Legal
Privacy Policy
Version: 2026-09-24 — the version string a consent record cites (CW-1374). It names the exact words an acceptance was shown, which is why it moves with every material edit while the effective date below does not. Bump it in the same change as any material edit — CURRENT_CONSENT_VERSIONS in packages/contracts is held to this line by a test, and every athlete whose accepted version is older is asked again on their next launch.
Effective date: September 1, 2026 Last updated: September 24, 2026
1. Who we are and what this covers
Courtwell, LLC ("Courtwell," "we," "us") is a Texas limited liability company based in Dallas, Texas. This Privacy Policy explains what personal information we collect through the Courtwell app, the courtwell.ai websites, and our coach and administrative consoles (together, the "Service"), why we collect it, who we share it with, and the choices you have.
Our role. For Athletes and Coaches using the Service, Courtwell is the controller (or, under U.S. state privacy laws, the "business") of the personal information described here. Where a Team or organization purchases the Service for its athletes, we act as a controller for the operation of the Service and may also act as a processor on that organization's behalf for records it directs us to hold; where those roles differ, the organization's own privacy notice also applies.
Contact. admin@courtwell.ai Postal: Courtwell, LLC, c/o United States Corporation Agents, Inc., 10601 Clarence Dr., Suite 250, Frisco, TX 75033.
2. The short version
- We collect what you tell us about your training, plus the minimum needed to run an account.
- We do not sell your personal information, and we do not share it for cross-context behavioral advertising or targeted advertising. We run no advertising.
- We do not permit your data to be used to train anyone else's AI models, and our AI provider is contractually excluded from doing so.
- We do not collect your date of birth. We store only a coarse age category.
- Your Coach sees your training records. Other coaches do not.
- You can ask for a copy of your data or ask us to delete it.
3. What we collect
3.1 Account and identity
| Data | Notes |
|---|---|
| Email address | The identifier your account is keyed to and how invitations reach you |
| Display name | A single name field; we do not collect a legal first/last name split |
| Phone number | Optional; collected only where you provide it |
| Role | Athlete, Coach, or administrator |
| Age category | adult, teen_13_17, or under_13 only. We do not ask for, transmit, or store a date of birth. Our system creates adult and teen_13_17 accounts and refuses under_13 — see Section 11 |
| Consent status | Whether the account is self-consented or guardian-consented. Every account is self-consented; our system refuses to record a guardian consent — see Section 11 |
| Guardian link | For a guardian-consented account, the linked Guardian's account. Reserved; not in use today, and no account can be given one |
| Sign-in credentials | Held by our identity provider (Clerk), not by Courtwell. If you sign in with Google, Google confirms your identity to Clerk; we receive the resulting account record, not your Google password |
3.2 Training and health-adjacent information
This is the most sensitive information we hold, and we treat it as such.
| Data | Notes |
|---|---|
| Daily readiness check-in | Fixed-choice answers on sleep, soreness, energy, and stress. No free-text journaling |
| Injury flag | If you report discomfort, the body area you indicate — chosen from a fixed picker of 16 areas, recorded against a 19-zone anatomical list — together with the dates it was first flagged, last confirmed, and cleared. Over time this builds a record of the shape "left knee, flagged twelve days running" |
| Session records | Which drills were delivered, completed, skipped (and the reason), and in what order |
| Post-session log | Effort rating, how it went, makes on shooting drills, and an optional free-text note |
| Benchmark results | Results of named physical tests, with dates |
| Coaching directives | A Coach's instruction to ease or hold your training, and any note attached |
We are not a healthcare provider and this is not medical data. We nonetheless treat it as sensitive and, where the law defines "consumer health data" broadly, we handle it under those rules. See Section 10.
3.3 Messages and free text
Messages you send to your Coach, replies your Coach sends you, notes on a session, support requests, and — for coaches — notes and chat with the in-product assistant. These are free text, so please do not include information you would not want stored, including clinical details about yourself or anyone else.
