Privacy Policy
Last updated: March 10, 2026
This Privacy Policy describes how MyMadden ("we", "us", or "our") collects, uses, and stores information when you use our website and mobile application (collectively, the "Service"). By using the Service you agree to the practices described below.
1. Information We Collect
Account Information
When you register for an account we collect your name, email address, and a hashed password. Your password is never stored in plain text.
Discord Account
If you choose to link your Discord account via OAuth we collect your Discord user ID and avatar URL. Linking Discord is optional and is used to power Discord bot notifications for your league. We do not access your Discord messages or any private Discord data beyond your public profile.
EA / Madden Sync Credentials
Commissioner sync requires authenticating with Electronic Arts. We perform an OAuth token exchange with EA's servers to obtain a temporary access token. We never store your EA email or password. The access token is used only to read your Madden franchise export and is discarded after each sync cycle.
League & Game Data
We store the Madden franchise data you sync through the Service, including standings, team stats, player stats, schedules, and trade history. This data is associated with your league account.
Usage & Log Data
Like most web services, our servers automatically record standard access logs including IP address, browser / device type, referring URL, and pages visited. These logs are used for security monitoring and operational purposes and are not shared externally.
2. How We Store Your Data
Server-Side Storage
Account information and league data are stored in a secured database on our servers. Access is protected by authentication and encrypted connections (HTTPS/TLS).
On-Device & Browser Storage
When you log in, an authentication token is stored locally on your device or browser to keep you signed in between sessions. This token is used to authenticate subsequent requests and is never shared with third parties. A copy of your basic profile (name, email, avatar, and roles) is cached locally and is cleared when you log out.
Cookies
The Service uses token-based authentication and does not rely on persistent login cookies. Our backend may set short-lived cookies for CSRF protection on certain requests, but no persistent tracking cookies are used.
3. How We Use Your Information
- Provide, maintain, and improve the Service
- Authenticate you and keep your account secure
- Sync your Madden franchise data and display it within the Service
- Send league notifications via Discord or GroupMe if you have configured those integrations
- Respond to support requests or inquiries you send us
- Monitor for abuse, security incidents, and technical errors
We do not sell, rent, or trade your personal information to third parties for marketing purposes.
4. Third-Party Services
Discord
Discord OAuth is used to link your Discord identity. We access only your public profile (user ID and avatar). Discord's own Privacy Policy governs data Discord holds about you.
Electronic Arts (EA)
EA OAuth is used solely to read Madden franchise export data. We do not store EA account credentials. EA's Privacy Policy governs data EA holds about you.
GroupMe
If you configure GroupMe notifications, we use your GroupMe Bot ID to post league updates. We do not access your GroupMe messages or contacts.
5. Data Retention
We retain your account information and league data for as long as your account is active or as needed to provide the Service. If you request deletion of your account, we will remove your personal information within a reasonable timeframe, subject to any legal obligations to retain certain records.
6. Security
We use industry-standard security measures including HTTPS/TLS encryption in transit, hashed passwords at rest, and token-based authentication. No method of electronic transmission or storage is 100% secure, however, and we cannot guarantee absolute security.
7. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us and we will delete it.
8. Your Rights
You may request to access, correct, or delete the personal information we hold about you at any time by contacting us. You may also unlink your Discord account from your Account Settings page at any time.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date at the top of this page. Continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
10. Contact Us
If you have any questions or concerns about this Privacy Policy or how we handle your data, please contact us at: