Legal
Privacy policy.
Last updated: August 2026. This describes what GOLSZ actually collects, how it's used, and the choices you have — for the real product, not a placeholder.
1. Who we are
GOLSZ is operated from Nicosia, Cyprus. This policy explains how we collect, use, store, and protect personal data when you create a GOLSZ account, build an athlete profile, use the AI assistant ("Scout"), or otherwise use the GOLSZ app at golsz.vercel.app (and, once connected, golsz.com). [Legal review advised] the exact registered legal-entity name and address for the data-controller identification should be confirmed and inserted here.
2. Data we collect
Account information. When you sign up, we collect your full name, email address, date of birth, and account type (player, scout, agent, coach, or physio). Your date of birth determines whether you can create your own account (16+) or whether a parent/guardian must create it on your behalf (under 16 — see Section 5).
Athlete profile data. If you build an athlete profile, we store what you choose to enter: sport, position, height, weight, graduation year, club/team name, country, playing foot, recruiting status, a short bio, and links to highlight footage you provide. All of this is optional beyond what's required to use core features, and you control what's visible on a shared Passport link.
Uploaded content. Profile photos and any images you attach to a post are stored in our file storage (Supabase Storage), each user's files kept in a folder scoped to their own account.
AI assistant (Scout) interactions. Questions you ask Scout and the responses you receive are stored so the conversation can continue across sessions. We also store structured signals used to personalize Scout's answers (e.g. your stated goals, sport, and profile context) and, separately for our own cost/quality monitoring, metadata about each AI request (which model handled it, token counts, estimated cost, response time) — this monitoring data is not shared externally and is not linked to what you asked beyond what's needed to debug or improve the service.
Payment information. If you subscribe to a paid plan, checkout is handled entirely by Stripe — GOLSZ never receives or stores your card number. We store only your Stripe customer reference, your plan tier, and subscription/payment status (e.g. whether a recent charge failed) so we can enforce what your plan includes.
Push notifications. If you opt in, your browser generates a push subscription (an endpoint URL and encryption keys) which we store so we can deliver notifications (e.g. reminders, messages). You can revoke this at any time from Settings or your browser's notification permissions.
Trust & safety data. If content is reported, reviewed by our automated moderation check, or you submit a verification request or an appeal, we store the relevant content, the decision, and (for admin actions) who took them, in order to keep the platform safe and to have a record if a decision is disputed.
Technical data. Our infrastructure providers (Supabase, Vercel) process standard request metadata (IP address, timestamps) as part of operating the service and preventing abuse (e.g. rate-limiting signup attempts) — we don't separately collect or sell this data.
3. Cookies and analytics
GOLSZ does not use cookies, and does not use any third-party advertising or analytics trackers (no Google Analytics, no ad pixels). The app stores a small amount of data in your browser's local storage: your theme (light/dark) and language preference, and — via our authentication provider's standard client library — your session sign-in token, so you stay signed in between visits. None of this is shared with third parties for advertising purposes.
Bot protection. The signup form is built to support Cloudflare Turnstile, a privacy-respecting CAPTCHA alternative. It is not currently active in production. If and when it's turned on, Cloudflare will process limited technical data (such as your IP address) to assess whether a signup attempt is automated, under Cloudflare's own privacy policy.
4. How we use your data
We use your data to: operate your account and athlete profile; power Scout's AI-assisted guidance; process payments and enforce plan entitlements; detect and act on abuse, spam, or unsafe content; send you notifications you've opted into; respond to support requests; and meet our legal obligations. We do not sell your personal data.
5. Under-16 accounts (parent/guardian-controlled)
An athlete under 16 cannot independently create or control a GOLSZ account. A parent or legal guardian creates the account, using their own email address; the child's profile exists as data linked to and controlled by that parent account. The child does not receive login credentials of their own and cannot sign in independently. Only the child's name and date of birth are collected at creation — the parent then manages what profile information is added over time, in the same way they'd manage the rest of the account. A parent can request full deletion of a managed child's profile and data at any time by contacting us, or by removing it themselves if that self-service option is available in the app. [Legal review advised] confirm this structure and the specific parental-consent record-keeping it implies satisfy GDPR Article 8 and any applicable Cyprus implementing rules, and whether COPPA-style US obligations apply given the product is available internationally.
6. AI processing and sub-processors
Scout is currently powered by Anthropic's Claude models. When you ask Scout a question, the relevant text (your question and enough profile/conversation context to answer it usefully) is sent to Anthropic's API to generate a response. Anthropic acts as a data processor for this purpose. [Legal review advised] Anthropic's own data-retention and model-training terms for API usage should be confirmed and summarized accurately here rather than assumed — we have not independently verified whether API-submitted content is used to train Anthropic's models.
Scout also has a second AI provider, xAI (Grok), used only as an emergency failover. If Anthropic's API is unavailable or fails to respond, the same request — your question plus the profile and conversation context needed to answer it — is sent to xAI's API instead, so Scout keeps working during an outage. It is not used for routine requests. Because a failover can happen on any message, including a message about or from a managed under-16 athlete, we name it here rather than treating it as an implementation detail. [Legal review advised] xAI's data-retention and model-training terms for API usage should be confirmed and summarized accurately here rather than assumed, on the same basis as Anthropic's above.
Our other core infrastructure sub-processors are Supabase (database, authentication, and file storage) and Vercel (application hosting) — both are necessary to any use of the product — and Stripe for payment processing. [Legal review advised] exact hosting regions for Supabase/Vercel and whether an international-transfer mechanism (e.g. Standard Contractual Clauses) is needed for any of these sub-processors, given GOLSZ's Cyprus/EU base, should be confirmed directly with each provider rather than assumed here.
7. Data retention
We keep your account and profile data for as long as your account is active. If you delete your account, your profile, uploaded images, and associated app data are permanently removed. If your account manages an under-16 athlete profile that nobody else can sign in to, we will not delete your account and leave theirs stranded: we tell you which profiles are affected and ask you to confirm, and confirming deletes those profiles together with yours. Some records — for example, moderation decisions, reports, or admin audit logs involving your account — may be retained for a longer period where necessary for safety, fraud-prevention, or legal record-keeping. [Legal review advised] specific retention periods for each data category (rather than "as long as necessary") should be defined with counsel to meet GDPR data-minimization requirements precisely.
8. Your rights
Depending on your location, you may have the right to access, correct, delete, restrict, or export your personal data, and to object to certain processing. You can delete your own account data at any time from Settings in the app. For anything else, contact us at hello@golsz.com. If you're in the EU/EEA, you also have the right to lodge a complaint with your local data protection authority — in Cyprus, the Office of the Commissioner for Personal Data Protection. [Legal review advised] a defined response-time commitment (e.g. "within 30 days") should be added once we've confirmed our internal process can meet it.
9. Security
Data is protected in transit with encryption, and access to your data within our database is enforced by row-level security policies so that, by default, only you (or, for a managed under-16 profile, the linked parent account) can read or write your own records. Administrative access is limited to authorized GOLSZ personnel and logged. No system is perfectly secure, and we can't guarantee absolute security of information transmitted to us.
10. Children's privacy (general)
Beyond the parent-controlled account structure in Section 5, GOLSZ is not directed at, and does not knowingly collect data from, children in a manner outside that structure. If you believe a child's data has been collected outside the parent-managed flow, contact us and we'll investigate and remove it.
11. Changes to this policy
We may update this policy as the product changes. Material changes will be reflected by updating the "last updated" date above, and where appropriate we'll notify account holders directly.
12. Contact
Questions about this policy, or requests relating to your data, can be sent to hello@golsz.com.