoo OAuth token envelope from League Ledger.
- Turn off Keep my leagues fresh when the app is closed in Settings — removes the encrypted ESPN cookie envelope and the stored platform identifiers from our server. Your leagues then refresh only while you have the app open.
- Delete your account entirely from inside the app: Settings → Delete Account → confirm. This immediately and permanently removes every row keyed to your account (leagues, rosters, matchups, push tokens, error logs, profile, auth row) and signs you out. No email exchange or wait period — it happens in the tap.
- Export your data first if you want a copy: Settings → Export My Data returns a JSON file with every league, roster, and matchup row we hold for you.
- If anything blocks an in-app deletion, email support@leagueledger.co and we'll handle it manually within 7 days.
Changes to this policy
If we make material changes, the new policy will be posted here and dated above. Continued use of the app constitutes acceptance.