Trust Center
Student-safe coaching for schools, clubs, and colleges
We take student privacy seriously. This page says exactly what that means: what we promise, what we have built, who we work with, and the documents your privacy officer will ask for.
Last updated: September 2026
Our privacy posture
-
We do not sell student data. Ever.
Not to anyone, not for any purpose. No renting, licensing or trading either.
-
We do not use student data for advertising or profiling.
No targeted ads, no profiles, and no training of AI models on your data.
-
Schools stay in control.
When a school or district rosters athletes, we act as its service provider under FERPA’s school-official exception: the school directs how the data is used, and we use it only to deliver the coaching service.
-
We do not accept athletes under 13.
A neutral age check at registration refuses anyone under 13. The birth month and year are used for the check and never stored.
-
Coaches certify parental consent for athletes 13 and older.
Before an invite is issued, the coach certifies that any parental or guardian consent the law requires has been obtained. We record who certified, and when.
-
Student data is used only to deliver coaching.
Workouts, results and training load, for the athlete and the coach. Nothing else.
-
We delete data when asked, and when a contract ends.
Deletion completes within 30 days of a valid request and is confirmed by a signed destruction certificate. A school’s student data is destroyed within 60 days of its written notice.
For K-12 districts
Everything a district privacy officer needs to review us, in one place. When a school rosters athletes, the school controls the data and we process it only to deliver the coaching service.
Documents
-
Parents’ Bill of Rights
PDF · 1 page · v1.0, effective September 15, 2026
Modeled on New York Education Law § 2-d. What every parent and student can expect from us, in every state.
-
Data Retention & Deletion Policy
PDF · 4 pages · v1.0, effective September 15, 2026
The full schedule: what we keep, for how long, what triggers deletion, and how backups are handled.
-
Privacy Policy
Web page · plain-language summary above the full legal text
What we collect, why, who we share it with, and the rights of students, parents and coaches.
-
Terms of Service
Web page · plain-language summary above the full legal text
Eligibility, data ownership, cancellation and export, and the minor-athlete consent model.
Data privacy agreement
Does your district use its own DPA? Send it to [email protected] and we respond within 5 business days. Our standard form is the Student Data Privacy Consortium’s National Data Privacy Agreement; ask and we will send it.
Security questionnaires
Send us your district’s vendor questionnaire (K-12CVAT or your own form) at [email protected] and we will complete it. The security program and service provider sections below answer most questions up front.
For colleges and universities
What your IT security and vendor-review office will want to know before an athletics department signs up.
Vendor security review
Send your HECVAT or institutional questionnaire to [email protected] and we will complete it. The security program below is mapped to NIST CSF 2.0 so your reviewer can start there.
Data privacy agreement
We sign institutional data privacy agreements. Send yours, or ask for ours, at [email protected]; we respond within 5 business days.
Scope: performance training data, not medical records
Smagpie handles performance training data only: workouts, pace, heart rate, power and training load. Clinical injury records belong in your athletic training EMR. We are not a HIPAA-covered entity and do not ask to be one.
Athletes own their device connections
Watches and training platforms (Garmin, COROS, Strava, Intervals.icu) are connected by the athlete, under the vendor’s own terms. Coaches see synced results inside Smagpie; we never hold the athlete’s vendor password, and disconnecting takes one click.
For parents
Your child’s coach uses Smagpie to plan training, send workouts to a watch, and follow progress. Here is how consent works and what you can do.
No athletes under 13
Registration asks for birth month and year, refuses anyone under 13, and keeps only the fact that the check passed, never the birth date. If you believe a child under 13 has registered, email [email protected] and we delete the account.
Ages 13 and up: the coach certifies consent
The school, club or coach that rosters your child is responsible for any parental consent the law requires, and certifies that before the invite is issued. Smagpie records that certification. We do not collect consent from parents directly, so start with your child’s coach or school for questions about how the team uses Smagpie.
What you can do
- Review and correct the personal information Smagpie holds about your child. Both are self-service in the athlete’s account.
- Export it in standard formats: original activity files, CSV and JSON.
- Delete the account. Deletion completes within 30 days and is confirmed by a signed destruction certificate.
Ask the school or organization first, because it controls the student’s data. If you write to [email protected] about a school-rostered student, we follow the school’s instruction and tell you whom to contact; for a club or independent athlete, we verify you and act.
Read the full commitments in the Parents’ Bill of Rights (PDF), the privacy policy’s Children & Youth Athletes section, and the terms’ Minor Athletes & Parental Consent section.
Our security program
Organized by the six functions of the NIST Cybersecurity Framework 2.0. Each item is a control that is running today or a commitment already published in our policies.
Govern
Who is accountable, and how the rules stay current.
- Peter Galbraith, Smagpie’s founder, is the designated Data Protection Officer ([email protected]).
- Every published policy carries a next-review date and is reviewed at least annually.
- Every service provider that handles athlete data processes it only on our instructions, to deliver its service, under a data processing agreement.
Identify
Know the data, and treat it as sensitive.
- What we collect, why, and for how long is published in the privacy policy and the retention policy. We collect nothing the service does not need.
- All athlete training and health-adjacent data (heart rate, GPS, power, pace) is treated as sensitive.
- The service-provider list on this page is audited against our live deployment, not copied from a template.
