Courtwell

Legal

Privacy Policy

Version: 2026-09-24 — the version string a consent record cites (CW-1374). It names the exact words an acceptance was shown, which is why it moves with every material edit while the effective date below does not. Bump it in the same change as any material edit — CURRENT_CONSENT_VERSIONS in packages/contracts is held to this line by a test, and every athlete whose accepted version is older is asked again on their next launch.

Effective date: September 1, 2026 Last updated: September 24, 2026


1. Who we are and what this covers

Courtwell, LLC ("Courtwell," "we," "us") is a Texas limited liability company based in Dallas, Texas. This Privacy Policy explains what personal information we collect through the Courtwell app, the courtwell.ai websites, and our coach and administrative consoles (together, the "Service"), why we collect it, who we share it with, and the choices you have.

Our role. For Athletes and Coaches using the Service, Courtwell is the controller (or, under U.S. state privacy laws, the "business") of the personal information described here. Where a Team or organization purchases the Service for its athletes, we act as a controller for the operation of the Service and may also act as a processor on that organization's behalf for records it directs us to hold; where those roles differ, the organization's own privacy notice also applies.

Contact. admin@courtwell.ai Postal: Courtwell, LLC, c/o United States Corporation Agents, Inc., 10601 Clarence Dr., Suite 250, Frisco, TX 75033.


2. The short version


3. What we collect

3.1 Account and identity

DataNotes
Email addressThe identifier your account is keyed to and how invitations reach you
Display nameA single name field; we do not collect a legal first/last name split
Phone numberOptional; collected only where you provide it
RoleAthlete, Coach, or administrator
Age categoryadult, teen_13_17, or under_13 only. We do not ask for, transmit, or store a date of birth. Our system creates adult and teen_13_17 accounts and refuses under_13 — see Section 11
Consent statusWhether the account is self-consented or guardian-consented. Every account is self-consented; our system refuses to record a guardian consent — see Section 11
Guardian linkFor a guardian-consented account, the linked Guardian's account. Reserved; not in use today, and no account can be given one
Sign-in credentialsHeld by our identity provider (Clerk), not by Courtwell. If you sign in with Google, Google confirms your identity to Clerk; we receive the resulting account record, not your Google password

3.2 Training and health-adjacent information

This is the most sensitive information we hold, and we treat it as such.

DataNotes
Daily readiness check-inFixed-choice answers on sleep, soreness, energy, and stress. No free-text journaling
Injury flagIf you report discomfort, the body area you indicate — chosen from a fixed picker of 16 areas, recorded against a 19-zone anatomical list — together with the dates it was first flagged, last confirmed, and cleared. Over time this builds a record of the shape "left knee, flagged twelve days running"
Session recordsWhich drills were delivered, completed, skipped (and the reason), and in what order
Post-session logEffort rating, how it went, makes on shooting drills, and an optional free-text note
Benchmark resultsResults of named physical tests, with dates
Coaching directivesA Coach's instruction to ease or hold your training, and any note attached

We are not a healthcare provider and this is not medical data. We nonetheless treat it as sensitive and, where the law defines "consumer health data" broadly, we handle it under those rules. See Section 10.

3.3 Messages and free text

Messages you send to your Coach, replies your Coach sends you, notes on a session, support requests, and — for coaches — notes and chat with the in-product assistant. These are free text, so please do not include information you would not want stored, including clinical details about yourself or anyone else.

3.4 Device and notification information

Push notification token and device platform (iOS/Android); your time zone; and your per-category notification preferences. If a message to you bounces or you opt out, we record that so we stop sending.

3.5 Usage and product analytics

Events describing how the Service is used — for example that a check-in was completed or a session generated — keyed to an internal, opaque account identifier, never your email, and carrying derived flags rather than your raw answers (for example, "readiness was low," never your four check-in values).

3.6 Website information

Our public site uses Cloudflare Web Analytics, which is cookieless and does not fingerprint or track you across sites. The site loads no third-party advertising, tracking, or font services; fonts are served from our own domain. We do not use advertising cookies or pixels anywhere.

3.7 Waitlist

If you submit our waitlist form we collect your name and email address, and any note you add. We use it to contact you about Courtwell's availability and for nothing else. Every waitlist email carries a one-click unsubscribe link, and using it stops all email from Courtwell to that address. You can also be removed at any time by emailing admin@courtwell.ai.

3.8 Billing information

When paid plans begin: your billing contact details, subscription status and period, and identifiers issued by our payment processor. Card numbers go directly to the processor and never reach Courtwell's systems.

3.9 Technical logs and security records

Application logs containing a request identifier, the account, workspace, and session identifiers involved, and the operation performed — identifiers and pointers, not the content of your check-ins or sessions. Your IP address is processed transiently for rate limiting and abuse prevention and is not stored in our application database; our hosting provider logs request metadata, including IP address, as part of operating the network.

