Privacy Policy

Last updated: July 31, 2026

Scoutyx ("we", "us") connects athletes, scouts, and organisations. This policy explains what data we collect, why, the legal basis for it, and the choices you have — including the extra protections we apply to everyone under 18.

1. Information we collect

  • Account data: email address, password (hashed with bcrypt, never stored in plain text), and role (athlete, scout, or organisation).
  • Profile data: name, date of birth, country, sport, position, physical measurements, sport-specific statistics, bio, and any photos or videos you upload.
  • Guardian data (under-18 accounts only): a parent or guardian's email address and a record of their consent, collected only to satisfy COPPA and GDPR Article 8. See section 5.
  • Content you create: posts, comments, direct messages between users, and shortlists.
  • Search queries: the natural-language searches scouts and organisations type into Athene.
  • Payment data: handled entirely by Stripe on our website. Scoutyx never receives or stores card numbers.

2. Legal basis for processing (GDPR Article 6)

  • Performance of a contract — operating your account, showing your profile to scouts, delivering messages, and providing a subscription you have paid for. Without this data there is no service.
  • Consent — for under-18 accounts, the verifiable consent of a parent or guardian before any profile becomes visible (Article 8). Consent can be withdrawn at any time; see section 5.
  • Legitimate interests — keeping the platform safe: preventing fraud and abuse, scanning uploads for malware, rate-limiting, and reviewing reported content. We balance this against your rights and collect no more than the purpose needs.
  • Legal obligation — retaining payment and tax records where law requires it.

3. How we use it

  • To operate your profile and let scouts and organisations find athletes who match what they are looking for.
  • To power Athene search. Athene uses an AI model to extract intent from a natural-language query — it never invents athlete data. Every result comes from our own database. Only the query text is sent to the model; profiles are not.
  • To send transactional email: email confirmation, guardian consent, password resets, and security notices.
  • To process subscription payments, which happen on our website.
  • To detect and prevent abuse, fraud, and breaches of our terms.

We do not sell your personal data. We do not use your profile data to train AI models, ours or anyone else's. We do not run third-party advertising.

4. Who we share data with

Only the providers needed to run Scoutyx, each acting as a processor under its own agreement:

  • Railway (EU region) — application hosting, database, and storage of uploaded photos and videos.
  • Vercel — hosting for this website.
  • Stripe — subscription payments, and the card check used for guardian verification (section 5).
  • Resend — delivery of transactional email.
  • OpenAI — intent extraction for Athene searches. Query text only; never profile data or personal details.

Some of these providers process data outside the European Economic Area. Where that happens, transfers rely on the European Commission's Standard Contractual Clauses.

Your profile is not visible to other users until your account is active — and, if you are under 18, not until a guardian has completed verification.

5. Under-18 accounts (COPPA and GDPR Article 8)

Scoutyx welcomes athletes under 18. COPPA applies in the United States to users under 13 and GDPR Article 8 applies in the EU to users under 16; rather than track thresholds per country, we apply the same protections to everyone under 18.

This is what actually happens when someone under 18 signs up:

  • The account is immediately placed in a restricted state. It does not appear in search or in Athene results, no scout or organisation can see it or make contact, and the account cannot post or send messages.
  • We ask for a parent or guardian's email address and send them a verification link.
  • The guardian confirms they are the parent or guardian and verifies with a payment card on a page hosted by Stripe. In most regions this verifies the card with no charge at all; where that method is unavailable, a small charge (currently $0.50) is taken and refunded immediately. The card is used only to confirm that an adult is giving consent. We never see or store the card details.
  • Only after consent does the account move to a limited sandbox state, and from there to full visibility. A minor's account never goes straight to public.
  • A minor's contact details are never shown anywhere on the platform. Scouts and organisations can only reach them through in-app messaging, which can be blocked and reported.

A guardian can withdraw consent at any time and ask us to delete the account and its data by emailing gcampoyf@gmail.com. We act on this without requiring a reason.

6. User-generated content and moderation

Posts, comments, profiles and direct messages are created by users, not by us. Every post and every profile carries a report and a block option in the app.

  • Blocking takes effect immediately and works in both directions — a blocked user cannot see or contact you.
  • Reports go to a moderation queue that a human reviews. We may remove content, restrict, or delete an account that breaks our terms.
  • Uploaded photos and videos are scanned for malware before they are published. An upload that fails the scan is never served.

Reports about a user under 18 are treated as a priority. If you believe a minor is at risk, email gcampoyf@gmail.com as well as reporting in the app.

7. Your rights

You can request a copy of your data, ask us to correct it, ask us to delete it, object to processing, or ask for it in a portable format. EU and UK users have the full set of GDPR rights, and you may also complain to your national data protection authority.

You can delete your account yourself, from Profile → Settings → Delete account in the app. For anything else — including a parent or guardian asking us to remove a minor's account — email gcampoyf@gmail.com. We reply within 30 days, usually much sooner.

8. Data retention

We keep your data for as long as your account exists. When an account is deleted, we erase or anonymise the profile, media, and personal details at that point rather than on a schedule.

Two things survive deletion, both deliberately. Messages you sent stay visible to the people you sent them to, without your personal details attached — otherwise deleting an account would silently rewrite other people's conversations. And payment records are kept where tax and accounting law requires it.

9. Security

Passwords are hashed with bcrypt and never stored in a readable form. All traffic uses TLS. Access tokens on mobile are held in memory only, never written to disk, and are rotated on every use. Uploaded media is scanned for malware before it is published. Authentication endpoints are rate-limited.

No system is perfect. If you find a security problem, please report it to gcampoyf@gmail.com and we will act on it.

10. Changes to this policy

We update the date at the top of this page whenever it changes, and we will tell you in the app before a material change takes effect.

11. Contact

Scoutyx is operated from Spain. For any question about this policy, your data, or a request to exercise the rights in section 7, email gcampoyf@gmail.com.