Legal
Privacy policy.
Last updated: August 2026. This describes what GOLSZ actually collects, how it's used, and the choices you have — for the real product, not a placeholder.
1. Who we are
GOLSZ is operated from Montreal, Canada. This policy explains how we collect, use, store, and protect personal data when you create a GOLSZ account, build an athlete profile, use the AI assistant ("Scout"), or otherwise use the GOLSZ app at golsz.vercel.app (and, once connected, golsz.com). [Legal review advised] the exact registered legal-entity name and address for the data-controller identification should be confirmed and inserted here.
2. Data we collect
Account information. When you sign up, we collect your full name, email address, date of birth, and account type (player, scout, agent, coach, or physio). Your date of birth determines whether you can create your own account (18+) or whether a parent/guardian must create it on your behalf (under 18 — see Section 5).
Athlete profile data. If you build an athlete profile, we store what you choose to enter: sport, position, height, weight, graduation year, club/team name, country, playing foot, recruiting status, a short bio, and links to highlight footage you provide. All of this is optional beyond what's required to use core features, and you control what's visible on a shared Passport link.
Uploaded content. Profile photos and any images you attach to a post are stored in our file storage (Supabase Storage), each user's files kept in a folder scoped to their own account.
AI assistant (Scout) interactions. Questions you ask Scout and the responses you receive are stored so the conversation can continue across sessions. We also store structured signals used to personalize Scout's answers (e.g. your stated goals, sport, and profile context) and, separately for our own cost/quality monitoring, metadata about each AI request (which model handled it, token counts, estimated cost, response time) — this monitoring data is not shared externally and is not linked to what you asked beyond what's needed to debug or improve the service.
Payment information. If you subscribe to a paid plan, checkout is handled entirely by Stripe — GOLSZ never receives or stores your card number. We store only your Stripe customer reference, your plan tier, and subscription/payment status (e.g. whether a recent charge failed) so we can enforce what your plan includes.
Push notifications. If you opt in, your browser generates a push subscription (an endpoint URL and encryption keys) which we store so we can deliver notifications (e.g. reminders, messages). You can revoke this at any time from Settings or your browser's notification permissions.
Trust & safety data. If content is reported, reviewed by our automated moderation check, or you submit a verification request or an appeal, we store the relevant content, the decision, and (for admin actions) who took them, in order to keep the platform safe and to have a record if a decision is disputed.
Technical data. Our infrastructure providers (Supabase, Vercel) process standard request metadata (IP address, timestamps) as part of operating the service and preventing abuse (e.g. rate-limiting signup attempts) — we don't separately collect or sell this data.
3. Cookies and analytics
GOLSZ does not use cookies, and does not use any third-party advertising or analytics trackers (no Google Analytics, no ad pixels). The app stores a small amount of data in your browser's local storage: your theme (light/dark) and language preference, and — via our authentication provider's standard client library — your session sign-in token, so you stay signed in between visits. None of this is shared with third parties for advertising purposes.
Bot protection. The signup form is built to support Cloudflare Turnstile, a privacy-respecting CAPTCHA alternative. It is not currently active in production. If and when it's turned on, Cloudflare will process limited technical data (such as your IP address) to assess whether a signup attempt is automated, under Cloudflare's own privacy policy.
4. How we use your data
We use your data to: operate your account and athlete profile; power Scout's AI-assisted guidance; process payments and enforce plan entitlements; detect and act on abuse, spam, or unsafe content; send you notifications you've opted into; respond to support requests; and meet our legal obligations. We do not sell your personal data.
5. Under-16 accounts (parent/guardian-controlled)
GOLSZ does not currently collect personal data about anyone under 18. As of 20 September 2026 an account requires the holder to be 18 or over, sign-up refuses a date of birth under 18, and the endpoint that formerly created parent-managed profiles for children refuses every request. No route in the product creates an under-18 profile.