3.4 Device and notification information
Push notification token and device platform (iOS/Android); your time zone; and your per-category notification preferences. If a message to you bounces or you opt out, we record that so we stop sending.
3.5 Usage and product analytics
Events describing how the Service is used — for example that a check-in was completed or a session generated — keyed to an internal, opaque account identifier, never your email, and carrying derived flags rather than your raw answers (for example, "readiness was low," never your four check-in values).
3.6 Website information
Our public site uses Cloudflare Web Analytics, which is cookieless and does not fingerprint or track you across sites. The site loads no third-party advertising, tracking, or font services; fonts are served from our own domain. We do not use advertising cookies or pixels anywhere.
3.7 Waitlist
If you submit our waitlist form we collect your name and email address, and any note you add. We use it to contact you about Courtwell's availability and for nothing else. Every waitlist email carries a one-click unsubscribe link, and using it stops all email from Courtwell to that address. You can also be removed at any time by emailing admin@courtwell.ai.
3.8 Billing information
When paid plans begin: your billing contact details, subscription status and period, and identifiers issued by our payment processor. Card numbers go directly to the processor and never reach Courtwell's systems.
3.9 Technical logs and security records
Application logs containing a request identifier, the account, workspace, and session identifiers involved, and the operation performed — identifiers and pointers, not the content of your check-ins or sessions. Your IP address is processed transiently for rate limiting and abuse prevention and is not stored in our application database; our hosting provider logs request metadata, including IP address, as part of operating the network.
We also keep an audit record of security-relevant actions — for example when a coach overrides a system recommendation, when an administrator reads records across workspaces or is granted temporary support access to one, and (when guardian consent exists) guardian consent events. Section 13 describes how finely each of those is recorded. No guardian consent event has ever been recorded, because no guardian relationship can be created — see Section 11.
3.10 Information we deliberately do not collect
Date of birth. Home address. Government identifiers. Payment card numbers. Precise geolocation. Biometric identifiers. Clinical or medical records, diagnoses, or treatment information. Advertising identifiers. We do not buy personal information from data brokers.
3.11 Information from your Google Account
We receive information from Google only when you choose to connect your Google Account to Courtwell, and only what the permission you approve on Google's screen allows. This section covers that information, which Google calls "Google user data".
What we access.
- Signing in with Google. Your basic profile: your name, email address and profile picture. Google shares it with our identity provider, Clerk, which creates or links your Courtwell account. We never receive your Google password.
- Google Calendar, for coaches. If you are a coach and connect a Google Calendar, Courtwell asks for one permission only: to see when you are busy (Google's
calendar.events.freebusypermission). We read the start and end times of the busy periods on your primary calendar, and Google tells us when that calendar changes. We cannot see event titles, descriptions, locations or attendees, and we never create, change or delete anything in your calendar.
How we use it. Your Google profile identifies you and signs you in. Your busy periods are used for one thing: so that athletes are never offered a session time that clashes with them, and so those times stay current as your calendar changes. We use Google user data only to provide and improve these features. We do not sell it, use it for advertising, or use it to train artificial intelligence models, ours or anyone else's.
How we share it. We share Google user data only with the providers in Section 7 that host and run the Service on our behalf (Clerk holds your sign-in profile; Cloudflare hosts our database), under contracts that limit them to doing that. We do not share it with coaches, athletes or anyone else, except that your profile name appears to the people you work with in Courtwell, as any account name does. People at Courtwell do not read it except where you ask us to, where it is needed for security, or where the law requires it.
How we protect it. Google user data travels only over encrypted connections (Section 13). The credential Google issues for a calendar connection is encrypted before it is stored, is used only by the server to read busy times, and is never shown in the app or sent to your device. Data at rest is encrypted by our hosting provider.
