Privacy Policy
Effective Date: July 28, 2026
Data Controller
Lorenzo Peluso (sole trader / ditta individuale, Italy)
Via Resistenza Partigiana 27/O, 97015 Modica (RG), Italia
P.IVA: IT01888280888 — REA: RG-485912
PEC: [email protected]
Contact: [email protected]
The controller is established in the EU (Italy), so no EU Article 27 representative is required. We have not appointed a UK representative under Article 27 of the UK GDPR. UK data subjects may contact us directly at [email protected] and we handle UK requests on the same terms and timelines as EU requests.
This Privacy Policy explains how Athly AI (“we,” “us,” or “our”) collects, uses, shares, and protects the personal data of users who access or use our AI-powered college sports recruiting platform at athlyai.com. We are committed to transparency and to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the Italian Data Protection Code, and other applicable data protection laws.
1. Information We Collect
1.1 Account & Profile
- Full name, email, phone number
- Date of birth & graduation year
- Nationality & country of residence
- Profile photo & action photos
- Account credentials (hashed)
1.2 Athletic Information
- Sport(s), position(s), jersey number
- Team name, years of experience
- Height, weight, physical stats
- Performance stats (goals, assists, etc.)
- Highlight videos & tagged clips
1.3 Academic Information
- GPA (native system + US conversion)
- SAT, ACT, TOEFL, Duolingo scores
- Intended major & field of study
- Academic honors & achievements
1.4 Recruiting Preferences
- Recruiting goal & scholarship importance
- Target divisions (NCAA, NAIA, NJCAA)
- Preferred regions & target schools
- Target start year for college
1.5 User-Generated Content
- Emails composed & sent
- Messages exchanged with coaches
- AI assistant conversations
- Email templates & drafts
- Video tags, clips & highlight reels
1.8 Device & Technical
- IP address & geolocation
- Browser type & operating system
- Device type & screen resolution
- Pages visited & time spent
- Referral source & UTM parameters
[email protected]). Coaches sending through our platform use addresses in the form [email protected]. We only send messages you explicitly compose and approve.gmail.send, alongside the two standard sign-in scopes openid and email (which tell us only which Google account you connected, so we send from the right address). We store the resulting OAuth refresh token, encrypted at rest, solely to send the specific messages you compose and approve. The gmail.send scope is send-only: it does not allow Athly to read, search, download, modify, or delete any message in your mailbox, and we do none of those things. Connecting Gmail is never required to use Athly. You can disconnect at any time in Settings → Gmail, which deletes the stored token; you may also revoke access directly at myaccount.google.com/permissions.Mail.Send, User.Read and offline_access scopes and store the resulting OAuth refresh token, encrypted at rest, solely to send the specific messages you compose and approve. These scopes do not permit reading, searching, or deleting mail in your mailbox, and we do none of those things. Connecting Outlook is never required. You can disconnect at any time in Settings, which deletes the stored token, and revoke access at account.microsoft.com.- The app password is encrypted at rest with AES-256-GCM and is never shown back to you or sent to the browser
- Fetched messages (sender, subject, body, timestamp) are stored in our database and analysed by our AI providers to classify and summarise athlete enquiries
- We never send from the connected mailbox, and we do not modify or delete anything in it
- Connecting a mailbox is entirely optional; you can disconnect at any time, which deletes the stored credential and the mirrored messages
- Because a mailbox may contain messages from people who are not Athly users, connect only a mailbox you are entitled to process this way
1.9 Email Engagement Data
For emails sent through the Platform, we track: delivery status, open counts & timestamps, click counts & timestamps, and reply detection.
2. College Coach Data
Our platform includes a database of college coaching staff to help student-athletes identify and contact potential coaches. This section explains how we handle that data.
2.1 What Coach Data We Hold
- Coach name and professional title/role
- Institutional email address (e.g. [email protected])
- Office phone numbers (where published on institutional staff directories)
- School/university name and athletics program
- Sport and division (NCAA D1, D2, D3, NAIA, NJCAA)
Personal mobile phone numbers are not collected. The phone numbers stored are office / staff-directory numbers as published by the institution itself.
