PRIVACY POLICY
Last updated: October 5, 2026 · Version 1.3
1. WHO WE ARE
GOATED Athletics (“we”, “us”, “our”) operates the GOATED Training platform
at goated-training.com. We are committed to protecting the privacy and security of our users, including
athletes, coaches, and parents. This policy explains what data we collect, why we collect it, and how we keep
it safe.
2. DATA WE COLLECT
Account Information: When you sign up, we collect your name, email address, and an encrypted password.
Profile Information: Role (athlete or coach), sport preferences, position, jersey number, and optional profile picture.
Training Data: Lesson progress, quiz scores, practice logs, achievement badges, XP, streak counts, and leaderboard stats.
Team Data: Team membership, roster information, and team chat messages (coaches only create and manage teams).
Payment Information: Card payments on the website are processed by Stripe. Purchases inside the iPhone and Android apps are processed by Apple or Google and managed for us by RevenueCat. We never see or store your full card number, CVV, or billing address.
Photos, Videos and Voice: Videos you upload for analysis, a single still photo from the camera when you use drill review, and voice commands, only when you use those features (see Section 5).
Apple Health (iPhone, optional): If you turn on Apple Health sync, the workouts and step count we read from Apple Health to fill in your activity log.
3. HOW WE USE YOUR DATA
We use your data exclusively to provide and improve the GOATED Training experience:
- Deliver personalized training content and track your progress
- Power leaderboards, achievements, and team features
- Process subscription payments (Stripe on the website, Apple or Google in the apps)
- Send transactional emails (welcome messages, password resets)
- Send parents reminder emails about their child’s free week, with a one-click unsubscribe link (never to children, and never about a child whose parental consent is pending or refused)
- Power AI features such as workout plans, answer checking and drill review (see Section 5)
- Respond to support and contact form inquiries
We never sell, rent, or share your personal data with advertisers or data brokers.
4. HOW WE PROTECT YOUR DATA
- Authentication: Passwords are hashed and managed by Supabase Auth. We never store plaintext passwords.
- Row Level Security (RLS): Every database table is protected by row-level security policies. Users can only read and modify their own data.
- Encryption in Transit: All data transmitted between your browser and our servers is encrypted using TLS/HTTPS.
- Encryption at Rest: Your data is stored in Supabase’s PostgreSQL database, which encrypts data at rest using AES-256.
- Rate Limiting: All API endpoints are rate-limited to prevent abuse.
- Input Sanitization: All user inputs are sanitized to prevent injection attacks (XSS, SQL injection).
- Security Headers: We enforce strict HTTP security headers including X-Frame-Options, Content-Type-Options, and Referrer-Policy.
5. WHO PROCESSES YOUR DATA
We use the following companies to run GOATED Training. Each one gets only what it needs for its job, and we never sell your data. This list covers every outside service our app and website send personal data to.
- Supabase: Our database, sign-in and file storage. It holds your account, training progress, team messages and any videos you upload. Data is encrypted in transit and at rest.
- Vercel: Hosts the website and our server code. Every request passes through it, including your IP address.
- Stripe: Card payments on the website. Your card details go straight to Stripe; we never see or store them. Stripe is PCI DSS Level 1 certified.
- Apple App Store and Google Play: Purchases inside the iPhone and Android apps. Apple or Google bills you and handles your payment details.
- RevenueCat: Manages in-app purchases for us. It receives your GOATED account ID, your purchase and subscription status and the store receipt and, when a parent pays for a child, the child’s email address so the right account is unlocked.
- Anthropic (Claude AI): Powers our AI features: building workout plans, understanding typed workout requests, checking lesson and quiz answers, creating challenges, drill review, and scouting and recruiting helpers. It receives the text you type, the training details the feature needs (such as position, goals and level) and, for drill review, one still photo from your camera. Anthropic’s commercial terms do not allow it to train its models on this data.
- Modal: Runs our video analysis on videos you upload, and creates the coach’s voice audio from the text of the coaching lines.
- Sentry: Error reports when the app or our server hits a bug: the error message, the screen, the app version and the device and browser type. Reports are sent without your email address, and session recording is off.
- Resend (with SendGrid as a backup): Sends our emails. They receive your email address and the message.
- Apple Push Notification service and Google Firebase Cloud Messaging: Deliver push notifications to your phone. They receive a device token and the notification text.
- Google Analytics: On the website only, and only if you accept analytics cookies. It is never loaded in the iPhone or Android apps.
- Google Fonts: The app and website load their fonts from Google, which sees your IP address.
- Google Maps: When a coach searches for an event location in the calendar, the search text is sent to Google Maps.
- YouTube: If a recruiting profile links a YouTube highlight video, it plays in YouTube’s privacy-enhanced player (youtube-nocookie.com).
- Apple Health (HealthKit): iPhone only, and only if you turn on Apple Health sync. We read your workouts and step count to fill in your activity log. Health data is never used for advertising and never sold.
- Apple and Google speech recognition: Voice commands in workouts and the shot tracker use your phone’s built-in speech recognition from Apple or Google.
6. YOUR RIGHTS
You have the right to:
- Access your personal data through your Profile and Settings pages
- Update your profile information at any time from Settings
- Delete your account and all associated data from Settings > Danger Zone
- Contact us to request a full data export or ask questions about your data
When you delete your account, all your personal data, progress, quiz history, practice logs, and team memberships are permanently removed.
7. CHILDREN’S PRIVACY
GOATED Training is designed for athletes of all ages, including children under 13. We comply with the
Children’s Online Privacy Protection Act (COPPA) and take the following measures:
What we collect at signup: We collect a date of birth during registration to determine the
user’s age tier. For users under 13, we also collect a parent or guardian’s email address.
Parental consent (under 13): Before activating an account for a child under 13, we send
a consent email to the parent or guardian. The account remains restricted until the parent verifies consent
by clicking a secure link. The consent email describes exactly what data is collected.
Data collected from children: The same categories listed in Section 2 above — account
information, profile information, training data, and team data. We do not collect geolocation, photos, or
video from children unless explicitly uploaded by the user.
No advertising or data sales: We do not serve targeted advertising to any user, and we
never sell, rent, or share children’s data with advertisers or data brokers.
Parental rights: Parents and guardians may at any time:
- Review their child’s data through the Parent Portal
- Revoke consent, which restricts the child’s account
- Request complete deletion of their child’s data
- Contact us at support@goated-training.com for any data request
Teens (13–17): Users aged 13–17 may create accounts without prior parental consent.
If a parent email is provided, we send an informational notification inviting the parent to create a free Parent account.
8. DATA RETENTION
We retain your data for as long as your account is active. If you delete your account, your data is permanently
removed from our systems. Contact form submissions are retained for up to 12 months to ensure we can follow up
on your inquiries.
9. CHANGES TO THIS POLICY
We may update this Privacy Policy from time to time. When we do, we will update the “Last updated”
date at the top. We encourage you to review this page periodically.
10. CONTACT US
If you have any questions about this Privacy Policy or how we handle your data, please email us at
support@goated-training.com.