Privacy Policy
Last updated: June 25, 2026
Overview
Commitr is a lacrosse recruiting platform for student-athletes and families. This Privacy Policy explains what information we collect, how we use it, how we protect it, and how Google user data is handled when a user chooses to connect Gmail.
Gmail connection is optional. Commitr can be used for recruiting organization without granting Gmail access, although Gmail sending features require the user to connect Gmail and approve the requested Google permission.
Information We Collect
Commitr may collect the following categories of information:
- Account information: name, email address, authentication identifiers, account settings, and support contact information.
- Recruiting profile information: school year, position, academic information, athletic background, preferences, highlight links, and other recruiting details entered by the user.
- Recruiting workflow information: schools, coaches, outreach selections, message content, tracker status, notes, send status, and related recruiting activity created in Commitr.
- Google OAuth and Gmail Send information: Google account email, granted Gmail Send scope, encrypted connection tokens, token expiration metadata, Gmail message identifiers, email subject/body content reviewed or sent through Commitr, recipients, timestamps, delivery status, and related error information.
- Technical and security information: device/browser metadata, log data, IP-derived security signals, request IDs, idempotency keys, rate-limit data, and audit information needed to operate and protect the service.
How We Use Information
Commitr uses information to:
- provide account access and user-specific recruiting workflows;
- save recruiting profile information and outreach preferences;
- help users organize schools, coaches, drafts, and tracker status;
- send Gmail messages only after the user reviews and confirms them;
- show send history and prevent duplicate or unauthorized sends;
- provide support, troubleshoot issues, and protect against abuse;
- maintain, secure, debug, and improve Commitr's user-facing features.
Google OAuth and Gmail Data
Commitr uses Google OAuth only when a user chooses to connect Gmail. If Gmail is connected, Commitr requests the following permission:
https://www.googleapis.com/auth/gmail.send
Commitr uses this permission only to send recruiting outreach emails or test emails that the user reviews and explicitly chooses to send. Each coach message is sent as an individual email from the user's own Gmail account. Commitr does not send BCC blasts and does not send Gmail messages without a user action.
Commitr does not request permission to read Gmail inboxes, read replies, create Gmail drafts, modify labels, delete messages, access attachments, search mailbox contents, or access the full mailbox.
Users can disconnect Gmail from Commitr at any time from the product interface. Disconnecting Gmail prevents future Gmail sending through Commitr and causes stored Gmail connection tokens to be removed or revoked according to Commitr's token handling process.
Limited Use and AI/ML Model Training
Commitr's use and transfer of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
Commitr uses Google user data only to provide and improve user-facing Gmail sending and recruiting outreach features visible in the Commitr application. Commitr does not sell Google user data, does not use Google user data for advertising or retargeting, and does not transfer Google user data to data brokers or information resellers.
Commitr does not use Google user data obtained through Gmail APIs to train generalized artificial intelligence or machine learning models. Commitr does not allow third-party AI providers to use Google user data from Gmail APIs to train their models.
Data Protection Mechanisms for Sensitive Data
Commitr treats account information, recruiting profile information, OAuth tokens, Gmail Send authorization data, outreach message content, and send history as sensitive data. Commitr uses the following data protection mechanisms to protect sensitive data:
- Encryption in transit: Commitr uses HTTPS/TLS for data transmitted between the browser, Commitr, Google APIs, and service providers.
- Protected token storage: Gmail access and refresh tokens are stored server-side in encrypted or otherwise server-protected form. Refresh tokens are never exposed to the browser.
- Access controls: Commitr uses authenticated server-side routes, user ownership checks, and database access controls to separate user data and restrict access to sensitive records.
- Least-privilege authorization: Commitr requests only the Gmail Send scope needed for the user-facing Gmail sending feature and does not request broader Gmail permissions.
- Secret management: production secrets, OAuth client secrets, encryption keys, and service-role credentials are stored in protected server-side environments and are not exposed in client-side code.
- Operational safeguards: Gmail test sends use server-derived recipients, idempotency controls, and rate limits to reduce duplicate, unauthorized, or accidental sends.
- Logging limits: Commitr avoids logging raw OAuth tokens, refresh tokens, service-role credentials, or full secret values. Security and application logs are used for troubleshooting, fraud prevention, abuse prevention, and service reliability.
- Limited internal access: access to production data is limited to personnel and service providers who need it to operate, secure, support, or troubleshoot Commitr, subject to confidentiality and security obligations.
- Review and deletion controls: users may disconnect Gmail and may request account or data deletion by contacting Commitr at admin@commitr.ai.
No security measure is perfect, but Commitr uses reasonable technical and organizational safeguards designed to protect sensitive data from unauthorized access, disclosure, alteration, or destruction.
Sharing and Service Providers
Commitr does not sell personal information or Google user data. Commitr may share information with service providers that help operate, secure, host, process, or support the service, including hosting, database, authentication, email-delivery, analytics, logging, infrastructure, and customer-support providers.
Commitr may also disclose information when required by law, to protect rights and safety, to investigate abuse or security issues, or with the user's direction as part of recruiting outreach. Any transfer of Google user data is limited to what is necessary to provide or improve user-facing Commitr features, support security, comply with law, or as otherwise permitted by the Google API Services User Data Policy.
Retention and Deletion
Commitr keeps information for as long as reasonably needed to provide the service, maintain security, comply with legal obligations, resolve disputes, and support recruiting activity history. Gmail connection tokens are retained only while the user keeps Gmail connected or as needed for security, compliance, or recovery from a recent disconnect event.
Users can request account or data deletion by contacting admin@commitr.ai. Some records may be retained where required for legal, security, fraud-prevention, backup, or legitimate business purposes.
Children and Family Use
Commitr is intended for lacrosse recruiting use by student-athletes and families. Users under the age of majority should use Commitr with a parent or guardian. Commitr is not intended for children under 13.
Changes to This Policy
Commitr may update this Privacy Policy as the service changes. When we make material changes, we will update the date above and provide notice where appropriate. If Commitr changes how it uses Google user data, it will update this policy and seek consent where required before using Google user data for the new purpose.
Contact
Questions, privacy requests, or deletion requests can be sent to admin@commitr.ai.