We also keep an audit record of security-relevant actions — for example when a coach overrides a system recommendation, when an administrator reads records across workspaces or is granted temporary support access to one, and (when guardian consent exists) guardian consent events. Section 13 describes how finely each of those is recorded. No guardian consent event has ever been recorded, because no guardian relationship can be created — see Section 11.

3.10 Information we deliberately do not collect

Date of birth. Home address. Government identifiers. Payment card numbers. Precise geolocation. Biometric identifiers. Clinical or medical records, diagnoses, or treatment information. Advertising identifiers. We do not buy personal information from data brokers.

3.11 Information from your Google Account

We receive information from Google only when you choose to connect your Google Account to Courtwell, and only what the permission you approve on Google's screen allows. This section covers that information, which Google calls "Google user data".

What we access.

How we use it. Your Google profile identifies you and signs you in. Your busy periods are used for one thing: so that athletes are never offered a session time that clashes with them, and so those times stay current as your calendar changes. We use Google user data only to provide and improve these features. We do not sell it, use it for advertising, or use it to train artificial intelligence models, ours or anyone else's.

How we share it. We share Google user data only with the providers in Section 7 that host and run the Service on our behalf (Clerk holds your sign-in profile; Cloudflare hosts our database), under contracts that limit them to doing that. We do not share it with coaches, athletes or anyone else, except that your profile name appears to the people you work with in Courtwell, as any account name does. People at Courtwell do not read it except where you ask us to, where it is needed for security, or where the law requires it.

How we protect it. Google user data travels only over encrypted connections (Section 13). The credential Google issues for a calendar connection is encrypted before it is stored, is used only by the server to read busy times, and is never shown in the app or sent to your device. Data at rest is encrypted by our hosting provider.

How long we keep it, and how to delete it. We keep your sign-in profile for as long as you have an account, and delete it with the account (Section 8). We keep a coach's busy periods only for the booking window ahead, replacing them as the calendar changes. Disconnecting the calendar in Courtwell stops access immediately and deletes the stored busy periods and the credential. You can also remove Courtwell's access at any time from your Google Account's security settings (myaccount.google.com, under "Third-party apps and services"), which stops access; we then delete what we stored the next time we fail to reach your calendar. To ask us to delete anything sooner, email admin@courtwell.ai.

Limited Use. Courtwell's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.


4. Where it comes from

From you; from your Coach or Team when they add you to a roster; from your device when you use the app; and from our identity, payment, and infrastructure providers in the course of their services.


5. Why we use it, and our legal basis

PurposeWhat we useGDPR legal basis
Create and run your account§3.1Contract (Art. 6(1)(b))
Build and deliver your daily session, and adapt it to what you report§3.2Contract; and explicit consent for health-related data (Art. 9(2)(a))
Show your Coach your training records§3.2, §3.3Contract; explicit consent for health-related data
Send you notifications you have not opted out of§3.4Contract; legitimate interests (Art. 6(1)(f))
Improve reliability and quality of the Service§3.5, §3.9Legitimate interests
Keep the Service secure, prevent abuse, enforce our Terms§3.9, §3.1Legitimate interests; legal obligation
Bill you and keep financial records§3.8Contract; legal obligation
Respond to support and rights requests§3.3Contract; legal obligation
Waitlist communications§3.7Consent

Purpose limitation. We use your training information to serve you and your coaching relationship. We do not use it to set anyone's compensation, to evaluate a coach's pay, or for any commercial purpose unrelated to delivering your training. If we ever want to use it for a new purpose, we will tell you and, where required, ask for your consent first.

Where consent is our basis, you can withdraw it at any time, which will end the parts of the Service that depend on it.


6. Artificial intelligence

6.1 What the AI does. The Service uses automated logic — and on some tiers a large language model from Anthropic — to select and order drills from the set your Coach authored and assigned to you. The model works inside that set and cannot invent drills, prescriptions, or standards.

6.2 What is sent to the model. This differs by feature, so we set it out separately.

We do not send your age category or guardian details to the model.

6.3 Training. Anthropic is contractually excluded from using our data to train its models. Our AI observability provider receives metadata only — model name, prompt version, token counts, timing — and never the text of a prompt or a response, and does not train on client data.

6.4 Automated decisions. The Service does not make decisions producing legal or similarly significant effects about you. Your Coach can review and override anything the system proposes, and the system can only narrow or lighten a session in response to what you report — never intensify it.

6.5 Who is speaking. Content the system generates for you — your daily session, and in-app system messages — is presented distinctly from a message your Coach sent you personally.

