Privacy Policy

What we collect, who else touches it, how long we keep it, and how to get rid of it. Written to describe what the software actually does.

Effective August 31, 2026

1. Who this covers

Xqutive (“we”) runs the fantasy football decision engine at xqutive.app. This policy covers the website and the app behind sign-in. It does not cover Sleeper, ESPN, Yahoo, or any other league platform — those are separate services with their own policies, and connecting one does not put us inside it.

We do not serve the European Economic Area or the United Kingdom. Visitors from those countries get a notice instead of the site. The reason is section 6: our analytics include session recording, and running that lawfully there means asking consent before anything is set, which we have not built. We would rather not serve a region than serve it while quietly falling short of its rules. We intend to lift this, and when we do, this policy gains the sections that go with it.

2. What we collect

Account details. Your name and email address, and — if you sign in with Google — the identity Google returns to our authentication provider. We never see or store your password; sign-in is handled entirely by Clerk.

Your league. When you connect or set up a league we store its name, season, scoring settings, roster slots, and platform identifiers, plus your roster, your draft picks, and the recommendations we generate for you.

Other managers in your league. Making a useful call requires knowing what the rest of the league has. When you connect a league we store the other teams’ display names and rosters as your platform reports them. Those people are not our users and did not sign up with us. We use their data only to produce recommendations inside that league, we do not build profiles from it, and it is deleted along with the league.

Product analytics. In production we use PostHog to understand how the app is used. This includes session recordings — playback of pages you visit and actions you take in the app — and automatic capture of browser errors. Analytics do not run in development.

Diagnostics. When something breaks we record the error and the technical context around it, in PostHog and in Sentry. Error payloads are scrubbed before they leave your browser or our backend to strip values that look like secrets.

3. What we use it for

  • Generating draft, lineup, waiver, and trade recommendations, and the plain-English reasoning attached to them.
  • Keeping your league in sync with the platform it came from.
  • Answering you when you contact support.
  • Finding and fixing bugs, and understanding which parts of the product get used.

We do not sell your data, and we do not share it for advertising.

4. What the AI sees

The reasoning under each recommendation is written by Anthropic’s Claude models. What we send is the football situation and nothing else: player names, positions, projections, your roster composition, league scoring settings, pick numbers, and the matchup context for the decision at hand.

Your name, your email, your league’s name, and other managers’ names are not included in these requests. The model is asked to explain a roster, not to know whose it is.

5. Who else processes it

We run on other companies’ infrastructure. Each one receives only what it needs to do its job:

ServiceWhat it doesWhat it receives
ClerkAuthentication and account managementName, email, sign-in identity
ConvexApplication database and backendEverything in section 2 except analytics
VercelWebsite and app hostingRequests to the site, including IP address
AnthropicGenerates recommendation reasoningFootball context only — see section 4
PostHogProduct analytics, session recording, browser errorsUsage events, session recordings, error reports
SentryError monitoringError reports and technical context
Cloudflare R2Stores the nightly backupA copy of your account, league, roster and draft data

We also read from the league platform you connect — Sleeper today — which means sending it the identifiers needed to fetch your league.

6. Cookies and similar technologies

We use cookies and equivalent browser storage for exactly two purposes, and neither is advertising:

  • Keeping you signed in. Our authentication provider sets a session cookie. Without it there is no way to stay logged in between pages, so this one is not optional — blocking it means you cannot use the app.
  • Product analytics. PostHog stores an identifier in cookies and in your browser’s local storage so that separate page views can be recognized as one session. This is what section 2 describes, and it runs in production only.

We run no advertising cookies, no ad networks, and no cross-site tracking pixels. Nothing we set follows you to other websites, because we have no advertising business to follow you for.

You can switch the analytics off. Settings → Privacy has a “Share usage data” toggle that stops events and session recording in that browser straight away. It also stops browser error reports, since the same service carries them. The sign-in cookie stays either way — without it there is no way to keep you logged in.

You can also block or clear cookies in your browser, and a content blocker will stop the analytics ones. Because we do not sell or share personal information for advertising, a Do Not Track header or a Global Privacy Control signal has nothing here to switch off — there is no such sharing to begin with.

7. Other times we may disclose

Section 5 covers the companies that process data to make the product work. Three other situations are worth naming, because a policy that omits them is not describing reality:

  • When the law requires it. A subpoena, court order, or other legal demand we believe to be valid. Where we are legally permitted to tell you, we will, so that you have the chance to respond.
  • To protect people or stop abuse. To investigate suspected fraud or misuse, to enforce our terms, or where someone’s safety is at stake.
  • If the product changes hands. If Xqutive is acquired, merged, or its assets are sold, your data would transfer as part of that. The buyer would be bound by this policy until you are notified of a replacement, and we will tell account holders by email before any new policy takes effect — in time to delete your account first if you would rather not come along.

None of these is a sale. We do not sell personal information, and we do not share it for advertising.