2.2 Where Coach Data Comes From
Coach information is collected primarily from publicly available sources: official university athletics staff directory pages, publicly accessible school websites, and public athletic conference directories. We do not scrape coaches' personal social media accounts and we do not buy coach lists from consumer data brokers.
Third-party enrichment and verification. Where an institutional directory lists a coach by name and role but does not publish an email address, we may use Hunter.io (a B2B professional-email lookup service) to identify or confirm the likely institutional address at that university's domain, and we run automated checks (DNS/MX lookups and AI-assisted re-reading of the public directory page) to keep records accurate. We send Hunter.io only a coach's name and their institution's domain. No athlete or platform-user data is ever sent to enrichment providers. Coaches can object to this processing and be removed at any time (see 2.5).
Effective April 22, 2026, every newly-collected or refreshed coach record stores the source URL and timestamp of collection. Pre-existing records collected prior to this date do not carry per-record provenance metadata; the categorical sources for those records are the publicly accessible NCAA, NAIA, and NJCAA athletic-department staff directories described above (primarily Sidearm and PrestoSports CMS platforms).
2.3 Legal Basis & Purpose
We process coach data under legitimate interest (GDPR Art. 6(1)(f)). The purpose is to facilitate direct contact between student-athletes and college coaches — which is the coaches' professional function. This includes making verified coach professional contact details available to our users and customers — athletes, families, clubs, academies and recruiting agencies — both on the platform and through our paid Coach Database product, strictly for legitimate college-recruiting outreach. Coach contact information is institutional (not personal), published by universities for professional outreach. We have conducted a Legitimate Interest Assessment (LIA) documenting that this processing is necessary, proportionate, and balanced against coaches' rights, and coaches may object at any time (see 2.5).
2.4 Safeguards
- We share coach data only as professional/institutional contact details and only for legitimate recruiting outreach — never for unrelated marketing, profiling, or onward resale
- Customers who purchase the Coach Database are bound by a Data Licence that prohibits resale, redistribution and misuse and requires them to honour opt-outs and anti-spam law
- We collect only institutional contact data (name, title, institutional email, office phone) — never personal mobile numbers or private data (data minimization)
- Rate limiting prevents excessive or abusive outreach; quality controls ensure data accuracy and freshness
- We do not sell or license athletes’ or platform users’ personal data (see §7)
3. How We Use Your Information
- Provide the Platform: Create profiles, connect with coaches, send emails, generate highlight reels
- AI Personalization: Generate email drafts, coach recommendations, profile suggestions
- Coach Research: AI-powered web research to personalize your outreach
- Email Delivery: Send emails via Resend (resend.com) on your behalf from your @athlete.athlyai.com or @coach.athlyai.com address
- Engagement Analytics: Track email delivery, opens, and clicks
- Video Processing: Process, store, and optimize your highlight videos
- Payments: Process subscriptions, manage billing, send invoices
- Platform Improvement: Analyze usage patterns to improve performance and features
- Communications: Service updates, recruiting tips, marketing (with opt-out)
- Security & Compliance: Detect fraud, enforce Terms, comply with legal obligations
4. Legal Bases for Processing (GDPR)
Contract (Art. 6(1)(b))
Processing necessary to deliver the Platform: profile creation, email generation and delivery of the messages you compose, coach discovery, video processing, billing.
Consent (Art. 6(1)(a))
Optional features you switch on: analytics and marketing cookies, connecting Gmail/Outlook or a Coach Portal mailbox, voice mode, marketing emails, and making your profile public.
Legitimate Interests (Art. 6(1)(f))
Platform analytics, security monitoring, fraud prevention, service improvement.
Legal Obligation (Art. 6(1)(c))
Compliance with applicable laws, regulations, and legal processes.
