Privacy Policy
Last updated: August 17, 2026
Scoutyx ("we", "us") connects athletes, scouts, and organisations. This policy explains what data we collect, why, the legal basis for it, and the choices you have — including the extra protections we apply to everyone under 18.
1. Information we collect
- Account data: email address, password (hashed with bcrypt, never stored in plain text), and role (athlete, scout, or organisation).
- Profile data: name, date of birth, country, sport, position, physical measurements, sport-specific statistics, bio, and any photos or videos you upload.
- Guardian data (under-18 accounts only): a parent or guardian's email address and a record of their consent, collected only to satisfy COPPA and GDPR Article 8. See section 5.
- Content you create: posts, comments, direct messages between users, and shortlists.
- Search queries: the natural-language searches scouts and organisations type into Athene.
- Consent records: when you accept our terms, and when you grant or withdraw the optional marketing permission, we record the fact, the moment, the version of the wording you were shown, and the IP address it came from. See section 7 for why the withdrawals are kept as well as the grants.
- Payment data: handled entirely by Stripe on our website. Scoutyx never receives or stores card numbers.
- Identity verification (optional): if you choose to verify your identity, your document and selfie are sent directly to Stripe and are never received or stored by Scoutyx. We keep only whether the check succeeded, a Stripe reference so we can look up a support case, and how many attempts you have used. We do not keep the document, the photograph, your document number, or the date of birth printed on it. See section 6.
2. Legal basis for processing (GDPR Article 6)
- Performance of a contract — operating your account, showing your profile to scouts, delivering messages, and providing a subscription you have paid for. Without this data there is no service.
- Consent — for under-18 accounts, the verifiable consent of a parent or guardian before any profile becomes visible (Article 8). Consent can be withdrawn at any time; see section 5.
- Consent — for marketing email and for using your content to promote Scoutyx. This one is optional, separate from everything above, and switched off unless you switch it on. Withdrawing it costs you no part of the service; see section 7.
- Legitimate interests — keeping the platform safe: preventing fraud and abuse, scanning uploads for malware, rate-limiting, and reviewing reported content. We balance this against your rights and collect no more than the purpose needs.
- Legal obligation — retaining payment and tax records where law requires it.
3. How we use it
- To operate your profile and let scouts and organisations find athletes who match what they are looking for.
- To power Athene search. Athene uses an AI model to extract intent from a natural-language query — it never invents athlete data. Every result comes from our own database. Only the query text is sent to the model; profiles are not.
- To send transactional email: email confirmation, guardian consent, password resets, and security notices.
- To process subscription payments, which happen on our website.
- To detect and prevent abuse, fraud, and breaches of our terms.
We do not sell your personal data. We do not use your profile data to train AI models, ours or anyone else's. We do not run third-party advertising.
4. Who we share data with
Only the providers needed to run Scoutyx, each acting as a processor under its own agreement:
- Railway (EU region) — application hosting, database, and storage of uploaded photos and videos.
- Vercel — hosting for this website.
- Stripe — subscription payments, the card check used for guardian verification (section 5), and optional identity verification (section 6). Where you verify your identity, Stripe receives your document and selfie directly and acts as an independent controller for that check under its own privacy policy.
- Resend — delivery of transactional email.
- OpenAI — intent extraction for Athene searches. Query text only; never profile data or personal details.
Some of these providers process data outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses.
Your profile is not visible to other users until your account is active — and, if you are under 18, not until a guardian has completed verification.
5. Under-18 accounts (COPPA and GDPR Article 8)
Scoutyx welcomes athletes under 18. COPPA applies in the United States to users under 13 and GDPR Article 8 applies in the EU to users under 16; rather than track thresholds per country, we apply the same protections to everyone under 18.
This is what actually happens when someone under 18 signs up:
- The account is immediately placed in a restricted state. It does not appear in search or in Athene results, no scout or organisation can see it or make contact, and the account cannot post or send messages.
- We ask for a parent or guardian's email address and send them a verification link.
- The guardian confirms they are the parent or guardian and verifies with a payment card on a page hosted by Stripe. In most regions this verifies the card with no charge at all; where that method is unavailable, a small charge (currently $0.50) is taken and refunded immediately. The card is used only to confirm that an adult is giving consent. We never see or store the card details.
- Only after consent does the account move to a limited sandbox state, and from there to full visibility. A minor's account never goes straight to public.
- A minor's contact details are never shown anywhere on the platform. Scouts and organisations can only reach them through in-app messaging, which can be blocked and reported.
A guardian can withdraw consent at any time and ask us to delete the account and its data by emailing gcampoyf@gmail.com. We act on this without requiring a reason.
6. Identity verification (optional)
Any adult account can choose to verify its identity and display a verified badge. It is entirely optional — nothing on Scoutyx requires it, and choosing not to verify changes nothing about how your profile works.
The check is carried out by Stripe Identity. You photograph a government document and take a selfie on a page hosted by Stripe, and that material goes to Stripe directly. It does not pass through Scoutyx, it is not stored on our servers, and it is not written to our logs.
What Scoutyx receives and keeps:
- whether the check succeeded;
- a Stripe reference for the check, so we can look up a support case if you contact us;
- how many attempts you have used, and how you paid.
