Privacy
This policy explains what YUNO Sports collects, why, and the choices you have. Where it says "we" or "us" below, that means YUNO Sports. It covers yunosports.com and our related apps and services. Our browser extension has its own policy at /privacy/extension.
Information we collect
Information you give us:
- Account: your email address and account credentials. Sign-in is handled by Supabase, our authentication provider, and we never store your password.
- Profile & content: a display name, anything you post in community and forum features, the charts and articles you save, and whatever you send us for support.
- Payments: if you subscribe to a paid plan, Stripe processes the payment. We receive your subscription status and limited billing details such as your card brand and its last four digits. We never receive or store full card numbers.
- Fantasy connections: if you connect a fantasy league, we store the credentials needed to read it, encrypted at rest: ESPN session cookies, Yahoo OAuth tokens, or a Sleeper username. You can delete them at any time from Connected accounts in your account. See the extension policy for the ESPN connector.
- Ask CHAD: the questions and content you send to our AI assistant, so we can answer and improve the feature.
Information collected automatically:
- Usage & device data: aggregate page-view and page-speed measurements from Vercel Analytics and Speed Insights. These set no cookie and store nothing in your browser, but they do send us the page you are on, your browser type and your IP address, so they are part of the analytics you can switch off — see Cookies. Separately, and always on, we keep standard server logs of your IP address, browser type and the pages you viewed, for security and reliability.
- Product analytics: we use PostHog to understand how YUNO is used — the pages you visit, and a defined list of actions such as signing up, building a Lab chart, or reaching an upgrade prompt. If you have an account, this activity is linked to a random account identifier along with your plan tier. We do not send PostHog your email address, your name, or any payment details, and we do notrecord your screen. PostHog also processes your IP address to estimate approximate location. This, and the Vercel measurement above, are what you can switch off — see Cookies.
- Cookies: see below.
Usability testing is the one place we collect materially more than the above, and it only ever happens if you opt in; see Usability testing sessions below.
Usability testing sessions
From time to time we invite a small number of testers to take part in an in-app usability test: a few questions about your first impression, then some tasks to try while you think out loud. It is entirely optional, we ask for your consent before anything is recorded, and you can stop at any point.
If you take part, and only for the length of that session, we record:
- A replay of the page: the pages you visit, clicks, scrolling and navigation in that browser tab only. Text you type and the contents of form fields are masked, and we never capture passwords or payment details. This does not record your screen outside the tab, other tabs, or any other application.
- A video of the tab, but only if you separately agree to it. This is a picture of the page exactly as it appeared, so unlike the replay above nothing in it is masked, so we ask you to close anything private in that tab first, we only ever record the one tab (never your desktop or other windows), and your voice is recorded into the same file if you agreed to that too.
- Your voice, but only if you separately agree to it. Your browser will also ask for microphone permission, and declining either one means no audio is recorded; the rest of the test works normally. Voice recordings are personal data, and in some places they carry additional protection; we treat them accordingly and never share them outside our team.
- Your answers to the test's questions, which tasks you completed, and how long each took.
- A random session identifier stored in your browser, so the parts of a single test can be matched up. It is not linked to advertising and is not shared.
- An email address, only if you choose to give one at the end, and only so we can send the single follow-up email described below.
- A name and postal address, only if you ask for a hat, and only for as long as it takes to post it.
The week afterwards. At the end of a session you can choose to leave an email address. If you do, we use it for exactly one message: a single email about a week later inviting you to a short follow-up survey. It carries a one-click unsubscribe, we send nothing else to it, and we never add it to a mailing list. Leave it blank and there is nothing to unsubscribe from.
The thank-you. If you complete that survey you can pick a $20 Amazon gift card, a YUNO hat, or nothing at all. It is for completing the survey, not for what you said in it, and taking nothing is a real option that costs you nothing.
The two differ in what we need from you. The gift card is emailed to the same address the survey link went to, so there is nothing extra to give us and nothing extra for us to keep. The hat needs a name and a postal address. We use them to address the parcel and nothing else: they are kept apart from your session and your answers, and deleted about a month after the hat is posted. After that we keep only the fact that a hat was sent, not where. You can ask us to delete the address sooner at any time.