How long we keep it, and how to delete it. We keep your sign-in profile for as long as you have an account, and delete it with the account (Section 8). We keep a coach's busy periods only for the booking window ahead, replacing them as the calendar changes. Disconnecting the calendar in Courtwell stops access immediately and deletes the stored busy periods and the credential. You can also remove Courtwell's access at any time from your Google Account's security settings (myaccount.google.com, under "Third-party apps and services"), which stops access; we then delete what we stored the next time we fail to reach your calendar. To ask us to delete anything sooner, email admin@courtwell.ai.
Limited Use. Courtwell's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. Where it comes from
From you; from your Coach or Team when they add you to a roster; from your device when you use the app; and from our identity, payment, and infrastructure providers in the course of their services.
5. Why we use it, and our legal basis
| Purpose | What we use | GDPR legal basis |
|---|---|---|
| Create and run your account | §3.1 | Contract (Art. 6(1)(b)) |
| Build and deliver your daily session, and adapt it to what you report | §3.2 | Contract; and explicit consent for health-related data (Art. 9(2)(a)) |
| Show your Coach your training records | §3.2, §3.3 | Contract; explicit consent for health-related data |
| Send you notifications you have not opted out of | §3.4 | Contract; legitimate interests (Art. 6(1)(f)) |
| Improve reliability and quality of the Service | §3.5, §3.9 | Legitimate interests |
| Keep the Service secure, prevent abuse, enforce our Terms | §3.9, §3.1 | Legitimate interests; legal obligation |
| Bill you and keep financial records | §3.8 | Contract; legal obligation |
| Respond to support and rights requests | §3.3 | Contract; legal obligation |
| Waitlist communications | §3.7 | Consent |
Purpose limitation. We use your training information to serve you and your coaching relationship. We do not use it to set anyone's compensation, to evaluate a coach's pay, or for any commercial purpose unrelated to delivering your training. If we ever want to use it for a new purpose, we will tell you and, where required, ask for your consent first.
Where consent is our basis, you can withdraw it at any time, which will end the parts of the Service that depend on it.
6. Artificial intelligence
6.1 What the AI does. The Service uses automated logic — and on some tiers a large language model from Anthropic — to select and order drills from the set your Coach authored and assigned to you. The model works inside that set and cannot invent drills, prescriptions, or standards.
6.2 What is sent to the model. This differs by feature, so we set it out separately.
- Building your daily session. An opaque identifier for you — never your name or email — the candidate drills your Coach assigned, and recent training history: sessions completed, logs, benchmark results, and recent readiness values.
- Extracting structure from messages and notes. The text of those messages and notes is sent to the same provider so that structured facts can be drawn from it.
- The assistant your Coach uses. When a Coach asks the in-product assistant about their roster, the assistant retrieves roster and billing records to answer, and those records include athlete display names and email addresses. We are telling you this plainly rather than describing a narrower rule that holds only for session generation.
We do not send your age category or guardian details to the model.
6.3 Training. Anthropic is contractually excluded from using our data to train its models. Our AI observability provider receives metadata only — model name, prompt version, token counts, timing — and never the text of a prompt or a response, and does not train on client data.
6.4 Automated decisions. The Service does not make decisions producing legal or similarly significant effects about you. Your Coach can review and override anything the system proposes, and the system can only narrow or lighten a session in response to what you report — never intensify it.
6.5 Who is speaking. Content the system generates for you — your daily session, and in-app system messages — is presented distinctly from a message your Coach sent you personally.
Replies to your messages work differently, and you should know how. When you message your Coach, the Service may draft a suggested reply. A human on your Coach's side reviews every draft and decides whether to send it, edit it, or write their own — nothing is sent to you automatically. The reply is attributed to the person who sent it, because that person is accountable for it, and the reply also tells you which of the three happened: a system draft they sent as written, a system draft they edited, or their own words. We record which it was for every reply, and every reply says so — the absence of a note is never how you find out.
7. Who we share it with
We do not sell your personal information. We do not share it for advertising. We share it with:
Your Coach or Team, as described in the Terms — this is the purpose of the Service.
