StatMe Privacy Policy
Last Updated: July 31, 2026 | Effective Date: July 31, 2026
A. The Short Version
Here is the short version. The detailed sections below explain each point fully. If anything in this summary appears to conflict with a detailed section, the detailed section controls.
- Who uses StatMe. A Parent or Guardian — an adult who creates and manages the account — sets up the Service. Parents submit stats, game film, photos, and academic documents on behalf of their young athlete. Teen athletes aged 13 and older may also use the Service directly. StatMe is sold directly to families.
- What we collect. Names, contact details, date of birth, login credentials, game film and photos, player statistics, and — only for academic-eligibility verification — GPA, SAT, and ACT documents, which we delete immediately after verification. See Section D for the full list.
- Why we collect it. To deliver the StatMe analytics and highlight-reel service — that is it. We do not use your information for behavioral advertising, and we do not sell personal information.
- How the document scan works. When you submit an academic document for eligibility verification, we send it to Anthropic (through Amazon Web Services Bedrock) so a computer can read the text on it. The document is deleted immediately after verification is complete. This step is the only way the eligibility-verification feature can work, so it is covered by the same consent you give when you use the Service. See Section C.1 and Section K.
- Children under 13 — parental consent is required. We do not collect, use, or share personal information from a child under 13 until a parent provides Verifiable Parental Consent. See Section J.
- We keep data only as long as we need it. See the per-category retention table in Section G.
- You are in control. You may review, correct, or delete your information — and your child's information — at any time. See Sections M and N.
- Where StatMe is offered. StatMe is directed to users in the United States.
For questions, contact us:
StatMe LLC, 1206 Coleridge Street, Sugar Land, Texas, 77479
Email: matthew@statme.us
Phone: (713) 248-5383
B. A Few Terms We Use in This Policy
- "StatMe," "we," "us," "our" — StatMe LLC, a Texas limited liability company.
- "the App" — the StatMe mobile application for iOS and Android.
- "the Service" — the youth basketball analytics platform, highlight-reel generation, academic-eligibility verification, and related features we deliver through the App and our website at www.statme.us.
- "Parent" or "Guardian" — the adult who creates and manages a StatMe account, including a parent who submits data on behalf of a child under 13. When we say "you," we mean the Parent or Guardian (or, where the context fits, a teen user aged 13 or older acting for themselves).
- "Child" or "young athlete" — an athlete whose information is used in the Service. Where we specifically talk about COPPA protections, "Child" means a child under 13 whose personal information a Parent submits.
- "Children's personal information" — personal information that COPPA protects when it is collected from or about a child under 13, including the categories listed in Section D.
- "Subprocessor" or "service provider" — a company that processes personal information on our behalf, under a written contract, to help us deliver, host, secure, or support the Service.
- "Third party" — a recipient of personal information that is not StatMe and is not acting purely to support our own internal operations.
- "Verifiable Parental Consent" or "VPC" — the consent COPPA requires a parent to give before we may collect, use, or share a child under 13's personal information.
- "GPC" — Global Privacy Control, a browser or device signal that tells us you want to opt out of any sale or sharing of your personal information.
C. How StatMe Works
StatMe is a youth basketball analytics platform. Parents create accounts and upload game film, enter player statistics, and submit academic-eligibility documents for their athletes. StatMe turns that content into highlight reels and analytics reports. Teen athletes aged 13 and older may use the App directly.
StatMe is free at launch. A paid subscription tier will be added later.
C.1 — How Anthropic (through Amazon Web Services Bedrock) Reads Academic Documents
When a Parent submits a student-athlete's academic records — GPA, SAT, or ACT documents — for eligibility verification, StatMe sends those documents to Anthropic through Amazon Web Services Bedrock for optical character recognition (OCR). OCR is simply the automated process of reading the text off an uploaded document.
This step is essential to the eligibility-verification feature. StatMe does not run its own OCR technology. Sending the document to Anthropic through Bedrock is not an add-on or an optional extra — it is the only way the eligibility-verification step can function. Because the feature cannot be delivered without it, this transmission is integral to the Service, and it is covered by the same Verifiable Parental Consent you provide when you use the Service (Section J). There is no version of the eligibility-verification feature in which academic documents are processed without this step.
