SharperSunday Privacy Policy
SharperSunday LLC ("SharperSunday," "we," "us," or "our") operates the SharperSunday mobile application and related services available at sharpersunday.com (collectively, the "Service"). This Privacy Policy explains what information we collect, how we use it, who we share it with, and the rights you have over it.
By using the Service, you agree to the collection and use of information in accordance with this Policy. If you do not agree, do not use the Service.
1. Who we are
SharperSunday LLC is a limited liability company organized under the laws of the State of Maryland, United States. Our mailing address is 306 W Redwood St STE 201, Baltimore, MD 21201. You can reach us at [email protected].
2. Information we collect
We collect only the information needed to operate the Service. Categories of information we collect:
2.1 Information you provide directly
- Email address and account credentials — to create and authenticate your SharperSunday account, or when you contact support. We previously collected email addresses through a launch waitlist; that waitlist is closed and no longer accepts sign-ups. Any waitlist email still on file is deleted when you delete your account. You can sign up with an email address and password (your password is stored only as a secure hash by our authentication provider, Supabase) or with Sign in with Apple or Google sign-in (we receive your account email and basic profile information from Apple or Google — never your Apple or Google password).
- Name — if you use Sign in with Apple or Google sign-in, we receive and store the name on your Apple or Google account in your SharperSunday account. Apple shares your name only on your first sign-in and lets you edit or hide it before it reaches us. We use your name only to identify your account; we never link it to analytics or share it for advertising.
- Sleeper account identifier — your Sleeper username, user ID, and avatar, which you provide by connecting your Sleeper account inside the app.
- Promo and referral codes — when you redeem an invite or referral code, or when someone redeems a code generated by your account. We record the linkage between the redeeming account and the referring account so we can grant referral rewards.
- Support correspondence — anything you send us via email or in-app feedback, including any screenshots you choose to attach (stored privately and used only to diagnose the issue you report).
2.2 Information we collect from third parties on your behalf
When you connect your Sleeper account, we fetch the following from Sleeper's public API:
- League rosters, scoring settings, draft picks, and transaction history for the leagues you participate in
- Player data (statistics, ownership, trends) from public Sleeper endpoints
- League activity (waivers, trades, free agent moves) used to compute analytics like power rankings and league lore
We do not access your Sleeper password, payment information, or private messages.
When you connect an ESPN public league, we fetch its public league ID, league name and season, scoring and lineup settings, team names and records, and rosters from ESPN's public fantasy-football endpoints. We do not receive your ESPN password or access private ESPN leagues.
2.3 Information collected automatically
- Subscription status — managed by Apple App Store, Google Play, RevenueCat, and Stripe (for web subscriptions). We receive entitlement state but never see your full payment card details.
- Push notification token — a device-specific token used to deliver trial-expiry and referral-reward notifications. You can disable push notifications in your device settings at any time.
- Usage analytics — events such as app opens, paywall views, trial starts, subscription purchases, and feature use. We use this to understand which features are valuable and where users get stuck.
- Device information — operating system, app version, and similar context bundled with analytics events.
- IP address — our backend automatically receives the IP address you connect from when your device makes API requests. We use it for rate limiting, abuse prevention, and standard server logging. We do not use your IP address to derive your location in our analytics (GeoIP enrichment is disabled).
- Crash and error reports — when the app crashes or hits an error we record technical context (stack trace, OS version, app version) so we can diagnose and fix it. After you sign in, crash, error, and performance reports are linked to your account identifier so we can investigate problems you report.
2.4 Session replay (error recordings only)
To diagnose crashes and errors, we capture a masked session replay — a reconstruction ("screen recording") of the screens leading up to a problem. We do not continuously record your normal app usage.
- A replay is captured only when an error or crash occurs during your session, so we can see what led up to it. Error-free sessions are not recorded.
- Anything you type is masked — all text inputs are replaced with placeholders before the recording leaves your device. Images are masked the same way.
- Other content rendered on screen (for example, player names, rosters, and AI responses) may appear in these error recordings.
- These recordings are captured by Sentry and are linked to your account identifier so we can investigate problems you report.
