Privacy Policy
Effective date: June 2026 · Beta version
Important — Please read before using
Guardian is not a medical application and is not a HIPAA-covered service. The data collected is self-reported athletic wellness information — it is not Protected Health Information (PHI) under HIPAA and must not be treated as such. Do not enter medical records, diagnoses, or clinical data into this Platform. Guardian is currently in beta and data handling practices may evolve before general availability.
1. Not a HIPAA-covered service
Guardian is not subject to HIPAA. Synergy Sports and Rehab is not a covered entity (health plan, healthcare clearinghouse, or healthcare provider) as defined under 45 C.F.R. §160.103, and does not act as a business associate of any covered entity in connection with this Platform.
The information collected through Guardian — self-reported wellness check-in responses, readiness scores, body pain reports, and headache assessments — is not Protected Health Information (PHI) under HIPAA. It is not created, received, maintained, or transmitted in connection with the provision of healthcare, health plan administration, or healthcare payment operations.
Guardian does not provide HIPAA-compliant data handling, Business Associate Agreements (BAAs), or any other HIPAA-required safeguards. If you require HIPAA-compliant storage or transmission of health data, Guardian is not the appropriate tool for that purpose.
2. What we do NOT collect
Guardian is designed to collect only athletic wellness and readiness data. The following types of information are outside the scope of this Platform and must not be entered:
- Medical records or clinical documentation of any kind
- Diagnoses, treatment plans, or prescription information
- Health insurance information or claims data
- Information created or maintained by a licensed healthcare provider in a clinical context
- Any data that constitutes PHI under HIPAA or sensitive health information under applicable state law
If such information is inadvertently entered, it should be deleted immediately. Contact us at synergysportsrecovery@gmail.com if you believe sensitive health data has been entered into the Platform.
3. What we collect
When you use Guardian, we collect and store the following information:
- Account information — full name, email address, phone number, and mobile carrier (e.g. Verizon, AT&T). Phone and carrier are optional.
- Profile information — role (athlete, coach, athletic trainer, director), school, team, sport, and level (varsity, JV, etc.).
- Self-reported wellness check-ins — daily responses across eight categories: Sleep & Recovery, Muscle & Joint, Fatigue & Energy, Stress & Emotional State, Pain & Injury Risk, Hydration, Nutrition, and Academic/Life Load. Each submission includes individual question responses, category scores, and an overall wellness readiness score.
- Self-reported body discomfort — body area and discomfort level (0–10 scale) entered voluntarily by the athlete as part of the daily check-in. This is not a clinical pain assessment.
- Self-reported headache indicators — presence, self-assessed severity, associated symptoms (dizziness, nausea, light/sound sensitivity), and whether a head impact occurred. This is not a medical concussion evaluation.
- HRV reading — heart rate variability, if voluntarily entered. Currently stored but not used in scoring or displayed in the UI.
Passwords are never stored in our application database. Authentication is handled by Supabase Auth using bcrypt encryption.
4. How we use your data
- Display wellness trends, readiness scores, and alerts to authorized staff (coaches, trainers, directors) at your assigned school.
- Calculate daily and historical wellness scores to support athlete readiness decisions — not medical decisions.
- Send transactional emails: password reset and account setup only. We do not send marketing email.
- Allow school staff to manage rosters, update athlete records, and monitor athletic readiness over time.
Wellness scores and data on the Platform are readiness indicators, not medical assessments. They reflect only what an athlete self-reported and must not be relied upon as a substitute for evaluation by a licensed healthcare provider.
5. Who can see your data
Access to data is strictly role-based and enforced at the database level (row-level security):
- Athletes — can only see their own submissions, scores, and profile.
- Coaches — can see athlete profiles and wellness data for athletes at their assigned school. Cannot edit wellness data.
- Athletic Trainers & Directors — can see and manage athlete and staff records at their assigned school(s). Directors may be assigned to multiple schools.
- Administrators — can see and manage all data across all schools.
No user can access data outside their assigned school or role.
6. Third-party services
Guardian uses the following third-party services:
- Supabase — database, authentication, and file storage. Your data is stored on Supabase-managed infrastructure. See Supabase's Privacy Policy.
- Google Fonts CDN — the Geist typeface is loaded from Google's CDN when you visit the app. Google may log your IP address as part of this request. See Google's Privacy Policy.
We do not use analytics tools, advertising trackers, or error monitoring services. No data is sold or shared with third parties for any purpose beyond what is described in this policy.
7. Phone number and mobile carrier
If provided, your phone number and mobile carrier are stored securely in our database. These fields are not currently used to send any messages. They are reserved for a possible future SMS notification feature and will not be used for any other purpose.
8. Student athletes and minors
Guardian is used in school athletic programs and may collect wellness data from student athletes who are minors. Access to that data is limited to authorized school staff at the athlete's assigned school. We do not knowingly collect data from minors outside of this supervised school context, and we do not share student data with third parties beyond what is described in this policy.
Schools using Guardian are responsible for compliance with applicable student data privacy laws, including the Family Educational Rights and Privacy Act (FERPA) and any applicable state student privacy statutes.
9. Data retention and deletion
Data is retained for as long as an account is active. When an account is deleted by an administrator, all associated data is permanently removed — including wellness submissions, pain reports, and headache assessments. There is no soft-delete or archive; deletion is immediate and irreversible.
10. Your rights
Depending on your location, you may have rights to access, correct, or delete your personal data under applicable law (such as CCPA for California residents). To exercise these rights, contact your school administrator or reach out to us directly at the address below. Because Guardian does not collect PHI, HIPAA's individual rights provisions (right of access, amendment, etc.) do not apply to data in this Platform.
11. Changes to this policy
Because Guardian is in beta, this policy may be updated as the platform evolves. Material changes will be communicated to users before taking effect.
12. Contact
For privacy questions or data requests, contact the Guardian team at synergysportsrecovery@gmail.com.