Skip to main content

Trust Center

Student-safe coaching for schools, clubs, and colleges

We take student privacy seriously. This page says exactly what that means: what we promise, what we have built, who we work with, and the documents your privacy officer will ask for.

Last updated: September 2026

Our privacy posture

  • We do not sell student data. Ever.

    Not to anyone, not for any purpose. No renting, licensing or trading either.

  • We do not use student data for advertising or profiling.

    No targeted ads, no profiles, and no training of AI models on your data.

  • Schools stay in control.

    When a school or district rosters athletes, we act as its service provider under FERPA’s school-official exception: the school directs how the data is used, and we use it only to deliver the coaching service.

  • We do not accept athletes under 13.

    A neutral age check at registration refuses anyone under 13. The birth month and year are used for the check and never stored.

  • Coaches certify parental consent for athletes 13 and older.

    Before an invite is issued, the coach certifies that any parental or guardian consent the law requires has been obtained. We record who certified, and when.

  • Student data is used only to deliver coaching.

    Workouts, results and training load, for the athlete and the coach. Nothing else.

  • We delete data when asked, and when a contract ends.

    Deletion completes within 30 days of a valid request and is confirmed by a signed destruction certificate. A school’s student data is destroyed within 60 days of its written notice.

For K-12 districts

Everything a district privacy officer needs to review us, in one place. When a school rosters athletes, the school controls the data and we process it only to deliver the coaching service.

Documents

Data privacy agreement

Does your district use its own DPA? Send it to [email protected] and we respond within 5 business days. Our standard form is the Student Data Privacy Consortium’s National Data Privacy Agreement; ask and we will send it.

Security questionnaires

Send us your district’s vendor questionnaire (K-12CVAT or your own form) at [email protected] and we will complete it. The security program and service provider sections below answer most questions up front.

For colleges and universities

What your IT security and vendor-review office will want to know before an athletics department signs up.

Vendor security review

Send your HECVAT or institutional questionnaire to [email protected] and we will complete it. The security program below is mapped to NIST CSF 2.0 so your reviewer can start there.

Data privacy agreement

We sign institutional data privacy agreements. Send yours, or ask for ours, at [email protected]; we respond within 5 business days.

Scope: performance training data, not medical records

Smagpie handles performance training data only: workouts, pace, heart rate, power and training load. Clinical injury records belong in your athletic training EMR. We are not a HIPAA-covered entity and do not ask to be one.

Athletes own their device connections

Watches and training platforms (Garmin, COROS, Strava, Intervals.icu) are connected by the athlete, under the vendor’s own terms. Coaches see synced results inside Smagpie; we never hold the athlete’s vendor password, and disconnecting takes one click.

For parents

Your child’s coach uses Smagpie to plan training, send workouts to a watch, and follow progress. Here is how consent works and what you can do.

No athletes under 13

Registration asks for birth month and year, refuses anyone under 13, and keeps only the fact that the check passed, never the birth date. If you believe a child under 13 has registered, email [email protected] and we delete the account.

Ages 13 and up: the coach certifies consent

The school, club or coach that rosters your child is responsible for any parental consent the law requires, and certifies that before the invite is issued. Smagpie records that certification. We do not collect consent from parents directly, so start with your child’s coach or school for questions about how the team uses Smagpie.

What you can do

  • Review and correct the personal information Smagpie holds about your child. Both are self-service in the athlete’s account.
  • Export it in standard formats: original activity files, CSV and JSON.
  • Delete the account. Deletion completes within 30 days and is confirmed by a signed destruction certificate.

Ask the school or organization first, because it controls the student’s data. If you write to [email protected] about a school-rostered student, we follow the school’s instruction and tell you whom to contact; for a club or independent athlete, we verify you and act.

Read the full commitments in the Parents’ Bill of Rights (PDF), the privacy policy’s Children & Youth Athletes section, and the terms’ Minor Athletes & Parental Consent section.

Our security program

Organized by the six functions of the NIST Cybersecurity Framework 2.0. Each item is a control that is running today or a commitment already published in our policies.

Govern

Who is accountable, and how the rules stay current.

  • Peter Galbraith, Smagpie’s founder, is the designated Data Protection Officer ([email protected]).
  • Every published policy carries a next-review date and is reviewed at least annually.
  • Every service provider that handles athlete data processes it only on our instructions, to deliver its service, under a data processing agreement.

Identify

Know the data, and treat it as sensitive.

  • What we collect, why, and for how long is published in the privacy policy and the retention policy. We collect nothing the service does not need.
  • All athlete training and health-adjacent data (heart rate, GPS, power, pace) is treated as sensitive.
  • The service-provider list on this page is audited against our live deployment, not copied from a template.

Protect

Encryption, strong authentication and least privilege.

  • AES-256 encryption at rest for the database and for stored files. TLS 1.2 or higher in transit, TLS 1.3 where the client supports it.
  • Multi-factor authentication is required for every administrative account. Sensitive actions, such as support staff viewing an account, require a fresh MFA step-up.
  • Role-based access control (admin, coach, athlete), with every team-scoped request checked against the caller’s team.
  • Sign-in defenses: hashed passwords, account lockout, per-IP rate limits, and a bot check on registration.
  • Per-device sessions with token rotation and reuse detection. Users can see and revoke their own active sessions.
  • Application secrets are held in a managed secrets vault, never in source code.

Detect

See what happened, and be told when something is wrong.

  • A compliance audit log records sign-ins and MFA events, privileged actions, data exports, deletions, consent certifications and admin role changes. Events are kept for one year.
  • Automated alerts on suspicious authentication activity, such as a reused session token or a spike in failed MFA attempts.
  • Centralized error and log monitoring across the platform.

