Skip to main content
Legal

Privacy Policy

Effective Date: July 28, 2026

Data Controller

Lorenzo Peluso (sole trader / ditta individuale, Italy)
Via Resistenza Partigiana 27/O, 97015 Modica (RG), Italia
P.IVA: IT01888280888 — REA: RG-485912
PEC: [email protected]
Contact: [email protected]

The controller is established in the EU (Italy), so no EU Article 27 representative is required. We have not appointed a UK representative under Article 27 of the UK GDPR. UK data subjects may contact us directly at [email protected] and we handle UK requests on the same terms and timelines as EU requests.

This Privacy Policy explains how Athly AI (“we,” “us,” or “our”) collects, uses, shares, and protects the personal data of users who access or use our AI-powered college sports recruiting platform at athlyai.com. We are committed to transparency and to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the Italian Data Protection Code, and other applicable data protection laws.

1. Information We Collect

1.1 Account & Profile

  • Full name, email, phone number
  • Date of birth & graduation year
  • Nationality & country of residence
  • Profile photo & action photos
  • Account credentials (hashed)

1.2 Athletic Information

  • Sport(s), position(s), jersey number
  • Team name, years of experience
  • Height, weight, physical stats
  • Performance stats (goals, assists, etc.)
  • Highlight videos & tagged clips

1.3 Academic Information

  • GPA (native system + US conversion)
  • SAT, ACT, TOEFL, Duolingo scores
  • Intended major & field of study
  • Academic honors & achievements

1.4 Recruiting Preferences

  • Recruiting goal & scholarship importance
  • Target divisions (NCAA, NAIA, NJCAA)
  • Preferred regions & target schools
  • Target start year for college

1.5 User-Generated Content

  • Emails composed & sent
  • Messages exchanged with coaches
  • AI assistant conversations
  • Email templates & drafts
  • Video tags, clips & highlight reels

1.8 Device & Technical

  • IP address & geolocation
  • Browser type & operating system
  • Device type & screen resolution
  • Pages visited & time spent
  • Referral source & UTM parameters
1.6 Email Delivery: By default, athlete-to-coach outreach emails are sent via Resend (resend.com) from your personal subdomain address (e.g. [email protected]). Coaches sending through our platform use addresses in the form [email protected]. We only send messages you explicitly compose and approve.
1.6a Optional Gmail Sending (Google account connection): You may optionally connect your Google account so outreach you compose is sent from your own Gmail address instead of your Athly subdomain. If you connect Gmail, the only mailbox scope we request is gmail.send, alongside the two standard sign-in scopes openid and email (which tell us only which Google account you connected, so we send from the right address). We store the resulting OAuth refresh token, encrypted at rest, solely to send the specific messages you compose and approve. The gmail.send scope is send-only: it does not allow Athly to read, search, download, modify, or delete any message in your mailbox, and we do none of those things. Connecting Gmail is never required to use Athly. You can disconnect at any time in Settings → Gmail, which deletes the stored token; you may also revoke access directly at myaccount.google.com/permissions.
1.6c Optional Outlook / Microsoft 365 sending: You may optionally connect a Microsoft account so outreach you compose is sent from your own Outlook address. We request the Mail.Send, User.Read and offline_access scopes and store the resulting OAuth refresh token, encrypted at rest, solely to send the specific messages you compose and approve. These scopes do not permit reading, searching, or deleting mail in your mailbox, and we do none of those things. Connecting Outlook is never required. You can disconnect at any time in Settings, which deletes the stored token, and revoke access at account.microsoft.com.
1.6d Coach Portal inbox connection (coaches only — we do read this mailbox): Coaches using the Coach Portal Inbox may optionally connect a mailbox (Gmail, Outlook, Yahoo, iCloud, or any IMAP server) by entering an email address and an app password. Unlike the athlete sending features above, this connection is read-only and we do read your INBOX: we fetch incoming messages so the portal can surface athlete enquiries. What this means concretely:
  • The app password is encrypted at rest with AES-256-GCM and is never shown back to you or sent to the browser
  • Fetched messages (sender, subject, body, timestamp) are stored in our database and analysed by our AI providers to classify and summarise athlete enquiries
  • We never send from the connected mailbox, and we do not modify or delete anything in it
  • Connecting a mailbox is entirely optional; you can disconnect at any time, which deletes the stored credential and the mirrored messages
  • Because a mailbox may contain messages from people who are not Athly users, connect only a mailbox you are entitled to process this way
1.6b Limited Use of Google user data: Athly's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data obtained through Google authorization is used only to provide the email-sending feature you request, is never sold, is never used for advertising, and is never used to train generalized AI/ML models. It is not transferred to others except as necessary to provide and secure the feature (e.g. Google's own APIs), to comply with applicable law, or as part of a merger or acquisition with your consent.
1.7 Payment Data: Processed securely via Stripe. We do not store your full credit card number, CVV, or banking details. We retain only a transaction reference and subscription status.

