Back home

Privacy Policy

Last updated: July 20, 2026

This Privacy Policy explains how Flyt House (operated by FLYT Studios LLC — collectively “Flyt House,” “flythouse.com,” “we,” “us”) collects, uses, shares, and safeguards your information when you use the Flyt House website, mobile experience, and any product operated under the flythouse.com domain (the “Service”). By using the Service you agree to this Policy.

1. Information We Collect

We collect three broad types of information:

a. Information you give us directly. Your name, email, phone number (if you provide one), date of birth, school + team, sport + position, jersey number, photos + video highlights, milestones and achievements, bio text, social handles, and any files you upload (transcripts, NIL disclosures, brand contracts). If you set up payouts, Stripe collects additional identity and banking data on our behalf — see Section 4.

b. Information generated as you use the Service. Pages you visit, features you use, buttons you tap, sign-in timestamps, device type + operating system, browser type, IP address, approximate location derived from IP, referrer URL, and interactions with push notifications and emails we send.

c. Information from third parties. If you sign in with Google, we receive your Google account name, email, and profile photo. If you connect a social account (Instagram, TikTok, X), we may receive your handle, public profile info, and follower counts. If you're added to a roster or program by a coach or agent, we may receive contact information about you from them.

2. How We Use Your Information

We use the information above to:

  • Run the Service — create and manage your account, show you your dashboard, deliver profile pages, roster grids, messages, and stories
  • Process payments and payouts through Stripe, and calculate the platform fee
  • Verify identity (through Stripe Identity) when you claim a profile, request a verified badge, or set up payouts
  • Send transactional emails (checkout confirmations, trial reminders, roster invites) via Resend
  • Send push notifications you opted into (through Apple Push, Google Firebase Cloud Messaging, or Web Push / VAPID) — new messages, brand-deal offers, payout confirmations
  • Measure product usage (which features get used, where users drop off) through privacy-respecting analytics on our own servers plus PostHog
  • Prevent fraud, abuse, spam, and violations of our Terms
  • Comply with legal obligations — tax reporting (1099-K via Stripe), subpoenas, court orders
  • Communicate with you about product updates and, if you've opted in, marketing news — you can unsubscribe from marketing any time

3. Legal Bases (GDPR)

If you're in the EU, UK, or EEA, we process your personal data on these legal bases:

  • Contract — to deliver the Service you signed up for
  • Legitimate interests — to improve the Service, prevent fraud, secure our systems
  • Consent — for marketing emails, push notifications, and non-essential cookies (you can withdraw consent any time)
  • Legal obligation — to comply with tax, financial, and identity-verification rules

4. Payments & Stripe

All payments are processed by Stripe, Inc. Stripe collects your payment card, banking, tax ID, government ID, and business information directly — we never see or store the raw card, SSN, or bank credentials. Stripe is a PCI-DSS Level 1 processor and is bound by its own privacy policy: stripe.com/privacy.

When you set up a Stripe Express connected account for payouts, Stripe performs KYC (Know Your Customer) and shares back with us only the minimum fields we need to display your payout status (name, business type, details_submitted, charges_enabled, payouts_enabled, country).

5. Who We Share Data With

We do not sell your personal data. Ever. We share it only with:

  • Sub-processors we depend on to run the Service: Stripe (payments + KYC + tax forms), Google (authentication, Firebase Cloud Messaging), Resend (transactional email), MongoDB Atlas (database hosting), Emergent (application hosting), PostHog (product analytics), Cloudflare (edge caching + DDoS)
  • Other users of the Service, but only what you've explicitly published — your public profile, bio-link page, stories, roster info
  • Your linked coach, agent, school, or program, if you've joined their roster (they see your name, sport, stats, and messages you send them)
  • Law enforcement or regulators when required by a valid subpoena, court order, or when we in good faith believe someone is at risk of serious harm
  • A successor entity in the event Flythouse is merged, acquired, or reorganized — we'll notify you before your data moves and give you a chance to delete your account first

All sub-processors are bound by data-protection agreements requiring them to protect your data at least as strictly as we do.

6. Cookies & Tracking

We use a small set of cookies + browser storage:

  • Session cookie (dl_session) — httpOnly JWT that keeps you signed in. Essential.
  • LocalStorage / IndexedDB — caches your recent stories + roster tiles so the app loads instantly on repeat visits. Essential.
  • PostHog analytics cookie — anonymous product-usage measurement. You can opt out from your account settings.
  • Stripe cookies — set during checkout for fraud prevention. Governed by Stripe's privacy policy.

We don't use ad-tech tracking, cross-site tracking pixels, or advertising cookies of any kind.

7. Push Notifications

If you allow push notifications on your device, we'll send you transactional pings (new messages, brand-deal offers, payout confirmations, trial-ending reminders). We use Apple Push Notification service on iOS, Firebase Cloud Messaging on Android, and Web Push (VAPID) in the browser. You can turn push off any time in your device or browser settings; the app keeps working normally without it.

8. Children & Parent-Managed Accounts

Flythouse is not directed at children under 13. If you're under 13, please don't create an account. If we learn we've collected personal data from a child under 13 without verified parental consent, we'll delete it promptly.

Athletes ages 13–17 may use Flythouse with a parent or legal guardian's consent. Parents can request access to, correct, or delete their child's data by emailing privacy@flythouse.com.

9. Your Rights

No matter where you live, you can:

  • Access the personal data we hold about you
  • Correct anything that's inaccurate
  • Export your data in a machine-readable format
  • Delete your account — use the setting in-app or email us and we'll process it within 30 days
  • Opt out of marketing emails (every marketing email has a one-click unsubscribe)

California residents (CCPA/CPRA): You have the right to know what personal information we collect, request deletion, and opt out of any “sale” or “sharing” of your personal information — though we don't sell or share it for cross-context behavioral advertising. Email privacy@flythouse.com with “CCPA Request” in the subject.

EU/UK residents (GDPR): In addition to the rights above, you may object to processing, request restriction of processing, and lodge a complaint with your local data-protection authority.

10. Data Retention

We keep your account data as long as your account is active. When you delete your account we remove your profile, bio, uploaded media, and messages within 30 days — except for a narrow set of data we're legally required to keep longer: financial records (Stripe holds transaction data for 7 years for tax + anti-fraud rules) and audit logs (we hold sign-in logs for 90 days for security).

Content that other users have interacted with (e.g. messages sent to your agent) may remain in those users' message history after your deletion, but with your name replaced by “Deleted user.”

11. International Data Transfers

Flythouse operates from the United States. If you're accessing the Service from outside the US, your information will be transferred to and processed in the US. Where required, we use Standard Contractual Clauses (SCCs) with our sub-processors for EU/UK data transfers.

12. Security

We protect your data with TLS in transit, encryption at rest for sensitive fields, bcrypt-hashed passwords, short-lived session tokens, and least-privilege access for our own team. Stripe (payments) and Google (auth) each meet SOC 2 Type II standards.

No system is 100% impenetrable. If we ever suffer a breach that affects your personal data, we'll notify you and applicable regulators within the timelines required by law (72 hours under GDPR).

13. Changes to This Policy

We'll update this Policy when we materially change how we handle personal data. When we do, we'll post the new version here and update the “Last updated” date at the top. For significant changes we'll also email account holders.

14. Contact Us

Questions, deletion requests, or a formal privacy complaint? Reach us at privacy@flythouse.com.

See also our Terms of Service.

FLYT Studios LLC · Austin, Texas · USA