YTLast updated: July 20, 2026
We collect three broad types of information:
a. Information you give us directly. Your name, email, phone number (if you provide one), date of birth, school + team, sport + position, jersey number, photos + video highlights, milestones and achievements, bio text, social handles, and any files you upload (transcripts, NIL disclosures, brand contracts). If you set up payouts, Stripe collects additional identity and banking data on our behalf — see Section 4.
b. Information generated as you use the Service. Pages you visit, features you use, buttons you tap, sign-in timestamps, device type + operating system, browser type, IP address, approximate location derived from IP, referrer URL, and interactions with push notifications and emails we send.
c. Information from third parties. If you sign in with Google, we receive your Google account name, email, and profile photo. If you connect a social account (Instagram, TikTok, X), we may receive your handle, public profile info, and follower counts. If you're added to a roster or program by a coach or agent, we may receive contact information about you from them.
We use the information above to:
If you're in the EU, UK, or EEA, we process your personal data on these legal bases:
All payments are processed by Stripe, Inc. Stripe collects your payment card, banking, tax ID, government ID, and business information directly — we never see or store the raw card, SSN, or bank credentials. Stripe is a PCI-DSS Level 1 processor and is bound by its own privacy policy: stripe.com/privacy.
When you set up a Stripe Express connected account for payouts, Stripe performs KYC (Know Your Customer) and shares back with us only the minimum fields we need to display your payout status (name, business type, details_submitted, charges_enabled, payouts_enabled, country).
We do not sell your personal data. Ever. We share it only with:
All sub-processors are bound by data-protection agreements requiring them to protect your data at least as strictly as we do.
We use a small set of cookies + browser storage:
dl_session) — httpOnly JWT that keeps you signed in. Essential.We don't use ad-tech tracking, cross-site tracking pixels, or advertising cookies of any kind.
If you allow push notifications on your device, we'll send you transactional pings (new messages, brand-deal offers, payout confirmations, trial-ending reminders). We use Apple Push Notification service on iOS, Firebase Cloud Messaging on Android, and Web Push (VAPID) in the browser. You can turn push off any time in your device or browser settings; the app keeps working normally without it.
Flythouse is not directed at children under 13. If you're under 13, please don't create an account. If we learn we've collected personal data from a child under 13 without verified parental consent, we'll delete it promptly.
Athletes ages 13–17 may use Flythouse with a parent or legal guardian's consent. Parents can request access to, correct, or delete their child's data by emailing privacy@flythouse.com.
No matter where you live, you can:
California residents (CCPA/CPRA): You have the right to know what personal information we collect, request deletion, and opt out of any “sale” or “sharing” of your personal information — though we don't sell or share it for cross-context behavioral advertising. Email privacy@flythouse.com with “CCPA Request” in the subject.
EU/UK residents (GDPR): In addition to the rights above, you may object to processing, request restriction of processing, and lodge a complaint with your local data-protection authority.
We keep your account data as long as your account is active. When you delete your account we remove your profile, bio, uploaded media, and messages within 30 days — except for a narrow set of data we're legally required to keep longer: financial records (Stripe holds transaction data for 7 years for tax + anti-fraud rules) and audit logs (we hold sign-in logs for 90 days for security).
Content that other users have interacted with (e.g. messages sent to your agent) may remain in those users' message history after your deletion, but with your name replaced by “Deleted user.”
Flythouse operates from the United States. If you're accessing the Service from outside the US, your information will be transferred to and processed in the US. Where required, we use Standard Contractual Clauses (SCCs) with our sub-processors for EU/UK data transfers.
We protect your data with TLS in transit, encryption at rest for sensitive fields, bcrypt-hashed passwords, short-lived session tokens, and least-privilege access for our own team. Stripe (payments) and Google (auth) each meet SOC 2 Type II standards.
No system is 100% impenetrable. If we ever suffer a breach that affects your personal data, we'll notify you and applicable regulators within the timelines required by law (72 hours under GDPR).
We'll update this Policy when we materially change how we handle personal data. When we do, we'll post the new version here and update the “Last updated” date at the top. For significant changes we'll also email account holders.
Questions, deletion requests, or a formal privacy complaint? Reach us at privacy@flythouse.com.
See also our Terms of Service.
FLYT Studios LLC · Austin, Texas · USA