1.9 Email Engagement Data

For emails sent through the Platform, we track: delivery status, open counts & timestamps, click counts & timestamps, and reply detection.

2. College Coach Data

Our platform includes a database of college coaching staff to help student-athletes identify and contact potential coaches. This section explains how we handle that data.

2.1 What Coach Data We Hold

  • Coach name and professional title/role
  • Institutional email address (e.g. [email protected])
  • Office phone numbers (where published on institutional staff directories)
  • School/university name and athletics program
  • Sport and division (NCAA D1, D2, D3, NAIA, NJCAA)

Personal mobile phone numbers are not collected. The phone numbers stored are office / staff-directory numbers as published by the institution itself.

2.2 Where Coach Data Comes From

Coach information is collected primarily from publicly available sources: official university athletics staff directory pages, publicly accessible school websites, and public athletic conference directories. We do not scrape coaches' personal social media accounts and we do not buy coach lists from consumer data brokers.

Third-party enrichment and verification. Where an institutional directory lists a coach by name and role but does not publish an email address, we may use Hunter.io (a B2B professional-email lookup service) to identify or confirm the likely institutional address at that university's domain, and we run automated checks (DNS/MX lookups and AI-assisted re-reading of the public directory page) to keep records accurate. We send Hunter.io only a coach's name and their institution's domain. No athlete or platform-user data is ever sent to enrichment providers. Coaches can object to this processing and be removed at any time (see 2.5).

Effective April 22, 2026, every newly-collected or refreshed coach record stores the source URL and timestamp of collection. Pre-existing records collected prior to this date do not carry per-record provenance metadata; the categorical sources for those records are the publicly accessible NCAA, NAIA, and NJCAA athletic-department staff directories described above (primarily Sidearm and PrestoSports CMS platforms).

2.3 Legal Basis & Purpose

We process coach data under legitimate interest (GDPR Art. 6(1)(f)). The purpose is to facilitate direct contact between student-athletes and college coaches — which is the coaches' professional function. This includes making verified coach professional contact details available to our users and customers — athletes, families, clubs, academies and recruiting agencies — both on the platform and through our paid Coach Database product, strictly for legitimate college-recruiting outreach. Coach contact information is institutional (not personal), published by universities for professional outreach. We have conducted a Legitimate Interest Assessment (LIA) documenting that this processing is necessary, proportionate, and balanced against coaches' rights, and coaches may object at any time (see 2.5).

2.4 Safeguards

  • We share coach data only as professional/institutional contact details and only for legitimate recruiting outreach — never for unrelated marketing, profiling, or onward resale
  • Customers who purchase the Coach Database are bound by a Data Licence that prohibits resale, redistribution and misuse and requires them to honour opt-outs and anti-spam law
  • We collect only institutional contact data (name, title, institutional email, office phone) — never personal mobile numbers or private data (data minimization)
  • Rate limiting prevents excessive or abusive outreach; quality controls ensure data accuracy and freshness
  • We do not sell or license athletes’ or platform users’ personal data (see §7)
2.6 Coach Database Product: Our paid Coach Database makes verified coach contact lists available for download. Buyers receive institutional contact data only and act as independent data controllers for their own outreach; their use is governed by our Data Licence, which requires a lawful basis, honouring coach opt-outs, and compliance with GDPR and anti-spam law. Coaches who opt out (see 2.5) are suppressed from the product going forward.
2.5 Coach Opt-Out (Right to Object): If you are a coach and wish to have your information removed from our database, you may submit a removal request at athlyai.com/coach-removal or email us at [email protected]. To prevent abuse, removal is confirmed via a one-time link sent to your institutional email address on record — only the actual mailbox owner can complete the removal. Once you click the link, your record is hidden from search and outreach within 5 business days. This right is guaranteed under GDPR Article 21.