5. AI Features & Data Processing
We are transparent about how your data is used by AI:
- What AI accesses: Your athletic profile, academic information, recruiting preferences, and previous email history are provided to AI models to generate personalized content.
- AI providers: We use Kimi (Moonshot AI), Google Gemini, and Groq (Llama). Hugging Face Inference is used only as an automatic fallback for coach-record verification when Groq is rate-limited, and processes coach directory data, not athlete profiles. Under these providers' API terms, your data is not used to train their models. We periodically verify each provider's terms.
- Voice assistant: If you start a voice conversation with the assistant, your live audio and a snapshot of your profile (name, sport, position, school, recruiting goals) are sent to ElevenLabs, which powers the voice agent. Voice mode is optional and only runs when you start it.
- Coach research: AI compiles publicly available information about coaches and programs (such as official athletic department staff directories) to provide recruiting context.
- Connecting Athly to an external AI assistant (MCP): You can connect Athly to an AI assistant you already use — such as ChatGPT, Claude, or a code editor — through our Model Context Protocol (MCP) connector at athlyai.com/api/mcp. This is entirely optional and off unless you set it up. Once connected, the assistant you chose can call Athly on your behalf and will receive whatever those calls return: your athlete profile, your outreach history and statistics, and coach records you look up. That data then sits with the assistant's provider under THEIR privacy policy, not ours, and we cannot delete it for you — disconnect there as well as here. Access is granted per-account with OAuth, is limited to your own data, never includes another athlete's data unless you hold a verified coach account, and can be revoked at any time from your Athly dashboard. Where the account belongs to a minor or an unverified age, every response we send is tagged as a minor's data so the assistant is told to handle it accordingly, and we refuse to send coach emails at all without guardian consent on record.
- No automated decisions: AI generates suggestions and drafts, but you always have final control. No decisions with legal or significant effects are made solely by automated processing.
- Conversation history: AI assistant conversations are stored to provide context in future interactions. Deleted upon account deletion.
6. Email Delivery
Athly AI uses Resend (resend.com) as our default transactional email delivery provider. Optionally, you may connect your Google account (see 1.6a — the send-only gmail.send scope, and 1.6b for our Google API Limited Use commitment) or a Microsoft account (see 1.6c — the Mail.Send scope) to send outreach from your own address instead. Separately, coaches may connect a mailbox that we do read for incoming athlete enquiries — see 1.6d.
[email protected]. Coaches send from [email protected]. All addresses are subdomains of athlyai.com, authenticated with SPF, DKIM, and DMARC.- We only send emails you explicitly compose, review, and approve inside Athly AI
- We do not send emails in the background, in bulk, or on any automated schedule without your action
- If you connect Gmail or Outlook (optional), we store only an encrypted OAuth refresh token for the send-only scope, and never read, modify, or delete your mailbox; you can disconnect anytime
- Email content is transmitted to the delivery provider (Resend, or Gmail/Outlook if you connected one) solely for delivery and is not used for advertising or model training
- Outgoing messages carry a tracking pixel and, where enabled, redirect links so we can report delivery, opens and clicks back to you; the footer of every message tells the recipient this and gives them a one-click opt-out
- You may contact [email protected] to request deletion of your sending address and associated email logs
7. Data Sharing
We may share limited data with:
8. Data Security
- Data encrypted in transit (TLS) and at rest
- Row-Level Security (RLS) enabled on every table in our application database
- Passwords hashed (never stored in plain text); connected-mailbox credentials and OAuth tokens encrypted with AES-256-GCM
- Secure cloud infrastructure via Supabase, hosted on AWS in the United States (us-east-2)
- Regular security reviews and access controls
9. Data Retention
10. Cookies & Tracking Technologies
Authentication, session management, security, checkout, and your cookie choice itself. Cannot be disabled.
Google Analytics 4 and PostHog. Loaded only after you opt in. You can also opt out of Google Analytics via the GA Opt-out Add-on.
