ESPN auction-draft assistant · Last updated 2026-10-05
What this extension does
NineDraft reads the live data stream of an ESPN auction fantasy draft
while you are on an ESPN draft page, and turns it into real-time bid/pass guidance. To do that it
observes the WebSocket messages the ESPN draft page already exchanges (nominations, bids, the clock,
and sales) and forwards a normalized version of them to its configured receiver.
What data is handled
Draft event data from the active ESPN auction draft: nominated players, bid
amounts and the seats that placed them, the draft clock, and completed sales. This is
fantasy-sports gameplay data, not personal browsing history.
Draft context data read from the draft page to make the above usable: the
league ID, the team display names and team IDs in your draft, each team's budget and roster (the
player names, positions, and prices they've won), and the pre-draft dollar ESPN displays beside
the selected player and beside the available players listed in that room. Team/owner display
names are league-chosen
labels that can contain real names or usernames — this is the in-draft state visible to your
league, not your personal account data.
Your league's settings and team names/logos, read from ESPN as you — only
when you ask for it on the war-room site ("Choose from my ESPN leagues", or setting up a private
league), and, for a league you have already saved there, when you open that league's page on
ESPN so its draft date and any settings change stay current. For that second case the extension
first sends the league's id (the number in the ESPN address) to the war-room service to
ask whether it is a league you saved; for a league you did not save, nothing else is read from
ESPN and nothing else is sent. The extension makes these reads from your own browser with your
own ESPN session: it never reads, stores or sends your ESPN password or login cookie, and it
strips ESPN's member list, owner ids and account ids before anything leaves the extension. Team
names are whatever your league calls them and can contain real names or usernames, as above.
The one account-level value it keeps is ESPN's account identifier (the SWID), held
in the browser's session storage only so it can list your leagues, never sent to us, and
forgotten the next time you open ESPN fantasy signed out, or when Chrome closes.
Your league's in-season state, read from ESPN as you — when you click
"Connect ESPN" or "Read again" on a saved private league's Waivers or Draft tab on the
war-room site, and, for this season's saved private league, when you open that league's page on
ESPN (at most once every six hours per league while Chrome stays open, after the same saved-league check as above). The extension reads that league's current rosters (player ids, lineup slots and injury
status, and each player's fantasy point totals so far and ESPN's projections for him, as the league scores them), each team's waiver budget and pickup counts, the league's waiver/free-agent log for
the season's played weeks, and the league's own schedule and shape — each matchup period's
team scores and winner, the playoff and division settings, each team's division, and how many
managers ESPN lists for a team (a count only, never who they are) — and, on a click only, while the site holds
no finished record of that league's draft, its draft results: each pick's player id, the team that
took him, the price or the round and slot, and the draft's type, budget and date — from your own browser with your own ESPN session, and hands the page
those ids, counters, point totals and projections plus each team's league-chosen name (which can contain a real name or
username): no member list, owner ids, player names, scoring-category breakdowns or cookie. The war-room service
keeps that read beside the league you saved, as it keeps the daily read of a public league. Both
reads made while you are on ESPN (the settings above and this one) stop when you untick "Keep my
leagues current while I'm on ESPN" in the extension's options, or press "Disconnect" beside it on
your Account page.
A cached copy of the latest draft snapshot and a sold-player index, written to
Chrome's local storage on your own device so the war room can resume after a page
reload. These hold the draft-context data above; they live only on your machine and are cleared
when you remove the extension.
A short, bounded local retry queue of draft events awaiting forwarding, so a
brief network or relay hiccup doesn't drop picks. It is held in Chrome's local storage on
your device only (never synced), is capped in size, and is cleared when you remove the extension.
Events wait here when the receiver cannot be reached, and go out on the next successful
forward; with forwarding switched off, nothing is captured into it at all.
Your extension settings, stored by Chrome: the configured forwarding
destination (in the developer / side-load build you can pick Local or Hosted; the Chrome Web Store
build uses Hosted), whether forwarding is enabled, the optional raw-capture toggle, and the status
of the last forward.
