Privacy Policy
Last updated July 2026
What we collect
Account details (name, email, role), the academic and athletic information you enter (courses, grades, GPA, sport, graduation year, school), your activity in the product (practice test results and answers, Sport IQ results, evaluations, assignments), files you upload (a profile photo, and a transcript if you attach one to an evaluation — the transcript is read to build the report, not kept as a file), and payment records from our processor. We do not collect payment card numbers — Stripe handles those directly.
Who can see an athlete's information
Access is enforced in the database itself, not just the interface:
- The athlete always sees their own data.
- A linked parent or guardian sees their child's data.
- Coaches and school staff see athletes on their own roster.
- Recruiters see an athlete only after that athlete accepts them or shares a code — and even then they see the athletic profile, eligibility status, and Sport IQ results. Raw grades and marking-period records are never visible to recruiters.
- Administrators of PlayEligible can access accounts for support and safety.
Students under 13
A student under 13 cannot create their own PlayEligible account. A parent, guardian, or school creates it, provides consent, and links the student — which is why we ask for date of birth at signup. A parent may withdraw that consent at any time, which ends collection and allows deletion of what was collected. This is how we meet the Children's Online Privacy Protection Act (COPPA).
The laws this policy is written against
We hold academic information about minors, which places us under several regimes at once. Rather than leave that implicit:
- COPPA — no account creation or data collection for a child under 13 without verifiable parental consent.
- FERPA — where a school or district places student data with us, those are education records. We act as a school official with a legitimate educational interest, use the data only to provide the service, and follow the district's instructions on retention and deletion.
- State student-privacy laws (California's SOPIPA, New York Ed Law §2-d, and their equivalents elsewhere) — no selling student data, no targeted advertising to students, deletion on district request, and a published Parents' Bill of Rights.
- CCPA/CPRA — rights to access, delete, correct, and port your information, all available from Settings → Privacy & data. We do not sell or share personal information as those terms are defined.
AI processing
The full NCAA report sends the course information you enter — and the transcript you attach, if you attach one — to Anthropic's API to draft it. Every result is then re-checked by our own deterministic rules engine before you see it, so the arithmetic and the verdict are ours rather than the model's. Your free eligibility verdict is computed in your own browser and makes no AI call at all. The Co-pilot, essay review and resume polish work the same way as the report: what you submit is sent for that one request. None of it is used to train models.
What we never do
We do not sell personal information. We do not share athlete data with recruiters, colleges, or anyone else without the athlete's explicit action.
Your rights, and how to use them
These run from inside the product — Settings → Privacy & data — rather than by emailing a request and waiting on us:
- Export. Download every record we hold for your account as a single file.
- Correct. Dispute a grade or detail entered by a coach or school; it creates a tracked record.
- Delete. Request deletion, with a 30-day grace period during which you can cancel.
- Withdraw consent. Marketing email is controlled from email preferences; consent history is visible in settings and included in your export.
Retention and deletion
Account data is kept while the account is active. Deletion runs 30 days after you request it, and cascades through every record tied to you. Financial records of payments are retained for seven years as tax rules require, separated from your identity. Full periods are on our data retention schedule.
Who else processes your data
A small number of vendors — hosting, database, payments, email, and AI — are listed with what each receives on our subprocessor page.
Security
Data is encrypted in transit and at rest. Access rules are enforced at the database row level rather than only in the interface. Passwords are stored as salted hashes and are not readable by anyone here. Account activity is recorded and visible to you in settings. If a breach affects student data, we will notify affected families and any district that placed the data with us.
Contact
Privacy questions: privacy@playeligible.com. Districts: districts@playeligible.com. Everything else: hello@playeligible.com. See also the Legal & Privacy Center.