← NineDraft

Privacy Policy

ESPN auction-draft assistant · Last updated 2026-10-05

What this extension does

NineDraft reads the live data stream of an ESPN auction fantasy draft while you are on an ESPN draft page, and turns it into real-time bid/pass guidance. To do that it observes the WebSocket messages the ESPN draft page already exchanges (nominations, bids, the clock, and sales) and forwards a normalized version of them to its configured receiver.

What data is handled

The extension's content scripts run on ESPN domains — it reads and acts on your live auction-draft page. The extension also declares a small content script on the war-room site. Builds from the current source cover ninedraft.ai — where the service is served today — and alphadraft.ai, the earlier address for the same service (a browser asking it for a page is sent here, though this policy still answers there too); the developer / side-load build additionally covers the legacy war-room address draft.ninetalents.com. Its job is to be the messenger between your own signed-in war-room page and the extension: it carries the connection messages described above — the forwarding-credential handoff and its status, and the draft-capture authorization — and, when you turn on the optional in-page overlay, the short-lived overlay access token you enable there. It runs only on our own site and reads no other website's content. The only non-ESPN addresses the extension can reach are the receiver destinations for the draft data it forwards: a local receiver on your own computer (loopback) or the hosted war room — which one is the default depends on how you installed the extension (see below). The first time it runs after you install it, the extension sends that same receiver one empty message — no account, no identifier of ours, nothing about you or the page you are on, and no more request metadata than any web request carries — so we can count how many installs there are; if it cannot be delivered, nothing is retried and nothing is kept. It does not track your browsing, contains no analytics or advertising SDKs, and the extension itself does not collect your name, email, contacts, location, or financial information.

Where the data goes (this is the important part)

Where the extension forwards your draft events depends on how you installed it. (If the extension's options page offers only a hosted receiver, you have the Chrome Web Store build; if it offers both a local and a hosted receiver, you have the developer / side-load build.)

  1. Chrome Web Store build — the default destination is the hosted war room. The published package is preconfigured to forward draft events to the hosted war room at https://alphadraft.ai, and it carries the site permission it needs to do that as a declared permission of the package — Chrome asks about it while it installs the extension, in the same prompt as the ESPN access, so there is no separate permission click afterwards. Forwarding is enabled by default, so a draft you open on ESPN is sent to and stored by the hosted service, as described under "Storage and retention" below. The extension reads only ESPN pages and our own war-room site — and the options page's "POST captured frames to the receiver" checkbox switches the forwarding off, after which it sends no draft events or snapshots. (Draft capture you separately authorize for a war-room room is its own stream on its own credential, described above, and is not governed by that checkbox.) Chrome's own site-access controls can also withhold the permission. The Store build does not include the local-receiver option.
  2. Developer / side-load build — the default destination is your own computer. The beta / developer build is preconfigured to forward draft events to http://127.0.0.1:8971 — a server running on your own computer (the loopback address). If you have not started that local receiver, nothing is received and nothing leaves your machine. This build sends to the hosted war room only if you switch the receiver to "Hosted" and grant the hosted site permission. Older side-load builds configured for the legacy war-room address (draft.ninetalents.com) keep working — it is the same hosted service, which answers at every one of these addresses.

What the defaults are, per build: event forwarding is enabled by default in both builds, but the default destination differs. In the Chrome Web Store build the default destination is a remote server (alphadraft.ai), which the package is permitted to reach from the moment you install it; a draft you open is forwarded there unless you switch forwarding off. In the developer / side-load build the default destination is your own computer (loopback), and no draft data is transmitted off your device unless you switch to the Hosted receiver and grant that permission.

Raw capture (off by default, local only)

The options page has an optional "Capture the raw frame stream" toggle used for diagnostics. It is off by default, and the extension structurally refuses to send raw frames to any non-local address — raw capture only functions when the receiver is the loopback address, and that setting is stored locally and is never synced to other devices. (Because the Chrome Web Store build has no local receiver, raw capture cannot send anywhere in that build.) This guard exists because a raw frame can embed session/room material.

Signing in to the hosted war room (Google)

The hosted war-room service (at alphadraft.ai and ninedraft.ai, which are the same service) is access-controlled, so if you opt into it you sign in with Google. We request the standard, non-sensitive sign-in scopes openid email profile — that is your email address and basic profile (your name and profile picture), which we use to identify your account and gate access. We do not request access to Gmail, Google Drive, your contacts, your calendar, or any other Google data. The browser extension itself does not sign you in and requests no Google permissions.

Storage and retention

How the data is used

Solely to provide the draft-assistant functionality: turning the live draft into bid/pass guidance for you, and (for the hosted service) identifying your account so your war room is yours.

Usage analytics

To understand whether the site is reaching and helping people, we keep a small amount of first-party, aggregate usage analytics on our own servers. We never use advertising-company analytics (such as Google Analytics), and we set no tracking cookies.

We also use Umami, a privacy-focused, cookieless analytics service, hosted for us by Umami Cloud, to measure how the site is used. Umami sets no cookies and stores nothing in your browser, and we send it no account identity. For each page view or usage milestone it receives standard web request data — the address and title of the page on our site (our configuration strips any query parameters), the campaign label of the link that brought you when it carries one (the standard utm_source, utm_medium and utm_campaign tags, and nothing else from the address), the referring site, your browser, operating system, device type, screen size, and language, and — like any web server — your IP address, which it uses to derive an approximate location and to distinguish visits using rotating, anonymized identifiers computed on its servers (never placed in your browser; the provider states it does not store the IP address itself). We use the resulting statistics to understand aggregate usage, never for advertising or to identify you. Shared-link pages send a category such as /s/playoffs instead of their access link, plus the public league ID and name, share type, live or frozen status, season, week, standings view, and team names for trade offers, where available. We count opens and actions such as opening that league; the link’s access code is never sent to analytics. For exactly how the service processes this, see Umami’s privacy policy.

What we keep on our own servers are aggregate counts — plus, only so we can de-duplicate (count an account once), a one-way, salted digest we cannot reverse back to the underlying id. For these counts we never store the raw ids themselves (what you do in a draft's war room is kept with that draft's records instead, with your account attached — see "Storage and retention" above):

AI-generated explanations (optional)

Some hosted war-room features use an AI provider (Anthropic) to put the engine's reasoning into plain English. The recommendation itself is always made by our own deterministic engine, not the AI. These features only run when the hosted service is configured for them; if it is not, nothing is sent to any AI provider. Three paths use it:

What we never do

Affiliation and trademarks

NineDraft is an independent tool compatible with ESPN Fantasy. It is not affiliated with, endorsed by, or sponsored by ESPN, The Walt Disney Company, or the National Football League. "ESPN" is a trademark of its respective owner and is used here only nominatively, to describe what the tool is compatible with — not to imply any partnership. The tool reads the draft data shown in your own authenticated ESPN session, on your behalf; it does not circumvent ESPN's access controls or speak for ESPN.

Changes

Material changes to this policy will be reflected here with an updated "Last updated" date.

Contact

Questions or deletion requests: support@ninedraft.ai.