Anthropic deletes the submitted documents immediately after verification.
Section D describes everything we collect. Section F identifies Anthropic and our other subprocessors. Section K explains, in plain language, why this transmission is covered by your primary consent.
D. The Information We Collect, and How We Use It
We collect only the information we need to deliver, support, and secure the StatMe Service. We do not collect more than we need, and we do not require you to give us more than is reasonably necessary to use StatMe.
D.1 — General User Data (all users)
| Category | How We Collect It | How We Use It |
|---|---|---|
| Full name | Registration form; social sign-in (Apple/Google) | Create your account; identify you; address our communications to you |
| Email address | Registration form; social sign-in | Account authentication; transactional email; parental contact |
| Date of birth | Registration form | Age verification; COPPA compliance; account management |
| Login credentials (hashed password or social sign-in token) | Registration form; Sign in with Apple; Google Sign-In | Authentication |
| IP address | Automatically when you use the App or website | Security; fraud prevention; geographic access controls |
| Device identifiers (iOS IDFV; Android equivalent) | Automatically by your device | Internal operations (see Section H); crash reporting; push notifications |
| Country, state, city, ZIP | Registration form | Compliance; geographic context |
| Job position / workplace (optional, for coaches and admins) | Registration form (optional) | Identify a user's role within the platform |
| Push notification token | Expo push registration | Deliver in-app notifications about the athlete's content |
D.2 — Athlete Performance Content (submitted by a Parent or teen user)
| Category | How We Collect It | How We Use It |
|---|---|---|
| Game film (video) | Parent or user upload | Core service delivery; highlight-reel generation; analytics |
| Photos of the athlete | Parent or user upload | Athlete profile; highlight-reel content |
| Player statistics (game stats, performance metrics) | Parent or user manual entry | Analytics reports; highlight reels; career tracking |
| Highlight reels (generated output) | Created by StatMe from uploaded film and stats | Delivered to the Parent or user; stored while the account is active |
D.3 — Academic-Eligibility Documents (sensitive)
| Category | How We Collect It | How We Use It |
|---|---|---|
| GPA, SAT/ACT scores, academic transcripts | Parent or teen user upload | Eligibility verification through Anthropic/Bedrock OCR (see Section C.1); deleted immediately after verification |
D.4 — App Usage and Diagnostics
| Category | How We Collect It | How We Use It |
|---|---|---|
| App-open activity / usage events | Automatically in the App | Service improvement; feature analytics (internal only) |
| Crash and stability diagnostics | Sentry (Functional Software, Inc.) SDK | Diagnose and fix App crashes; monitor stability |
D.5 — What We Do Not Do
We do not use personal information for behavioral advertising. We do not sell personal information — not to data brokers, not to advertisers, not to anyone. We do not combine your information with information from other sources to build a profile of you. We do not use children's personal information for targeted advertising. And we do not require you to hand over more information than is reasonably necessary to use StatMe.
D.6 — Our Position on Biometric Data
StatMe processes game film that may show players' faces and bodies. Our film analysis uses player tracking, pose estimation, and jersey-number recognition — and, based on the way the Service is built as of this policy's effective date, it does not create a recognition-capable biometric identifier (such as a facial recognition template or a voiceprint) of any athlete.
If we ever change our processing in a way that creates a recognition-capable biometric identifier, we will update this policy and obtain any additional consent the law requires before that processing begins.
E. Information We Collect From Parents and Teen Users Directly
In addition to the athlete data a Parent submits, StatMe collects information from the account holder directly:
- Parent or guardian: name, email, date of birth (for age and consent verification), account credentials, and — once the paid tier is live — billing information processed by RevenueCat.
- Teen users (13–17, direct accounts): name, email, date of birth, account credentials, and the athlete content they submit.
- Marketing preferences: if you opt in to receive StatMe news and feature updates, we store your email for that purpose. You can opt out at any time. We use your information only to tell you about our own offerings — never anyone else's.
F. How We Share Information — Our Subprocessors and Third Parties
We do not sell personal information. We share information only with the subprocessors listed below, only for the purposes stated, and only under written contracts that require each subprocessor to keep the information confidential, use it solely to provide services to StatMe, and maintain reasonable data security.