Service providers ("subprocessors") who process it on our behalf under contract, listed below and kept current at courtwell.ai/subprocessors.
<!--subprocessors-table-start-->
| Provider | Entity | What they receive | Processing location |
|---|---|---|---|
| Cloudflare | Cloudflare, Inc. (US) | Hosting, database, object and video storage, video delivery, email sending, request logs, cookieless site analytics — effectively all Service data at rest and in transit | Global edge; primary database in the United States (western North America) |
| Supabase | Supabase, Inc. (US) | Managed PostgreSQL holding the billing ledger, AI agent run records, derived facts extracted from your messages, and curriculum embeddings; the primary athlete record is being migrated here | US (N. Virginia) |
| Clerk | Clerk.com (US) | Identity of record: email, name, credentials, session tokens, Google sign-in linkage | US |
| Anthropic | Anthropic, PBC (US) | AI processing as described in Section 6. Excluded from training on our data | US |
| Stripe | Stripe, Inc. (US) | Payment and subscription processing. Receives card details directly from you | US |
| Expo | Expo (650 Industries, Inc.) (US) | Push notification token and a content-free message body, relayed onward to Apple (APNs) or Google (FCM). Also delivers over-the-air app updates, so the app contacts Expo on launch, sending device and app-version metadata and your IP address | US |
| PostHog | PostHog Inc. (US) | Product analytics events keyed to an opaque identifier, with derived flags only | US |
| Langfuse | Langfuse GmbH | AI request metadata only — surface, model, prompt version, token counts, timing. No prompt or response text | US |
| Sentry | Functional Software, Inc. (US) | Application error reports: error type, message, stack, route. No account identifier, email, or training data | US |
| Google LLC (US) | Sign-in, where you choose Google; a coach's calendar busy times, where the coach connects a Google Calendar (Section 3.11); push delivery to Android devices | US |
<!--subprocessors-table-end-->
Others. We may disclose information to comply with law or valid legal process, to enforce our Terms, to protect the rights or safety of any person, and to a successor in a merger, acquisition, or sale of assets (we will notify you if that happens and this Policy would materially change).
8. How long we keep it
| Category | Retention |
|---|---|
| Training history — check-ins, sessions, logs, benchmarks, injury flags | Retained for as long as your account is open, and not on a fixed schedule. Multi-season history is the point of the product. Deleted on request, or when your account is closed and any grace period ends |
| Account and identity records | Life of the account, then deleted with it |
| Messages and notes | Life of the account, then deleted with it |
| Photos and clips sent inside a message | Deleted 180 days after they are attached to a message. This is enforced by a job that runs daily and deletes the stored file; the message itself stays in the conversation and shows that the attachment has expired. It applies to photos and clips in either direction, from you or from your coach. It does not apply to coaching videos in the drill library, which are not personal recordings of you and are kept for as long as the library is |
| Waitlist entries | Until you ask to be removed, or until we announce general availability |
| Financial and transaction records | At least seven years, for tax and accounting. Not deleted on request |
| Audit and consent records | Retained beyond deletion of the related account, because a consent record cannot be destroyed by the act it documents. Consent records are kept for three years after the account closes; other audit records are kept for seven years. |
| Application logs | 30 days at most. In practice they expire sooner — our logging platform's own retention window is shorter than that — and we do not extend it beyond 30 days. These logs hold identifiers and pointers, never the content of a check-in, a session, or a message |
| Analytics, error, and AI-metadata records held by providers | Kept for the retention period each provider sets in its own terms. We do not ask any provider to keep them longer |
| Database backups | Data you delete is removed from the live Service immediately and from any export, but a copy may persist in our providers' backup and point-in-time recovery snapshots until those age out. Our primary database keeps point-in-time snapshots for approximately 30 days. Our managed PostgreSQL provider takes a daily backup and keeps the most recent 7 days; we do not run point-in-time recovery on that database, so there is no longer window behind those daily copies. We do not restore a backup in order to recover deleted personal data |
9. Your rights and choices
9.1 Everyone. Whatever jurisdiction you are in, you may ask us to:
- access the personal information we hold about you and get a copy in a portable format;
- correct information that is inaccurate;
- delete your information, subject to the retention exceptions in Section 8;
- object to or restrict certain processing;
- withdraw consent where consent is our basis; and
- complain to us, and to a regulator.