An in-page overlay credential (only if you turn on the optional in-page
overlay): a short-lived, read-only access token and the war-room room id, written to
Chrome's local storage on your device only (never synced) so the on-page advice can
authenticate. It is never sent anywhere except as an authorization header to the war-room service
when fetching your own draft advice.
A war-room forwarding credential (only when you use the hosted war room
signed in): opening your war room while signed in connects the extension automatically — your
own signed-in war-room page hands the extension a room-scoped, per-account,
replaceable forwarding credential, which is then held in Chrome's local storage
on your device only (never synced;
web pages cannot read the extension's storage) and sent nowhere except as a request header to
the hosted war-room service, so the
draft events it forwards are attributed to your own account. Connecting replaces any
credential this room issued to another of your browsers; when a credential issued earlier is
still in force and this browser is not the one holding it, it asks you first instead of
connecting silently. The credential
is cleared when you remove the extension.
A draft-capture write credential and a local transition ledger (only if you
authorize draft capture for a war-room room from the hosted dashboard): authorizing issues the
extension a single-draft, room-scoped, expiring write credential, held in Chrome's
local storage on your device only (never synced) and sent nowhere except as an
authorization header to the hosted war-room service when forwarding that room's draft capture.
Alongside it the extension keeps a local ledger of the draft's lot transitions and a
queue of not-yet-acknowledged capture records (draft gameplay facts — which player's
auction opened or closed, in what order) so a browser or page restart cannot lose or reorder
them. The credential and ledger are readable only by the extension itself (never by web pages),
are replaced only through a fresh dashboard authorization, and are cleared when you remove the
extension. The extension uses Chrome's identity permission solely
to run that authorization redirect against our own service — it never requests, reads, or
receives your Google account identity.
The extension's content scripts run on ESPN domains — it reads and acts on your live auction-draft
page. The extension also declares a small content script on the war-room site. Builds from the
current source cover ninedraft.ai — where the service is served today — and
alphadraft.ai, the earlier address for the same service (a browser asking it
for a page is sent here, though this policy still answers there too); the developer /
side-load build additionally covers the legacy war-room address
draft.ninetalents.com. Its job is to be the messenger between your own signed-in
war-room page and the extension: it carries the connection messages described above — the
forwarding-credential handoff and its status, and the draft-capture authorization — and, when you
turn on the optional in-page overlay, the short-lived overlay access token you
enable there. It runs only on our own site and reads
no other website's content. The only
non-ESPN addresses the extension can reach are
the receiver destinations for the draft data it forwards: a local receiver on your own computer
(loopback) or the hosted war room — which one is the default depends on how you installed the
extension (see below). The first time it runs after you install it, the extension sends that same
receiver one empty message — no account, no identifier of ours, nothing about you or
the page you are on, and no more request metadata than any web request carries — so we can count how many installs there are; if it cannot be delivered, nothing
is retried and nothing is kept. It does not track your browsing, contains no
analytics or advertising SDKs, and the extension itself does not collect your name, email, contacts,
location, or financial information.
Where the data goes (this is the important part)
Where the extension forwards your draft events depends on how you installed it.
(If the extension's options page offers only a hosted receiver, you have the Chrome Web
Store build; if it offers both a local and a hosted receiver, you have the developer /
side-load build.)
Chrome Web Store build — the default destination is the hosted war room. The
published package is preconfigured to forward draft events to the hosted
war room at https://alphadraft.ai, and it carries the site permission it needs to do
that as a declared permission of the package — Chrome asks about it while it installs the
extension, in the same prompt as the ESPN access, so there is no separate permission click
afterwards. Forwarding is enabled by default, so a draft you open on ESPN is sent to and stored by
the hosted service, as described under "Storage and retention" below.
The extension reads only ESPN pages and our own war-room site — and the options
page's "POST captured frames to the receiver" checkbox
switches the forwarding off, after which it sends no draft events or snapshots. (Draft capture
you separately authorize for a war-room room is its own stream on its own credential, described
above, and is not governed by that checkbox.) Chrome's own site-access controls can also withhold
the permission. The Store build does not include the local-receiver option.