- PostHog collects product-analytics events only and does not record your screen.
- We use recordings only for debugging and improving usability — never for advertising — and they are retained for a limited window (see §8), then deleted.
2.5 Information we do not collect
- Your physical address
- Your payment card number, expiration, or CVV — these go directly to Apple, Google, or Stripe (for web subscriptions), never to us
- Your Sleeper password
- Your contacts, photos, microphone, or camera content
- Sensitive personal data. We do not collect or process "sensitive personal information" as defined under the California Consumer Privacy Act, the Maryland Online Data Privacy Act, or analogous state privacy laws — including racial or ethnic origin, religious beliefs, health or biometric data, precise geolocation, sexual orientation, or government identifiers.
2.6 Cookies and similar technologies on our website
Our marketing website (sharpersunday.com, including www.sharpersunday.com and our blog) uses two first-party storage items so we can measure how the website itself is performing. No advertising, social-media, or other third-party tracking script runs on those pages.
- ss_landing_anon_id — a first-party cookie holding a randomly generated identifier and nothing else: no name, no email address, no account data. It is scoped to the sharpersunday.com domain so one visitor is not counted twice when they move between sharpersunday.com and www.sharpersunday.com, and it expires 400 days after it is last written. The same value is mirrored in your browser's local storage for that site.
- ss_utm_attribution — stored in your browser's local storage rather than as a cookie. It records the campaign tags on the link you first arrived from (for example the utm_source value) for about 30 days, so we can tell which channels bring people to the website.
These are website-only. The SharperSunday iOS and Android apps set no cookies and never read either value; both exist only in the browser you visit the website with. If you create an account in the web version of the app, it reads the saved campaign tags once, at sign-up, so we know which page brought you here.
How to clear them. Clearing cookies and site data for sharpersunday.com in your browser removes both immediately. To stop them from being set at all, block both cookies and site storage (some browsers call it "site data") for that site — blocking cookies alone is not enough, because the website falls back to your browser's local storage, so cookie-only blocking may leave this measurement active. Please note that the "Product analytics" toggle in the app (Settings → Privacy) switches off analytics inside the app only — it does not switch off this website measurement, because the website cannot tell which app account, if any, a visitor holds.
We do not use either value for advertising, and we do not sell or share it. The events these identifiers appear on are retained on the schedule in §8, and the rights in §9 apply to them.
3. How we use your information
We use the information we collect to:
- Provide AI-generated fantasy football advice tailored to your roster and league
- Authenticate your subscription and grant access to paid features
- Send transactional emails (for example, support replies and account notices)
- Send relevant push notifications you have not opted out of (such as trial expiry reminders and referral rewards)
- Respond to your support requests
- Improve the Service through aggregated and pseudonymous analytics (event data is linked to a stable user identifier, not your name)
- Diagnose and fix crashes, bugs, and performance issues (including review of masked session replays)
- Detect and prevent fraud, abuse, or violations of our Terms of Service
- Comply with legal obligations
We do not sell your personal information. We do not use your information to build advertising profiles for third parties.
4. AI processing of roster and league data
When you use AI features (chat, trade evaluator, league lore reports, win window advisor, etc.), the relevant context — your roster, league settings, and the question you asked — is sent to our AI provider, Anthropic, for processing. Anthropic processes the data to generate a response and, per their terms, does not use API content to train their models.
We never send Anthropic your email address, push token, payment information, or any data that personally identifies you outside the fantasy-football context.
5. Third-party service providers
We share information with the following third parties strictly to operate the Service. Each provider is listed with the category of data they receive and a link to their own privacy policy.
