Last updated: August 29, 2026. This is a baseline version describing our actual current data practices. A fuller legal review (including GDPR/CCPA/COPPA considerations) is planned, and this page will be updated as that happens.
When you create an account: your name, email, mobile number, and city/state. If you set up an Athlete Hub: whatever bio, stats, photos, recruiting details, and social links you choose to add. If you set up a Team: your organization's legal name, EIN, and contact details. If you're a brand contacting an athlete: your name, email, and brand information. If you use workout logging: the exercises, weights, reps, and other training data you choose to log. If you optionally add a photo to a logged workout: that photo, used only to generate a workout graphic for you to download or share, and not shown anywhere on your public Hub.
If you contact us, whether through our Contact page, a camp partnership request, or an account deletion request: your name, email, and the details of your message. You don't need an account to submit any of these.
We don't collect or store your payment card details directly. Subscription payments are handled entirely by Stripe.
We also automatically collect some basic technical data as you browse, like which pages are viewed and when. This includes a real-time, anonymous indicator of which pages are currently active, visible only to platform admins as an aggregate count, not tied to your name or account.
When you sign a brand partnership contract through the Partnership Hub, we also record your IP address, device/ browser information, and a timestamp, alongside the agreement itself. This is part of maintaining a real, legally defensible signature record for both sides, not general tracking, and it's only collected at the moment you sign.
The account holder managing an athlete's Hub must be 18 or older, even when the athlete herself is a minor. Any information entered on a minor athlete's Hub is entered at that account holder's discretion. We don't independently verify or moderate what's shared, so we rely on account holders to only share information they're comfortable being public.
To operate your account and the features you use: displaying your Hub, processing your subscription, sending you notifications and reminders you've opted into, and generating Social Media Captions from your activity when that feature is enabled. We also use aggregate browsing data to monitor site performance, catch and fix errors, and understand how the platform is being used. We don't sell your personal information.
We use a small set of service providers to run the platform: Supabase (database and file storage), Stripe (payments), Resend (email delivery), Cloudflare (video hosting), OpenAI (generating Social Media Captions), Vercel (hosting and privacy-friendly, cookieless site analytics), and Sentry (error and performance monitoring, so we can catch and fix problems). Each only receives what it needs to do its job. We don't sell or share your data beyond what's needed to operate the service.
We use a small number of cookies, all functional rather than for tracking or advertising: one to keep you signed in, and one that temporarily remembers a team's invite code while you finish creating your account, so you don't have to re-enter it. We don't use analytics or advertising cookies. If you view a highlight video on a Hub, that video is embedded from Cloudflare Stream and may set its own cookies as part of playback.
Your Athlete Hub is only reachable through a link you share yourself. There's no public search or directory anywhere on the platform. By default, your Hub also isn't indexed by search engines like Google; you can choose to turn that on in your Hub Builder settings if you want it discoverable that way. You can also set a password on your Hub for an additional layer of privacy; with a password set, visitors need it to view anything on your Hub at all.
You can update most of your information directly in your account and Hub Builder settings. You can control which sections of your Hub are public, opt in or out of email notifications, and control search engine visibility and password protection, all from your own dashboard.
You can request account closure or permanent deletion of your data at any time through your account settings. Requests are reviewed and processed manually, not instantly. Exactly what must be retained versus can be fully erased (for example, records tied to a completed brand partnership or a payment) is still being finalized as part of our legal review. We'll honor deletion requests as fully as we're legally able to. One exception: your username isn't released back for someone else to claim, even after deletion. It's not personal data on its own, and keeping it retired prevents someone else from later claiming a URL you may have already shared.
We may update this policy as the platform evolves. Material changes will be reflected here with an updated date.
Questions about your data or this policy? Reach out through our Contact page.
Pricing · FAQ · Blog · Athlete Guide · Team Guide · Contact us · Billing Policy · Terms · Privacy