Keeping Your Account Safe
Security at AthleticScholar
How AthleticScholar protects your account, your Gmail and your data, and how to report a security issue











Last Updated — September 30th, 2026
Our Approach
AthleticScholar sends recruiting emails from your own Gmail account, so we treat the access you give us with care. We collect only what we need to run the Service, protect it with layered safeguards, and give you clear ways to disconnect, delete or ask about your data at any time. This page describes those safeguards in plain language. For full details on what we collect and why, see our Privacy Policy.
How We Protect Your Data
- • Encrypted connections: every connection to AthleticScholar uses HTTPS, and browsers are instructed to always connect securely.
- • Encrypted Gmail credentials: the access tokens that let us send and read recruiting emails for you are encrypted with AES-256 before they are stored, and are only decrypted at the moment we send a message or check for a coach's reply.
- • Encryption at rest: our database and file storage are hosted by Supabase, which encrypts stored data at rest.
- • Least access: only the parts of our system that need your data can reach it, and access to production systems is limited to the people who operate the Service.
- • Browser protections: our pages send security headers that prevent other sites from embedding them, restrict where content can load from, and block common injection attacks.
Your Gmail Account
- • We use Gmail access only to send the recruiting messages and follow-ups written for you, and to recognize when a college coach replies to one of those messages.
- • Messages that are not part of your AthleticScholar conversations are not stored.
- • We never sell your Gmail data, use it for advertising, or use it to train AI models.
- • AthleticScholar's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- • You can disconnect Gmail at any time from the Accounts page. Disconnecting revokes our access with Google immediately.
Account Security
- • Verified accounts: new accounts confirm their email address with a one-time code before they can use the Service.
- • Brute-force protection: sign-in, sign-up, password reset and verification codes are rate limited, so repeated guessing is blocked.
- • Strong passwords: new passwords must meet minimum strength rules, and passwords found in known data breaches are rejected.
- • Secure Google connections: connecting Gmail uses Google's authorization code flow with PKCE and a one-time state check, which protects against intercepted or forged sign-in attempts.
- • Safe sessions: sign-in sessions are managed by Supabase Auth using secure, http-only cookies.
Payments
Payments are processed by Stripe, a PCI DSS Level 1 certified payment provider. Your full card details are entered directly into Stripe's secure fields and never touch AthleticScholar's servers. We only receive limited details, such as your subscription status and the last digits of your card.
Your Control Over Your Data
- • Delete your account: you can permanently delete your account from Settings, under Data & privacy. This immediately removes your profile, messages, recruiting data and uploaded files, revokes our access to your Gmail and cancels your subscription.
- • Get a copy of your data: download a copy of your account, profile, outreach and message history at any time from Settings, under Data & privacy.
- • Disconnect Gmail: stop all sending and reply checking at any time from the Accounts page.
Monitoring and Response
We monitor the Service for errors and suspicious activity, including failed sign-ins, rate-limit hits, password resets and changes to Gmail connections. We keep our software dependencies up to date and apply security fixes promptly. If we learn of a security incident that affects your personal information, we will investigate, contain it, and notify affected users as required by law.
Report a Vulnerability
If you believe you have found a security vulnerability in AthleticScholar, please tell us so we can fix it.
- • Email security@athleticscholar.net with a description of the issue, the steps to reproduce it, and the pages or requests involved.
- • Please give us a reasonable amount of time to fix the issue before sharing it publicly.
- • Only test against your own account. Do not access or change other users' data, disrupt the Service, or send messages to coaches or other users.
- • We aim to acknowledge reports within 3 business days and to keep you updated as we work on a fix.
We will not take legal action against anyone who reports a vulnerability in good faith and follows these guidelines.
Contact
For security questions or reports, email security@athleticscholar.net. For privacy questions, email admin@athleticscholar.net.