| Provider |
What they receive |
Purpose |
Their privacy policy |
| Sleeper |
Your Sleeper user ID (for read-only API access) |
Fetching public league/roster data |
https://sleeper.com/privacy |
| ESPN |
Public league ID; no ESPN account credentials |
Fetching public league settings, team records, and rosters |
https://privacy.thewaltdisneycompany.com/en/current-privacy-policy/ |
| Anthropic (Claude AI) |
Roster, league settings, your question text |
Generating AI responses |
https://www.anthropic.com/legal/privacy |
| Apple |
Subscription transaction state |
iOS in-app purchase processing |
https://www.apple.com/legal/privacy/ |
| Google |
Subscription transaction state; your Google account email and basic profile if you use Google sign-in |
Android in-app purchase processing; optional Google sign-in |
https://policies.google.com/privacy |
| RevenueCat |
Subscription state; your SharperSunday account identifier (a pseudonymous UUID) |
Cross-platform subscription management |
https://www.revenuecat.com/privacy |
| Stripe |
Payment card details (handled directly by Stripe — we never see card numbers), web subscription transaction state |
Payment processing for web subscriptions |
https://stripe.com/privacy |
| Vercel |
Server logs, IP addresses (for API requests) |
Hosting our backend |
https://vercel.com/legal/privacy-policy |
| Upstash |
Push tokens, trial timers, referral codes (keyed by your SharperSunday account identifier, a pseudonymous UUID) |
Server-side state storage |
https://upstash.com/trust/privacy.pdf |
| Expo |
Push notification tokens |
Push notification delivery |
https://expo.dev/privacy |
| Resend |
Email address (for transactional emails) |
Sending support replies and account notices |
https://resend.com/legal/privacy-policy |
| Supabase |
Account email, hashed password, account identifier; feedback screenshots you attach |
Account creation, authentication, and user-data storage (including feedback screenshots) |
https://supabase.com/privacy |
| PostHog |
Pseudonymous event data (linked to a stable user identifier) and device info. No screen recording. No IP-derived location (GeoIP disabled). |
Product analytics (see §2.4) |
https://posthog.com/privacy |
| Sentry (when enabled) |
Crash, error, and performance reports, plus a masked session replay captured only when an error occurs — linked to your account identifier after sign-in |
Crash, error, and performance monitoring (see §2.4) |
https://sentry.io/privacy/ |
We do not sell, rent, or trade your information with any other third party for their independent commercial purposes.
6. Legal basis for processing (EEA / UK users)
If you are in the European Economic Area or the United Kingdom, our legal bases for processing your personal information are:
- Contract — to provide the Service you signed up for
- Legitimate interests — to improve the Service, prevent abuse, and operate our business
- Consent — for push notifications and any optional analytics where consent is required by local law
- Legal obligation — when we are required by law to retain or disclose information
7. Data security
We use industry-standard technical and organizational measures to protect your information, including:
- HTTPS / TLS encryption for all data in transit
- Encrypted storage at rest by our cloud providers (Vercel, Upstash)
- Restricted access — only the SharperSunday team can access production data
- Secrets and API keys stored in environment variables, never in the app bundle
No system is perfectly secure. If we experience a data breach affecting your information, we will notify you as required by Maryland's Personal Information Protection Act (generally within 45 days of discovery) and any other applicable law.
8. Data retention
We retain your information only as long as we need it to provide the Service:
- Account credentials (email address, hashed password, and Supabase account identifier) — for as long as your account is active; permanently removed when you delete your account (see §10)
- Account data (Sleeper user ID, push token, subscription state, referral codes) — for as long as your account is active
- Billing-consent receipts (the exact subscription terms shown when you authorize web checkout) — up to 400 days to document what you agreed to, unless you delete your account sooner
- Analytics events — up to 24 months in PostHog before anonymization or deletion
- Session replay recordings (error recordings only, captured by Sentry) — retained for a limited window (currently up to 90 days), then automatically deleted
- Crash and error reports — up to 90 days
- Support correspondence — up to 24 months
- Account-deletion audit record — up to 90 days after deletion, so we can investigate "where did my data go?" inquiries without retaining your full data
- Operational backups — daily snapshots of limited server-side account state are kept in restricted-access storage for up to 30 days, then automatically deleted
9. Your rights
Depending on where you live, you may have the following rights regarding your personal information:
- Access — request a copy of the information we hold about you
- Correction — ask us to correct inaccurate information
- Deletion — ask us to delete your account and associated data
- Portability — request your data in a machine-readable format
- Objection — object to certain processing (such as analytics)
- Withdraw consent — for processing based on consent
To exercise any of these rights, email [email protected] from the address associated with your account. We will respond within 30 days.