Replies to your messages work differently, and you should know how. When you message your Coach, the Service may draft a suggested reply. A human on your Coach's side reviews every draft and decides whether to send it, edit it, or write their own — nothing is sent to you automatically. The reply is attributed to the person who sent it, because that person is accountable for it, and the reply also tells you which of the three happened: a system draft they sent as written, a system draft they edited, or their own words. We record which it was for every reply, and every reply says so — the absence of a note is never how you find out.


7. Who we share it with

We do not sell your personal information. We do not share it for advertising. We share it with:

Your Coach or Team, as described in the Terms — this is the purpose of the Service.

Service providers ("subprocessors") who process it on our behalf under contract, listed below and kept current at courtwell.ai/subprocessors.

<!--subprocessors-table-start-->

ProviderEntityWhat they receiveProcessing location
CloudflareCloudflare, Inc. (US)Hosting, database, object and video storage, video delivery, email sending, request logs, cookieless site analytics — effectively all Service data at rest and in transitGlobal edge; primary database in the United States (western North America)
SupabaseSupabase, Inc. (US)Managed PostgreSQL holding the billing ledger, AI agent run records, derived facts extracted from your messages, and curriculum embeddings; the primary athlete record is being migrated hereUS (N. Virginia)
ClerkClerk.com (US)Identity of record: email, name, credentials, session tokens, Google sign-in linkageUS
AnthropicAnthropic, PBC (US)AI processing as described in Section 6. Excluded from training on our dataUS
StripeStripe, Inc. (US)Payment and subscription processing. Receives card details directly from youUS
ExpoExpo (650 Industries, Inc.) (US)Push notification token and a content-free message body, relayed onward to Apple (APNs) or Google (FCM). Also delivers over-the-air app updates, so the app contacts Expo on launch, sending device and app-version metadata and your IP addressUS
PostHogPostHog Inc. (US)Product analytics events keyed to an opaque identifier, with derived flags onlyUS
LangfuseLangfuse GmbHAI request metadata only — surface, model, prompt version, token counts, timing. No prompt or response textUS
SentryFunctional Software, Inc. (US)Application error reports: error type, message, stack, route. No account identifier, email, or training dataUS
GoogleGoogle LLC (US)Sign-in, where you choose Google; a coach's calendar busy times, where the coach connects a Google Calendar (Section 3.11); push delivery to Android devicesUS

<!--subprocessors-table-end-->

Others. We may disclose information to comply with law or valid legal process, to enforce our Terms, to protect the rights or safety of any person, and to a successor in a merger, acquisition, or sale of assets (we will notify you if that happens and this Policy would materially change).


8. How long we keep it

CategoryRetention
Training history — check-ins, sessions, logs, benchmarks, injury flagsRetained for as long as your account is open, and not on a fixed schedule. Multi-season history is the point of the product. Deleted on request, or when your account is closed and any grace period ends
Account and identity recordsLife of the account, then deleted with it
Messages and notesLife of the account, then deleted with it
Photos and clips sent inside a messageDeleted 180 days after they are attached to a message. This is enforced by a job that runs daily and deletes the stored file; the message itself stays in the conversation and shows that the attachment has expired. It applies to photos and clips in either direction, from you or from your coach. It does not apply to coaching videos in the drill library, which are not personal recordings of you and are kept for as long as the library is
Waitlist entriesUntil you ask to be removed, or until we announce general availability
Financial and transaction recordsAt least seven years, for tax and accounting. Not deleted on request
Audit and consent recordsRetained beyond deletion of the related account, because a consent record cannot be destroyed by the act it documents. Consent records are kept for three years after the account closes; other audit records are kept for seven years.
Application logs30 days at most. In practice they expire sooner — our logging platform's own retention window is shorter than that — and we do not extend it beyond 30 days. These logs hold identifiers and pointers, never the content of a check-in, a session, or a message
Analytics, error, and AI-metadata records held by providersKept for the retention period each provider sets in its own terms. We do not ask any provider to keep them longer
Database backupsData you delete is removed from the live Service immediately and from any export, but a copy may persist in our providers' backup and point-in-time recovery snapshots until those age out. Our primary database keeps point-in-time snapshots for approximately 30 days. Our managed PostgreSQL provider takes a daily backup and keeps the most recent 7 days; we do not run point-in-time recovery on that database, so there is no longer window behind those daily copies. We do not restore a backup in order to recover deleted personal data

9. Your rights and choices

9.1 Everyone. Whatever jurisdiction you are in, you may ask us to:

How. Email admin@courtwell.ai. We will respond within 45 days, and will tell you if we need a further 45 days. We verify requests through the email address on the account. There is no charge for the first request in a 12-month period.