Developer / side-load build — the default destination is your own computer. The
beta / developer build is preconfigured to forward draft events to http://127.0.0.1:8971
— a server running on your own computer (the loopback address). If you have not
started that local receiver, nothing is received and nothing leaves your machine. This build sends
to the hosted war room only if you switch the receiver to "Hosted" and grant the hosted site
permission. Older side-load builds configured for the legacy war-room address
(draft.ninetalents.com) keep working — it is the same hosted service,
which answers at every one of these addresses.
What the defaults are, per build: event forwarding is enabled by default in both
builds, but the default destination differs. In the Chrome Web Store build
the default destination is a remote server (alphadraft.ai), which the package is
permitted to reach from the moment you install it; a draft you open is forwarded there unless you
switch forwarding off. In the
developer / side-load build the default destination is your own computer (loopback),
and no draft data is transmitted off your device unless you switch to the Hosted receiver and grant
that permission.
Raw capture (off by default, local only)
The options page has an optional "Capture the raw frame stream" toggle used for diagnostics. It is
off by default, and the extension structurally refuses to send raw frames
to any non-local address — raw capture only functions when the receiver is the loopback
address, and that setting is stored locally and is never synced to other devices. (Because the
Chrome Web Store build has no local receiver, raw capture cannot send anywhere in that build.) This
guard exists because a raw frame can embed session/room material.
Signing in to the hosted war room (Google)
The hosted war-room service (at alphadraft.ai and ninedraft.ai, which
are the same service) is access-controlled, so if you opt
into it you sign in with Google. We request the standard, non-sensitive sign-in
scopes openid email profile — that is your email address and basic profile (your name
and profile picture), which we use to identify your account and gate access. We do
not request access to Gmail, Google Drive, your contacts, your calendar, or any
other Google data. The browser extension itself does not sign you in and requests no Google
permissions.
Storage and retention
Settings are stored using Chrome's storage API on your device (non-sensitive
preferences in your Chrome profile sync; the raw-capture toggle in local storage only). In
addition, the latest draft snapshot and a sold-player index are cached in Chrome's
local storage on your device (never synced) so the war room can recover after a
reload — this is draft-context data, held locally, not personal account data. Chrome's local storage
also holds one timestamp recording that the first-run message above was delivered, so it is never
sent twice; it says nothing about you. You can clear all of
it by removing the extension.
The extension itself does not maintain a server-side database of your data. When the
Hosted receiver is used (the default in the Chrome Web Store build), the
NineDraft service stores the
room state needed to run and support your war room on its server: the draft events and snapshots
you forward, the engine's decisions, capture/health diagnostics, your account profile (your email
and Google display name), and the league setups you save. Your account also carries a small number of
first-time timestamps — when your browser first reported the extension present,
and when you finished the welcome steps — kept so the site does not walk you through setup again
on a second computer, and so we can count how many accounts got that far. This is retained while
you use the service and for support; you can request deletion via the contact below. You can turn
draft-data retention on or off from your account page — open it from your name
at the top of your signed-in home ("Keeping your drafts
to help improve this service"). An account created from an invitation, or an operator's own
account, starts with it on; an account created by signing in without an invitation
starts with it off. It applies to drafts connected to your account through a saved
league: while it is off, the service does not keep the draft records for those drafts from then on.
It does not reach a draft that is not connected to your account that way — a practice draft, or a
draft the extension forwards that was not matched to one of your leagues — which is kept whether the
switch is on or off. The draft records include what you do in a draft's war room, recorded with your
account attached when you are signed in; once you have turned the switch off yourself, that is not
recorded in any draft. It does not delete what was kept earlier (use the contact below for that) and
does not affect your account or saved league setups.
If you sign in with Google and your account has not been given access, we record your
access request — your email address, your Google display name, when you
asked, and which of our sites you asked at — so the operator can approve or decline it, and so
the reply reaches you naming the site you actually used. No account is created unless it is approved.
