Privacy Policy
Last updated: 2026-07-19
This Privacy Policy explains how DFS Degen (“DFS Degen,” “we,” “us”) collects, uses, and shares personal information when you use dfsdegen.com and related services (the “Service”). We collect the minimum data needed to operate the Service and describe below exactly how it is used, who receives it, and how you can control it. By using the Service you agree to the practices described here.
1.Who we are
DFS Degen is operated by DFS Degen, with a registered address at Linden, MI, 48451, USA. For the purposes of the EU and UK General Data Protection Regulation (“GDPR”), we are the “controller” of personal data processed through the Service. For privacy questions or data-rights requests, contact privacy@dfsdegen.com.
2.What we collect
We collect three categories of data:
(a) Information you give us.
- Account data — email address, password (stored as a salted bcrypt hash; never the plaintext), and optional display name.
- Subscription preferences — the sports you selected for your tier and when you last changed the selection.
- Uploads — projection CSVs you upload for use within your own account.
- Support correspondence — emails you send to us and our replies.
(b) Information generated by your use.
- Simulation history — the slates, models, iteration counts, and constraints you ran, plus the resulting lineups. Used to power the “Recent simulations” view and a shared-cache optimization that returns instant results for identical requests.
- Lineup edits and shares — manual swaps you make after a sim; lineup-share tokens are generated client-side and do not require us to store the lineup contents.
- Operational logs — request IDs, IP addresses, user agents, route paths, response codes, error traces, and request durations. Used for debugging, abuse prevention, and rate-limiting.
- Product analytics — pages viewed, features used, buttons clicked, approximate location derived from IP, device and browser type, and referring site. Before you consent this is anonymous and stored only in memory for the duration of the tab; if you choose “Accept all” it is linked to your account and we additionally record replays of your sessions. Section 6 sets out exactly what is captured, what is masked, and how to turn it off.
(c) Information from third parties.
- Stripe — when you subscribe, Stripe sends us a customer ID, subscription status, plan identifier, and billing-event metadata (charge success, failure, refund, cancellation). We never receive or store your full payment-card number, CVC, or bank credentials; those live with Stripe. Stripe’s own privacy policy applies to data you provide them directly through the checkout.
3.Why we use it (and the legal basis)
Under GDPR we rely on the following legal bases:
- Performance of a contract. To create your account, run the simulations you request, deliver CSV exports, charge subscription fees through Stripe, and provide customer support.
- Legitimate interests. To prevent fraud and abuse, secure our infrastructure, debug errors via logs, improve the Service through aggregate analytics, enforce rate limits and tier rules, and defend legal claims. We balance these interests against your rights and freedoms and do not use them where your interests override ours.
- Legal obligation. To respond to lawful requests from public authorities, comply with tax and accounting law, and meet other regulatory obligations applicable to us.
- Consent. Where required by local law (for example, non-essential cookies or marketing email). You may withdraw consent at any time without affecting the lawfulness of processing carried out before withdrawal.
4.Who we share it with
We do not sell personal information and we do not “share” it for cross-context behavioral advertising, as those terms are defined under the CCPA/CPRA. We disclose data only to vendors that help us operate the Service, and only to the extent each vendor needs:
- Stripe, Inc. — payment processing, subscription management, and the customer portal. Stripe receives your email and billing details directly through their checkout under their own privacy policy.
- Infrastructure hosting — the application and its Postgres database run on infrastructure managed by us through Coolify. The underlying servers are provided by our infrastructure vendor and are located in data centers in the United States. Backups are encrypted in transit to our offsite object-storage provider, which encrypts them at rest on its servers.
- Email delivery — transactional email (verification, password reset, billing notifications) is sent via Resend (Resend, Inc.). Resend processes recipient email addresses and message content solely to deliver the message.
- Error monitoring — when enabled by the operator, error traces and request metadata are sent to Sentry (Functional Software, Inc.) for debugging. Personal data in error payloads is minimized and, where possible, scrubbed before transmission.
