Privacy policy

Updated October 7, 2026. Ron’s Fantasy Basketball Assistant is operated by Ron Ligsay on his own server.

Information collected and stored

The app stores your username, a password hash (not your password), account status and administrator flag, account-session records, and saved league/team profiles. Profiles can include league settings, team names, draft picks, player eligibility and status imported from Yahoo, your preferences and uploaded custom projection rows. Uploads are parsed for preview; applying an upload stores the accepted projection rows in the profile.

Cookies and browser storage

A signed session cookie keeps you logged in. Account sessions expire after 12 hours. Browser local storage keeps draft data, profile backups and the selected profile on that device. It is not automatically cleared when you log out. Use separate browser profiles on a shared computer and clear this site’s browser data when needed.

Yahoo and other providers

You sign in directly on Yahoo’s website; this app never receives your Yahoo password. The app receives OAuth tokens and the Fantasy information you authorize it to access. Tokens are held in server memory, not saved in the database or browser storage. Disconnecting or restarting the server removes the active connection; inactive connections are cleared when checked after 24 hours. Logout ends the app login. Yahoo processes its own login and API requests under Yahoo’s privacy policy.

The server retrieves player news and schedule information from external providers. Opening source links or loading external player images can disclose your IP address and browser information to those providers. Their own privacy policies apply. This app does not include advertising analytics or sell account data.

Access and retention

Saved profiles are separated by account. Ron, as server operator, can access the underlying database and server files. League/team and draft data remain stored until deleted; there is currently no automatic expiry for saved Yahoo imports. Account records remain until removed by the operator. Server and reverse-proxy logs may record IP addresses, request paths and times; log and backup retention depends on the server’s configuration.

Deletion and contact

Deleting a saved profile removes it from the active database and clears that profile’s backup in the browser performing the deletion. Other browser copies and server backups must be cleared separately. Contact Ron Ligsay directly for account deletion, data access or privacy questions. A privacy policy describes actual handling of data; it does not grant permission to use third-party content.

Back to assistant