Privacy Policy
Last updated September 6, 2026
GoAthlete is for athletes aged 13 and up. Accounts and public board participation are optional. We do not sell personal data or use advertising pixels.
The scan and age check
The web scan uses your answers in your browser. The app keeps your name and scan answers on your device. A blank birth-date check comes before the scan. We use your date to check eligibility and update your age. A rejected under-13 date stops the flow. The anonymous scan keeps a restriction flag on the device. An existing account age check also sends the date for server validation. If it is under 13 the server retains a restriction flag rather than the rejected date.
If you request an emailed result we store your email, your update consent, your sport, your whole-year age and a result summary. The result recap can include measurements. The exact birth date from this request is checked but not saved with the email signup.
Accounts and backup
Better Auth runs on our own server. An account stores your name and email and accepted birth date. Email sign-in stores a password hash. Apple or Google sign-in stores provider identifiers and may store provider access or refresh tokens. Session records can include IP address and user agent. Essential cookies on web and secure credential storage in the native app keep you signed in.
Signing in enables a backup linked to your account. Its allowlisted fields are your private name, birth date, scan profile, test readings, workout history, training goals, equipment and schedule. Injury and current-pain answers remain on the device. Device credentials, notification permission, Apple Health imports and purchase flags are not included in new backups. Older backups may contain additional legacy fields until replaced or deleted.
When both the account and device have different progress you choose which snapshot to use. Signing out clears the visible profile but keeps an account-specific local recovery copy on that device. In-app account deletion removes that account's local recovery copy on the current device. Other devices keep their local copies until erased there.
Board and private crews
Joining the board sends your validated profile and curated self-test readings for score calculation and purchase verification. The public entry uses a generated alias with your sport and age band and scores. Sex is used as a cohort filter. Region is optional. Your exact age and email and date of birth are not displayed. The server links the entry to your account for ownership and deletion. VERIFIED means Pro and all curated self-tests are logged. It does not mean a test was independently supervised.
Crews require confirmed accounts and a private code. Crew names and member aliases are generated. Members see aliases and board scores. There is no chat or public free text or photo sharing. The server stores crew ownership and membership linked to accounts. Legacy device-only memberships can remain until removed by the owner or on request.
Referrals and subscriptions
Invite codes and redemption and reward status are linked to accounts. A confirmed account needs a backed-up measured test to redeem a code. RevenueCat receives an app user identifier and purchase or entitlement information to manage Pro and promotional access. Apple or Google handles payments. We do not receive card details. Store billing records are controlled by those providers. Account deletion does not cancel a subscription.
Apple Health and notifications
Apple Health is optional on supported native builds. With permission the app reads workout days and can write a completed workout with its recorded duration. Imported Health days and Health permission state stay on the device and are excluded from new cloud backups. They are not used for advertising. Local re-test notifications are optional. Resend delivers requested account and result emails and opted-in updates.
Analytics and security logs
Our first-party event endpoint stores an event name and a daily rotating hash derived from network and browser information. The event record does not include your account ID. A hash is pseudonymous rather than a guarantee of anonymity. No third-party product analytics or cross-app advertising trackers are installed. Rate limits use a salted IP hash. Security reports retain only allowlisted violation categories in hosting logs and do not deliberately log page URLs or script samples.
Processors and retention
Vercel hosts the service and its operational logs. Neon stores application and auth data. Resend processes email addresses and message content. RevenueCat processes subscription identities and entitlements. Apple and Google process store purchases and any sign-in you choose. Better Auth is self-hosted rather than a separate hosted account service.
Account backups and scans and email signup records are kept until deleted or requested for removal. There is currently no automatic inactive-account expiry. Board entries stop appearing after 45 days without an update but are not automatically erased. Rate-limit buckets are pruned after two days when the limiter runs. First-party event rows currently have no automatic expiry. Provider operational logs and backups follow each provider's configured retention rather than disappearing immediately with an account deletion.
Deletion and your choices
In the app open Settings then Delete account. A recent sign-in can confirm deletion for email, Apple or Google accounts. The account operation removes saved scans, cloud progress, board entries, account-linked memberships, owned crews, referral records and email signup records. A failed application-data purge aborts deletion so it can be retried. The email unsubscribe suppression is retained to prevent future marketing. Aggregate event hashes cannot reliably be mapped back to a deleted account.
For a signed-out device the erase action first removes its known board entry and then clears the visible local profile. Sign in first to delete a cloud account. Contact goathlete.app@gmail.com for email-only records or legacy device memberships or data access and correction requests. Do not send additional sensitive information unless needed to resolve your request.
Young athletes
We do not knowingly offer accounts or scans to children under 13. Accepted account birthdays cannot be edited through Settings or backup. An older account found to be under 13 is restricted. If you believe a child submitted personal information contact goathlete.app@gmail.com so we can investigate and remove it. The age check is self-declared and is not identity verification.