Recording stops when the test ends or when you leave it. If you leave partway through, any audio captured up to that point is discarded rather than uploaded. Recordings are stored privately, are viewable only by the YUNO team through short-lived internal links, and are used solely to find and fix usability problems and never for advertising, profiling, or automated decisions about you. Recordings are deleted automatically within 90 days, and you can delete yours sooner at any time, without giving a reason. If you left us an email address, the follow-up message carries a link that erases your whole session on the spot: the recordings, your answers, your email address and any postal address you gave us for a hat. Otherwise, just contact us. If you took part without leaving an email address, we have no way to tell which session was yours, which also means there is nothing there that identifies you.
Where usability recordings go. They are stored and reviewed in the United States. If you took part from the UK or EU, that is a transfer out of your own data-protection regime: the US has no UK or EU adequacy decision, and for these recordings we do not yet have standard contractual clauses in place, so the protection is weaker than it would be at home and your rights are harder to enforce there. We tell you this on the consent screen before anything is recorded, and taking part is you agreeing to that particular transfer. It is also why the erasure link above exists and why these sessions are deliberately few; this route is meant for occasional one-off transfers, not routine ones.
How we use information
- Provide, maintain, and secure the service and your account.
- Process subscriptions and send service-related messages.
- Power the features you use, such as fantasy sync, Ask CHAD and notifications.
- Send notifications and email digests you've enabled; you can turn these off at any time.
- Understand usage in aggregate to improve the product.
- Run opt-in usability tests to find and fix confusing parts of the product.
- Prevent abuse, fraud, and rate-limit excessive requests.
We do not sell your personal information, and we do not use it for third-party advertising.
Cookies
Strictly necessary cookieskeep the site working. They are always on, because without them you could not sign in, get through the private-beta gate, or have us remember that you turned analytics off. All of them are first-party — set by us or by Supabase on our domain — and none is used for advertising.
- sb-…-auth-token(Supabase) — keeps you signed in. Lasts as long as your session; signing out clears it.
- site-access— records that you got through the private-beta gate, so you are not asked again. 30 days.
- yuno_pass— a temporary access pass, if you were given a code. Up to 7 days.
- yuno-consent— your analytics choice, so we can honour it and stop asking. 12 months.
- yuno-consent-required— whether your region is one where we must ask before setting analytics cookies. It holds a yes or no, not a location. 30 days.
- yuno_usability_tier— only if you take part in a usability test; unlocks the paid features the test asks you to try. 7 days.
- yahoo_oauth_state— only while you are connecting a Yahoo fantasy league; it is a one-time value that protects that connection from being tampered with. 10 minutes.
- yuno_editor_width— a layout preference in the admin article editor. Only ever set for our own staff accounts. 12 months.
Analytics cookies are one cookie, set by PostHog (ph_…_posthog, 12 months). It holds a random identifier and nothing else, so we can tell a returning visit from a new one and follow a journey through the site. It is first-party: it is not used for advertising and does not follow you to other websites.
The same analytics choice also controls Vercel Analytics and Speed Insights, which measure page views and page speed. Those two set no cookie and store nothing in your browser, so they are not cookies in the strict sense — but they are analytics, they process your IP address, and turning analytics off stops them along with PostHog.
Two things that commonly do set cookies here do not. Stripe sets nothing on our domain: paying takes you to a page hosted by Stripe, and nothing of theirs runs on ours beforehand. Sentry, which we use for error monitoring, sets no cookie and stores nothing in your browser either.
Where the law requires us to ask first — the EU, EEA, UK and Switzerland — analytics stay off until you accept, and nothing is set in the meantime. Everywhere else they are on by default. Either way you can change your mind at any time using Cookie settings in the footer, and turning them off stops further collection immediately.
What we store in your browser
Cookies are not the only thing a site can put on your device. YUNO also uses your browser’s local storage, which works like a cookie except that it is never attached to a request automatically — it stays on your device unless something deliberately sends it. We are describing it here because it is storage on your device, and you should know what is in it.