Earlier versions of this policy described a parent- or guardian-managed profile in which a child's name and date of birth were collected and held inside an adult's account. That structure has been withdrawn. [Legal review advised] counsel should confirm what must be done about any under-18 data recorded while that structure was live — retention, deletion, or notification — and should review the reinstated clauses before managed profiles are ever reintroduced, rather than afterwards.
6. AI processing and sub-processors
Scout is currently powered by Anthropic's Claude models. When you ask Scout a question, the relevant text (your question and enough profile/conversation context to answer it usefully) is sent to Anthropic's API to generate a response. Anthropic acts as a data processor for this purpose. [Legal review advised] Anthropic's own data-retention and model-training terms for API usage should be confirmed and summarized accurately here rather than assumed — we have not independently verified whether API-submitted content is used to train Anthropic's models.
Scout also has a second AI provider, xAI (Grok), used only as an emergency failover. If Anthropic's API is unavailable or fails to respond, the same request — your question plus the profile and conversation context needed to answer it — is sent to xAI's API instead, so Scout keeps working during an outage. It is not used for routine requests. Because a failover can happen on any message, including a message about or from a managed under-18 athlete, we name it here rather than treating it as an implementation detail. [Legal review advised] xAI's data-retention and model-training terms for API usage should be confirmed and summarized accurately here rather than assumed, on the same basis as Anthropic's above.
Our other core infrastructure sub-processors are Supabase (database, authentication, and file storage) and Vercel (application hosting) — both are necessary to any use of the product — and Stripe for payment processing. [Legal review advised] exact hosting regions for Supabase/Vercel and whether an international-transfer mechanism (e.g. Standard Contractual Clauses) is needed for any of these sub-processors, given that GOLSZ is based in Canada while serving users in the EU/EEA, should be confirmed directly with each provider rather than assumed here.
7. Data retention
We keep your account and profile data for as long as your account is active. If you delete your account, your profile, uploaded images, and associated app data are permanently removed. If your account manages an under-18 athlete profile that nobody else can sign in to, we will not delete your account and leave theirs stranded: we tell you which profiles are affected and ask you to confirm, and confirming deletes those profiles together with yours. Some records — for example, moderation decisions, reports, or admin audit logs involving your account — may be retained for a longer period where necessary for safety, fraud-prevention, or legal record-keeping. [Legal review advised] specific retention periods for each data category (rather than "as long as necessary") should be defined with counsel to meet GDPR data-minimization requirements precisely.
8. Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. You can delete your own account data at any time from Settings in the app. For anything else, contact us at hello@golsz.com. If you're in the EU/EEA or the UK, you also have the right to lodge a complaint with the data protection authority in your own country of residence. If you're in Canada, you can complain to the Office of the Privacy Commissioner of Canada, and in Québec to the Commission d'accès à l'information. [Legal review advised] a defined response-time commitment (e.g. "within 30 days") should be added once we've confirmed our internal process can meet it, and counsel should confirm whether an EU/UK representative must be appointed under GDPR Article 27 now that GOLSZ is established outside the EU but still offers the service to people in it.
9. Security
Data is protected in transit with encryption, and access to your data within our database is enforced by row-level security policies so that, by default, only you (or, for a managed under-18 profile, the linked parent account) can read or write your own records. Administrative access is limited to authorized GOLSZ personnel and logged. No system is perfectly secure, and we can't guarantee absolute security of information transmitted to us.
10. Children's privacy (general)
Beyond the parent-controlled account structure in Section 5, GOLSZ is not directed at, and does not knowingly collect data from, children in a manner outside that structure. If you believe a child's data has been collected outside the parent-managed flow, contact us and we'll investigate and remove it.
11. Changes to this policy
We may update this policy as the product changes. Material changes will be reflected by updating the "last updated" date above, and where appropriate we'll notify account holders directly.
12. Contact
Questions about this policy, or requests relating to your data, can be sent to hello@golsz.com.