- Product analytics and session replay — with your consent, usage events, page views, and session recordings are sent to PostHog, Inc. (United States) so we can understand how the Service is used and fix what does not work. If you are signed in, PostHog receives your email address, account identifier, subscription tier, and selected sports so that recordings and events can be linked to your account for support. PostHog acts as our processor and does not use this data for its own purposes or for advertising. See section 6 for what is recorded, what is masked, and how to withdraw consent.
- Legal — we may disclose data when required by law, court order, or valid government request, or where we have a good-faith belief that disclosure is necessary to protect our or others’ rights, property, or safety.
- Corporate transactions — if we are acquired, merged, or reorganized, your data may transfer to the acquiring entity, subject to this Policy or a successor policy with equivalent protections. We will notify you of any material change of controller.
Each vendor is contractually required to protect your data, process it only on our documented instructions, and apply appropriate technical and organizational safeguards.
5.International data transfers
The Service is operated from the United States. If you access the Service from outside the United States, the personal data you provide will be transferred to, stored, and processed in the United States (or any other country where our vendors operate).
For transfers of personal data out of the European Economic Area, the United Kingdom, or Switzerland, we rely on the European Commission’s Standard Contractual Clauses (as supplemented by the UK Addendum and the Swiss adequacy regime where applicable), together with supplementary technical measures (encryption in transit and at rest, minimized log retention, and access controls). A copy of the applicable transfer mechanism is available on request from privacy@dfsdegen.com.
6.Cookies, analytics, and session replay
We do not use third-party advertising cookies or cross-site tracking pixels, and we never sell your data. We do use a small number of essential browser-storage mechanisms, plus — only with your consent — product analytics and session replay.
Essential storage (no consent required). These are strictly necessary to deliver the Service; without them it does not function.
- Authentication. A JWT session token is stored in browser
localStorageto keep you signed in between visits. - Theme preference. Your light/dark selection is stored in
localStorageso the UI does not flash the wrong theme on load. - Simulation history cache. Recent simulation results may be cached client-side so the “Recent simulations” view loads instantly. Capped at 30 entries and never transmitted to us.
- Your consent choice. We store the choice you make in the consent banner so we do not have to ask again.
Analytics and session replay (consent required). When you choose “Accept all”, we enable PostHog product analytics and session replay.
- Before you consent, nothing is stored on your device. We measure page views and feature usage using an anonymous identifier held only in memory, which is discarded when you close the tab. No cookies are set and nothing is written to
localStorage. Session replay is off. - After you consent, PostHog sets a first-party cookie and a
localStorageentry so your activity can be recognised across visits, and session replay begins. - What session replay records. A reconstruction of the pages you saw and how you interacted with them — clicks, scrolling, and navigation. It is not video and it does not use your camera or microphone.
- What is always masked or excluded. The contents of every form input — including passwords, email fields, and payment details — are masked before the recording leaves your browser, so we never see what you typed. Network request and response bodies are never recorded. Administrative pages are excluded from recording entirely. Security-sensitive values that appear in a web address, such as a password-reset token or a shared-lineup payload, are stripped before any event is transmitted.
- Where it goes. PostHog processes this data on servers in the United States under our instructions, as described in section 4, with the transfer safeguards in section 5.
Changing your mind. You can withdraw or grant consent at any time from Account settings. Withdrawing consent stops session replay immediately, deletes the analytics identifier stored on your device, and returns us to anonymous, storage-free measurement. It does not affect the lawfulness of processing carried out beforehand. You can also clear all locally stored data by signing out or clearing your browser’s site data for dfsdegen.com, and you may ask us to delete previously collected analytics data using the contact details in section 16.
7.How long we keep it
- Account data — for as long as your account is active, plus up to 90 days after deletion to complete backup rotation.
- Simulation history — retained while your account is active; deleted with the account.
- Billing records — retained for at least seven years, or the period required by applicable tax and accounting law.
