๐ Privacy Policy
Last updated: 27 September 2026
Who we are. FPL Quant is run by Waqas Hussain, the data controller for the personal data described here. Contact: [email protected].
What we collect
- Your email address, to identify your account and sign you in.
- Your password, as a bcrypt hash only. We never store or see the password itself.
- Your FPL Manager ID, and the public FPL data we fetch with it: your squad, transfers and chip history.
- Your planning data: saved transfer plans (including your most recent optimiser result, kept so it's still there after a reload), decisions and chip plays, and the squad and fixture preferences you set in the planner.
- Manager ID change requests, including the reason you give.
- Sign-in records: when each session started, was last used and expires. Signing in sets one essential, HttpOnly session cookie; Keep me signed in keeps it for 30 days instead of until you close the browser. There are no advertising or analytics cookies.
- Squad screenshots you choose to upload, read by Google Gemini to fill in your squad. We don't keep the image.
Why we use it, and the lawful basis (UK GDPR)
- To provide the service you signed up for: your account, and the optimisation outputs built from your squad. Performance of a contract, Article 6(1)(b).
- To keep the platform and your account secure: sign-in sessions, signing devices out, and preventing misuse. Legitimate interests, Article 6(1)(f).
- To stop a deleted account's FPL team being registered again: fraud prevention, anti-abuse and enforcing our terms. Legitimate interests, Article 6(1)(f). See Retired Manager IDs below.
We don't sell your data or use it for advertising, and we make no automated decisions with legal or similarly significant effects on you.
Who processes it for us
- Railway: hosts the application's backend.
- Cloudflare: serves this website and is the edge proxy and security in front of it.
- Supabase: the PostgreSQL database holding your account, hashed credentials and planning data.
- Google (Gemini API): reads a squad screenshot, only when you upload one.
Your Manager ID is also used to fetch public data from the official Fantasy Premier League API. Some of these providers may process data outside the UK; where they do, the transfer relies on UK adequacy regulations or the contractual safeguards in their data-processing terms.
How long we keep it
Until you delete your account. Ended and expired sign-in records are kept with the account and deleted with it.
Retired Manager IDs
When you delete your account, your personal identifiers are erased completely: your email address, password hash, sign-in records, planning data and preferences. The one thing kept is the numerical FPL Manager ID, which is retained indefinitely in an isolated blocklist of retired IDs, with nothing else attached to it (not your email, and no link to the deleted account), so that the same FPL team can never be registered again. We keep it under legitimate interests, Article 6(1)(f) UK GDPR: fraud prevention, preventing abuse, and enforcing our terms of service. You can object to this under Article 21; we'll weigh your objection against that anti-abuse purpose.
Your rights
You can access, correct, export or erase your data, and restrict or object to how it is used. Signed in, open Account:
- Export: Download my data gives you everything we hold about your account, as a JSON file.
- Delete: Delete my account erases your account, sign-in records, change requests and everything stored against your Manager ID, immediately and permanently. Only the retired Manager ID is kept, as described above.
- Correct: change your password in Account; a wrong Manager ID can be changed through Need to request a Manager ID change? there.
- Anything else, or if you can no longer sign in: email [email protected].
If you're unhappy with how we handle your data, you can complain to the Information Commissioner's Office at ico.org.uk.