Meta Pixel (ad measurement). Loaded only after you opt in to analytics cookies — there is no separate marketing toggle, so accepting analytics enables these too.
Remember your preferences such as language, translation, and sidebar layout. Some of these are set when you actively change a preference, regardless of your analytics choice.
We do not sell cookie data. Analytics and marketing scripts (Google Analytics, PostHog, Meta Pixel) only load if you opt in via the cookie banner. Note that the banner appears on our public pages; if you are signed in and browsing the dashboard it is not shown there — manage your choice any time from the Privacy Center.
11. International Data Transfers
Your data may be transferred to countries outside the EEA, including the US. We ensure appropriate safeguards through:
- Standard Contractual Clauses (SCCs) approved by the European Commission, with supplementary measures where needed
- The EU-US Data Privacy Framework, where the provider is certified under it
- Adequacy decisions where applicable
In practice, our primary database and file storage (Supabase, on AWS) is located in the United States, so account, profile, and uploaded media data is stored in the US rather than the EEA. The table in §17 states the transfer mechanism we rely on for each provider.
12. Children's Privacy
Athly AI is intended for users aged 16 and older. Users between 16 and 18 must have parental or guardian consent.
We ask for your date of birth and block any account where the calculated age is under 16, regardless of country — this is a single global minimum, not a per-country digital-consent age. The check is applied on our servers and in our database, not only in the sign-up form, so it holds however you create your account: by email and password, by signing in with Google, or by completing onboarding afterwards. If you are 16 or 17, you must confirm that a parent or guardian consents on your behalf and give us their name and email address; we record that confirmation with its date, the policy version in force, and the IP it came from, and we email the guardian a notice that the account exists so they can object or withdraw at any time. Accounts created before we collected this are asked for the missing details the next time they sign in. We do not knowingly collect data from anyone under 16, and if we learn that we have, we delete it promptly. Note that we do not independently verify a stated date of birth, nor a guardian's identity beyond emailing the address given.
Given that we serve student-athletes (many aged 16-18), we apply these protections, each enforced in code rather than by policy alone:
- Minimize data collection to what is necessary for recruiting
- Not share minor athletes' data with third parties for marketing
- Your public web profile — the page at athlyai.com/profile/… that anyone with the link can open — is private until you publish it yourself, and a minor's stays private until guardian consent is on record, whatever the setting says. This is separate from the recruiting directory: verified college coaches can see athlete profiles there, which is the purpose of the Platform and why you created an account
- A minor's public profile is never listed in our sitemap and always carries a “no index” instruction, so it does not appear in search engines. We also ask AI crawlers not to read any athlete profile page
- Without guardian consent on record, we will not send an email to a coach on a minor's behalf — including through a connected external AI assistant
- When a minor connects Athly to an external AI assistant, every response we send is labelled as a minor's data, with explicit instructions to the assistant not to republish or redistribute it
- A guardian can withdraw consent at any time by writing to [email protected]; we then treat the account as having no consent, which makes the profile private and stops coach outreach
13. Marketing Communications
With your consent, we may send marketing emails about updates, features, and recruiting tips. You may opt out at any time by:
- Clicking the unsubscribe link in any marketing email
- Updating your communication preferences in account settings
- Contacting us at [email protected]
Opting out of marketing does not affect transactional emails (subscription confirmations, security alerts, account notifications).
14. Your Rights
Under the GDPR and applicable data protection laws, you have the following rights:
Request a copy of your personal data
Correct inaccurate or incomplete data
Request deletion ("right to be forgotten")
Limit processing in certain circumstances
Receive data in JSON/CSV format
Object to processing based on legitimate interests
Withdraw consent for email delivery, marketing, public profile
File with your local data protection authority
• Download my data or delete my account (in Settings)
• Submit a Data Subject Access Request
• Coach data removal
• Email: [email protected] (30-day response time)
In Italy, you can also file a complaint with the Garante per la protezione dei dati personali.