- Operational logs — retained for up to 90 days and then deleted or anonymized.
- Backups — daily backups are retained for up to 30 days on a rolling basis on the primary server and then overwritten. When configured, an encrypted copy is also synced to an offsite object-storage provider on the same 30-day rolling window.
8.How we protect it
We apply industry-standard technical and organizational safeguards: TLS encryption in transit, encryption at rest for offsite backup copies, salted bcrypt password hashing, scoped database credentials, structured audit logs, rate-limiting on authentication endpoints, and least-privilege access controls for staff. Production access is restricted to named administrators, gated by key-based SSH (password authentication disabled), and logged.
No system is perfectly secure. If we become aware of a personal-data breach affecting your data, we will notify you and the relevant supervisory authorities within the timeframes required by applicable law (within 72 hours of becoming aware, under GDPR, for notifications to authorities).
9.Your rights
Depending on where you live, you may have the following rights in respect of your personal data:
- Access. Receive a copy of the personal data we hold about you.
- Correction. Ask us to correct inaccurate or incomplete data.
- Deletion. Ask us to delete your account and the personal data associated with it. We will honor the request unless we are legally required to retain the data (for example, tax records or fraud-prevention logs).
- Portability. Receive a machine-readable copy of the data you provided us, in a structured, commonly used format.
- Objection and restriction. Object to processing based on our legitimate interests, or ask us to restrict processing while we assess your request.
- Withdraw consent. Where processing relies on consent, you can withdraw it at any time.
- Complain. Lodge a complaint with your local data-protection authority. EU users may complain to the supervisory authority in their country of residence.
To exercise any of these rights, email privacy@dfsdegen.com from the address associated with your account. We verify identity before acting on any request. We will respond within 30 days (or sooner if required by law) and will explain any extension. We do not charge a fee unless requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or decline to act as permitted by law.
10.Automated decision-making
The Service uses statistical simulation and, where enabled by your plan, machine-learning models to generate lineup recommendations and projections. These outputs are decisionsupport only. They do not produce legal or similarly significant effects on you within the meaning of GDPR Article 22, and you remain solely responsible for how you use them. We do not use your data for automated creditworthiness, insurance, or employment decisions.
11.Do Not Track and Global Privacy Control
Browser “Do Not Track” signals do not have a uniform legal meaning and we do not currently respond to them differently from other requests. Because we do not sell or share personal information for cross-context behavioral advertising, and because we do not run advertising or cross-site tracking, a Global Privacy Control (“GPC”) signal from your browser has no additional effect on how we process your data. If we introduce advertising or tracking in the future, we will honor GPC as an opt-out request in the jurisdictions that require it.
12.California residents (CCPA / CPRA)
In addition to the rights in §9, California residents have the right to know what categories of personal information we collect, the purposes for which it is used, the categories of sources it is collected from, and the categories of third parties to whom it is disclosed — all of which are described in this Policy. We do not “sell” or “share” personal information as those terms are defined under the CCPA/CPRA, and we do not process sensitive personal information for the purpose of inferring characteristics about you. California residents have the right to be free from discrimination for exercising their privacy rights and may designate an authorized agent to submit requests on their behalf.
13.Children
The Service is not directed to children under 18 and we do not knowingly collect personal data from anyone under 18. If you believe a child has provided us personal data, contact privacy@dfsdegen.com and we will delete it promptly.
14.Third-party links and features
The Service links to third-party sites (including DraftKings, FanDuel, Yahoo, and community platforms such as Discord) and may embed content served by them. Those third parties operate under their own privacy policies and terms; this Policy does not cover any data they collect. Review their policies before providing personal information through their platforms.
15.Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified by email to active subscribers at least 14 days before they take effect and posted at this URL with a new “Last updated” date. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
16.Contact
Privacy questions, data-rights requests, or complaints: email privacy@dfsdegen.com. Postal mail: DFS Degen, Linden, MI, 48451, USA.
See also our Terms of Service.