How. Email admin@courtwell.ai. We will respond within 45 days, and will tell you if we need a further 45 days. We verify requests through the email address on the account. There is no charge for the first request in a 12-month period.
Appeals. If we decline a request, you may appeal by replying to our decision. We will respond within 60 days with our reasoning and, where your state provides one, information on contacting your attorney general.
No retaliation. We will not deny you service, charge you a different price, or give you a lesser experience for exercising these rights.
Being straight with you about the mechanism. On the effective date these requests are fulfilled manually by our team, not through a self-service button in the app. That does not change your rights or our deadlines. An in-app export and deletion flow is being built.
9.2 Notifications. You can turn off notification categories in the app. We will still send a small number of messages you cannot opt out of — safety escalations, guardian-consent confirmations, and billing notices to the person paying.
9.3 U.S. state privacy rights. If you are a resident of California, Colorado, Connecticut, Texas, Virginia, Utah, Oregon, Montana, or another state with a comprehensive privacy law, the rights in 9.1 are yours, including the right to know the categories of personal information collected, the sources, the purposes, and the categories of third parties we disclose to — all of which are set out in Sections 3, 4, 5, and 7.
We have not sold personal information or shared it for cross-context behavioral advertising in the preceding 12 months, and we do not do so now. We process sensitive personal information (health-related training data) only to provide the Service you asked for, and not to infer characteristics about you.
An authorized agent may submit a request on your behalf with written proof of authorization.
9.4 California "Shine the Light." We do not disclose personal information to third parties for their own direct marketing.
10. Health-related information
Several states — Washington's My Health My Data Act, Nevada's SB370, and Connecticut's health-data provisions among them — define "consumer health data" broadly enough to include information about your body, your soreness, your sleep, and your injuries, even when it is collected for coaching rather than clinical purposes. We treat your check-in answers, injury flags, session logs, and benchmark results as consumer health data.
- We collect and use it only to deliver your training and to make it visible to your Coach, as described in Section 5.
- We do not sell it. We will not sell it. Any sale would require your separate written authorization, which we do not seek.
- We do not use it for advertising, and we do not use it to make inferences about your health.
- You may withdraw your consent to our collection and use of it at any time by emailing admin@courtwell.ai, and you may ask us to delete it — including from our service providers.
- Employees and contractors have access to it only where their role requires it.
11. Children and minors
The Service is available to athletes aged 13 and over. We do not knowingly collect personal information from anyone under 13. Our system refuses to create an account in the under-13 age category; that refusal is a check in the account-creation code, not a screen a person can skip past.
An athlete aged 13 to 17 consents for themselves. We do not currently ask a parent or legal guardian to create, approve or activate an account, and we do not currently collect a date of birth or a country of residence from any athlete. An athlete aged 13 to 17 is asked to accept these terms and this Policy in the same way an adult is, and the information we collect about them is the same information Section 3 describes for everyone else. This is a product decision, made by Courtwell, that has not been reviewed by a lawyer. If you are a parent or guardian and you would rather your athlete not use the Service, or you want to see or delete what we hold about them, contact admin@courtwell.ai and we will act on it.
The guardian-consent mechanism described in the Terms of Service is not built. There is no way today for a guardian account to be linked to an athlete's, no verified-parent check, and no guardian-facing screen. The "Guardian link" field in Section 3.1 is reserved and unused, and the guardian consent events named in Section 3.9 have never been recorded, because nothing can create the relationship they would describe.