9.1 California residents (CCPA / CPRA)
If you are a California resident, you have the right to:
- Know what personal information we have collected about you, the sources, and the purposes
- Request deletion of your personal information
- Opt out of the "sale" or "sharing" of your personal information — we do not sell or share personal information as defined by the CCPA
- Be free from discrimination for exercising your rights
9.2 EEA / UK residents (GDPR)
In addition to the rights above, you may lodge a complaint with your local data protection authority if you believe we have processed your information unlawfully.
9.3 Maryland residents (MODPA)
Under the Maryland Online Data Privacy Act, Maryland residents have the right to:
- Confirm whether we are processing your personal data and access that data
- Correct inaccuracies in your personal data
- Delete personal data we have collected or obtained about you
- Obtain a portable copy of your personal data
- Opt out of the processing of your personal data for purposes of (i) targeted advertising, (ii) the sale of personal data, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects
We do not sell personal data, do not engage in targeted advertising, and do not use profiling to make decisions that have legal or similarly significant effects. We also commit to data minimization — we collect only what we need to operate the Service.
To exercise any MODPA right, email [email protected] from the address tied to your account. We will respond within 45 days. If we decline your request, you have the right to appeal — instructions will be included in our response.
9.4 Other US state privacy laws
Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, New Hampshire, New Jersey, Minnesota, and Rhode Island (and any other state whose comprehensive consumer privacy law applies to us) have rights substantially similar to those described in §9.1 and §9.3. To exercise any of these rights, email [email protected] from the address tied to your account.
10. Account deletion
You can delete your SharperSunday account at any time:
- Open the app
- Tap your profile / menu
- Tap "Delete my account"
- Confirm
Deletion immediately wipes:
- Your account sign-in record (email address and hashed password), hard-deleted from our authentication provider
- Your Sleeper session
- Your push notification token
- Your trial timer and referral history
- Your in-app preferences
- Your in-app feedback submissions and any attached screenshots
- Billing-consent receipts stored by SharperSunday
A record that the account was deleted (and the date) is retained for up to 90 days for support and audit purposes, then permanently removed.
Limited server-state copies can remain in restricted-access operational backups for up to 30 days while those backups cycle out; those copies are used only for disaster recovery and then automatically deleted.
You can also delete your account from the web without signing in, at https://sharpersunday.com/delete-my-account. Enter the email address on your account and we will send you a one-time confirmation link; nothing is deleted until you click it.
Or email [email protected] from the address tied to your account. We will complete the deletion within 30 days.
Retained after deletion:
- Pages you chose to publish. A League Lore recap or a Team Grade you published lives at its own public link, is visible to anyone who has that link, shows the real Sleeper display names of the league's managers, and expires one year after publication. Deleting your account does not retract a page you already shared. Email [email protected] with the link and we will take that page down sooner.
- Billing and tax records where the law requires us to keep them, plus the deletion audit record and the operational backups described above.
- Product-analytics events, for the window in §8. They are not used to identify you after deletion.
Note: Deletion does not automatically refund or restore subscriptions. Web subscriptions are canceled automatically when you delete your account. Subscriptions purchased through Apple or Google must be canceled separately in your Apple ID or Google Play account settings.
11. Children's privacy
The Service is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If you are a parent or guardian and believe your child has provided information to us, please email [email protected] and we will delete it.
12. International users
The Service is operated from the United States. If you access the Service from outside the United States, your information will be transferred to, processed, and stored in the United States, where data protection laws may differ from those in your country. By using the Service, you consent to this transfer.
13. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will:
- Update the "Last updated" date at the top
- Post the new Policy at sharpersunday.com
- For material changes, notify you via in-app notice or email at least 14 days before the change takes effect
Your continued use of the Service after the effective date of an updated Policy constitutes acceptance of the updated terms.
14. Contact us
If you have any questions about this Privacy Policy or how we handle your information, contact us:
- Email: [email protected]
- Mail: SharperSunday LLC, 306 W Redwood St STE 201, Baltimore, MD 21201
SharperSunday LLC, organized under the laws of Maryland.
Last updated: 2026-09-18