A request is kept until it is acted on, and afterwards as the record of that decision — except
that once a request has been approved — at which point your address is on the access list and
an account is created the next time you sign in — its record may be dropped as older entries age out. Ask via the contact below to have it deleted. The phone alert the operator receives about a new
request contains no personal data: it says only that someone asked, because it
travels through an outside push service. The operator is also emailed at their own address, and
that message does name you — your email address, and your Google display name when Google gave
us one — so the person deciding can see what they are deciding; it leaves through the same mail
provider that delivers our messages to you, and is then handled by whatever mailbox provider
serves the operator's own address, exactly as any email to them would be. It goes to no one
else.
When we email you that you have been approved or invited, we keep a
one-line record of how that send went: your email address, which of the two messages it
was, what our mail system answered (accepted, failed, or not sent at all), and when. It is
how the operator can see that somebody was let in and never actually told. It records the
send, not whether the message reached you — there is no read receipt,
open tracking or bounce record anywhere in this service. Only the most recent send is
kept, it is visible to the operator alone, removing your invite removes it, and it goes
with your account if you ask for deletion via the contact below.
Contest simulator — the players, salaries and slots from the entries file you
choose, your entries, and your projection's per-player figures are sent to NineDraft to run the
simulation, kept ten days so a finished contest can be graded against the run, then deleted. The
projection file's other columns, both files' names and DraftKings' instructions stay in your browser.
The page keeps the run's token and the two file names in your browser's local storage (the key
fah.dfsSim.run) so the result can be reopened; clearing this site's data removes it.
It also keeps the last entries file and projection file you brought, whole, in that same local storage
(the keys fah.dfs.entries and fah.dfs.projections) so your next visit can offer
them. A file older than six days is no longer offered and is deleted the next time either of the two
DraftKings pages is opened; Forget on the page, or clearing this site's data, removes them at once.
The service counts finished, failed and refused runs, with nothing else attached.
A finished contest's standings file is graded in your browser and never sent: it holds every entrant's
username. When you grade it with the send box ticked (it starts ticked), that contest's lineups and
ownership table are sent and kept without usernames or entry ids to improve the field model, for two years at
most; untick it
before grading and nothing is sent.
The Local receiver writes files on your own machine that you control entirely.
How the data is used
Solely to provide the draft-assistant functionality: turning the live draft into bid/pass guidance
for you, and (for the hosted service) identifying your account so your war room is yours.
Usage analytics
To understand whether the site is reaching and helping people, we keep a small amount of
first-party, aggregate usage analytics on our own servers. We never use
advertising-company analytics (such as Google Analytics), and we set no tracking
cookies.
We also use Umami, a privacy-focused, cookieless analytics service, hosted for us by Umami Cloud, to measure how the site is used. Umami sets no cookies and stores nothing in your browser, and we send it no account identity. For each page view or usage milestone it receives standard web request data — the address and title of the page on our site (our configuration strips any query parameters), the campaign label of the link that brought you when it carries one (the standard utm_source, utm_medium and utm_campaign tags, and nothing else from the address), the referring site, your browser, operating system, device type, screen size, and language, and — like any web server — your IP address, which it uses to derive an approximate location and to distinguish visits using rotating, anonymized identifiers computed on its servers (never placed in your browser; the provider states it does not store the IP address itself). We use the resulting statistics to understand aggregate usage, never for advertising or to identify you. Shared-link pages send a category such as /s/playoffs instead of their access link, plus the public league ID and name, share type, live or frozen status, season, week, standings view, and team names for trade offers, where available. We count opens and actions such as opening that league; the link’s access code is never sent to analytics. For exactly how the service processes this, see Umami’s privacy policy.
What we keep on our own servers are aggregate counts — plus, only so we can de-duplicate (count an
account once), a one-way, salted digest we cannot reverse back to the underlying
id. For these counts we never store the raw ids themselves (what you do in a draft's war room is
kept with that draft's records instead, with your account attached — see "Storage and retention"
above):
No page activity — our own servers do not count landing-page views, "Sign in"
clicks, reaching the signed-in app or seeing a draft recommendation, and the site keeps no
analytics id in your browser. Earlier versions of the service did:
a persistent local-storage visitor id (retired, and deleted if your browser still holds one) and then a temporary
session-storage session id (also retired and deleted the same way). The one-way digests of the
visitor id have been discarded. The aggregate counts and the per-day one-way digests of the session
id stay on our servers as they were, unread; no new ones are added. We store no IP address and no browser fingerprint as part of these analytics.
