Last updated: 2026-09-09 · Privacy questions: privacy@guardnilu.com
Privacy Policy
For the GuardNIL University app at guardnilu.com · Effective date: 2026-09-09 · Version 2.0
Who We Are and What This Policy Covers
This Privacy Policy is issued by GuardNIL ("GuardNIL," "we," "us," or "our"). It governs GuardNIL University (guardnilu.com), an app offered directly to families that helps parents turn household and athletic goals into a funded allowance system for their student-athletes.
This Policy explains what information we collect through GuardNIL University, how we use and share it, and the choices and rights available to you. If you are a parent, guardian, student-athlete, or website visitor, this Policy applies to you.
Our separate professional-development platform for NCAA athletic programs, GuardNIL (guardnil.com), is governed by its own privacy policy.
What Information Is Collected?
We collect information because we need it to provide our services, because you have given it to us directly, or because you have asked us to process it.
If You Visit Our Website or Contact Us
Whether or not you are a GuardNIL University customer, if you fill out a form, send us an email, or otherwise contact us through our website, we collect the information you provide: typically your name, email address, organization or role, and the content of your message.
If Your Family Uses GuardNIL University
From you, as the parent or guardian and account holder: your name, email address, state of residence, and password (stored in hashed form, never in plain text); your wallet balance and transaction history; and, for a linked bank account, only the last four digits and a yes/no verification flag. We do not store your full bank account or card number. Full payment details are held by our payment processor, Stripe, not by us.
About your child, which you provide as the account holder: date of birth, gender (optional), school and team affiliation, grades or GPA, athletic participation and performance stats, and progress and achievement data such as streaks and experience points. Children under 13 do not have their own login. You are always the account holder, and you provide any information about your child yourself.
Collected automatically: device and browser information, IP address, and usage logs, which we use in aggregate to operate and improve the app. Analytics data of this kind is automatically deleted after 90 days.
Children's Privacy
GuardNIL University is used by families with children under 13, and we comply with the Children's Online Privacy Protection Act (COPPA).
- A child never creates their own login or account. A parent or guardian is always the account holder, and provides any information about a child directly.
- We obtain verifiable parental consent before collecting personal information from or about a child, and we obtain separate, specific consent before any of a child's information is used with our AI-assisted features.
- As a parent or guardian, you may review, correct, export, or request deletion of your child's information, or revoke your consent, at any time, by contacting privacy@guardnilu.com. We respond to these requests within 45 days.
- We operate under our own direct COPPA compliance program. We are not enrolled in a COPPA Safe Harbor program; if we enroll, this Policy will say so.
- We do not knowingly collect personal information from a child through any means other than a parent-managed account, and we do not knowingly allow a child to communicate directly with anyone outside the app without a parent's review and approval.
Our COPPA Direct Notice states these commitments in the form the FTC rule requires.
How Is the Collected Information Used?
We use the information we collect to operate, provide, and improve GuardNIL University; to communicate with you; to process payments and deliver the services or information you have requested; to obtain and honor parental consent; to maintain the security of our services; and to comply with our legal and tax obligations. We may use and disclose information that has been aggregated or de-identified so that it no longer identifies you or your child.
What Legal Basis Do We Have for Processing Your Information?
We process personal information because:
- We have a contract with you to provide our services;
- You (or, for a child's information, your parent or guardian) have given consent, including the verifiable parental consent COPPA requires before we collect a child's information;
- We must process certain information to provide the services you have requested, including processing payments;
- We must retain certain records, such as consent and financial records, to comply with the law; and
- We have a legitimate interest in keeping our services secure and in working order, which we balance against your privacy interests.
How Is the Information Shared?
We do not sell personal information, and we do not share a child's information for behavioral advertising. We may share information as follows:
- With service providers and processors we use to support our business, described in more detail below;
- To provide you with information or services you have requested;
- To respond to subpoenas, court orders, and other legal process, or as otherwise required by law;
- To exercise our legal rights or defend against legal claims, enforce our agreements, or investigate and resolve problems or inquiries;
- In connection with an actual or potential merger, sale, acquisition, or transfer of assets or lines of business;
- With our affiliates or parent company; and
- With your consent.