F.1 — Our Subprocessors
| Subprocessor | Category and COPPA Role | What It Receives | Purpose |
|---|---|---|---|
| Anthropic (through Amazon Web Services Bedrock) | Third party to which we disclose children's personal information; this disclosure is integral to the eligibility-verification feature (see Sections C.1 and K) | Academic documents (GPA/SAT/ACT) submitted for eligibility verification | OCR-based eligibility verification; document deleted immediately after verification |
| Amazon Web Services (AWS) | Subprocessor — hosting, database, file storage; supports our internal operations | All server-side data, including athlete content stored in our cloud infrastructure | Hosts StatMe's backend, database, and file storage; does not use the data for its own purposes |
| Expo | Subprocessor — push notifications; supports our internal operations | Push notification tokens | Delivers push notifications to users' devices |
| Apple (Sign in with Apple; App Store; APNs) | Authentication provider; app distribution; push delivery | Sign-in tokens (no password); app-distribution data; APNs device tokens | Authentication; app distribution; push delivery through Apple Push Notification service |
| Google (Google Sign-In; Google Play) | Authentication provider; app distribution | Sign-in tokens; app-distribution data | Authentication; app distribution through Google Play |
| Sentry (Functional Software, Inc.) | Subprocessor — crash and error reporting; supports our internal operations | Crash diagnostics and stability logs | Diagnoses App crashes; monitors stability |
| RevenueCat | Subprocessor — subscription billing (once the paid tier is live) | Subscription status; billing identifiers (parent accounts only; no child data is sent to RevenueCat) | Manages the subscription lifecycle when the paid tier activates |
F.2 — How These Subprocessors Are Categorized
- Integral, delivery-essential disclosure. Anthropic (through Bedrock) — covered by the primary Verifiable Parental Consent (Section J); NOT a separate opt-in.
- Support for our internal operations. AWS (hosting and storage), Expo (push), and Sentry (crash reporting) handle data only to support StatMe's internal operations.
- Authentication providers. Apple and Google receive sign-in tokens; no children's personal information beyond an authentication token is shared.
- Subscription billing. RevenueCat receives parent billing data only; no athlete or child data is sent.
F.3 — Anthropic/Bedrock Data-Handling Terms
Anthropic does not use the academic documents we send it to train its own AI models, under the contractual terms of Amazon Web Services Bedrock.
G. How Long We Keep Information — and When We Delete It
We keep personal information only as long as we reasonably need it for the purpose we collected it for, and we do not keep it indefinitely.
| Category of Personal Information | Why We Collect It | Why We Keep It | When We Delete It |
|---|---|---|---|
| Academic documents (GPA/SAT/ACT) | Eligibility verification | OCR processing only | Immediately after verification is complete — not retained |
| Game film and photos | Core service delivery; highlight reels | The athlete's performance record | While the account is active; deleted immediately and automatically when the account is closed |
| Highlight reels (generated) | Athlete showcase content | Deliver the value of the Service | While the account is active; deleted immediately and automatically when the account is closed |
| Player statistics and performance data | Analytics; career tracking | Core service record | While the account is active; deleted immediately and automatically when the account is closed |
| Account identifiers (name, email, DOB, credentials) | Account management; COPPA compliance | Authenticate and identify the user | Deleted immediately and automatically when the account is closed or a deletion request is made |
| Parent account data (name, email, billing identifiers) | Account and billing management | Manage the account and (once live) the subscription | While the account is active; deleted immediately and automatically when the account is closed or a deletion request is made |
| Push notification tokens | Deliver notifications | Active notification delivery | Deleted when you turn off notifications or close your account |
| Crash and diagnostic logs (Sentry) | App stability | Diagnose the cause of a crash | 90 days after collection |
| IP address and device identifiers | Security; fraud prevention | Rolling security window | No more than 90 days |
When you ask us to delete personal information (Section M or N), we delete it promptly from our systems and direct our subprocessors to delete it. When an account is closed, we delete the associated personal information immediately and automatically, except where applicable law requires us to keep it.
About Anthropic/Bedrock vendor retention: Academic documents submitted for eligibility verification are deleted by StatMe immediately after verification.