3. How We Use Your Information

  • Provide the Platform: Create profiles, connect with coaches, send emails, generate highlight reels
  • AI Personalization: Generate email drafts, coach recommendations, profile suggestions
  • Coach Research: AI-powered web research to personalize your outreach
  • Email Delivery: Send emails via Resend (resend.com) on your behalf from your @athlete.athlyai.com or @coach.athlyai.com address
  • Engagement Analytics: Track email delivery, opens, and clicks
  • Video Processing: Process, store, and optimize your highlight videos
  • Payments: Process subscriptions, manage billing, send invoices
  • Platform Improvement: Analyze usage patterns to improve performance and features
  • Communications: Service updates, recruiting tips, marketing (with opt-out)
  • Security & Compliance: Detect fraud, enforce Terms, comply with legal obligations

Contract (Art. 6(1)(b))

Processing necessary to deliver the Platform: profile creation, email generation and delivery of the messages you compose, coach discovery, video processing, billing.

Consent (Art. 6(1)(a))

Optional features you switch on: analytics and marketing cookies, connecting Gmail/Outlook or a Coach Portal mailbox, voice mode, marketing emails, and making your profile public.

Legitimate Interests (Art. 6(1)(f))

Platform analytics, security monitoring, fraud prevention, service improvement.

Legal Obligation (Art. 6(1)(c))

Compliance with applicable laws, regulations, and legal processes.

5. AI Features & Data Processing

We are transparent about how your data is used by AI:

  • What AI accesses: Your athletic profile, academic information, recruiting preferences, and previous email history are provided to AI models to generate personalized content.
  • AI providers: We use Kimi (Moonshot AI), Google Gemini, and Groq (Llama). Hugging Face Inference is used only as an automatic fallback for coach-record verification when Groq is rate-limited, and processes coach directory data, not athlete profiles. Under these providers' API terms, your data is not used to train their models. We periodically verify each provider's terms.
  • Voice assistant: If you start a voice conversation with the assistant, your live audio and a snapshot of your profile (name, sport, position, school, recruiting goals) are sent to ElevenLabs, which powers the voice agent. Voice mode is optional and only runs when you start it.
  • Coach research: AI compiles publicly available information about coaches and programs (such as official athletic department staff directories) to provide recruiting context.
  • Connecting Athly to an external AI assistant (MCP): You can connect Athly to an AI assistant you already use — such as ChatGPT, Claude, or a code editor — through our Model Context Protocol (MCP) connector at athlyai.com/api/mcp. This is entirely optional and off unless you set it up. Once connected, the assistant you chose can call Athly on your behalf and will receive whatever those calls return: your athlete profile, your outreach history and statistics, and coach records you look up. That data then sits with the assistant's provider under THEIR privacy policy, not ours, and we cannot delete it for you — disconnect there as well as here. Access is granted per-account with OAuth, is limited to your own data, never includes another athlete's data unless you hold a verified coach account, and can be revoked at any time from your Athly dashboard. Where the account belongs to a minor or an unverified age, every response we send is tagged as a minor's data so the assistant is told to handle it accordingly, and we refuse to send coach emails at all without guardian consent on record.
  • No automated decisions: AI generates suggestions and drafts, but you always have final control. No decisions with legal or significant effects are made solely by automated processing.
  • Conversation history: AI assistant conversations are stored to provide context in future interactions. Deleted upon account deletion.

6. Email Delivery

Athly AI uses Resend (resend.com) as our default transactional email delivery provider. Optionally, you may connect your Google account (see 1.6a — the send-only gmail.send scope, and 1.6b for our Google API Limited Use commitment) or a Microsoft account (see 1.6c — the Mail.Send scope) to send outreach from your own address instead. Separately, coaches may connect a mailbox that we do read for incoming athlete enquiries — see 1.6d.