Appeals. If we decline a request, you may appeal by replying to our decision. We will respond within 60 days with our reasoning and, where your state provides one, information on contacting your attorney general.

No retaliation. We will not deny you service, charge you a different price, or give you a lesser experience for exercising these rights.

Being straight with you about the mechanism. On the effective date these requests are fulfilled manually by our team, not through a self-service button in the app. That does not change your rights or our deadlines. An in-app export and deletion flow is being built.

9.2 Notifications. You can turn off notification categories in the app. We will still send a small number of messages you cannot opt out of — safety escalations, guardian-consent confirmations, and billing notices to the person paying.

9.3 U.S. state privacy rights. If you are a resident of California, Colorado, Connecticut, Texas, Virginia, Utah, Oregon, Montana, or another state with a comprehensive privacy law, the rights in 9.1 are yours, including the right to know the categories of personal information collected, the sources, the purposes, and the categories of third parties we disclose to — all of which are set out in Sections 3, 4, 5, and 7.

We have not sold personal information or shared it for cross-context behavioral advertising in the preceding 12 months, and we do not do so now. We process sensitive personal information (health-related training data) only to provide the Service you asked for, and not to infer characteristics about you.

An authorized agent may submit a request on your behalf with written proof of authorization.

9.4 California "Shine the Light." We do not disclose personal information to third parties for their own direct marketing.


10. Health-related information

Several states — Washington's My Health My Data Act, Nevada's SB370, and Connecticut's health-data provisions among them — define "consumer health data" broadly enough to include information about your body, your soreness, your sleep, and your injuries, even when it is collected for coaching rather than clinical purposes. We treat your check-in answers, injury flags, session logs, and benchmark results as consumer health data.


11. Children and minors

The Service is available to athletes aged 13 and over. We do not knowingly collect personal information from anyone under 13. Our system refuses to create an account in the under-13 age category; that refusal is a check in the account-creation code, not a screen a person can skip past.

An athlete aged 13 to 17 consents for themselves. We do not currently ask a parent or legal guardian to create, approve or activate an account, and we do not currently collect a date of birth or a country of residence from any athlete. An athlete aged 13 to 17 is asked to accept these terms and this Policy in the same way an adult is, and the information we collect about them is the same information Section 3 describes for everyone else. This is a product decision, made by Courtwell, that has not been reviewed by a lawyer. If you are a parent or guardian and you would rather your athlete not use the Service, or you want to see or delete what we hold about them, contact admin@courtwell.ai and we will act on it.

The guardian-consent mechanism described in the Terms of Service is not built. There is no way today for a guardian account to be linked to an athlete's, no verified-parent check, and no guardian-facing screen. The "Guardian link" field in Section 3.1 is reserved and unused, and the guardian consent events named in Section 3.9 have never been recorded, because nothing can create the relationship they would describe.

Under-13 accounts remain closed, and we intend to open them only once the following are in place:

If you believe a child under 13 has provided us information, contact admin@courtwell.ai and we will delete it.


12. If you are in the European Economic Area, the United Kingdom, or Switzerland

12.1 Controller. Courtwell, LLC, c/o United States Corporation Agents, Inc., 10601 Clarence Dr., Suite 250, Frisco, TX 75033, is the controller. We have not appointed a representative in the European Union or the United Kingdom. Contact us directly at admin@courtwell.ai.

12.2 Legal bases. See the table in Section 5. Your training information is health-related data under Article 9, and we process it on the basis of your explicit consent, which you give at signup and may withdraw at any time.

12.3 Your rights. Access, rectification, erasure, restriction, objection, portability, and the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects (Section 6.4 explains why the Service does not make such decisions). Exercise them at admin@courtwell.ai.

12.4 Complaints. You may complain to your local supervisory authority, or to the UK Information Commissioner's Office.

12.5 International transfers. We process personal data in the United States. Where we transfer personal data out of the EEA, the UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (with the UK Addendum or Swiss equivalent as applicable), together with the transfer safeguards our providers maintain. You may request a copy of the relevant safeguards at admin@courtwell.ai.

12.6 Retention. As set out in Section 8.


13. How we protect information

We describe only measures that are actually in place.

No system is perfectly secure, and we cannot guarantee the security of information transmitted to us. We have not obtained SOC 2, ISO 27001, or HIPAA attestations, and we do not claim them.


14. Changes to this Policy

We will post any change here and update the date at the top. If a change is material, we will notify you by email or in the app before it takes effect. Where the change requires your consent, we will ask for it.


15. Contact us

Privacy questions and rights requests: admin@courtwell.ai Security: courtwell.ai/.well-known/security.txt Post: Courtwell, LLC, c/o United States Corporation Agents, Inc., 10601 Clarence Dr., Suite 250, Frisco, TX 75033