Student Data Privacy
1. Who we are and who uses the product
Pro Coach Studio, a product of ProCoach Institute, is used by school athletic staff — coaches and athletic directors. Accounts are for adults: the Terms require account holders to be at least 18 and acting in a professional coaching capacity. Students do not have accounts and cannot sign in.
2. Our role: school official under FERPA
We process student data solely on the instruction of the school or district, as a "school official" with a legitimate educational interest under FERPA 34 CFR §99.31(a)(1)(i)(B). Concretely:
- The district remains the controller of the record. We do not decide what goes in it.
- We use student data only to provide the service the district authorized.
- We do not redisclose student data to anyone other than the subprocessors listed in §6, each of which processes it only on our behalf.
- We do not sell student data, use it for targeted advertising, or build profiles for any purpose other than delivering the service.
- The district can direct us to return or delete its data at any time (§9).
3. What student data the product can hold
Precisely these fields, and no others. The complete field-level record is Data Inventory.
Athlete (roster entry, scoped to one season): name; grade (6–12); jersey number; position; and — subject to the limits in §5 — the athlete's own phone number and email address.
Parent or guardian: name, phone number, email address.
Events: date, venue, opponent, which athletes participated, and per-athlete statistics the coach records.
Team communications: the message a coach sent, its subject, and a
delivery record naming who received it. Recipient email addresses are
not stored in the message record — they are stored once on the roster,
resolved at send time, and kept in the audit log only as a keyed hash and a
masked form (m•••@example.com).
Anything a coach types or uploads into an AI tool. These are free-text fields. We cannot constrain what a coach enters, and we do not filter or redact it. See §7.
4. What we never ask for and do not want
The product has no field for, and we instruct coaches not to enter: health or medical information, IEP/504 or special-education records, disciplinary records, eligibility determinations, Social Security or student ID numbers, immigration status, free/reduced-lunch status, home addresses, dates of birth, or student photographs.
Grade is the only age-related field, and it exists for eligibility and grouping.
5. Children under 13 (COPPA)
Middle-school grades are supported, so some athletes on a roster are under 13. We therefore do not collect a child's own contact details:
A player's own phone number and email address can only be stored from grade 9 up. Below that the field is rejected by the server, not merely hidden in the interface, and a roster entry with no grade recorded is treated as below the threshold. A younger athlete is reached through their parent or guardian's contact record instead.
Where a school directs us to process any student personal information, it does so under COPPA's school-consent mechanism, and the school warrants that it has authority to provide that consent on parents' behalf. That warranty belongs in the signed agreement, not only here.
Separately, no phone number or email address for any athlete or guardian can be stored at all until the school's Athletic Director account has been approved by us. Rosters work without an approved AD; contact details do not. This is enforced server-side.
6. Subprocessors
The current list, with the data categories each receives, is Subprocessors. We will maintain it and can commit contractually to advance notice of additions where a district's agreement requires it.
7. AI processing
Content a coach submits to an AI feature — including uploaded roster images and documents — is sent to Google's Gemini API to generate the response.
Pro Coach Studio does not use customer content to train any model.
Gemini is currently reached through the Gemini Developer API. A migration to Vertex AI, whose terms address model training directly, is planned; until it is complete and verified we will not claim a contractual no-training guarantee on Google's behalf. We would rather state this plainly than overstate it in a document a district relies on.
The practical control today is §4 plus the in-product warning: AI tool inputs are free text and are not filtered, so student names and anything sensitive should stay out of them. Roster and messaging features are the purpose-built place for student data.
8. Retention
| Data | Kept for |
|---|---|
| Rosters, guardians, seasons, events | For as long as the school keeps them. No automatic expiry — this is durable program data, and deleting a roster mid-season would be a defect, not a feature |
| Team message audit records (including recipient names and message bodies) | 365 days, then deleted automatically |
| Unsubscribe records | Permanently, deliberately — an expiring unsubscribe silently re-subscribes someone who asked to be left alone. Stored as a keyed hash, never a readable address |
| AI tool inputs and outputs | 730 days |
| Uploaded documents (extracted text only; the file itself is never stored) | 730 days |
| Assistant Coach chat transcripts | 730 days |
| Coach account and profile | For the life of the account |
Automatic deletion is enforced two ways: a scheduled purge job, and native Firestore TTL policies as a backstop. An automated test fails our build if a retention period is documented without a TTL policy actually enforcing it.
9. Deletion on request, and at contract termination
- A district or school may direct us to delete its data at any time. We will complete deletion within 30 days of a written request and confirm in writing.
- At contract termination we will delete all student data within 30 days, or return it first in a machine-readable export if the district asks.
- A coach can delete their own account from their profile page, which immediately removes their profile, seasons, rosters, uploaded documents and tool history.
- Unsubscribe records survive deletion by design, as a keyed hash with no readable contact details. Nothing in them identifies a student to anyone who does not already hold that person's address.
10. Security
- All traffic over TLS. Data encrypted at rest with Google-managed keys. We do not currently use customer-managed encryption keys or application-level encryption, and we do not claim to.
- Client applications have no direct database access. Firestore security rules deny everything; all access is server-side and every read and write is ownership-checked against the signed-in account.
- One login system with email verification. Athletic Directors must be approved by us before they can see any of their organization's data.
- Firebase App Check with reCAPTCHA Enterprise is enforced on roster writes and on the AI endpoints.
- Team messages are one-way broadcasts. There is no mechanism for a coach to message a single student privately through the product, and a send is rejected if it would reach fewer than two distinct households. Sending is restricted to 5 AM–9 PM school-local time. This is aligned with Utah USBE R277-515 and SafeSport MAAPP expectations for adult–minor communication.
- Every message is delivered individually; recipients are never exposed to one another on a shared To: or Cc:.
- Personal data is not written to application logs.
- Records subject to a litigation hold can be exempted from automatic deletion.
11. Breach notification
If we determine that student data has been subject to unauthorized access or disclosure, we will notify the affected district without unreasonable delay and within 72 hours of that determination, at the contact on file. The notification will describe what happened, the data categories involved, what we have done, and what we recommend. We will cooperate with the district's own notification obligations, which in several states are stricter than this baseline.
Security contact: privacy@pro-coach-institute.com.
12. Data location
All processing is in the United States. Compute runs in Google Cloud's
us-west1 region; the database is Google Cloud Firestore in the nam5
United States multi-region. We do not transfer student data outside the
United States.
13. Parent and student rights
Under FERPA the school or district is the controller of the education record. A parent's request to access, correct, or delete their student's information should go to the school, which can act on it directly in the product or instruct us to. We act on the district's instruction and will not disclose or delete a student's record on a third party's say-so.
A parent who wants to stop receiving team emails can unsubscribe from any message immediately, without contacting anyone. Unsubscribing does not remove their athlete from the roster; only the school can do that.
14. Agreements we will sign
- The Student Data Privacy Consortium National Data Privacy Agreement (NDPA) standard form, plus the applicable state exhibit.
- A district's own data-privacy rider or DPA, subject to review.
- State-specific requirements where they apply, including but not limited to Utah's Student Data Protection Act and USBE R277-487, New York Education Law §2-d (with the required Parents' Bill of Rights supplement and written data security plan), Illinois SOPPA, and California SOPIPA / AB 1584.
Contact for agreements and privacy questions: privacy@pro-coach-institute.com, ProCoach Institute, 430 West 200 North, Provo, Utah 84601.