Who we are
The service at https://secondgm.com is provided by SecondGM Ltd. For privacy questions, contact pj@secondgm.com.
SECONDGM LTD is a private limited company, company number 17373814. Registered office: 80 Grosvenor Court Adenmore Road, London, England, SE6 4FE. Registered in England and Wales. Incorporated 31 July 2026. Status: Active.
What this notice covers
It covers the public website, guest Sleeper connect, optional SecondGM accounts, prepaid Usage, Ask SecondGM, feedback, and the processors the live product uses today. It does not cover Sleeper’s own app or website. We do not introduce processors here that the current production code does not use.
Using SecondGM without an account
You can connect a public Sleeper username and use every supported non-AI tool for one chosen league without creating a SecondGM account. Portfolio requires an account and Multi-League. Guest use does not create a login for you. Your connected Sleeper identity and league list are stored in this browser (localStorage) so the site can keep working on this device. A strictly functional cookie mirrors the league chosen for the guest preview so access is rendered consistently before the page becomes interactive.
Information we process
Depending on how you use the service, we may process:
- Sleeper identifiers and public league data. Username, Sleeper user id, league ids, roster ids, public display names, rosters, settings, schedule, matchups and related public league information. We read this from Sleeper’s public API. We never ask for your Sleeper password and we do not write anything back to your league.
- Account and authentication data if you create an account: email address, password (stored by our auth provider as a hash, not as plain text), optional display name, email-verification status, and a public account id. If you sign in with Google or Apple, that provider shares the identity information needed to create or open your session.
- Saved Sleeper connection if you are signed in: the Sleeper username and user id you choose to link, so we can restore your leagues across devices. Linking is claim-based. Sleeper does not provide an OAuth proof of ownership.
- Usage and wallet records if you use paid AI features: prepaid SecondGM Usage balance, ledger entries, and references to top-ups or promo credits.
- Ask SecondGM and other AI interactions if you use them: the questions you send, conversation history, optional images you attach, connected league context, and the tool results the product looks up before answering. We store the transcript in our database so you can return to the conversation.
- Payment information if you add Usage or subscribe to Multi-League: email, order and subscription identifiers, subscription status, renewal date, and Stripe checkout or payment-intent references. Card numbers are handled by Stripe, not stored by SecondGM.
- Support and feedback if you send a report: what you write, the page you were on, optional league name, a short device summary, optional screenshot, and an optional reply email. If you are signed in we also include your account email, display name, linked Sleeper username and public account id so we can investigate. Feedback is emailed to the founder, and a copy of the report is kept in our database so it can be tracked to a fix. Screenshots are emailed only and are not stored in the database. AI conversations are not attached.
- Saved preferences such as starred players, mock-draft or rookie-board state if you save them to an account, and on-device UI preferences.
Why we use this information
- To load your public Sleeper leagues and run the free analysis tools.
- To create and keep an optional account, including email verification and password reset.
- To answer Ask SecondGM questions about your actual team, trades or league.
- To take prepaid Usage payments and keep an accurate wallet ledger.
- To investigate bugs and product feedback.
- To keep the service secure, rate-limit abuse, and understand basic public-site use.
Where UK GDPR applies, we use this information to provide the service you ask for, to take steps at your request, to run a legitimate small business (security, debugging, understanding whether the public site works), and to meet legal obligations such as keeping payment records.
Who processes this information for us
These are the processors and data sources the current production product uses:
- Vercel hosts the website. Production is configured to run in Vercel’s Dublin region. Vercel also provides Web Analytics for page views on the public site.
- Supabase provides authentication, account records, and the hosted Postgres databases the product uses — including league analysis data, conversations and the Usage wallet.
- Stripe processes prepaid Usage top-ups and Multi-League subscriptions.
- Resend sends feedback emails to the founder. Auth verification and password-reset emails are sent through Supabase Auth, not Resend.
- OpenAI generates Ask SecondGM answers and optional AI trade evaluation. We send the relevant question, conversation and SecondGM lookup results. Requests are made with OpenAI storage disabled on our side (store: false); our own database keeps the customer transcript. OpenAI may also run a bounded web search on allowlisted NFL and fantasy sources when the question needs current news.
- Sleeper is the source of public league and player data. We call Sleeper’s public read-only API. We also load public player images from Sleeper’s CDN.
- SportsGameOdds supplies market and prop context for the lineup view. Those server-side requests are for NFL events, not for your name or email.
- MET Norway supplies kickoff weather for outdoor games, using stadium location only.
- Google if you choose Google sign-in.
- Apple if Apple sign-in is enabled and you choose it.
Player values shown in the product come from the provider you select: Dynasty Dealer or Stats Guy Fantasy. NFL research tables are built from public nflverse data we import. Those are data sources we store and serve ourselves. The live site does not send your account to either value provider or nflverse when you open a page.
