Privacy Policy
Effective date: July 11, 2026.
This policy describes what the current wcdraft website and game collect, process, and store. If the product changes, we will update this page so the policy matches the code that is running.
What we collect
wcdraft collects the information needed to run drafts, save and replay runs, keep leaderboards honest, and secure sign-in.
- Account and sign-in data. If you create an account, we store your email, public username, password hash, password-set timestamp, and email verification timestamp when verification is complete. If you request a magic-link sign-in, verification link, or password reset, we store the submitted email address with the magic-link record. Magic-link flows also use a purpose, delivery outcome, PII-free correlation id, token hash, expiry time, consumed time, session identifier, CSRF secret, and session expiry so the link can be single-use and your session can stay secure. Password sign-in verifies against the stored password hash.
- Gameplay and history data. Draft runs can include the run id, parent seed, version anchors, squad, manager, match results, score summary, share token, claim state, and timestamps. Runs are saved locally in this browser. Completed runs may also be mirrored to the server under an anonymous session or a signed-in account so history, claiming, and replay can work across the site.
- Leaderboard data. When you post a result, we store the season, board mode, draft mode, display name, run token, verified score, score breakdown, account or session link, and timestamps.
- Share links. Share URLs contain a self-contained run token. Anyone you give the link to can use that token to replay the run summary encoded in the URL.
- Security and technical data. Sign-in and leaderboard submission use rate limits based on hashed email, IP, or session buckets. Our hosting provider may process standard request and server logs such as IP address, browser details, requested URLs, and timestamps. Vercel may also process performance-only Web Vitals measurements; wcdraft does not use those measurements for advertising or behavior profiles.
What we do not collect
wcdraft does not collect or process these categories in the current product:
- Plaintext passwords.
- Third-party or social sign-in identifiers.
- Payment details, billing records, or paid entitlements.
- Ad targeting profiles, ad cookies, or ad delivery data.
- Product-behavior analytics, marketing tracker events, or advertising profiles.
- Player photos, likeness rights, or biometric data.
Cookies and local storage
wcdraft uses same-site application cookies for sessions and protected actions: wcdraft_sid for the session, wcdraft_csrf for CSRF protection, a short-lived wcdraft_bootstrap proof before the first mutation, and a short-lived wcdraft_recent_magic proof after a completed email-link sign-in. Session and proof cookies are HTTP-only where browser JavaScript does not need them; all are marked secure in production.
The game also uses browser local storage for recent local runs, the run history index, a local run counter, the last leaderboard display name, last submitted leaderboard token, and the Synergy panel preference. Clearing browser data removes local records from that browser. It does not delete server-saved runs, account sessions, or leaderboard entries.
How we use information
- To send sign-in, verification, and password-reset emails and keep sessions secure.
- To run drafts, score tournament results, save history, and replay share links.
- To verify and display leaderboard submissions.
- To prevent abuse, rate-limit sensitive actions, investigate failures, and debug the service.
Service providers
wcdraft relies on service providers that process data only as needed to run the site:
- Vercel hosts the website and may process request/server logs and performance-only Web Vitals measurements.
- Neon Postgres stores account, session, run, leaderboard, and rate-limit data. The application accesses that database through Drizzle.
- Resend processes your email address and magic-link email content when we send sign-in, verification, or password-reset links.
Retention and deletion
Magic links expire quickly and are single-use. Session cookies expire automatically. Browser runs stay in local storage until you clear browser data or the app evicts old local records. Anonymous server history keeps the 5 most recent unpinned runs. Signed-in account history is capped at 500 rows and 8 MiB; when a cap is crossed, the oldest unpinned rows are removed deterministically. Leaderboard entries may remain visible as season standings unless they are removed for moderation, security, or a valid privacy request.
Clearing browser data removes local browser copies. It does not remove a run that was already saved to the server, posted to the leaderboard, or shared with someone else. Deleting an account from Account deletes that account's sessions, saved runs, and account-owned leaderboard rows. A share URL already given to someone remains a copy in that recipient's possession. Contact us if you want help with access, correction, deletion, or export.
Data attribution
wcdraft uses football data derived from public sources under the terms described on the attribution page, including CC BY-SA source attribution. The app uses names and statistical records to power gameplay; it does not store or display player photos.
Contact and privacy requests
Questions about this policy or your data? Reach us via the contact page. We will update this page when the product changes in ways that affect what data is collected, processed, or retained.