Privacy
PlayPath answers coaching questions from a sports content library. This page says what we store, why, and who else touches it — in the order that actually matters to you.
Who we are
PlayPath operates playpath.io and the API that partner platforms embed in their own products. If you reached us through another site's coaching assistant, that platform is the organisation you have a relationship with; we process data on their behalf.
What we store
- Account
- Email address and a hashed password. If you sign in with Google, GitHub or Facebook we receive the email address on that account, not your password.
- Sign-in records
- Sign-in counts, timestamps, and the IP address of your current and previous sign-in. Used to secure the account and investigate abuse.
- What you create
- Conversations with the assistant, session plans, squads and players you add, and match files you upload for analysis.
- Question and answer logs
- The text of questions and answers, which library items were retrieved, the model used, token counts and response time. We use these to measure and improve answer quality.
- Partner catalogue
- Public content metadata a partner sends us: identifier, title, topics, coach name, availability and publication date. No paywalled body text.
- Partner activity
- What a member assigned, opened, played or finished, keyed to an identifier the partner chooses. We do not receive their name or email unless the partner chooses to send one. From this we derive a coaching profile — topics they work on, recurring weaknesses — to rank what we show them.
- Analytics
- Google Analytics runs on our own site's pages and sets cookies. It does not run inside a partner's embedded widget.
Who else processes it
We use these providers to run the service. Each sees only what its job requires.
- OpenAI — generates embeddings and drafts answers. Question text and retrieved passages are sent for processing.
- Anthropic — reads uploaded match files and writes the analysis narrative.
- Stripe — takes payment. Card details go to Stripe directly; we never see or store them.
- Mailtrap — delivers transactional email such as password resets and invitations.
- Amazon Web Services — hosts the application and database.
- Google Analytics — usage measurement on our own site.
How content is kept separate
Every query, embedding and recommendation is scoped to a single organisation. One organisation's content is not reachable using another organisation's credential. API keys carry explicit scopes and default to deny: a key issued for sending us catalogue cannot read answers back out.
Retention
Account and content data is kept while the account is open. Close the account and we delete or anonymise it, except where we must keep records for tax or legal reasons. Question and answer logs are retained for quality analysis. Partner activity events are retained while the partner's integration is active.
Your choices
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to hello@playpath.io and we will respond within 30 days. If you came via a partner platform, ask them first — they control the account, and we will act on their instruction.
Analytics cookies can be blocked in your browser without affecting how the product works. The cookie that keeps you signed in is required for the site to function.
Children
PlayPath is built for coaches, not for the athletes they coach. Do not create an account for someone under 16. If you record player details as part of a squad, you are responsible for having the right to do so.
Changes
We will update this page when what we do changes, and move the date at the top. Material changes will be sent to account holders by email.
Contact
Questions about any of this: hello@playpath.io.