H. Persistent Identifiers and Internal Operations
The App uses a device-level persistent identifier — specifically, the iOS Identifier for Vendor (IDFV) on Apple devices and the equivalent identifier on Android — for these specific internal operations only:
- Push notifications: matching a push notification token to the right user session so that alerts about the athlete's content reach the right device.
- Crash reporting: connecting a crash report to a session in our Sentry logs so we can find and fix the cause.
- Security and fraud prevention: spotting unusual session patterns to protect accounts.
- Support debugging: finding the relevant session in our logs when a Parent contacts support.
Our safeguards. We do not use these identifiers for behavioral advertising. We do not use them to track users across other apps. We do not use them to build advertising profiles. And we do not share them with advertising networks.
We have put the safeguards above in place to make sure persistent identifiers are not used for anything else.
I. No Secondary or Optional Use of Children's Data
StatMe does not use children's personal information — game film, photos, statistics, academic documents, or anything else a Parent submits about a child under 13 — to train AI models, for general product research unrelated to delivering the Service, or for any other secondary purpose that would require a separate opt-in.
If StatMe ever introduces an optional secondary use of personal information — for example, allowing data to be used to improve future models — we will present a separate, default-off opt-in to parents before that use begins.
J. Verifiable Parental Consent (Children Under 13)
We will not collect, use, or share personal information from a child under 13 until a parent or guardian provides Verifiable Parental Consent.
J.1 — Consent During the Free-Launch Period
Because StatMe is free at launch, there is no payment at sign-up that we can use to confirm a parent's identity. So, at launch, we verify parental consent through the "email plus" method before we collect any personal information from a child under 13. During account setup, you will see a direct notice that summarizes what we collect from your child and how we use it, and you will be asked to complete that verification before your child's account is activated. Under this method, we verify the parent's email address, keep a record of the consent (the version accepted and a timestamp), and send a confirmation of the consent to the parent's verified email address with instructions for reviewing or revoking it.
J.2 — Consent Once the Paid Tier Is Live
Once the paid subscription tier is live, we will also use your payment transaction as a way of obtaining Verifiable Parental Consent for new accounts. When you subscribe and provide your payment method, you will see a direct notice and be asked to confirm your consent before your payment is processed. Using a payment method to purchase the Service will count as your Verifiable Parental Consent to our collection, use, and disclosure of your child's personal information as described in this policy. Until the paid tier is available, the interim method named in Section J.1 is the operative method.
J.3 — Your Consent Covers the Anthropic/Bedrock Step
Your consent for the Service covers sending academic documents to Anthropic through Bedrock for eligibility verification, because that step is essential to delivering the eligibility-verification feature you enrolled in (see Sections C.1 and K). You do not need to make a separate opt-in choice for this essential step.
J.4 — Consent Is Per-Child, Not Per-Household
We keep a separate consent record for each child under 13 you enroll. If you add a child to your account later, you will see the direct notice for that child and be asked to confirm your consent for that specific child before we collect any of that child's personal information.
K. Why the Anthropic/Bedrock Step Is Covered by Your Consent
StatMe cannot verify an athlete's academic eligibility without reading the content of the submitted documents, and StatMe does not run its own optical-character-recognition technology. Sending the document to Anthropic through Bedrock is not a choice or an add-on — it is the only way the eligibility-verification feature can work. Because the feature you enrolled in cannot be delivered without it, this step is integral to the Service, and it is covered by the primary Verifiable Parental Consent for the Service.
This does not allow us to use your child's academic documents for any purpose outside eligibility verification — including AI training, advertising, or monetization. Anthropic's contractual terms with StatMe bar training on, or otherwise exploiting, the documents we submit.
Any future use of submitted documents for other purposes would require a separate opt-in from you.
L. Security — Our Written Children's Personal Information Security Program
We maintain a written Children's Personal Information Security Program with safeguards appropriate to the sensitivity of the information we collect. Our program includes:
- A program coordinator. We have designated Matthew Atme as Privacy and Security Coordinator to coordinate the Security Program.
- A risk assessment. We identify and assess risks to the confidentiality, security, and integrity of the personal information we collect and maintain, with particular attention to children's personal information and sensitive data (game film, photos, academic documents).