Sending addresses
Athletes send from [email protected]. Coaches send from [email protected]. All addresses are subdomains of athlyai.com, authenticated with SPF, DKIM, and DMARC.
  • We only send emails you explicitly compose, review, and approve inside Athly AI
  • We do not send emails in the background, in bulk, or on any automated schedule without your action
  • If you connect Gmail or Outlook (optional), we store only an encrypted OAuth refresh token for the send-only scope, and never read, modify, or delete your mailbox; you can disconnect anytime
  • Email content is transmitted to the delivery provider (Resend, or Gmail/Outlook if you connected one) solely for delivery and is not used for advertising or model training
  • Outgoing messages carry a tracking pixel and, where enabled, redirect links so we can report delivery, opens and clicks back to you; the footer of every message tells the recipient this and gives them a one-click opt-out
  • You may contact [email protected] to request deletion of your sending address and associated email logs
Resend processes email data as a sub-processor under a Data Processing Agreement. See Resend's Privacy Policy and Data Processing Agreement for details.

7. Data Sharing

We do not sell your personal information. This refers to your personal account data as an athlete or platform user. Verified college-coach institutional contact data is made available to customers for recruiting outreach as described in §2 (College Coach Data) and our Data Licence.

We may share limited data with:

College CoachesProfile information and communications when you send messages or enable your public profile.
Infrastructure ProvidersSupabase (database, authentication, and file storage for your photos and videos) and Vercel (hosting) to operate the Platform.
Video RenderingAmazon Web Services (AWS Lambda) renders your highlight reels from your uploaded clips.
Payment ProcessorStripe processes your payment data under their own privacy policy.
AI ProvidersKimi (Moonshot AI), Google Gemini, and Groq receive profile data solely for real-time content generation. ElevenLabs receives audio and a profile snapshot if you use voice mode. Not retained for training.
Analytics (opt-in)Only if you accept analytics cookies. Google Analytics 4 receives usage data including a pseudonymous client ID and IP-derived approximate location (it is not anonymous data). PostHog receives product usage events and session recordings with inputs masked. Meta Pixel receives page views and conversion events plus the associated cookie identifiers and IP address — we do not send Meta your email address or use advanced matching.
Resend (resend.com)Transactional email delivery — outgoing emails sent via Resend from your @athlete.athlyai.com or @coach.athlyai.com address.
Legal AuthoritiesIf required by law, regulation, or legal process.

8. Data Security

  • Data encrypted in transit (TLS) and at rest
  • Row-Level Security (RLS) enabled on every table in our application database
  • Passwords hashed (never stored in plain text); connected-mailbox credentials and OAuth tokens encrypted with AES-256-GCM
  • Secure cloud infrastructure via Supabase, hosted on AWS in the United States (us-east-2)
  • Regular security reviews and access controls
Please read this before uploading media. Files you upload — profile photos, gallery images, source videos, and generated highlight reels — are stored in public storage buckets. Anyone who has a file's URL can open it, and this is independent of your profile visibility setting: turning your public profile off hides your profile page, but does not make a file someone already has the link to unreachable. Files can no longer be listed or browsed in bulk — we removed that in July 2026 — so a URL has to have been shared with someone for them to reach it. We are still working to move these buckets behind signed, expiring links; this notice will be updated when that lands. In the meantime, do not upload anything you would not be comfortable sharing by link.
No system can guarantee 100% security. If we become aware of a data breach affecting your rights, we will notify you and relevant authorities within 72 hours as required by GDPR.

9. Data Retention

Active accountsData retained as long as your account is active and necessary to provide the Platform.
After deletionDeleting your account from Settings immediately removes your profile, emails and drafts, AI assistant conversations and the memory the assistant held about you, your recruiting plan and interview answers, message threads with coaches, community posts, stats, credits, subscription records, notifications, connected-mailbox credentials and API access tokens, video tags and reels, and your uploaded files. Two things are kept on purpose: records we are legally required to retain (billing and tax, see below), and any unsubscribe/opt-out record — erasing that would cause us to contact you again. Backups roll off on our provider’s standard cycle, within 30 days.
Billing & tax recordsBilling and tax records: 10 years (Italian fiscal law, Art. 2220 Codice Civile and Art. 22 D.P.R. 600/1973).
Email trackingEngagement metrics retained for the duration of your subscription.
AI conversationsRetained while account is active. Deleted upon account deletion.
Email sending logsDelivery status, open, and click data retained for the duration of your subscription. Deleted upon account deletion.

10. Cookies & Tracking Technologies

Essential

Authentication, session management, security, checkout, and your cookie choice itself. Cannot be disabled.

