Skip to content

Privacy

Last updated September 2, 2026

Gloatroom is a private clubhouse for your fantasy league: the whole product is built around the idea that what happens in your clubhouse stays in your clubhouse. This page says, in plain language, what we collect, why, where it lives, and how to get it out.

What we collect

  • Your account. An email address or phone number (whichever you sign in with), and, if you use Google sign-in, your name and email from Google. We never see or store passwords; sign-in is by emailed magic link, texted code, or your Google account.
  • Your clubhouse. Messages, reactions, pinned posts, and images you share in The Room; your display name; your clubhouse membership and role.
  • Your league data. Sleeper leagues are read through Sleeper's public API via a username you provide; no Sleeper password or token is involved. Historical Yahoo imports and encrypted connection rows remain preserved, but Gloatroom no longer creates, refreshes, or uses Yahoo connections. When a commissioner links a Google Sheet, we read that sheet and nothing else in their Drive.
  • Notifications. If you turn on push notifications, your browser gives us a delivery address (a push subscription) plus your notification preferences. Turning notifications off deletes the subscription.

We do not run ads, sell data, or use third-party analytics or tracking scripts. Anonymous visits to this website set no cookies.

What we can't do

Provider access is read-only by design. We cannot set lineups, make trades, place waiver claims, or change anything in your fantasy account. Provider credentials stay on the server and are never sent to your browser.

Where it lives

These services process data on our behalf (our subprocessors):

  • Supabase: database, authentication, realtime chat, and image storage. Every table is protected by row-level security: members of one clubhouse cannot read another clubhouse's data.
  • Vercel: hosts the website and application.
  • Google: optional sign-in, and reading a league sheet a commissioner explicitly links.
  • Sleeper: the active fantasy platform we read league data from, only for accounts a member links.
  • Your browser's push service (for example Google or Apple's): delivers push notifications if you opt in.

How long we keep it

The Record Book is the point: league history, records, and receipts are kept for as long as your clubhouse exists, so a season played in 2026 is still there in 2036. Chat and images follow the clubhouse the same way. Disconnecting a provider deletes its stored tokens. Leaving a clubhouse removes your access; the group's shared history stays with the group.

Getting your data out, or gone

  • Disconnect a provider any time in Settings: its tokens are deleted immediately.
  • Leave a clubhouse any time in Settings.
  • Export your data yourself: Settings has a Download my data button that hands you a JSON file of everything we store about you (never your provider tokens).
  • Delete your account: contact us via the support page and we'll complete it within 30 days.

Security

Everything is served over HTTPS. Provider tokens are encrypted at rest. Database access is enforced row-by-row so clubhouses are isolated from each other. If you believe you've found a security issue, please tell us through the support page. We take reports seriously and respond quickly.

Changes

If this policy changes in a way that matters, we'll say so in the app before the change takes effect. The date at the top always reflects the current version.