Respond

A named contact, and a clock we commit to.

  • Report a concern to [email protected]. We acknowledge within one business day.
  • Schools and organizations are notified within 72 hours of a confirmed incident affecting their student data: what happened, whose data was involved, and what we are doing about it.
  • If a breach is our fault, we reimburse the school’s cost of notifying parents.

Recover

Backups that are encrypted, off-site and proven.

  • Nightly database backups are encrypted before they leave our servers and kept off-site in the United States, with a provider separate from the production servers.
  • Backups are kept daily for 7 days, weekly for 4 weeks and monthly for 5 months, so deleted data leaves every backup within six months.
  • Restores are rehearsed quarterly. Recovery targets: service restored within 4 hours, with at most 24 hours of data loss.
  • Every completed deletion produces a signed destruction certificate.

Service providers

The providers that process data on our behalf. Each processes data only on our instructions, to deliver its service, under a data processing agreement. Student data is stored in the United States.

Interested in Smagpie Coaching but need data stored in a specific region or country? Reach out. We may be able to stand up an instance of the platform in your area.

Service providers
Hostinger Cloud hosting and storage Account and training data, encrypted at rest United States
Microsoft Azure Cloud hosting and storage Account and training data, encrypted at rest United States
Sinch Mailgun Transactional email Recipient name and email address, message content, delivery logs United States
Cloudflare Website hosting, content delivery and DDoS protection Requests in transit, re-encrypted to our servers; nothing is stored Global edge network; origin in the United States
Anthropic AI-assisted workout drafting for coaches Designed to work without athlete data: it receives only the coach’s typed instruction, the team’s sport and training zones, and exercise names United States

Also used, with no athlete data: hCaptcha (a bot check on sign-up and on this website’s forms, which sees an IP address and browser signals), Stripe (payments, made by adults; card numbers never touch Smagpie), and the browser push services that deliver end-to-end encrypted notifications. Analytics on this website are self-hosted, cookie-less and contain no personal data.

Device vendor integrations

Garmin, COROS, Strava, Intervals.icu. Athletes connect these themselves and agree to the vendor’s own terms; data flowing through them is governed by that vendor’s privacy policy. Smagpie shares only what is needed to sync workouts to a device the athlete has chosen to connect. These are not service providers under our data privacy agreements, and changes to them are disclosed in the privacy policy rather than here.

Our notice commitment

We will tell schools and organizations when we change a service provider that handles athlete data, in advance where practical. Subscribe to be notified by email; every notice carries a one-click unsubscribe link.

Get notified when our service providers change

Advance notice when Smagpie adds, replaces or removes a service provider that handles athlete data.

We send a confirmation email first — nothing is subscribed until you click the link in it. Every message carries a one-click unsubscribe link.

Data retention and deletion

The short version of our Data Retention & Deletion Policy (PDF). Where the two differ, the policy document is authoritative.

Retention periods by data category
Category Retention
Active account Retained while the account is active.
Account deletion Requested by the athlete, by the head coach on the school’s behalf, or by support on a written request. The account is disabled immediately and connected devices are disconnected; permanent deletion completes within 30 days; a signed destruction certificate is issued.
Contract end (school or organization) All of its student data is destroyed within 60 days of written notice, and a team-level destruction certificate is issued on completion.
Encrypted backups Daily copies for 7 days, weekly for 4 weeks, monthly for 5 months. Deleted data leaves every backup within 6 months.
Audit log events 1 year.
Billing and transaction records 7 years (tax and accounting), with the purchaser reference pseudonymized when the account is deleted.
Server logs (anonymized) 90 days.
Support correspondence 2 years after resolution.

Questions reviewers ask

Do you have a SOC 2 report?
No. Smagpie holds no third-party certifications today. At our size we have put the effort into things you can verify for yourself: the controls above, mapped to NIST CSF 2.0; published policies with signatures and review dates; a written data privacy agreement on request; and a complete response to your own security questionnaire. We will list attestations here as we earn them.
Are you HIPAA compliant?
Smagpie handles performance training data (workouts, pace, heart rate, power), not clinical health records, and is not a HIPAA-covered entity. Clinical injury records belong in your athletic training EMR. We still treat all fitness data as sensitive.
Where is our data stored?
In the United States. Application data, stored files and encrypted backups are all stored in the United States. Wearable-device data an athlete chooses to sync (Garmin, COROS, Strava, Intervals.icu) is governed by that vendor’s own privacy policy. If you are interested in Smagpie Coaching but need data stored in a specific region or country, reach out. We may be able to stand up an instance of the platform in your area.
Do you sell data or do targeted advertising?
No. Never. It is written into our privacy policy, our Parents’ Bill of Rights, and every data privacy agreement we sign.
Do you use AI on student data?
Our AI feature is designed to work without student data. Coaches can ask for an AI-drafted workout, and the request carries only the coach’s instruction, the team’s sport and training zones, and exercise names. Smagpie never attaches athlete names, results or health data to it, and student data is never used to train AI models.
Will you sign our district’s data privacy agreement?
Send it to [email protected] and we respond within 5 business days. Our standard form is the Student Data Privacy Consortium’s National Data Privacy Agreement; ask and we will send it.
How do I report a security issue?
Email [email protected]. We acknowledge every report within one business day and look into it as soon as possible.

Contact

Real people read these, and we acknowledge every inquiry within one business day.

Privacy questions
[email protected]
Security incidents and vulnerability reports
[email protected]
Data privacy agreements, contracts and questionnaires
[email protected]
Data Protection Officer — Peter Galbraith, Founder
[email protected]