(Like any web server, our host may keep operational request logs, which can include an IP; those
are not part of these analytics and are not used to profile you.) Ordinary functional preferences
you set, such as the display theme, and a once-per-visit marker so a recommendation milestone is
sent at most once, are stored in your browser but are not identifiers and are never sent to us.
Shared lists — when you share a list by link from My League (a public ESPN
league's playoff odds), we keep a copy of that list as it stood — the league's name, team names
and crests, and the numbers on it; no manager or account field is copied, though a league or
team name is whatever the league chose and can itself name someone — tied to your account so a deleted
league or account takes it down, and one number per link: how many times its page was loaded.
No IP address, browser or time is kept with that count, and the page carries no analytics.
Withdrawing a link deletes its copy at once; otherwise it is deleted within a day of the link
expiring, 90 days after you made it, and only the two dates are kept for about 90 more days so
the page can say it expired. Your links go with your account if you ask for deletion.
DraftKings entries check — the file you choose on that page is read in your
browser and is never uploaded. For each file it reads, the page sends us three things: the
date of the slate's first game, whether the file could be read (or why not), and whether this
browser had read a different slate before. To answer that last one it keeps the date of the
last slate it read in your browser's local storage (the key fah.dfs.lastSlate;
clearing this site's data removes it). That date is not an identifier. The page also keeps
the last file it read, whole, in that local storage (the key fah.dfs.entries), so
your next visit — and the contest simulator — can offer it without choosing it again. A file
older than six days is no longer offered and is deleted the next time the page is opened;
Forget on the page removes it at once, and a kept file read again sends us nothing. We keep only the
counts, with no player, lineup, contest, IP address or time attached. We also count each
time the page is opened and each time its sample file is tried — a number per day, nothing
else. The page is open to anyone, so a repeat or a bot can inflate these counts.
Signed-in activity counts — how many distinct accounts were active on a given
day, how many leagues were created, how many drafts got going, and the aggregate outcome of
sign-in attempts (how many succeeded versus were turned away — for example because an email is not
yet invited). These are plain counts with no account attached to them. For the daily-active count we
store only a one-way, salted digest per day so we can count distinct accounts without keeping a list
of who was active; we surface only the totals.
Onboarding & reliability counts — how many times an ESPN league was looked
up to import it and the outcome (found, incomplete, or couldn't be read), an aggregate count
of extension "test connection" reachability pings, an aggregate count of first runs
(the empty message a newly installed extension sends once), and an aggregate count of how many
accounts reported the extension present for the first time. The league-lookup and
account counts come from signed-in
sessions, and the league-lookup ones count the lookup/preview step, not saved leagues; the
reachability ping and the first-run message are
unauthenticated, so a repeat or a bot can inflate them. All are
plain counts with nothing about you attached; they tell us whether onboarding is working.
AI-generated explanations (optional)
Some hosted war-room features use an AI provider (Anthropic) to put the engine's
reasoning into plain English. The recommendation itself is always made by our own deterministic
engine, not the AI. These features only run when the hosted service is configured for them; if it is
not, nothing is sent to any AI provider. Three paths use it:
The automatic one-line "why." Next to a recommendation, the service sends a
curated, allow-listed set of decision facts for the current player — projections,
your roster needs, and the market math the engine used — to phrase a single sentence. This
projection is structured to exclude your account identity and other managers' or
league display names, so that identity data is not sent.
The interactive advisor (only when you ask it). If you open the advisor to argue
a case for a player, the text you type is sent to the AI provider along with the
target bid and the same curated facts, so it can weigh your argument. Because this is free text,
treat it like any message to an AI service: don't type anything into it you wouldn't want
sent to the AI provider.