Analytics

Google Analytics 4 and PostHog. Loaded only after you opt in. You can also opt out of Google Analytics via the GA Opt-out Add-on.

Marketing

Meta Pixel (ad measurement). Loaded only after you opt in to analytics cookies — there is no separate marketing toggle, so accepting analytics enables these too.

Functional

Remember your preferences such as language, translation, and sidebar layout. Some of these are set when you actively change a preference, regardless of your analytics choice.

We do not sell cookie data. Analytics and marketing scripts (Google Analytics, PostHog, Meta Pixel) only load if you opt in via the cookie banner. Note that the banner appears on our public pages; if you are signed in and browsing the dashboard it is not shown there — manage your choice any time from the Privacy Center.

For a full list of every cookie we use (name, provider, purpose, and duration), see our Cookie Policy. You can change your cookie preferences at any time from the Privacy Center.

11. International Data Transfers

Your data may be transferred to countries outside the EEA, including the US. We ensure appropriate safeguards through:

  • Standard Contractual Clauses (SCCs) approved by the European Commission, with supplementary measures where needed
  • The EU-US Data Privacy Framework, where the provider is certified under it
  • Adequacy decisions where applicable

In practice, our primary database and file storage (Supabase, on AWS) is located in the United States, so account, profile, and uploaded media data is stored in the US rather than the EEA. The table in §17 states the transfer mechanism we rely on for each provider.

12. Children's Privacy

Athly AI is intended for users aged 16 and older. Users between 16 and 18 must have parental or guardian consent.

We ask for your date of birth and block any account where the calculated age is under 16, regardless of country — this is a single global minimum, not a per-country digital-consent age. The check is applied on our servers and in our database, not only in the sign-up form, so it holds however you create your account: by email and password, by signing in with Google, or by completing onboarding afterwards. If you are 16 or 17, you must confirm that a parent or guardian consents on your behalf and give us their name and email address; we record that confirmation with its date, the policy version in force, and the IP it came from, and we email the guardian a notice that the account exists so they can object or withdraw at any time. Accounts created before we collected this are asked for the missing details the next time they sign in. We do not knowingly collect data from anyone under 16, and if we learn that we have, we delete it promptly. Note that we do not independently verify a stated date of birth, nor a guardian's identity beyond emailing the address given.

Given that we serve student-athletes (many aged 16-18), we apply these protections, each enforced in code rather than by policy alone:

  • Minimize data collection to what is necessary for recruiting
  • Not share minor athletes' data with third parties for marketing
  • Your public web profile — the page at athlyai.com/profile/… that anyone with the link can open — is private until you publish it yourself, and a minor's stays private until guardian consent is on record, whatever the setting says. This is separate from the recruiting directory: verified college coaches can see athlete profiles there, which is the purpose of the Platform and why you created an account
  • A minor's public profile is never listed in our sitemap and always carries a “no index” instruction, so it does not appear in search engines. We also ask AI crawlers not to read any athlete profile page
  • Without guardian consent on record, we will not send an email to a coach on a minor's behalf — including through a connected external AI assistant
  • When a minor connects Athly to an external AI assistant, every response we send is labelled as a minor's data, with explicit instructions to the assistant not to republish or redistribute it
  • A guardian can withdraw consent at any time by writing to [email protected]; we then treat the account as having no consent, which makes the profile private and stops coach outreach

13. Marketing Communications

With your consent, we may send marketing emails about updates, features, and recruiting tips. You may opt out at any time by:

  • Clicking the unsubscribe link in any marketing email
  • Updating your communication preferences in account settings
  • Contacting us at [email protected]

Opting out of marketing does not affect transactional emails (subscription confirmations, security alerts, account notifications).

14. Your Rights

Under the GDPR and applicable data protection laws, you have the following rights:

AccessArt. 15

Request a copy of your personal data

RectificationArt. 16

Correct inaccurate or incomplete data

ErasureArt. 17

Request deletion ("right to be forgotten")

Restrict ProcessingArt. 18

Limit processing in certain circumstances

Data PortabilityArt. 20

Receive data in JSON/CSV format

ObjectArt. 21

Object to processing based on legitimate interests

Withdraw Consent

Withdraw consent for email delivery, marketing, public profile

Lodge a Complaint

File with your local data protection authority

Take action now: Visit our Privacy Center to manage your data, or use these direct links:
Download my data or delete my account (in Settings)
Submit a Data Subject Access Request
Coach data removal
Email: [email protected] (30-day response time)

In Italy, you can also file a complaint with the Garante per la protezione dei dati personali.

