Privacy Policy
This policy explains what information Fantasy Goblin collects, how we use it, and the choices you have when using our fantasy sports tools, MCP, Ask My Goblin, and merchandise store.
Information We Collect
- Account information: name, email, username, encrypted password, and account settings.
- Fantasy content you create: rankings, player values, notes, tags, saved archives, and other tool settings you choose to use in the app.
- Connected-provider data: information retrieved from Sleeper, ESPN, or Yahoo when you connect an account, such as league identifiers, rosters, and team information. See Connected Fantasy Providers below.
- Ask My Goblin content: prompts, conversation messages, and related usage records when you use Ask My Goblin. See Ask My Goblin below.
- Payment and order metadata: for Ask My Goblin credit purchases and merchandise orders, payment metadata supplied by Stripe and, for merchandise, order and fulfillment details shared with Printful. We do not store full card numbers.
- Technical data: IP address, browser, device, request logs, timestamps, and diagnostics used for security and reliability.
- Cookies and sessions: essential cookies or similar storage used to keep you signed in and make the site work.
How We Use Information
- To create, secure, and maintain your account.
- To load leagues, rankings, trade tools, saved boards, MCP access, and Ask My Goblin.
- To process Ask My Goblin credit purchases and merchandise orders, and to review related purchase questions.
- To troubleshoot bugs, prevent abuse, improve performance, and respond when you contact us.
Connected Fantasy Providers
When you connect Sleeper, ESPN, or Yahoo, we retrieve and store the league, roster, and account information needed to provide the features you use, such as displaying your leagues, rosters, and team details inside Fantasy Goblin. You can disconnect a connected provider from Account Settings at any time. The Fantasy Goblin ESPN Helper browser extension has its own detailed data-handling section further below.
Ask My Goblin and AI Data
Ask My Goblin is Fantasy Goblin's own in-site AI chat feature. When you use it, relevant information — which may include your prompts, rankings, notes, tags, league and roster context, and recent conversation messages, is sent to Anthropic, the provider behind Claude, to generate a response.
Chat messages and related usage records may be stored on Fantasy Goblin's servers. We do not currently apply a fixed automatic deletion period to stored chat messages. You can delete an individual chat thread yourself at any time from within Ask My Goblin, which removes that thread's stored messages.
We don't share internal details like AI model settings or what each request costs us to run, that stays internal to operating the feature.
MCP and Connected AI Clients
MCP lets you connect a supported external AI client to your own Fantasy Goblin account. MCP access requires a Fantasy Goblin account, and connecting a client requires your explicit authorization through Fantasy Goblin's login and consent screen, it is never available anonymously.
Once authorized, the supported MCP tools may give that client access to information you have in Fantasy Goblin, such as your rankings, notes, tags, connected leagues, rosters, draft context, and trade-related information.
You can review and revoke a connected client's access at any time from Connected Apps in Account Settings. Your OAuth access and refresh tokens for a connection are stored only to operate that connection, and are removed when you disconnect the client or when your Fantasy Goblin account is deleted.
The external AI client you authorize is a separate service with its own privacy practices, which we do not control. Review that client's own privacy policy before connecting it.
Merchandise Orders
When you place a merchandise order, Stripe processes your payment, and we share the order and shipping information Printful needs to produce and ship it. This may include your name, shipping address, contact details, the products and options you selected, and artwork or order details associated with your order. See Purchases & Refunds for our merchandise purchase and refund policy.
When We Share Information
- Service providers: we may share limited information with vendors that help with hosting, analytics, email, payments, fulfillment, security, or app operations.
- Payments: Stripe handles payment details for Ask My Goblin credit purchases and merchandise orders under its own policies.
- Merchandise fulfillment: Printful receives the order and shipping information needed to produce and ship merchandise orders, under its own policies.
- AI processing: when you use Ask My Goblin, relevant information is sent to Anthropic to generate a response, under its own policies.
- Legal and safety: we may disclose information when reasonably necessary to comply with law, protect users, or investigate misuse.
