Privacy Policy
Last updated September 14, 2026
Otto reads a fantasy league and talks in that league's chat. That means it handles some of your league's data and a little about the people in it. This page says exactly what, why, and for how long, in plain words.
Who we are
Otto is operated by a sole proprietor in Wisconsin, United States ("we"). We are the data controller for everything described here. Otto is not affiliated with ESPN, Sleeper, Discord, GroupMe, or the NFL.
What Otto collects
Your account
- Your email address and the display name you choose.
- If you sign in with Discord or Google, the account id that service gives us and the name and email it shares. We never see your password for either service.
- When you signed up and when you last signed in.
- Sign-in links sent by email are single use and expire after fifteen minutes; only a hashed form of each link is stored.
Your league
- The league's id on its fantasy platform (ESPN today), its name, its time zone, its plan, and the settings you choose, such as which posts are on.
- The two ESPN session cookies (
espn_s2andSWID) supplied when a league is connected or relinked. They are checked once against ESPN to confirm the account is a member of the league. They are kept, encrypted, only when the league is private, and used for one thing: reading that league from ESPN. For a public league they are discarded after the check. Your ESPN password is never asked for. - What the platform reports about the league: teams and their owners' team names, rosters, matchups, scores, transactions, and drafts, for the current season and past seasons. Otto keeps its own copy so it can answer questions about league history.
Your chat
- The Discord server Otto is added to: its id and name, the channels you pick for alerts and posts, and the Discord id of the person who connected it.
- Owner links: which Discord account plays which team, set by the commissioner so alerts can mention the right person and direct messages know whose league they belong to.
- Messages in the channels Otto is set to read: who sent them, when, and what they said. Otto keeps recent messages so that a question like "what did we decide about the trade deadline" can be answered from the conversation. It does not read channels it has not been given.
- Direct messages sent to Otto, and the questions people ask it anywhere, together with the answer it gave, which lookups it ran to answer, which model answered, and what the answer cost us. We keep this so we can see why an answer was wrong and fix it.
Technical
- Ordinary web server records: the address a request came from, the page asked for, and the time. Our hosting and network providers keep the same for a short period.
How it is used
- To post the alerts and reports your league turned on, in the channels you chose.
- To answer questions about your league, using your league's data and recent chat for context.
- To sign you in, keep you signed in, and let you manage your league on this website.
- To apply the limits of your plan, such as the daily question cap on the Free plan.
- To troubleshoot: when an answer is wrong or a post fails, we read the record to find out why.
- To email you about your account or your league: sign-in links, and notices that matter, such as expired ESPN cookies or a change to these terms. We do not send marketing email.
AI models and other services
Otto's answers and its written reports come from large language models run by outside providers. To answer a question, Otto sends the model the question, the name of the person asking, a summary of the league (standings, rosters, matchups, recent transactions), recent messages from the channel the question was asked in, and the results of any lookups it runs. The providers process that request to produce the answer and, under our agreements with them, do not use it to train their models. We do not send them your email address, your ESPN cookies, or anything from leagues other than the one asked about.
The services Otto relies on, and what each one sees:
| Service | What for | What it sees |
|---|---|---|
| Discord | The chat platform Otto posts in and listens to | Everything Otto posts and reads there, under Discord's own privacy policy |
| ESPN | The source of your league's data | Requests for your league, made with the cookies the commissioner supplied |
| Sleeper | A public list of NFL players used to match player names across platforms | Nothing about you; the list is public and the request carries no league data |
| AI model providers | Writing answers and reports | The question, the asker's display name, league data, and recent channel messages, as described above |
| A web search service used by the model provider | Looking up NFL news for the weekly recap's commentary | Searches about NFL players and games; nothing about your league or its members |
| An email delivery service | Sending sign-in links and account notices | Your email address and the message |
| Our network and DNS provider | The network in front of this website | Ordinary request records, including the address a request came from |
Otto runs on servers we operate in the United States. If you use Otto from elsewhere, your data is processed there.
How long it is kept
- Channel messages: up to one year, then deleted automatically.
- Questions, answers, and lookups: while the league is connected, for troubleshooting.
- ESPN cookies (private leagues only): until the commissioner replaces them or removes the league. Removing the league deletes them immediately.
- League data, settings, owner links, and the league's history copy: while the league is connected, and for up to ninety days after it is removed so that a league removed by mistake can be restored. After that it is deleted.
- Your account: until you ask us to delete it. Deleting an account removes the account and its sign-in identities; leagues it owned are removed with it unless another member has taken them over.
- Backups: nightly, kept for fourteen days, then overwritten.
What is never done
- Nothing is sold. Nothing is shared with advertisers or data brokers.
- No advertising, no analytics trackers, no marketing lists.
- Your league's data is never shown to another league, and a model answering one league never sees another.
- We only disclose data when the law requires it, and we will tell you if we are allowed to.
Cookies and storage
This website sets two cookies: one that keeps you signed in, and one that protects forms from being submitted by other sites. Neither is used for tracking. Your browser may also keep small preferences, such as light or dark mode, on your own device. Discord and Google set their own cookies when you sign in through them.
Security
Traffic to the website and to every service Otto talks to is encrypted in transit. ESPN cookies are encrypted at rest with keys held only on our servers. Sign-in links are stored hashed. The bot's own Discord token and other service credentials are never stored in the database. Access to production systems is limited to the operator. No system is perfectly secure, and if a breach ever affects your data we will tell you as soon as we reasonably can.
Your choices
- See or correct your data: your account page shows your email, name, and linked sign-in methods, and lets you change or unlink them. Your league's settings are on its pages.
- Stop Otto reading a channel: change the channels on the league's chat page, or remove Otto from the server in Discord.
- Remove a league: the Remove league button on its settings page. Posting stops and the ESPN cookies are deleted immediately.
- Delete your account, or anything else: email us. We answer within thirty days and usually much sooner.
- Not in charge of the league? Your commissioner connected it. Ask them, or email us and we will help.
Depending on where you live you may have further rights, such as to receive a copy of your data or to object to how it is used. Email us and we will honour them.
Children
Otto is not for anyone under thirteen, and Discord's own terms already require that. If we learn we hold data about a child under thirteen, we delete it.
Changes
If this policy changes in a way that matters, we email account holders before the change takes effect and update the date at the top. Small clarifications are simply published here.
Contact
For any questions or concerns about this policy, or to exercise any of the choices above, please contact us. We answer within thirty days and usually much sooner.