The in-season write-up (only when you press the button). Under a week's
review on My League you can ask for that week written up, and under the waiver claims you can
ask for the league's claims written up. Nothing is generated unless you press
it. What is sent for a week is that week's scores and the figures on that card — every
game's final score, and the top and bottom score, the closest game, the luckiest win and the
odds move. What is sent for the claims is that week's whole waiver activity —
every claim that went through and the biggest of the bids that did not, who dropped whom and on what day,
what each team has spent this week and this season and what it has left, and who did nothing at
all, with the totals worked out here. Either way the team names in your league and the
league's own name are sent with the figures, as are the public NFL player names where a
write-up names one. What is never sent: a manager's name (we do not collect
one), your account, a team id, or which team is yours. Today this runs on
public ESPN leagues only.
What we never do
We do not sell or rent your data.
We do not use it for advertising or to build advertising profiles.
We do not use advertising-company analytics (such as Google Analytics) or
tracking cookies — usage analytics are first-party aggregate counts on our own servers, plus a
cookieless privacy-focused analytics service if one is running. The
"Usage analytics" section above states whether one is running right now, and exactly what it
can see.
We do not transfer it to third parties except: the receiver the extension
forwards your draft data to; if a cookieless analytics service is running (see "Usage
analytics" above), the standard web request data it receives on each page view — including
your IP address — which that section enumerates in full; — only for the optional
AI explanation features described above — the data those features send to our AI provider (the
curated decision facts, plus the text you type if you use the interactive advisor, plus the
week's figures or the claim log's, with your league's and its teams' names, if you press for
an in-season write-up); and, when
we email you, your email address and the message itself — which greets you by the
name your Google account gave us, when we have one — to the mail provider that delivers it,
since that is the only way an email can reach you at all; that same provider also carries the
one message that tells the operator you asked for access, which names your address and, when we
have one, your display name, and which is then handled by the mailbox provider serving the
operator's address; and, when something in a live draft room needs the operator's attention —
the draft starting, or advice being withheld from it for several minutes — a short alert to the
push service that delivers it to the operator's phone, containing the room identifier (which
contains your league ID), whether the room is a league draft or a practice mock, whether it is
still receiving updates, and, for a withheld-advice alert, the reason and roughly how long it
has lasted. Those alerts carry no email address, no account identifier, and no player, roster,
bid or price data. There are two kinds of message we send to you, and no others.
About your access: a confirmation when you ask for access; a notice if you
are approved; if the operator puts your address on the access list without you asking, one
message telling you that you can sign in and how; and, if you signed yourself up or were
let in as a tester (rather than being approved or invited as above), one welcome message
when your first sign-in creates your account, saying what to set up first. (Asking again
later, being approved after an earlier decline, or being invited again after being removed
can produce another of those.) And, rarely, one you did not ask for: a
message to somebody who signed up and then stopped, asking whether something got in the
way. There is no newsletter and no mailing list to be added to. Both of the messages you
did not ask for — the unrequested invitation and that one — carry a link that
stops messages like them, and it works without signing in. Using that link, or telling us
by reply, records a one-way fingerprint of your address (a keyed hash) so a later message
of that kind can be checked against it before it is sent; that record is a hash, a
timestamp and how it was recorded, and holds no address and nothing anyone wrote. It is
kept even if you delete your account, because deleting it would let a later message reach
you again; messages about your own account are unaffected and still reach you.
We do not use it for any purpose unrelated to the single purpose stated above
(consistent with the Chrome Web Store Limited Use requirements).
Affiliation and trademarks
NineDraft is an independent tool compatible with ESPN Fantasy. It is
not affiliated with, endorsed by, or sponsored by ESPN, The Walt Disney Company, or
the National Football League. "ESPN" is a trademark of its respective owner and is used here only
nominatively, to describe what the tool is compatible with — not to imply any partnership. The tool
reads the draft data shown in your own authenticated ESPN session, on your behalf; it does not
circumvent ESPN's access controls or speak for ESPN.
Changes
Material changes to this policy will be reflected here with an updated "Last updated" date.