Service Providers Used by GuardNIL University
To operate GuardNIL University, we work with a limited set of service providers, each of which is only permitted to use family data to perform services for us. These include:
- Payments: Stripe, Inc., which holds full bank account and payment card details on our behalf and maintains PCI DSS compliance. Bank credentials are typed into Stripe, never into GuardNIL.
- Hosting and database: Supabase, Inc. (database, sign-in, and file storage) and Vercel, Inc. (application hosting, which sees request logs and metrics but not database content).
- AI-assisted features: Anthropic, OpenAI, Google, and Voyage AI. Each receives only the text of the feature a parent just used, not the child's profile, wallet, grades, or the rest of the database.
- Search: Tavily, which receives the search text typed into the Scout assistant.
- Maps and weather: Google Maps Platform and OpenWeather, which receive the city or destination a parent enters for the trip planner, or a city typed during sign-up or on the waitlist form.
- Email delivery: Resend, which receives email addresses and the content of the emails we send.
- Background jobs: Inngest, which receives account identifiers in job payloads, not profile fields.
- Product analytics: PostHog, which runs on our public pages only (not inside the signed-in app) and receives page views, campaign parameters, device information, and, for a signed-in visitor, the account ID.
This may not be a complete list of every service provider we use, and we maintain and update it as our providers change. If we add a new category of service provider that will process family data, we will give you at least 30 days' advance notice before that provider begins processing your information. If we replace a provider with another provider performing the same category of service already disclosed here, we will update this list without a waiting period.
Third-Party Links and Services
Our website, products, and services may contain links to third-party websites and services. We do not control those linked sites, and this Privacy Policy does not apply to them. We encourage you to read the privacy policy of any third-party site before you provide it with any information.
Data Security
We use technical and organizational measures designed to protect the information we hold, including encryption of data in transit and at rest, role-based access controls, and multi-factor authentication before a parent can approve a payment. We maintain a security contact and vulnerability-disclosure process, published at guardnilu.com/legal/security. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
How Long Will You Keep My Information?
We do not retain personal information for longer than we need it. Our current retention practice is:
- Active account data: retained while your subscription is active, plus 30 days after cancellation;
- Parental consent records: retained for 3 years, consistent with COPPA;
- Financial and transaction records: retained for 7 years, consistent with tax recordkeeping requirements;
- Audit log: retained for at least 3 years, and in practice not deleted, because it is the record behind our access-control and consent commitments;
- Deleted athlete data: soft-deleted immediately and hard-deleted after 30 days, with consent and financial records retained as above;
- Analytics data: automatically deleted 90 days after collection.
More generally, we keep personal information for as long as required by law, until we no longer have a valid reason to keep it, or until you ask us to stop using it, whichever comes first. We may retain a limited record of your request not to use your information, even after we act on it, solely to honor that request going forward. If you have questions about our data-retention practices, contact privacy@guardnilu.com.
Your Rights and Choices
You may ask us to access, correct, export, or delete the personal information we hold about you or, if you are a parent or guardian, about your child, by contacting privacy@guardnilu.com. Parents can also request a copy of their family's data from Settings within GuardNIL University; it is delivered as a download link to the account email. The same page has a Do Not Sell or Share control. Turning it on also stops product analytics from being captured for your account.
Payments and Financial Information
GuardNIL University is not a bank, and wallet balances are not deposits and are not FDIC-insured. Funds are held by our payment processor, Stripe. The household "contracts" you create in the app to structure allowance arrangements are educational tools intended to support family agreements. They are not legally binding contracts.
Do We Collect Information About Children?
Yes, through GuardNIL University, as described in "Children's Privacy" above. Outside of that parent-managed flow, we do not knowingly collect personal information from a child.
How Will You Be Notified of Changes to This Policy?
We may update this Privacy Policy from time to time. If we make a material change to how we handle your information, we will post the revised Policy with a new "Last Updated" date, and where required by law, including for material changes affecting a child's information, we will provide additional notice, such as an email to the account holder. We encourage you to review this Policy periodically.
Whom Can You Contact If You Have Questions?
If you have questions about this Privacy Policy or how we handle your information, contact us at:
- General privacy questions: privacy@guardnilu.com
- Security reports: see guardnilu.com/legal/security