Protect
Encryption, strong authentication and least privilege.
- AES-256 encryption at rest for the database and for stored files. TLS 1.2 or higher in transit, TLS 1.3 where the client supports it.
- Multi-factor authentication is required for every administrative account. Sensitive actions, such as support staff viewing an account, require a fresh MFA step-up.
- Role-based access control (admin, coach, athlete), with every team-scoped request checked against the caller’s team.
- Sign-in defenses: hashed passwords, account lockout, per-IP rate limits, and a bot check on registration.
- Per-device sessions with token rotation and reuse detection. Users can see and revoke their own active sessions.
- Application secrets are held in a managed secrets vault, never in source code.
Detect
See what happened, and be told when something is wrong.
- A compliance audit log records sign-ins and MFA events, privileged actions, data exports, deletions, consent certifications and admin role changes. Events are kept for one year.
- Automated alerts on suspicious authentication activity, such as a reused session token or a spike in failed MFA attempts.
- Centralized error and log monitoring across the platform.
Respond
A named contact, and a clock we commit to.
- Report a concern to [email protected]. We acknowledge within one business day.
- Schools and organizations are notified within 72 hours of a confirmed incident affecting their student data: what happened, whose data was involved, and what we are doing about it.
- If a breach is our fault, we reimburse the school’s cost of notifying parents.
Recover
Backups that are encrypted, off-site and proven.
- Nightly database backups are encrypted before they leave our servers and kept off-site in the United States, with a provider separate from the production servers.
- Backups are kept daily for 7 days, weekly for 4 weeks and monthly for 5 months, so deleted data leaves every backup within six months.
- Restores are rehearsed quarterly. Recovery targets: service restored within 4 hours, with at most 24 hours of data loss.
- Every completed deletion produces a signed destruction certificate.
Service providers
The providers that process data on our behalf. Each processes data only on our instructions, to deliver its service, under a data processing agreement. Student data is stored in the United States.
Interested in Smagpie Coaching but need data stored in a specific region or country? Reach out. We may be able to stand up an instance of the platform in your area.
| Provider | Role | Data it handles | Where data is stored |
|---|---|---|---|
| Hostinger | Cloud hosting and storage | Account and training data, encrypted at rest | United States |
| Microsoft Azure | Cloud hosting and storage | Account and training data, encrypted at rest | United States |
| Sinch Mailgun | Transactional email | Recipient name and email address, message content, delivery logs | United States |
| Cloudflare | Website hosting, content delivery and DDoS protection | Requests in transit, re-encrypted to our servers; nothing is stored | Global edge network; origin in the United States |
| Anthropic | AI-assisted workout drafting for coaches | Designed to work without athlete data: it receives only the coach’s typed instruction, the team’s sport and training zones, and exercise names | United States |
Also used, with no athlete data: hCaptcha (a bot check on sign-up and on this website’s forms, which sees an IP address and browser signals), Stripe (payments, made by adults; card numbers never touch Smagpie), and the browser push services that deliver end-to-end encrypted notifications. Analytics on this website are self-hosted, cookie-less and contain no personal data.
Device vendor integrations
Garmin, COROS, Strava, Intervals.icu. Athletes connect these themselves and agree to the vendor’s own terms; data flowing through them is governed by that vendor’s privacy policy. Smagpie shares only what is needed to sync workouts to a device the athlete has chosen to connect. These are not service providers under our data privacy agreements, and changes to them are disclosed in the privacy policy rather than here.
Our notice commitment
We will tell schools and organizations when we change a service provider that handles athlete data, in advance where practical. Subscribe to be notified by email; every notice carries a one-click unsubscribe link.
Get notified when our service providers change
Advance notice when Smagpie adds, replaces or removes a service provider that handles athlete data.
Data retention and deletion
The short version of our Data Retention & Deletion Policy (PDF). Where the two differ, the policy document is authoritative.
| Category | Retention |
|---|---|
| Active account | Retained while the account is active. |
| Account deletion | Requested by the athlete, by the head coach on the school’s behalf, or by support on a written request. The account is disabled immediately and connected devices are disconnected; permanent deletion completes within 30 days; a signed destruction certificate is issued. |
| Contract end (school or organization) | All of its student data is destroyed within 60 days of written notice, and a team-level destruction certificate is issued on completion. |
| Encrypted backups | Daily copies for 7 days, weekly for 4 weeks, monthly for 5 months. Deleted data leaves every backup within 6 months. |
| Audit log events | 1 year. |
| Billing and transaction records | 7 years (tax and accounting), with the purchaser reference pseudonymized when the account is deleted. |
| Server logs (anonymized) | 90 days. |
| Support correspondence | 2 years after resolution. |
Questions reviewers ask
Do you have a SOC 2 report?
Are you HIPAA compliant?
Where is our data stored?
Do you sell data or do targeted advertising?
Do you use AI on student data?
Will you sign our district’s data privacy agreement?
How do I report a security issue?
Contact
Real people read these, and we acknowledge every inquiry within one business day.
- Privacy questions
- [email protected]
- Security incidents and vulnerability reports
- [email protected]
- Data privacy agreements, contracts and questionnaires
- [email protected]
- Data Protection Officer — Peter Galbraith, Founder
- [email protected]