Dugout SuperstarsBeta

Privacy Policy

Last updated: July 3, 2026

This policy explains what Dugout Superstars (“we,” “us”) collects, why we collect it, and what choices you have. We run a small fan project for Mario Superstar Baseball netplay leagues — not a data broker.

What we collect

  • Account info: username, email address, and a hashed password (we never store plain-text passwords).
  • Profile info: your Rio/netplay display name, used to match uploaded game stats to the right teams.
  • Google sign-in: if you use Google OAuth, we receive your Google account ID and email from Google to create or link your account.
  • Discord sign-in: if you use Discord OAuth, we receive your Discord account ID, username, and email (when Discord provides it) to create or link your account.
  • League activity: game statistics you or your league upload, standings, schedules, trades, and other content you submit as part of running a league.
  • Technical logs: basic server logs (IP address, browser type, timestamps) needed to keep the site secure and debug problems.

Why we collect it

  • Create and secure your account.
  • Run leagues — schedules, stats, standings, playoffs, and news.
  • Send transactional email (password resets, notifications you opt into).
  • Generate AI-written league articles (“Inky”) when your commissioner enables them.
  • Process payments when that feature launches (handled by Stripe).

Cookies and sessions

We use an encrypted session cookie (via iron-session) to keep you logged in. This cookie is essential for the site to work. We do not use advertising or third-party tracking cookies.

We do not sell your data

We do not sell, rent, or trade your personal information. We only share data with the service providers listed below, and only as needed to run the site.

Third-party services

We rely on a few outside providers to operate:

  • Railway — hosts the application and database.
  • Resend — sends transactional email (password resets, notifications).
  • Google — optional OAuth sign-in.
  • Anthropic— powers Inky, our AI league reporter. When Inky writes an article, game and league context is sent to Anthropic's API to generate the text. Articles are labeled as AI-generated.
  • Stripe — will process payments when that feature launches. Stripe has its own privacy policy for payment data.

Each provider processes data under their own terms. We only send them what they need to perform their function.

How long we keep data

We keep your account and league data for as long as your account exists and the leagues you participate in need it. Server logs are rotated periodically. If we shut the project down, we will try to give reasonable notice.

Your choices

  • Update your profile info anytime on your account page.
  • Request deletion of your account and associated personal data by emailing us (see Contact below). League stats you contributed may remain in aggregate league records unless your commissioner removes them.
  • Opt out of Google sign-in by using a username/password account instead.

Children

The site is not intended for children under 13. We do not knowingly collect data from anyone under 13. If you believe a child has created an account, contact us and we will delete it.

Changes

We may update this policy as features change (for example, when Stripe payments go live). We will post the new version here with an updated date.

Contact

Privacy questions or data-deletion requests? Email lucasvonderheyde@gmail.com.

See also our Terms of Service.