This policy explains what After The Timeout collects about you, why, who else handles it, how long we keep it, and how to delete it. It covers afterthetimeout.com and app.afterthetimeout.com.
After The Timeout ("ATO," "we," "us") is a sole proprietorship based in North Carolina, USA. Our Terms say who runs it.
- We collect what we need to sign you in, take your subscription payment, and run the tools. That is mostly your email address and what you put into the tools.
- Your card details go to Stripe. We never see or store your full card number.
- We do not sell your information, and we do not run ads or share data with ad networks.
- We use Google Analytics and PostHog to see which pages and tools get used, and how people get from a first visit to signing up and subscribing.
- You can delete your account and its data yourself from My Account.
1. What we collect
When you create an account or sign in
You can sign in to app.afterthetimeout.com three ways: with Google, with a one-time sign-in link we email you, or with an email and password. Depending on which you use, we store:
- Your email address, and a username if you choose one.
- Your password, but only in hashed form. A hash is a scrambled version that cannot be turned back into the password. We never store the password itself.
- If you use Google: Google sends us your email address and a Google account ID number. Google also shares your basic profile, such as your name, during sign-in, but we do not store it. We use the ID to recognize you next time. We never receive your Google password.
- Sign-in records: when your account was created, when you last signed in and were last active, and how you signed in.
- Session records: a record that you are signed in on a browser, and when it expires. Sessions last 30 days. We store only a hashed copy of the session token, not the token itself.
- Sign-in link requests: when you ask for an emailed sign-in link, we record the email address, the time, and the IP address the request came from. Links expire after 15 minutes and work once.
When you subscribe
- Payment happens on Stripe's checkout page. Stripe collects your card and billing details. We do not receive your full card number.
- Stripe sends us back a customer ID, a subscription ID, and your subscription status (for example active or cancelled). We store those so we know which tools to unlock.
What you put into the tools
Some tools save your work to your account so it is there next time. This can include:
- Your own player rankings, projections, and notes.
- Exposure or draft files you import from fantasy sites, which can include tournament names, entry fees, and the picks you made.
- Saved simulations, draft logs, and the contests or tournaments you select.
- Display settings, such as your color theme and preferred sport.
If you join our email list
If you enter your email in a signup form on afterthetimeout.com without making an account, we store the email, which page or form you used, your browser's user-agent string (the browser and device type), and a salted hash of your IP address. We keep the hash, not the IP address, so we can stop spam signups.
If you reached the site from one of our own campaign links (for example a link in our TikTok or Instagram bio), we also store that link's campaign labels, the page you first landed on, and when you arrived, so we know which post brought you. The same labels are saved on your account and passed to Stripe with your checkout if you create an account or subscribe within 30 days. See the ato_attr cookie in our Cookie Policy. This does not depend on analytics and does not identify you on its own.
If you use a draft room
Draft rooms are for playing with friends and do not need an account. We store the name you type, the room code, the room settings, and the picks made. Anyone with the room code can see the room, so do not use a name you want kept private.
Collected automatically
- Security and rate limiting. The app briefly records IP addresses to stop people from flooding it with requests. These records are deleted once the time window they cover has passed.
- Analytics. Google Analytics collects information about your visit, such as pages viewed, rough location (city or region), device and browser type, and how you arrived. See section 4.
- Product analytics. PostHog records the pages you view and the links and buttons you click, with your device and browser type and rough location. Once you sign in, it links that activity to your app account ID, not your email, so we can see how people move from the site into the app. We do not use its session recording. See section 4.
- Server and network logs. Our hosting and security providers (NameHero and Cloudflare) keep standard request logs, which include IP addresses, under their own policies.
Kept only in your browser
Some tools save things in your browser's local storage instead of on our servers, for example your favorite DFS lineups or your progress on a college football draft board. We cannot see that data, and clearing your browser storage removes it. The Cookie Policy lists these items.
What we do not collect
We do not collect your precise location, your contacts, government ID numbers, or logins for any sportsbook or fantasy site. ATO does not take bets or hold money, so we have no betting account or balance for you.
2. How we use it
| Purpose | What we use |
|---|---|
| Sign you in and keep you signed in | Email, password hash, Google account ID, session records, sign-in link records |
| Unlock the tools you pay for | Stripe customer and subscription IDs, subscription status |
| Run the tools and save your work | Rankings, notes, imported files, simulations, draft logs, settings |
| Send sign-in links and account notices, such as a password change alert | Email address |
| Keep the service secure and stop abuse | IP addresses, sign-in records, request logs |
| See which pages and tools get used, so we can improve them | Google Analytics and PostHog data |
| Email people who joined the list about ATO | Email list signups |
We have not emailed the list yet. Every list email we send will include a working unsubscribe link, and you can ask to be removed at any time at [email protected].
We do not use your information to make automated decisions about you, like what you pay or whether you get access. Those follow the same fixed rules for everyone.
3. Who else handles your information
We do not sell your personal information. We do not share it for advertising. We share it only with the companies that help us run ATO, and only what each one needs:
| Company | What they do for us | What they receive |
|---|---|---|
| Stripe | Payments, subscriptions, and the "Manage or cancel" billing portal | Your email, your user ID, and the payment details you give them |
| "Continue with Google" sign-in; Google Analytics; web fonts | Sign-in requests you start; visit data from pages with analytics; your IP address when your browser loads fonts | |
| PostHog | Product analytics: which pages and tools get used, and how visitors move from the site to signing up and subscribing | Pages viewed, clicks, device and browser details, rough location from your IP address, and your app account ID once you sign in. Never your email, name, or payment details. |
| Cloudflare | Delivers both sites and screens out attacks | All traffic to the sites passes through Cloudflare, including IP addresses |
| NameHero | Hosts the sites and the account database, and the mailbox that sends sign-in emails | The data stored in our database and the emails we send |
| Neon | Database for email list signups and draft rooms | Email list and draft room data described above |
| Google Cloud | Runs the DFS simulation and lineup engine (Cloud Run) | The slate and lineup settings you send it, and your IP address, because your browser contacts it directly. No account details are sent. |
We may also share information if the law requires it, to protect people or the service from fraud or harm, or as part of a sale or transfer of ATO. If ATO changes hands, this policy keeps applying to data collected under it unless you are told otherwise first.
Public pages and crawlers. Our public pages can be read by search engines and AI crawlers. Your account data, saved work, and billing details are never on public pages.
4. Analytics
PostHog
Pages on afterthetimeout.com and app.afterthetimeout.com load PostHog. It gives your browser a random ID in a first-party cookie shared by both sites, so a visit to the site and a later sign-up in the app show up as one path. After you sign in, that path is linked to your app account ID. We use it to find where people get stuck, not for advertising, and we do not record sessions.
To stop PostHog, choose "Essential only" on our cookie banner (it applies to both sites), turn on your browser's Global Privacy Control or Do Not Track setting, or block cookies for our sites.
Google Analytics
Most public pages on afterthetimeout.com, plus the app's home page, landing page, and draft room, load Google Analytics 4. It uses cookies to tell visits apart and reports numbers to us in totals, like how many people used a tool this week. We do not use it for advertising and have not linked it to ad products.
To stop Google Analytics on our sites, choose "Essential only" on our cookie banner (it applies to both sites) or block its cookies in your browser. To stop it on every site that uses it, install Google's official opt-out browser add-on at tools.google.com/dlpage/gaoptout.
Neither PostHog nor Google Analytics loads, sets a cookie or sends anything until you choose "Accept" on the cookie banner. If your browser sends a Global Privacy Control or Do Not Track signal, we treat that as "Essential only" without asking. You can change your choice at any time from "Cookie settings" in the Help menu.
5. How long we keep it
- Account and saved tool data: until you delete your account.
- Sessions: they stop working after 30 days or when you sign out. Expired session records and sign-in link records, including the IP address that asked for the link, are deleted automatically once they have been expired for 90 days.
- Rate-limit records: deleted automatically once the time window they cover has passed.
- Email list signups: until you ask us to remove you.
- Analytics: PostHog keeps event data for 1 year. Google Analytics keeps event data for no more than 14 months, the longest period Google allows.
- Billing records: Stripe keeps payment records for as long as it and we must by law, even after you delete your ATO account.
- Backups: we copy the account database before each update to the service and keep those copies on a private, access-restricted system we control. Those copies are deleted automatically once they are about 30 days old, so a deleted account can remain in them for about a month.
6. Deleting your data
Your account. Sign in, open My Account, and choose to delete your account. You will be asked to confirm. If you have a subscription that is still set to renew, cancel it first with "Manage or cancel". Deleting the account removes your account record, your sessions, your sign-in link records, and everything you saved in the tools, and it clears the sign-in cookies on that browser.
What account deletion does not remove: Stripe's billing records, Google Analytics data (which is not tied to your name or email), PostHog analytics linked to your account ID, and email list signups. Contact us and we will delete the PostHog data too.
Email list signups. Go to afterthetimeout.com/account/ and use the delete form, or contact us.
7. Your choices and rights
Wherever you live, you can ask us to tell you what personal information we hold about you, give you a copy, correct it, or delete it. Contact us using the details below. We may need to confirm the request comes from you, usually by replying from the email on the account. We do not charge for this and will not treat you differently for asking.
Some US states and other countries give you added rights, such as appealing a decision we make about your request. We will honor the rights that apply to you. Because we do not sell or share personal information for advertising, there is nothing to opt out of on that front.
ATO is run from the United States and built for US users. If you use it from somewhere else, your information is stored and processed in the US.
8. Age requirement
ATO is for adults. You must be at least 18 to make an account. We do not knowingly collect personal information from children under 13. If we learn we have, we delete it.
9. How we protect your information
Both sites use HTTPS. Passwords and session tokens are stored only as hashes. Sign-in links expire in 15 minutes and work once. The sign-in session cookie only works on our own app site and cannot be read by scripts on the page. No system is perfectly secure. If a breach puts your information at real risk, we will tell you and explain what happened.
10. Changes to this policy
If we change this policy, we will update the date at the top. If a change affects how we use information we already have, we will email account holders before it takes effect.
11. Contact
Email: [email protected]