15. California Privacy Rights (CCPA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:
Right to Know
You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purpose for collecting it, and the categories of third parties with whom we share it.
Right to Delete
You may request deletion of your personal information, subject to certain exceptions (e.g., completing a transaction, security, legal obligations).
Right to Correct
You may request correction of inaccurate personal information we maintain about you.
Right to Opt Out of Sale / Sharing
We do not sell your personal information. If you opt in to analytics cookies, your browsing activity, cookie identifiers, and IP address may be shared with Meta for advertising measurement (Meta Pixel) — this counts as "sharing" for cross-context behavioral advertising under CCPA/CPRA. We do not send Meta your email address. You can opt out at any time via the cookie banner in our Privacy Center, which stops this sharing going forward.
Right to Limit Use of Sensitive Data
We do not use or disclose sensitive personal information beyond what is necessary to provide our Platform. You have the right to limit our use if we ever expand into such uses.
Right to Non-Discrimination
We will not discriminate against you for exercising any of your CCPA rights — no denial of service, different prices, or lower quality of service.
To exercise any of these rights, email [email protected] with the subject line “CCPA Request”. We will respond within 45 days. You may designate an authorised agent to make a request on your behalf by providing written authorisation.
We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age. Financial incentives, if any, will be separately disclosed and require your explicit opt-in.
16. Data Portability & Export
You can download your data yourself at any time from Settings. The self-service export is a JSON file containing:
- Your athlete profile and email profile
- Sent and draft emails, with delivery, open and click counts
- AI assistant conversations and messages
- What the AI assistant has stored about you (its memory), and your interview answers
- Your generated recruiting plan
- Message threads with coaches
- Community posts, achievements, and athletic stats log
- Credits, credit transactions, and subscription record
- Notifications, skipped coaches, and profile-view history
Items not in the self-service export — such as your uploaded media files, video tags and reel metadata, and Coach Portal inbox data — can be requested by emailing [email protected] or via the DSAR form, and we will provide them within 30 days.
17. Third-Party Services & Sub-processors
| Service | Purpose | Location & Transfer Mechanism |
|---|---|---|
| Supabase | Database, Auth & File Storage | US (AWS us-east-2) — Standard Contractual Clauses |
| Vercel | Hosting & CDN | Global — Standard Contractual Clauses |
| Stripe | Payments | US — EU-US Data Privacy Framework |
| Resend | Email Delivery | US — Resend DPA (Standard Contractual Clauses) |
| Google (Gmail API) | Optional Gmail sending | US — EU-US Data Privacy Framework |
| Microsoft (Graph API) | Optional Outlook sending | US/EU — EU-US Data Privacy Framework |
| Amazon Web Services | Highlight-reel rendering (Lambda) | US — Standard Contractual Clauses |
| Kimi (Moonshot AI) | AI Generation | Non-EEA — Standard Contractual Clauses |
| Google Gemini | AI Generation | US — EU-US Data Privacy Framework |
| Groq | AI Generation | US — Standard Contractual Clauses |
| Hugging Face | AI fallback for coach-record verification | US — Standard Contractual Clauses |
| ElevenLabs | Voice assistant (optional) | US — Standard Contractual Clauses |
| Hunter.io | Coach email lookup / verification | EU (France) — no transfer required |
| Google Analytics 4 | Analytics (opt-in) | US — EU-US Data Privacy Framework |
| PostHog | Product Analytics (opt-in) | US — Standard Contractual Clauses |
| Meta Platforms (Meta Pixel) | Advertising Measurement (opt-in) | US — EU-US Data Privacy Framework |
Each sub-processor is bound by data processing agreements that ensure GDPR compliance.
18. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide at least 15 days' notice via email or a prominent notice on the Platform. Continued use after changes constitutes acceptance of the updated policy.
19. Data Protection Contact
For any questions about this Privacy Policy, your data, or to exercise your rights:
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.
© Athly AI. All rights reserved. This Privacy Policy is publicly available at athlyai.com/privacy and may be updated periodically.