← Back to NBAi
NBAi Privacy Policy
Last updated: April 1, 2026
Overview
NBAi is a browser extension that provides analytics and insights for Yahoo Fantasy Basketball. This privacy policy explains what data we collect, how we use it, and your rights.
Data We Collect
Account Data
- Email address — used for account authentication (via Google Sign-In or email/password)
- Yahoo account email — scraped from the Yahoo Fantasy page to link your NBAi account to your Yahoo account (prevents account sharing abuse)
Fantasy Basketball Data
- League data — roster, matchup, standings, and league settings from your Yahoo Fantasy Basketball leagues
- Player statistics — game logs, season averages, and projection data from NBA.com and Yahoo APIs
Payment Data
- Subscription status — whether you have a free or premium account, and when it expires
- Payments are processed by Paddle (our Merchant of Record). We do not store credit card numbers, billing addresses, or other payment details. See Paddle's Privacy Policy.
How We Use Your Data
- Account authentication — to verify your identity and manage your subscription
- Fantasy analytics — to provide matchup projections, trade analysis, and other insights
- Yahoo email matching — to ensure your NBAi account is tied to your Yahoo Fantasy account (anti-abuse measure)
- License validation — to determine whether you have access to free or premium features
Where Data Is Stored
- Locally on your device — fantasy data is cached in your browser's local storage (IndexedDB and browser.storage.local). This data never leaves your device except as described below.
- Firebase (Google Cloud) — account data (email, Yahoo email, license status) is stored in Google Cloud Firestore. Firestore security rules ensure you can only access your own data.
- Paddle — payment and subscription data is managed by Paddle.
Data We Do NOT Collect
- We do not track your browsing history
- We do not collect analytics or telemetry
- We do not serve ads
- We do not sell or share your data with third parties
- We do not store your Yahoo OAuth credentials on our servers (tokens are stored locally in your browser)
Third-Party Services
Your Rights
- Access — you can view your account data in the extension popup
- Deletion — you can delete your account by signing out and requesting account deletion. Contact us at the email below.
- Data portability — your fantasy data is cached locally and can be exported via the debug bundle
- Opt out — uninstall the extension to stop all data collection immediately
Data Retention
- Local cache — automatically expires based on TTL (3 hours to 30 days depending on data type)
- Account data — retained until you delete your account
- Payment records — retained by Paddle per their retention policy
Security
- All communication uses HTTPS
- Firebase security rules enforce per-user data isolation
- Yahoo OAuth tokens are stored locally in your browser (not on our servers)
- Webhook signatures are verified using HMAC-SHA256
Children's Privacy
NBAi is not directed at children under 13. We do not knowingly collect data from children.
Changes to This Policy
We may update this policy from time to time. Changes will be posted at this URL.
Contact
For questions about this privacy policy or to request account deletion, contact: amitsmall89@gmail.com