Privacy Policy
Effective Date: February 7, 2025
This Privacy Policy explains how Athly AI (“we,” “us,” or “our”) collects, uses, shares, and protects the personal data of users who access or use our AI-powered college sports recruiting platform at athlyai.com. We are committed to transparency and to protecting your privacy in compliance with the General Data Protection Regulation (GDPR), the Italian Data Protection Code, and other applicable data protection laws.
1. Information We Collect
1.1 Account & Profile
- Full name, email, phone number
- Date of birth & graduation year
- Nationality & country of residence
- Profile photo & action photos
- Account credentials (hashed)
1.2 Athletic Information
- Sport(s), position(s), jersey number
- Team name, years of experience
- Height, weight, physical stats
- Performance stats (goals, assists, etc.)
- Highlight videos & tagged clips
1.3 Academic Information
- GPA (native system + US conversion)
- SAT, ACT, TOEFL, Duolingo scores
- Intended major & field of study
- Academic honors & achievements
1.4 Recruiting Preferences
- Recruiting goal & scholarship importance
- Target divisions (NCAA, NAIA, NJCAA)
- Preferred regions & target schools
- Target start year for college
1.5 User-Generated Content
- Emails composed & sent
- Messages exchanged with coaches
- AI assistant conversations
- Email templates & drafts
- Video tags, clips & highlight reels
1.8 Device & Technical
- IP address & geolocation
- Browser type & operating system
- Device type & screen resolution
- Pages visited & time spent
- Referral source & UTM parameters
gmail.send scope. We use Gmail solely to send messages you compose and approve. We do not read, store, scan, or analyze your inbox, drafts, contacts, or any other Gmail content. We do not use Gmail data for advertising or profiling.1.9 Email Engagement Data
For emails sent through the Platform, we track: delivery status, open counts & timestamps, click counts & timestamps, and reply detection.
2. How We Use Your Information
3. Legal Bases for Processing (GDPR)
Contract (Art. 6(1)(b))
Processing necessary to deliver the Platform: profile creation, email generation, coach discovery.
Consent (Art. 6(1)(a))
Optional features: Gmail integration, marketing communications, public profile visibility.
Legitimate Interests (Art. 6(1)(f))
Platform analytics, security monitoring, fraud prevention, service improvement.
Legal Obligation (Art. 6(1)(c))
Compliance with applicable laws, regulations, and legal processes.
4. AI Features & Data Processing
We are transparent about how your data is used by AI:
5. Gmail API Disclosure & Limited Use
This section specifically addresses our compliance with Google's policies:
We may share limited data with:
7. Data Security
8. Data Retention
Authentication, session management, security. Cannot be disabled.
Google Analytics cookies. Opt out via browser settings or the GA Opt-out Add-on.
Remember your preferences such as language and theme settings.
We do not use advertising or third-party tracking cookies.
10. International Data Transfers
Your data may be transferred to countries outside the EEA, including the US. We ensure appropriate safeguards through:
- EU-US Data Privacy Framework certifications of our providers
- Standard Contractual Clauses (SCCs) approved by the European Commission
- Adequacy decisions where applicable
11. Children's Privacy
Athly AI is intended for users aged 16 and older. Users between 16 and 18 must have parental or guardian consent. We do not knowingly collect personal information from children under 16. If we learn we have collected such data without appropriate consent, we will delete it promptly.
Given that we serve student-athletes (many aged 16-18), we take additional care to:
- Minimize data collection to what is necessary for recruiting
- Not share minor athletes' data with third parties for marketing
- Provide clear controls for profile visibility and public information
12. Marketing Communications
With your consent, we may send marketing emails about updates, features, and recruiting tips. You may opt out at any time by:
- Clicking the unsubscribe link in any marketing email
- Updating your communication preferences in account settings
- Contacting us at hello@athlyai.com
Opting out of marketing does not affect transactional emails (subscription confirmations, security alerts, account notifications).
13. Your Rights
Under the GDPR and applicable data protection laws, you have the following rights:
Request a copy of your personal data
Correct inaccurate or incomplete data
Request deletion ("right to be forgotten")
Limit processing in certain circumstances
Receive data in JSON/CSV format
Object to processing based on legitimate interests
Withdraw consent for Gmail, marketing, public profile
File with your local data protection authority
To exercise any of these rights, contact privacy@athlyai.com. We will respond within 30 days at no charge. In Italy, you can also file a complaint with the Garante per la protezione dei dati personali.
14. Data Portability & Export
You can request a full export of your data at any time by contacting privacy@athlyai.com. We will provide your data in JSON format including:
15. Third-Party Services & Sub-processors
| Service | Purpose | Location |
|---|---|---|
| Supabase | Database & Auth | EU / US |
| Stripe | Payments | US (DPF) |
| AWS SES | Email Delivery | US (SCCs) |
| Gmail API | User Email Sending | US (DPF) |
| Cloudinary | Media Storage | US (SCCs) |
| Google Analytics | Analytics | US (DPF) |
| Google Gemini | AI Generation | US (DPF) |
| Groq | AI Generation | US |
| Perplexity AI | Coach Research | US |
| Vercel | Hosting & CDN | Global (SCCs) |
Each sub-processor is bound by data processing agreements that ensure GDPR compliance.
16. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will provide at least 15 days' notice via email or a prominent notice on the Platform. Continued use after changes constitutes acceptance of the updated policy.
17. Data Protection Contact
For any questions about this Privacy Policy, your data, or to exercise your rights:
If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.
© Athly AI. All rights reserved. This Privacy Policy is publicly available at athlyai.com/privacy and may be updated periodically.