Retention and Deletion
We keep information only as long as reasonably needed to operate Fantasy Goblin, maintain account history, support purchase records, resolve disputes, prevent abuse, and meet legal obligations.
To request deletion of your account, contact us through the Contact page. We will delete or anonymize your information where practical. We do not commit to a fixed processing deadline. We may retain limited records where reasonably necessary for payment records, fraud prevention, dispute handling, tax or accounting requirements, security, or other legal obligations, and we cannot guarantee that information already shared with a service provider such as Stripe or Printful will be immediately deleted from that provider's own systems.
Your Options
- You can request access, correction, or deletion of your account by contacting us, see Retention and Deletion above.
- You can control cookies in your browser, though some site features may stop working correctly.
- You can disconnect Sleeper, ESPN, or Yahoo from Account Settings at any time.
- You can revoke a connected MCP client's access at any time from Connected Apps in Account Settings.
- You can delete an individual Ask My Goblin chat thread at any time from within Ask My Goblin.
Fantasy Goblin ESPN Helper — Extension Data Handling
The Fantasy Goblin ESPN Helper is an optional Chrome browser extension that connects your ESPN fantasy account to Fantasy Goblin. This section explains how the extension handles your ESPN session data.
What the extension collects
- SWID— your ESPN account identifier (a UUID-format string set by ESPN in your browser).
- espn_s2— your ESPN session credential, which allows Fantasy Goblin to retrieve your private ESPN fantasy league data on your behalf. ESPN marks this cookie as HttpOnly; it cannot be read by websites, only by browser extensions.
- Active tab URL— when you click the extension icon, the URL of your current browser tab is read to detect your ESPN fantasy league details (league ID, sport, season) from the URL path. No page content is read.
How your ESPN credentials are transmitted
When you click “Connect ESPN to Fantasy Goblin,” the extension sends your SWID and espn_s2 values once, over HTTPS, to your own Fantasy Goblin account using a one-time token you generate from your Account Settings. The token expires in 5 minutes and works only once. No credentials are sent to any other server.
How Fantasy Goblin stores ESPN credentials
- espn_s2 is encrypted at rest using AES-256-GCM before being written to the Fantasy Goblin database. The plaintext value is never logged, never returned in API responses, and never displayed in the interface after the initial connection.
- SWID is stored as your ESPN account identifier. Fantasy Goblin displays only a partial value (first 8 characters + last 4) in Account Settings as confirmation, the full value is never shown.
- Stored credentials are used exclusively to authenticate requests to the ESPN Fantasy API on your behalf to retrieve your team and league data.
What the extension does not store locally
The extension stores nothing in your browser. It does not write to
localStorage, sessionStorage, or chrome.storage.
ESPN credential values are held in extension memory only for the duration of the single
connection request and are immediately discarded after transmission.
Disconnecting your ESPN account
You can disconnect your ESPN account at any time from Account Settings → ESPN → Disconnect. Disconnecting revokes the stored credentials and removes the encrypted data from Fantasy Goblin's database. Deleting your Fantasy Goblin account removes all associated ESPN credentials.
Third-party sharing
Your ESPN credentials are never sold, shared, or transmitted to any party other than your own Fantasy Goblin account. Fantasy Goblin does not share ESPN credential data with ESPN, Google, or any other third party.
No official ESPN affiliation
Fantasy Goblin ESPN Helper is an independent tool. It is not affiliated with, endorsed by, or supported by ESPN or The Walt Disney Company. ESPN, ESPN Fantasy, and related marks are trademarks of ESPN, Inc.
Third-Party Services
Fantasy Goblin relies on outside services, which may include Sleeper, ESPN, and Yahoo for league data, Stripe for payments, Printful for merchandise fulfillment, and Anthropic (the provider behind Claude) for Ask My Goblin, each under its own privacy practices, separate from this policy. If you connect an external AI client through MCP, that client is also a separate service with its own privacy practices we don't control.
Children, Updates, and Contact
Fantasy Goblin is not intended for children under 13.
We may update this policy as the product changes. The date at the top reflects the current version.
Questions about privacy can be sent through the Contact page.