Almost all of it is preferences, and it never leaves your browser: your light/dark theme, chart defaults like number format and grid lines, export settings, page layouts, your favourite teams, which one-off notices and tips you have dismissed, and drafts of things you were building. Some of these are written the first time you load a page, before you have changed anything — they are the defaults being recorded, not a record of choices you made.
Two are random identifiers that we do receive, so they deserve to be called out separately:
- nfl-explorer-lab-client-id— a random value created the first time you build a chart in the Lab. It is sent with autosaved drafts so that your work comes back to you on that device. It is not linked to your identity and is not used to profile you.
- nfl-explorer-usability-anon-id— only if you take part in a usability test without an account. It is how the server recognises your session as yours, so treat it like a key: it is random, it says nothing about you, and clearing it ends that session’s link to your answers.
We also use session storage, which your browser throws away when you close the tab: a per-tab identifier for Ask CHAD conversations, and a marker that stops the same analytics event being counted twice in one visit.
None of this is advertising or tracking across other sites. You can clear all of it at any time by clearing site data for yunosports.com in your browser, which also removes every cookie listed above. Doing so signs you out and resets your preferences to their defaults.
How we share information
We share data only with service providers who process it on our behalf to operate YUNO, under contract and only for the purposes below:
- Supabase: authentication and database hosting.
- Vercel: application hosting and aggregate analytics.
- PostHog: product analytics. Processed on PostHog’s United States infrastructure.
- Cloudflare: content delivery and data storage infrastructure.
- Stripe: subscription payments and billing.
- Anthropic and OpenAI: to generate responses in Ask CHAD.
- Resend: to send transactional and digest emails.
- Upstash: rate limiting and caching.
- Sentry: error and performance monitoring. If you take part in a usability test, Sentry is also where the page replay from that session is stored and played back.
- ESPN, Yahoo and Sleeper: when you connect a fantasy league on one of these platforms, we use your credentials to read your league data on your behalf.
We may also disclose information if required by law, to enforce our terms, or to protect the rights, safety, and security of our users and the service. If YUNO is involved in a merger or acquisition, information may be transferred as part of that transaction.
Data retention & deletion
We keep your information while your account is active. You can delete your account from your account settings. Deletion is recoverable for a short grace period of about 30 days, after which your personal data is permanently removed. Content you posted in community features may be anonymized rather than deleted to preserve conversation threads. Some records may be retained as required for legal, tax, or security reasons.
Deleting your account also deletes your PostHog analytics profile and its event history, so the analytics record does not outlive the account it describes.
Usability-test recordings are kept separately and deleted automatically within 90 days of the session. We review them, write up what we learned, and the recording goes; the written findings stay, but they hold no voice and no identity. Recordings are also removed if you delete your account, and you can ask us to delete a specific session sooner than the 90 days.
Fantasy credentials are deleted the moment you disconnect that service under Connected accounts, and in any case when you delete your account.
Postal addresses given for a usability-test hat are deleted automatically about a month after the hat is posted; we keep only the record that one was sent. An email address given for the follow-up survey is used for that one message and then stops being used; unsubscribe at any time, from the link in the email or by contacting us.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, and to object to or restrict certain processing. You can exercise many of these directly in your account settings, or by contacting us. We will not discriminate against you for exercising these rights.
Security & data location
We use industry-standard measures to protect your information, including encryption of sensitive credentials at rest and in transit. No system is perfectly secure, so we cannot guarantee absolute security. Our providers may process data in the United States and other countries; where required, we rely on appropriate safeguards for international transfers.
Children
YUNO is not directed to children under 13, or the minimum age required where you live if that is higher, and we do not knowingly collect their personal information.
Changes
We may update this policy from time to time. Material changes will be reflected by updating the date above and, where appropriate, by additional notice.
Contact
Questions about this policy or your data? Reach us through our contact page. YUNO Sports is an independent site, run as a sole proprietorship by Jon Heston, and this policy is governed by the laws of the State of California.
