Privacy Notice
Last updated: July 11, 2026
Projectable Recruit LLC ("we," "us") operates Projectable Recruit™ and acts as the data controller for personal information processed through the Service. This notice explains what we collect, why, and who we share it with.
What we collect
- Account information: name, email, password (hashed), household/family member invites.
- Recruiting data you enter: schools, interactions, performance metrics, documents, financial estimates, and similar recruiting-related information about the student-athlete.
- Payment information: handled entirely by our payment processor, Paddle — we do not receive or store your card details.
- Usage data: basic product analytics to understand which features are used, device identifiers, and IP address for security and abuse prevention.
How we use it
- To operate the Service (contract performance): calculate scores, generate AI summaries, and display your recruiting data back to you.
- To process payments through Paddle, who acts as Merchant of Record for subscription purchases, subscription management, tax compliance, and invoicing.
- To communicate with you about your account, billing, and product updates.
- For security, fraud prevention, and product improvement (legitimate interests).
We do not sell your data, and we do not share your recruiting data with coaches, schools, or recruiting services without your direction.
AI processing
AI-generated summaries are produced using a third-party AI model provider. The data sent to generate a summary is limited to the structured recruiting data needed for that summary — the AI provider's use of that data is governed by their own data-processing terms.
Gmail sync (optional)
If you connect your Gmail account, we request a single Google OAuth scope: read-only access to your Gmail (https://www.googleapis.com/auth/gmail.readonly). We use this scope solely to identify and log recruiting communications from college coaches. We never send, delete, modify, archive, or change labels on any email on your behalf.
- What Gmail data we access: message metadata (sender name and address, recipient, subject line, direction, timestamp, and the Gmail thread/message IDs) and the plain-text body of messages that our classifier identifies as coach-related. Body text is stored so it can be shown to you when reviewing a candidate and, once confirmed, as part of your interaction history.
- Who can see this data: only the family account that connected the Gmail mailbox. Gmail-derived content is never shown to coaches, schools, other families, or any third party. It is not used for advertising, resold, or used to train generalized AI models.
- Where it is stored: encrypted at rest in our US-region Supabase database. OAuth refresh tokens are additionally encrypted with an application-level AES-256-GCM key and are accessible only to our backend sync process.
- Candidates are shown to you as suggestions only. Nothing is added to your interaction log without your explicit confirmation.
- How to revoke access: disconnect Gmail at any time from Settings → Gmail sync, which immediately stops future syncs and deletes your OAuth tokens on our side. You can also revoke Projectable Recruit from your Google account at myaccount.google.com/permissions. Deleting pending candidates removes them; interactions you already confirmed remain part of your recruiting record until you delete them.
- Questions about Gmail data specifically: email support@projectablerecruit.com.
- Projectable Recruit's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who we share data with
- Service providers / subprocessors: hosting, database, analytics, and support tooling used to run the Service.
- Merchant of Record: Paddle, for sale of the product, subscription management, payments, tax compliance, and invoicing.
- Professional advisers: legal and accounting, where necessary.
- Authorities: where required by law.
Student-athlete accounts
If an Account Owner invites a student-athlete who is a minor, that invitation and the athlete's resulting access are managed and controlled by the Account Owner (parent/guardian).
Data retention and deletion
We retain your data for as long as your account is active. When you request account deletion — either from within the Service or by contacting support@projectablerecruit.com — your account and associated recruiting data enter a 30-day soft-delete window. During that window the account is deactivated and hidden from the Service, and you may contact us to restore it. After 30 days, personal identifiers (name, email, contact details, invitees, and free-text notes) are permanently deleted or irreversibly anonymized. We may retain anonymized, aggregated data (for example, de-identified recruiting metrics used to improve scoring models and product analytics) indefinitely; anonymized data cannot be re-associated with you. We may also retain a limited set of records for as long as required by law (for example, billing and tax records held by our Merchant of Record, Paddle).
Security
We use appropriate technical and organizational measures — including encryption in transit, access controls, and row-level authorization — to protect your data. Platform security was most recently reviewed in July 2026.
Community-contributed data
When you use Projectable Recruit™, certain actions contribute information to a shared community data layer:
- Logging that a coach has moved from one program to another
- Confirming or denying a reported coaching staff change
- Submitting coach contact information (name, title, email, phone)
- Reporting that a coach email or phone number was undeliverable
- Reporting how many scholarships a program is funding
- Confirming or denying reported scholarship funding numbers
These contributions are voluntary and occur as part of normal platform use. Community data is aggregated to generate confidence-weighted signals — coaching change alerts, scholarship funding estimates, and contact quality warnings — that help all families make better recruiting decisions. Your identity is never disclosed to other families. Signals show only aggregate counts, medians, and confidence scores — never which families contributed.
Coach contact data
Families may enter contact information for college coaches (name, title, institutional email, phone). This reflects information coaches share publicly on school athletic websites or in the course of their professional recruiting activities. Coach contact data is:
- Stored in connection with your school record
- Used in aggregated, anonymized form to power community features
- Never sold or shared with third parties
Coaches may request confirmation, correction, or deletion of their personal data by contacting support@projectablerecruit.com. Verified requests are fulfilled within 30 days.
Crowdsourced features
Coaching staff changes. When you log a coach move, an anonymous report is created for the school the coach departed. Other families may be prompted to confirm or deny the change. Your identity is never disclosed. Signals expire after 60 days of inactivity.
Scholarship funding. Families and advisors may report how many scholarships a program is funding. Reports are aggregated into a community estimate displayed with a confidence indicator. This data is unverified and should be confirmed directly with the program.
Contact quality. Families may flag a coach's contact details as undeliverable. When two or more families independently flag the same contact, a warning is shown. The identity of families who submitted flags is never disclosed.
Data aggregation
All cross-family data sharing uses aggregation that prevents identification of individual families. Server functions that query cross-family data return only aggregated outputs — counts, medians, confidence scores — never raw rows with identifying information.
Your choices and rights
You can access, correct, or export your data from within the Service, or by contacting us. Depending on where you live, you may have additional rights under local law (such as the right to lodge a complaint with a supervisory authority).
Cookies
We use essential cookies to keep you signed in and secure. We may use limited analytics cookies to understand product usage; you can manage cookies through your browser settings.
Changes to this notice
We'll post updates here with a new "Last updated" date.