THE COLLEGE FOOTBALL REFERENCEIndependent. Data driven. Always curious.

Policy updated October 10, 2026. Publisher: CF Reference.

Public statistics and searches

The application stores public football datasets and retrieval records in a server database. Search terms are sent to the server and, for player searches, to CollegeFootballData. A normalized query may be cached to reduce duplicate requests. Avoid entering private personal information into the search field. The named provider and collection time appear with each data section.

Google advertising and cookies

Advertising is currently disabled. When configured and enabled, Google AdSense and its advertising partners may use cookies or similar technologies and process device identifiers, IP addresses, browser information and advertising interactions to deliver, measure and personalize advertising where permitted.

Google’s certified consent service manages applicable European and US privacy choices. Our integration waits for confirmed consent signals or a confirmed inapplicable status before requesting Google ads. Missing or denied consent and Global Privacy Control block those requests. Google and its partners maintain their own privacy notices and retention policies. See how Google uses information from partner sites and Google’s ad controls.

Your advertising choices

Google advertising is currently disabled. No AdSense or advertising-consent scripts are loaded by this site while advertising remains disabled.

Direct sponsorships and downloads

Direct sponsorships use contextual placements without tracking pixels or third-party advertising scripts added by CF Reference. Advertiser links are identified as paid links and take you to a separate website governed by that site’s privacy policy. CSV reports are generated in your browser from the displayed table. This application does not add a third-party audience analytics service.

External assets and hosting

Team logos, player photographs and news images may load from a provider’s image host, which receives the corresponding network request. Hosting infrastructure and data providers may process network information and retain operational logs under their own policies. Private access uses the hosting platform’s sign-in and access controls; its authentication cookies are managed by that platform.

Administration and retention

Administrator identity is verified through the hosting platform. A secure, HttpOnly, SameSite CSRF cookie protects administrative writes and expires after one hour. Administrative actions retain an audit record for 180 days. Request limits store hashed rate-limit identifiers with short expiry. Provider data is cached by resource; public facts and source revisions may remain in the reference archive. API credentials are excluded from exports and stored as server secrets or encrypted integration overrides.

Questions and corrections

Each data section links to its source, and Wikipedia adaptations include revision and license attribution. You can inspect our sources and correction methodology and advertising policy.