15. California Privacy Rights (CCPA)

If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following rights:

Right to Know

You may request disclosure of the categories and specific pieces of personal information we have collected about you, the sources of that information, the business purpose for collecting it, and the categories of third parties with whom we share it.

Right to Delete

You may request deletion of your personal information, subject to certain exceptions (e.g., completing a transaction, security, legal obligations).

Right to Correct

You may request correction of inaccurate personal information we maintain about you.

Right to Opt Out of Sale / Sharing

We do not sell your personal information. If you opt in to analytics cookies, your browsing activity, cookie identifiers, and IP address may be shared with Meta for advertising measurement (Meta Pixel) — this counts as "sharing" for cross-context behavioral advertising under CCPA/CPRA. We do not send Meta your email address. You can opt out at any time via the cookie banner in our Privacy Center, which stops this sharing going forward.

Right to Limit Use of Sensitive Data

We do not use or disclose sensitive personal information beyond what is necessary to provide our Platform. You have the right to limit our use if we ever expand into such uses.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your CCPA rights — no denial of service, different prices, or lower quality of service.

To exercise any of these rights, email [email protected] with the subject line “CCPA Request”. We will respond within 45 days. You may designate an authorised agent to make a request on your behalf by providing written authorisation.

We do not have actual knowledge that we sell or share personal information of consumers under 16 years of age. Financial incentives, if any, will be separately disclosed and require your explicit opt-in.

16. Data Portability & Export

You can download your data yourself at any time from Settings. The self-service export is a JSON file containing:

  • Your athlete profile and email profile
  • Sent and draft emails, with delivery, open and click counts
  • AI assistant conversations and messages
  • What the AI assistant has stored about you (its memory), and your interview answers
  • Your generated recruiting plan
  • Message threads with coaches
  • Community posts, achievements, and athletic stats log
  • Credits, credit transactions, and subscription record
  • Notifications, skipped coaches, and profile-view history

Items not in the self-service export — such as your uploaded media files, video tags and reel metadata, and Coach Portal inbox data — can be requested by emailing [email protected] or via the DSAR form, and we will provide them within 30 days.

17. Third-Party Services & Sub-processors

ServicePurposeLocation & Transfer Mechanism
SupabaseDatabase, Auth & File StorageUS (AWS us-east-2) — Standard Contractual Clauses
VercelHosting & CDNGlobal — Standard Contractual Clauses
StripePaymentsUS — EU-US Data Privacy Framework
ResendEmail DeliveryUS — Resend DPA (Standard Contractual Clauses)
Google (Gmail API)Optional Gmail sendingUS — EU-US Data Privacy Framework
Microsoft (Graph API)Optional Outlook sendingUS/EU — EU-US Data Privacy Framework
Amazon Web ServicesHighlight-reel rendering (Lambda)US — Standard Contractual Clauses
Kimi (Moonshot AI)AI GenerationNon-EEA — Standard Contractual Clauses
Google GeminiAI GenerationUS — EU-US Data Privacy Framework
GroqAI GenerationUS — Standard Contractual Clauses
Hugging FaceAI fallback for coach-record verificationUS — Standard Contractual Clauses
ElevenLabsVoice assistant (optional)US — Standard Contractual Clauses
Hunter.ioCoach email lookup / verificationEU (France) — no transfer required
Google Analytics 4Analytics (opt-in)US — EU-US Data Privacy Framework
PostHogProduct Analytics (opt-in)US — Standard Contractual Clauses
Meta Platforms (Meta Pixel)Advertising Measurement (opt-in)US — EU-US Data Privacy Framework

Each sub-processor is bound by data processing agreements that ensure GDPR compliance.

18. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will provide at least 15 days' notice via email or a prominent notice on the Platform. Continued use after changes constitutes acceptance of the updated policy.

19. Data Protection Contact

For any questions about this Privacy Policy, your data, or to exercise your rights:

If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.

© Athly AI. All rights reserved. This Privacy Policy is publicly available at athlyai.com/privacy and may be updated periodically.