Daily Fantasy Resource
Privacy
Last changed September 25, 2026
The short version
Daily Fantasy Resource stores your account, the things you make with it (picks, lineups, alert rules, saved views, shared links), and one row per page load so that we can see which pages are worth keeping. We do not sell any of it, we do not run advertising trackers, and we do not share it with anyone except the three processors named below.
Your account
Stored: your email address; your name and profile-image URL if you signed in with Google; a password hash if you set a password (pbkdf2 — we cannot read your password); your role and plan; your preferences (sports followed, default site, time zone, theme, email opt-ins); the time you completed onboarding; session and magic-link tokens.
Why: to let you sign in, to remember your settings, and to send the emails you asked for.
How long: until you delete your account. Session tokens expire; magic-link tokens are single-use and short-lived.
What you make
Stored: picks recorded to your ledger; lineup sets and their entries; alert rules and the alerts that fired; saved control-bar views; shared read-only tables you created (these are public to anyone with the link and expire on their own); your own scoring systems; contest standings and ownership files you upload.
Why: it is the product. Your picks are graded so that your ledger means something; your alert rules are evaluated so that alerts can fire.
How long: until you delete them, or your account. Shared tables expire without being deleted by hand.
Usage
Stored: one row per HTML page load by a signed-in account and one per CSV export — the account, the kind, the path and the time. Separately, and with no account attached, the server records how long a page took to render and counts loads per route so that slow and dead pages can be found.
Why: to know which of the site's pages are actually used, which is the only honest basis for removing the ones that are not, and to catch a page that has become slow.
How long: usage rows are pruned after 90 days; performance samples after 7.
What we do not do
No advertising networks, no third-party analytics scripts, no tracking pixels, no cookies beyond the session cookie that keeps you signed in and the one that remembers your theme. Nothing is sold, rented or shared for marketing. We do not attempt to identify visitors who are not signed in.
The site loads a web font from Google Fonts, which means Google's font server sees the request. That is the only third-party request a page makes.
Processors
Fly.io hosts the application and the database (United States).
Stripe processes payments if you subscribe. Stripe receives your email address and handles your card; we store only a customer id, a subscription id and a status.
An email provider delivers sign-in links, alerts and the weekly grid email, and therefore sees your email address and the contents of those emails.
Your choices
Every email we send that is not a sign-in link has a one-click unsubscribe link, and the same switches are on your Settings page. Turning them all off is fine; the account keeps working.
To see, correct, export or delete what we hold, write to contact@dailyfantasyresource.com. Deleting your account removes your rows; it does not retroactively remove a shared table someone else has already copied.
This site is not for anyone under 18.
Changes
If this page changes materially we will say so on the site rather than quietly re-dating it.