8. How long we keep it

Your data stays while your account is open. Two specifics are worth stating plainly, because both are longer than “immediately”:

  • Deleting your account starts a 30-day window, not an instant erase. Your data is hidden from the app straight away and permanently destroyed after 30 days by a nightly job. The delay is deliberate — it is what makes an accidental deletion recoverable instead of final.
  • Backups. A nightly copy is written to encrypted storage and expires automatically after 30 days, so a backup can never outlive the deletion window above.

Analytics and error data held by PostHog and Sentry follow those services’ own retention schedules and are not covered by the 30-day window.

9. Your choices

  • Delete a league. Remove it in the app. Re-syncing the same league later restores it from the platform.
  • Delete your account. Use the delete option in Settings. See section 8 for what happens next.
  • Change your mind inside 30 days. Recovery is possible but not self-service: deleting your account also removes your sign-in, so you cannot reverse it yourself. Email us and, once we have confirmed it is you, we will restore your data to a new sign-in.
  • Ask what we hold, or ask us to correct it. Email us and, once we have confirmed it is you, we will answer.

How we check that it is you. Every one of these requests is a way to reach your data, so none of them runs on an email alone. Before we tell you what we hold, change it, or restore a deleted account, we confirm the request came from the account holder.

  • The request has to come from the email address on the account. An email that merely claims to be you is not enough.
  • We may ask you to confirm details only the account holder would know — which league you connected, roughly when you signed up — or to complete a confirmation step from inside the app.
  • Account recovery gets the closest look. Restoring a deleted account means attaching your data to a new sign-in, which is the single most damaging request someone could fake. We would rather make a real user prove it twice than hand a stranger a roster.
  • If we cannot satisfy ourselves that a request is genuine, we will refuse it and tell you why. We will not use the information you send us for verification for anything else, and we delete it once the request is closed.

10. California privacy rights

California’s privacy law applies to businesses above certain revenue and volume thresholds, and Xqutive is well below all of them. Rather than re-measure that every year and hand you a different answer each time, we extend the following rights to everyone who uses Xqutive, wherever you live.

  • Know. Ask what personal information we hold about you, where it came from, what we use it for, and who else receives it. Sections 2 through 7 answer that in general; on request we will answer it for your account specifically.
  • Delete. Delete your account from Settings, as described in sections 8 and 9.
  • Correct. Ask us to fix personal information that is wrong.
  • Take it with you. Request a machine-readable copy of the data you gave us and the data we generated for you.
  • Opt out of sale or sharing. There is nothing to opt out of. We do not sell personal information, and we do not share it for cross-context behavioral advertising. If that ever changes we will say so here and offer a real opt-out before it starts, not after.
  • No penalty for asking. Exercising any of these costs you nothing and changes nothing about the service you get. We run no financial-incentive programs tied to your data.

Email xqutive@gmail.com to make a request. We will acknowledge it within 10 days and answer within 45 days. If a request is genuinely complicated we may take up to another 45 days, and we will tell you why before the first 45 are up. Every request goes through the identity check in section 9 first.

You may use an authorized agent. We will need written proof that you authorized them, and we will still confirm the request with you directly before acting on it.

11. Security

Data is encrypted in transit and at rest by the services above. Sign-in is handled by a dedicated provider and we never store passwords. Access to production data is limited to the people running the service. No system is perfect, and we will not claim otherwise — section 12 is what happens when one of ours is not.

12. If there is a breach

If personal information is exposed by a security breach, we will tell the people affected, and that promise has a deadline attached: notice without unreasonable delay and no later than 30 days after we determine a breach has happened. We will notify regulators wherever the law requires it.

State breach-notification laws differ, and which one applies depends on where youlive rather than where we are. Rather than hand you a different answer depending on your state, we hold one deadline for everyone — and we picked a short one on purpose. Thirty days is tighter than any state deadline we are aware of, so this is a commitment rather than a restatement of the slowest thing we could get away with.

  • What the notice will say. What happened and when, which categories of your information were involved, what we have done about it, and what — if anything — you should do. If we do not yet know the full extent, we will tell you that rather than hold the notice back until we have a tidy answer.
  • A breach at one of our processors counts as a breach. Most of your data sits with the companies in section 5 rather than on machines we own, and the nightly backup described in section 8 is in scope too. If any of them is breached in a way that affects your data, you hear it from us — though we depend on them telling us first, which is a real limit on how quickly we can move and not one we can promise our way out of.
  • One thing a breach here cannot expose. We never store passwords — sign-in is handled entirely by Clerk, as section 11 says — so there is no password of yours for us to lose. If you sign in with Google, that password never reaches either of us.

Notice goes to the email address on your account, which is a reason to keep it current.

13. Children

Xqutive is for adults — section 3 of the Terms requires you to be 18. It is not directed to children or teenagers, and we do not knowingly collect information from anyone under 18, children under 13 very much included. If you believe a minor has created an account, email us and we will delete it.

14. Changes

If this policy changes in a way that materially affects you, we will update the effective date above and tell account holders by email before the change takes effect.

Questions about this document? Email xqutive@gmail.com.