Privacy Policy
Last updated: July 1, 2026
This Privacy Policy explains how GridIQ (“GridIQ,” “we,” “us”) collects, uses, and shares information when you use our website and fantasy-football tools (the “Service”). GridIQ is an independent research and draft tool for Sleeper fantasy leagues. It is not affiliated with, endorsed by, or sponsored by Sleeper, the National Football League (NFL), or any team or player.
You can use most of GridIQ as a guest, without an account. Creating an account is optional and is only needed to sync your data across devices and to access paid features.
Information we collect
Information you provide
- Account information. If you create an account, we collect your email address and a password. Authentication is handled by our provider Supabase; your password is stored hashed and we never see it in plain text.
- Your content.The rankings, custom ranks, notes, tags, keeper settings, and preferences you create in GridIQ (collectively, your “Board”). When you are signed in, this is synced to our database so it follows you across devices. When you use GridIQ as a guest, it is stored only in your browser’s local storage on that device.
- Sleeper connection.When you connect a Sleeper account, you give us a Sleeper username. We then read publicly available Sleeper data for that username (leagues, rosters, drafts, matchups, and similar) through Sleeper’s public API. This data is already public on Sleeper; we do not receive your Sleeper password and cannot post to or change your Sleeper account.
- Feedback. If you send feedback through the in-app feedback button, we collect the message, the page you sent it from, any contact detail you choose to include, and basic technical details such as your browser type.
Information collected automatically
- Usage analytics. We use two analytics tools to understand which pages you visit, which features you use (through named events such as connecting a league or running an AI insight), and the general type of device you use. Vercel Web Analytics is cookieless and aggregated. PostHog (a product-analytics processor) may use cookies and browser storage to remember your session, and if you are signed in, its events are associated with your account identifier and email so we can understand how the product is used and fix problems. Neither tool is used to build advertising profiles, and we do not sell this data.
- Technical data. Like most web services, our servers process your IP address to deliver pages. To enforce usage limits and protect against abuse, we also store it briefly in rate-limit counters (typically for about a day).
Payment information
If you purchase a paid plan, payments are processed by Stripe. You enter your card details directly with Stripe; we never receive or store your full card number. We receive limited information such as your subscription status and a Stripe customer identifier so we can grant and manage your access.
How we use information
- Provide, maintain, and sync the Service and your Board across your devices.
- Generate AI insights you request (see “AI features” below).
- Enforce usage limits, secure the Service, and prevent abuse.
- Understand and improve how the Service is used.
- Respond to your feedback and support requests.
- Process payments and manage subscriptions.
AI features
Some features generate analysis using a third-party AI model provided by Anthropic (Claude). When you trigger an AI feature, the relevant context for that request — such as player, league, and matchup data and your prompt — is sent to Anthropic through our server to produce a response. Per Anthropic’s API terms, this content is not used to train their models. AI output is generated automatically, may be inaccurate or incomplete, and is provided for informational and entertainment purposes only — it is not professional, financial, or betting advice.
How we share information
We do not sell your personal information. We share information only with service providers that help us run GridIQ, and only as needed to provide the Service:
- Supabase — database and authentication.
- Anthropic — AI analysis.
- Stripe — payment processing (paid plans).
- Vercel — hosting and analytics.
- Upstash — rate limiting, abuse prevention, and storing submitted feedback.
- Sleeper — source of public fantasy data you choose to connect.
- Discord — delivery of feedback you submit, to our private channel.
We may also disclose information if required by law, to enforce our Terms, or to protect the rights, safety, and security of our users or the Service.
Cookies and local storage
When you sign in, Supabase sets a secure session cookie so you stay logged in. We use your browser’s local storage to save your Board and preferences (this is how guest mode works without an account). Our analytics are cookieless. We do not use third-party advertising cookies.
Data retention
We keep your account information and Board for as long as your account is active. Guest data stays in your browser until you clear it. You can ask us to delete your account and associated data at any time (see “Contact”).
Your choices and rights
- Use GridIQ as a guest without providing an account.
- Access and update your Board and preferences directly in the app.
- Sign out at any time; your data then stays on that device’s local storage.
- Request a copy or deletion of your account data by contacting us.
Depending on where you live, you may have additional rights over your personal information (such as access, correction, deletion, or portability). To exercise them, contact us using the details below.
Security
We protect your data with measures including encryption in transit and per-user database access controls (row-level security), so your account’s data is only accessible to you. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children
GridIQ is intended for adults (18 years or older) and is not directed to children. We do not knowingly collect personal information from anyone under 13. If you believe a child has provided us information, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy from time to time. When we do, we will revise the “Last updated” date above. Significant changes will be communicated through the Service.
Contact
Questions about this policy or your data? The fastest way to reach us is the Feedback button inside the app. See also our Terms of Service.