What Scoutyx never keeps:
- the image of your document, or the selfie — we never receive these at all;
- your document number, nationality or expiry date as printed on the document — we never receive these either;
- the name and address Stripe verified. These do reach our server, in the same response that carries the one field we asked for: Stripe returns them together and offers no way to request one alone. They are not read, not written to our database and not logged — the response is discarded as soon as the age check is done. We would rather say this plainly than claim a tidier thing that is not quite true.
- the date of birth on the document. We do read it once, at the moment the check completes, for the single purpose described below — and then we discard it. It is never written to our database.
- the reason a check failed.
Why we read the date of birth. Identity verification is not available to anyone under 18. Until this check, the only date of birth we hold is the one you typed in yourself. A government document is the one date nobody chose, so we compare it — once — and if it shows you are under 18 we refuse the badge, return your payment where we are able to, and move your account into the guardian consent process described in section 5. That is not a penalty: it means the parental consent this platform is legally required to obtain was never obtained, and we are asking for it now.
Stripe acts as an independent controller for the verification itself and holds the document under its own privacy policy and retention schedule. Requests to delete the material Stripe holds should be directed to Stripe; email gcampoyf@gmail.com and we will point you to the right place.
7. Marketing and promotion (optional)
Version 1.0 · effective August 17, 2026
Everything in this section is optional and switched off until you switch it on. Nothing about the service changes if you leave it off: no feature is withheld, your profile is not ranked lower, and scouts see you exactly the same either way.
What you are agreeing to, if you agree.
- Email from us that is not transactional — news about Scoutyx, offers, opportunities and events. Transactional email (confirming your address, guardian consent, password resets, security notices) is not part of this and continues either way, because it is how the service works.
- Letting Scoutyx feature your profile, your content or your achievements in its own promotion: on our website, our social media accounts, in app-store material, in press, or in paid advertising. The terms of that permission are in section 8 of our Terms of Service.
Where you say yes or no. There is an unticked box on the last screen of registration, and a switch afterwards in Profile → Settings → Privacy. The box is never pre-ticked and ticking it is never a condition of creating an account — a box you must tick to proceed is not a choice, and under GDPR Article 4(11) it would not be consent.
Nobody under 18. This is not a setting a minor can get wrong. The option is not shown to an account under 18, and our servers refuse to record it for one however the request arrives. If you registered as a minor, the question is simply never put to you until you turn 18 — and turning 18 does not switch anything on. We ask you once, and if you do not answer, the answer stays no.
Withdrawing. The same switch, any time, no reason needed, no penalty, and no part of the service withheld for it (GDPR Article 7(3)). New promotional use stops from that moment. Material already published cannot always be recalled — printed material in particular — but we remove what is still in our control and we do not reuse it.
What we record, and why we keep it. When you grant or withdraw this permission we store the fact, the moment, the version of the wording you were shown, and the IP address the decision came from. We keep the withdrawals as well as the grants, in a log that is only ever added to. That is deliberate: Article 7(1) requires us to be able to demonstrate that consent was given, and a record we overwrite every time someone changes their mind could not demonstrate anything. It also protects you — it is the evidence of what you actually agreed to, and when.
This record is kept for as long as your account exists and is deleted with it. It is not used for anything else: not for profiling, not for advertising targeting, and it is never shared. You can ask for a copy of it under section 9.
What this is not. We do not sell your personal data, we do not license your content to other companies for their advertising, and we do not run third-party advertising inside Scoutyx. This consent covers promoting Scoutyx, and nothing else.
8. User-generated content and moderation
Posts, comments, profiles and direct messages are created by users, not by us. Every post and every profile carries a report and a block option in the app.
- Blocking takes effect immediately and works in both directions — a blocked user cannot see or contact you.
- Reports go to a moderation queue that a human reviews. We may remove content, restrict, or delete an account that breaks our terms.
- Uploaded photos and videos are scanned for malware before they are published. An upload that fails the scan is never served.
Reports about a user under 18 are treated as a priority. If you believe a minor is at risk, email gcampoyf@gmail.com as well as reporting in the app.
9. Your rights
You can request a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable format. EU and UK users have the full set of GDPR rights, and you may also complain to your national data protection authority.
You can delete your account yourself, from Profile → Settings → Delete account in the app. For anything else — including a parent or guardian asking us to remove a minor's account — email gcampoyf@gmail.com. We reply within 30 days, usually much sooner.
10. Data retention
We keep your data for as long as your account exists. When an account is deleted, we erase or anonymise the profile, media, and personal details at that point rather than on a schedule.
Two things survive deletion, both deliberately. Messages you sent stay visible to the people you sent them to, without your personal details attached — otherwise deleting an account would silently rewrite other people's conversations. And payment records are kept where tax and accounting law requires it.
11. Security
Passwords are hashed with bcrypt and never stored in a readable form. All traffic uses TLS. Access tokens on mobile are held in memory only, never written to disk, and are rotated on every use. Uploaded media is scanned for malware before it is published. Authentication endpoints are rate-limited.
No system is perfect. If you find a security problem, please report it to gcampoyf@gmail.com and we will act on it.
12. Changes to this policy
We update the date at the top of this page whenever it changes, and we will tell you in the app before a material change takes effect.
13. Contact
Scoutyx is operated from Spain. For any question about this policy, your data, or a request to exercise the rights in section 9, email gcampoyf@gmail.com.