- Safeguards. We design and implement safeguards to control those risks, including:
- TLS 1.2 or higher for all data in transit;
- Encryption of stored personal information at rest on AWS infrastructure;
- Role-based access controls with least-privilege defaults for personnel access to production systems;
- Periodic access review of accounts that can reach production systems;
- Written data-processing agreements with all subprocessors that handle personal information;
- Logging and monitoring of access to production systems through AWS and Sentry;
- Immediate deletion of academic documents after eligibility verification; and
- Regular security updates to the App and our infrastructure.
We test and monitor these safeguards on a regular basis.
- An annual evaluation. We evaluate and adjust the Security Program at least once a year, and whenever there is a material change in our operations or in the threats we face.
No system is completely secure, and we cannot guarantee absolute security — but we take the measures described here.
M. Your Parental Rights (Children Under 13)
At any time, you may exercise these rights over your child's personal information:
- Review. You may review the personal information we have collected about your child by logging into your account and visiting the child's profile, or by contacting us at matthew@statme.us.
- Correction. You may ask us to correct inaccurate personal information about your child by contacting us at matthew@statme.us.
- Deletion. You may ask us to delete your child's personal information by contacting us at matthew@statme.us or by using the in-app account-deletion feature. We delete the information immediately and automatically, and we confirm the deletion. We also direct our subprocessors to delete it.
- Refuse further collection. You may tell us to stop collecting or using your child's personal information by closing the account (which we treat as a withdrawal of consent) or by contacting us at matthew@statme.us. Once you do, we stop collecting your child's personal information and delete what we have as described in Section G.
To protect your privacy and your child's privacy, we may ask you to verify your identity before we act on a request.
N. Privacy Rights for Everyone
We extend the rights described in this section to all StatMe users, no matter where you live.
N.1 — Texas: The Texas Data Privacy and Security Act (TDPSA)
StatMe does not sell personal information, including the personal information of known children. We do not process personal information for targeted advertising. And we do not use personal information for profiling that produces legal or similarly significant effects without appropriate safeguards.
Your TDPSA rights:
- Know / access — request to know what categories of personal information we have collected about you, and access that information.
- Correct — request correction of inaccurate personal information.
- Delete — request deletion of personal information you provided or that we collected about you.
- Data portability — request a copy of your personal information in a portable, readily usable format, where technically feasible.
- Opt out of sale — StatMe does not sell personal information, but you may exercise this right at any time and we will confirm that no sale is occurring.
Universal opt-out / Global Privacy Control (GPC). We recognize the Global Privacy Control (GPC) signal as a valid opt-out of any sale or sharing of your personal information. If your browser or device sends a GPC signal, we process it as an opt-out and display a confirmation that we have done so.
To exercise any TDPSA right, contact us at matthew@statme.us. We respond within 45 days (extendable by another 45 days with notice).
N.2 — Texas: The App Store Accountability Act (TASAA)
Texas law places age-verification and parental-consent duties on app stores — Apple's App Store and Google Play — not on individual app developers. StatMe honors any age-verification or parental-consent signals it receives from Apple and Google under their compliance programs. StatMe does not separately collect or store age-verification data from the app stores beyond what this policy already describes.
N.3 — Texas: The SCOPE Act
StatMe includes communication features that are limited by design: team chat, coach-only group chats, and direct messages restricted to people who share an active team. There are no public user profiles, no public content feed, and no open messaging with strangers. A player's profile is visible only within that player's team relationships (coaches, teammates, and linked parents) and, according to the player's own visibility settings, to approved scouts. Scouts cannot message players; scout messaging is limited to conversations with coaches.
For minors, StatMe provides parental tools. A parent may link to their 13-to-17 player's account to view activity, monitor direct messages, and manage settings. Users can block other users and report messages, and coaches can moderate and delete messages in their team's threads. Parents also hold the review, correction, and deletion rights described in Sections M and N. Children under 13 have no messaging at all and are never visible to scouts. If StatMe adds broader social features in the future, we will revise this section.
N.4 — Texas: Biometric Identifiers (CUBI)
See Section D.6 for our position on biometric identifiers.
N.5 — California and Beyond (CCPA/CPRA), Extended to All Users
We extend the following rights to all users, no matter where you live:
- Know and access — request the categories and specific pieces of personal information we have collected about you.
- Delete — request deletion of personal information we hold about you, subject to limited exceptions.
