What we collect
When you create an account we collect your email address and assign you an account identifier. You may optionally add a username, display name, and bio to your manager profile.
Using Capr. generates league data: rosters, contracts, salary-cap figures, bids, trades, waiver claims, draft activity, and league chat messages. This data is scoped to your leagues and is only visible to members of those leagues.
We also collect diagnostic data โ crash reports, page-load performance, and aggregate usage patterns โ to keep the app fast and reliable.
How we use it
Your data is used to run your leagues: enforcing cap rules, resolving auctions, scoring matchups, and notifying you of league activity. We do not sell your data, and we do not show ads.
Service providers
Capr. relies on a small set of infrastructure providers, each receiving only what its function requires:
- Supabase โ our database and authentication provider. Stores your email, account identifier, and league data, encrypted at rest.
- Anthropic โ powers optional AI-generated power ranking and weekly recap narratives. When these features run, league names, team names, manager display names, recent transactions, and cap figures are sent to the Claude API to compose the narrative. Anthropic does not train on this data under our API terms.
- Sentry โ crash and error reporting. Reports are scrubbed before transmission: query strings, request bodies, cookies, and identifying fields are removed; only an opaque account identifier is retained for deduplication.
- Vercel โ hosting, plus anonymous analytics and Core Web Vitals performance measurement. Not linked to your identity.
- Resend โ transactional email delivery (league notifications you have opted into). Receives your email address only.
- ESPN and Sleeper CDNs โ serve player photos and public player data. No personal data is sent to them.
Security
All traffic is encrypted in transit with TLS, and all stored data is encrypted at rest. Realtime league feeds are protected by row-level security so members of one league cannot read another league's data. API access is authenticated, rate-limited, and audited.
Retention and deletion
Your data is retained while your account is active. You can delete your account at any time in Settings โ Danger Zone โ Delete my account. Deletion is immediate and irreversible: your profile, email preferences, and achievements are erased, and your login is permanently removed. League history (past trades, scores, and transactions) is retained in anonymized form โ your name is detached from it โ so that other members' league records stay intact.
Your rights
Depending on where you live, you may have the right to access, correct, export, or erase your personal data. The in-app deletion flow covers erasure; for anything else, contact us at support@capr.app and we will respond within 30 days.
Children
Capr. is not directed at children under 13, and we do not knowingly collect data from them. If you believe a child has created an account, contact us and we will delete it.
Changes to this policy
If we make material changes we will update the effective date above and notify you in-app before the changes take effect.
See also our Terms of Service.