We do not use advertising networks, and we do not use a third-party product-analytics vendor such as PostHog or Google Analytics. First-party launch events are recorded by SecondGM as described above.
AI interactions
Ask SecondGM is optional and paid. If you use it, your prompts, attached images and the league facts the product looks up are sent to OpenAI so it can answer. The model is instructed not to guess unverifiable league-specific facts. It can still be wrong.
We review AI conversations for quality. Because the AI can be wrong, we check its work. The question you sent and the answer you received may be read — by us, and by an automated reviewer that reads the same conversation and flags answers that look worth a second look. We do this to find and fix mistakes, to support you if you tell us an answer was wrong, to prevent abuse, and to improve the product. It is not used to build an advertising profile, and we do not sell it.
We also record how the AI is performing: which part of the product a question came from, how long the answer took, how much it cost us, which lookups were used, and whether you flagged it. That record is kept even after the conversation text itself is removed, so we can still see whether the product is getting better. We do not store the model’s internal reasoning.
Access is restricted. Only SecondGM’s founder can read conversations, through a private internal tool that requires a verified founder sign-in, and access is logged.
Do not include passwords, payment card numbers, or anyone else’s private information in a question or screenshot.
Analytics
The site includes Vercel Web Analytics. It records page views and related usage on the public site so we can see whether pages load. It is not used to build an advertising profile.
SecondGM also records first-party launch funnel events on our own servers. Those events use a session-scoped anonymous identifier kept in sessionStorage and a first-party session cookie for the current browser session. If the current session arrived with UTM parameters or a referrer, we keep that attribution for the session. We do not use PostHog, Google Analytics, or Meta advertising pixels, and we do not keep a persistent anonymous identifier across sessions.
Some product events are account-linked. If you are signed in, those events can include your public account id so we can tell whether a session belonged to an account. They do not include question text, answer text, email addresses, promo codes, or wallet balances.
Cookies and browser storage
If you sign in, SecondGM uses essential Supabase authentication cookies to keep your session. Those cookies are first-party, set for the site path, use SameSite=Lax, and are marked Secure in production.
This browser may also store:
- Your guest Sleeper connect context, so this device remembers the username and leagues you opened.
- A random device identifier used to rate-limit guest refreshes and similar public actions.
- On-device UI preferences, such as table or trade-tool settings.
- Short-lived session values used to return you to the right page after Ask SecondGM.
- A session-scoped launch-analytics identifier in sessionStorage and a matching first-party session cookie, plus any current-session UTM or referrer attribution.
Guest connect context is not an account and is not proof that a Sleeper username belongs to you. You can clear it by using the disconnect action or by clearing this browser’s site data. Clearing site data also ends the current launch-analytics session. Vercel Web Analytics is designed not to use advertising cookies.
How long we keep information
There is no self-serve account-deletion button in the product today. In practice we keep account, wallet and league-analysis records while they are needed to provide the service and keep the ledger accurate.
AI conversations. We keep the text of your questions and the AI’s answers for about 90 days. After that the text is removed from the conversation record automatically. If you flagged an answer, or we are actively looking into a conversation, we keep that one for as long as the review is open and for up to a further 90 days after it closes, then remove the text in the same way. We keep the non-text record described above — timings, costs, which feature the question came from, and quality outcomes — for longer, so we can see whether the AI is improving.
Guest data in this browser stays until you clear it. Feedback reports are kept while the issue is open and afterwards as a record of what was fixed. Some operational caches (for example market movement used in lineup context) expire automatically after a short period.
To ask us to delete or correct account data, email pj@secondgm.com.
Security
We use HTTPS, access-controlled hosted databases, and signed-in checks for account, payment and Ask SecondGM routes. Guest tools still talk to our servers and are rate-limited. No internet service is perfectly secure. Do not send secrets through feedback or Ask SecondGM.
International processing
SecondGM Ltd is a United Kingdom company. Some processors are outside the UK, including services in the United States (for example Stripe, OpenAI, Resend, Google, and Sleeper) and MET Norway in Norway. Vercel hosts the production site in Dublin. Where a processor is outside the UK, we rely on that provider’s published transfer safeguards. Using the service means your information may be processed in those places.
Your rights
If UK GDPR applies to you, you can ask us for a copy of your information, to correct it, to delete it, to restrict or object to certain processing, or to receive an export of information you provided. You can also complain to the Information Commissioner’s Office. Email pj@secondgm.com and we will handle the request ourselves.
The service is aimed at people who already manage a fantasy football league. It is not directed at children.
Changes
We will update this notice when the product’s data practices change. The date at the top of the page is the latest revision (19 August 2026).
Related: Terms of use.