- Correct — request correction of inaccurate personal information.
- Opt out of sale or sharing — StatMe does not sell or share personal information for cross-context behavioral advertising. You may exercise this right at any time, and we will confirm that no sale or sharing is occurring.
- Limit the use of sensitive personal information — request that we limit our use of sensitive personal information (including academic data, biometric identifiers if any, and children's personal information) to what is necessary to provide the Service.
- Non-discrimination — we will not discriminate against you for exercising any privacy right.
GPC / universal opt-out. If your browser or device sends a GPC signal, we treat it as an opt-out of any sale or sharing and display a confirmation that we have processed it.
To exercise any of these rights, contact us at matthew@statme.us. We respond within 45 days (extendable with notice where the law permits).
O. Highlight Reels and Your Athlete's Name, Image, and Likeness (NIL)
StatMe creates highlight reels from the game film and statistics uploaded to the platform. These reels are shown within your private StatMe account, for your own use.
If you share, publish, distribute, or authorize the commercial use of a highlight reel or other content that identifies a minor athlete — outside the StatMe platform, in a promotional or commercial context — you may need the parent's consent (if you are not the parent) and, where it applies, the athlete's consent. StatMe does not commercially use a minor athlete's name, image, or likeness without separate Verifiable Parental Consent.
P. Cookies and Automatic Data Collection
In the App (iOS/Android). The StatMe app does not use browser cookies. It uses the device identifiers and push notification tokens described in Section H, and the analytics and crash-reporting tools (Expo, Sentry) described in Sections D and F.
On our website (www.statme.us). Our website may use session cookies or similar technologies for authentication and security. We do not use behavioral-advertising cookies or third-party tracking cookies.
Links to social platforms. Our website may link to or integrate with Facebook, Instagram, LinkedIn, TikTok, Twitter, and YouTube. Those platforms' own privacy policies govern any information they collect when you use their features. StatMe does not control those platforms' data practices.
Q. Where You Can Find This Policy
This Privacy Policy is available:
- From the StatMe listing in the Apple App Store;
- From the StatMe listing in the Google Play Store;
- From our website at www.statme.us/privacy;
- From within the App in Settings > About & legal > Privacy & Terms; and
- At www.statme.us/privacy
R. How You Accept This Policy
By creating a StatMe account, using the App, or submitting any information through www.statme.us, you acknowledge that you have read this Privacy Policy and agree to it.
Parents completing the Verifiable Parental Consent process for a child under 13 (Section J) receive a direct notice of our data practices and provide consent before any of the child's personal information is collected.
S. Changes to This Policy
We may update this Privacy Policy from time to time. We will tell you about any material change — including a change to the types of personal information we collect, the third parties we share it with, our retention periods, or our parental-consent mechanism — by:
- Sending a notice to the email address associated with your account; and
- Displaying a notice within the App or on our website at www.statme.us.
If a material change requires your fresh or updated consent — for example, if we add a new use of personal information that needs a separate parental opt-in — we will ask for that consent before the new use begins.
If you do not agree to a material change, you may close your account as described in Section M.
The "Last Updated" date at the top of this policy reflects the most recent revision.
T. Who We Are — Operator Contact
The following identifies the operator that collects or maintains personal information through StatMe:
Operator: StatMe LLC
Physical Address: 1206 Coleridge Street, Sugar Land, Texas, 77479
Telephone: (713) 248-5383
Email: matthew@statme.us
StatMe LLC is the sole operator of StatMe. Amazon Web Services, Anthropic, Expo, Apple, Google, Sentry (Functional Software, Inc.), and RevenueCat are subprocessors and service providers — not co-operators of StatMe.
Please direct all parental inquiries, consent requests, parental-rights requests, and deletion requests to the contact information above.
U. General
Governing law. This Privacy Policy is governed by, and construed in accordance with, the laws of the State of Texas, without regard to conflict-of-laws principles, and subject to applicable federal law.
Relationship to our Terms of Service. This Privacy Policy is separate from StatMe's Terms of Service. If anything in the Terms of Service appears to conflict with this Privacy Policy about how we handle personal information, this Privacy Policy controls.
Conflict. If anything in this Privacy Policy appears to conflict with any other StatMe document about personal information, this Privacy Policy controls.