Under-13 accounts remain closed, and we intend to open them only once the following are in place:
- verifiable parental consent obtained before we collect any personal information from a child under 13, as the Children's Online Privacy Protection Act requires;
- the age of digital consent that applies where the athlete lives, applied per athlete rather than as one global number — it is 13 in the United States and varies between 13 and 16 across the European Union;
- a way for a Guardian to review the child's information, refuse to permit further collection, and require deletion; and
- a rule that a child's participation is not conditioned on disclosing more information than is reasonably necessary.
If you believe a child under 13 has provided us information, contact admin@courtwell.ai and we will delete it.
12. If you are in the European Economic Area, the United Kingdom, or Switzerland
12.1 Controller. Courtwell, LLC, c/o United States Corporation Agents, Inc., 10601 Clarence Dr., Suite 250, Frisco, TX 75033, is the controller. We have not appointed a representative in the European Union or the United Kingdom. Contact us directly at admin@courtwell.ai.
12.2 Legal bases. See the table in Section 5. Your training information is health-related data under Article 9, and we process it on the basis of your explicit consent, which you give at signup and may withdraw at any time.
12.3 Your rights. Access, rectification, erasure, restriction, objection, portability, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Section 6.4 explains why the Service does not make such decisions). Exercise them at admin@courtwell.ai.
12.4 Complaints. You may complain to your local supervisory authority, or to the UK Information Commissioner's Office.
12.5 International transfers. We process personal data in the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or Swiss equivalent as applicable), together with the transfer safeguards our providers maintain. You may request a copy of the relevant safeguards at admin@courtwell.ai.
12.6 Retention. As set out in Section 8.
13. How we protect information
We describe only measures that are actually in place.
- Encryption in transit. Connections to the Service use TLS, and our servers send HTTP Strict Transport Security headers instructing browsers to use HTTPS. Our API refuses an unencrypted request outright rather than relying only on a redirect. We require TLS 1.2 or newer, and our HTTP Strict Transport Security policy lasts twelve months.
- Encryption at rest. Our database and object storage are encrypted at rest by our hosting provider using platform-managed keys.
- Separation between coaches. Every athlete record carries a workspace identifier, and ordinary access to athlete records is routed through an access layer that applies it — no query can omit it. Two isolation cases are verified automatically on every change and were confirmed by deliberately breaking them. A separate, restricted path exists for our own administrators to read across workspaces; it is reachable only by an administrator and is audited as described above.
- Minimized data. We do not collect a date of birth. Check-ins are fixed-choice rather than free text. Analytics carry derived flags rather than your answers. Notification messages contain no training content. Logs contain identifiers, not content.
- Access control. Administrative access across workspaces is restricted and recorded. Where an administrator reads records across all workspaces from our internal console, each read writes its own audit record. Where an administrator is granted temporary scoped access inside a single workspace for support, the grant itself is audited as one record covering that window, and every write made under it is audited individually — individual reads within the window are not recorded separately.
- Site protections. Our public site sets a strict content security policy that permits one third-party origin — the cookieless Cloudflare Web Analytics beacon described in Section 3.6 — and no others. It loads no advertising or cross-site tracking scripts, and serves its fonts from our own domain. It also sets
X-Frame-Options,Referrer-Policy, and a permissions policy denying camera, microphone, and geolocation. - Secret scanning and dependency checks run automatically before any change is released.
- Vulnerability disclosure. Report a security issue via
courtwell.ai/.well-known/security.txt. We offer safe harbour for good-faith research.
No system is perfectly secure, and we cannot guarantee the security of information transmitted to us. We have not obtained SOC 2, ISO 27001, or HIPAA attestations, and we do not claim them.
14. Changes to this Policy
We will post any change here and update the date at the top. If a change is material, we will notify you by email or in the app before it takes effect. Where the change requires your consent, we will ask for it.
15. Contact us
Privacy questions and rights requests: admin@courtwell.ai Security: courtwell.ai/.well-known/security.txt Post: Courtwell, LLC, c/o United States Corporation Agents, Inc., 10601 Clarence Dr., Suite 250, Frisco, TX 75033