MFL Sideline — Privacy Policy
Last updated: 4 September 2026
MFL Sideline is an unofficial Android app for viewing and managing your own MyFantasyLeague teams. It is not affiliated with, endorsed by, or connected to MyFantasyLeague, the NFL, or any NFL team.
This policy describes every piece of data the app touches. It is short because the app does very little: it talks to MyFantasyLeague on your behalf and stores the answers on your phone.
The short version
- The app sends your MyFantasyLeague username and password to MyFantasyLeague only, once, when you sign in.
- Your password is never stored on the device.
- Everything else the app holds is a local cache on your phone.
- There is no analytics, no advertising, no tracking, and no third-party service of any kind.
- No data is sent to the developer. There is no server; the app has no backend to send it to.
What the app sends, and to whom
The app communicates with exactly one destination: MyFantasyLeague's servers, over HTTPS.
When you sign in, your username and password are sent to MyFantasyLeague's login endpoint in the body of an HTTPS request. MyFantasyLeague returns a session cookie. Your password is used for that one request and is then cleared from memory — it is not written to disk, not logged, and not retained, whether the sign-in succeeded or failed.
Afterwards, the app sends that session cookie with requests for your league, roster, scores, schedule and player information, and — when you submit a lineup — sends the lineup you chose. These are the same requests MyFantasyLeague's own website makes.
The app identifies itself to MyFantasyLeague with a registered client name and the app version.
Your use of MyFantasyLeague remains governed by MyFantasyLeague's own privacy policy and terms, which this app does not alter.
What is stored on your device
Your session cookie. Encrypted with an AES-GCM key generated in, and held by, the Android Keystore. The key never leaves your device and is not included in any backup. The cookie is what keeps you signed in.
A cache of the fantasy data the app has fetched, in a local database: leagues, franchises, rosters, players, projections, scores, standings, matchups, injuries, the NFL schedule, and the scoring rules your league uses. This exists so the app opens quickly and keeps working when you have no signal. It is a copy of information MyFantasyLeague already holds.
Your display preferences, such as theme, text size, density and reduced motion.
All of this is stored in the app's private storage on your phone. Automatic cloud backup is disabled for the app, so none of it is copied to Google's servers.
What the app does not do
- It does not collect analytics or usage statistics. No analytics library is included in the app at all.
- It does not show advertising and does not read an advertising ID. The advertising-ID permissions are explicitly removed from the app's manifest.
- It does not include crash reporting or any third-party SDK.
- It does not request your location, contacts, camera, microphone, files, or any other device permission. The app requests exactly two permissions: internet access, and the ability to see whether you are online.
- It does not create an account with the developer. There is no account to create.
- It does not sell, share, or transmit your information to anyone.
Children
The app is not directed at children under 13 and does not knowingly collect information from them.
Deleting your data
Sign out removes the session cookie, deletes the Keystore key that encrypted it, and clears the cached league data from your device.
Uninstalling the app removes everything the app has stored.
Because the app has no server, there is nothing held elsewhere that could need deleting. To delete your MyFantasyLeague account or the data MyFantasyLeague holds, contact MyFantasyLeague directly.
Changes to this policy
If this policy changes, the updated version will be published at this address and the date at the top will change.
Contact
Questions about this policy: apps@dccb-enterprises.com