Browser Extension Privacy Policy

Last updated: September 5, 2026

This policy covers the Commish HQ browser extension only. Use of the Commish HQ website and service is covered by our Privacy Policy and Terms of Service.

The extension exists for one reason: ESPN only permits reading a private fantasy league with the session from a signed-in browser, and that session expires. The extension supplies it so your league keeps working.

1. What the extension reads

Exactly two cookies from fantasy.espn.com: espn_s2 and SWID. These are the authentication values ESPN itself uses to identify your signed-in session.

It reads no other cookie, from ESPN or from any other website. It writes no cookie and deletes none. It does not read page content, and it has no content scripts, so it cannot read, change, or inject anything into any page you visit — including pages on espn.com. It does not access your browsing history, bookmarks, downloads, or the contents of other tabs.

2. How it is used

The two cookie values are sent to your own Commish HQ account and used solely to read the ESPN leagues you commission: rosters, matchups, standings and transactions. Access to ESPN is read-only. The extension cannot make trades, set lineups, change league settings, drop or add players, or post anything on your behalf.

3. When it transmits

The extension contacts exactly one server, commishhq.ai, over HTTPS. It never contacts any other destination, and contains no analytics, telemetry, advertising, or remotely-loaded code.

It checks roughly twice a day and transmits only when there is a reason to: the cookie values have changed since the last successful send, or one of your leagues has stopped working and needs a fresh session. An unchanged session on healthy leagues is not re-transmitted.

During league setup, the Commish HQ website may ask the extension for the session so you do not have to copy it by hand. Only commishhq.ai can make that request; the restriction is declared in the extension’s manifest and enforced by the browser, not by our own code.

4. Storage and retention

In your browser, the extension stores its own Commish HQ access token, the timestamp of its last check, and the last values it successfully sent so it can avoid sending them again. This is held in the browser’s extension storage and never leaves your machine except as described above.

On our servers, the ESPN session is encrypted at rest and retained only while you keep the league connected. Deleting the league, or revoking the install, removes it.

5. Sharing, sale, and advertising

We do not sell your authentication information or league data. We do not share it with third parties, and we do not use it for advertising, profiling, credit assessment, or anything unrelated to running your league in Commish HQ.

6. Chrome Web Store Limited Use

Our use of information received from the extension adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Data is used only to provide and improve the single purpose described above, is not transferred except as required to operate the service or to comply with law, is not used for advertising, and is not used to determine creditworthiness or for lending purposes.

7. Your choices

Remove the extension at any time from your browser’s extensions page — that deletes everything it stored locally. You can revoke an individual browser without uninstalling it, under Settings → Connections in Commish HQ. Signing out of ESPN invalidates the session the extension holds. Deleting a league removes the stored credentials for it.

8. Contact

Questions about the extension specifically? Email support@commishhq.ai.