Privacy Policy
Last updated: September 6, 2026
ScoutGlimpse is a self-serve tool for sports-sponsorship agencies and brands to check an athlete's real public audience numbers before signing a deal. This page covers two different things, because they're genuinely different: the account data you give us when you sign up, and the public athlete data our product looks up on your behalf. We only collect what the product needs to function — nothing more.
Account data (what we collect from you)
- Signup details. Email address, a password (stored as a salted PBKDF2 hash — we never store or can see your plaintext password), and an optional company name.
- Watchlist configuration. Which athletes you've added to your watchlist, and your subscription tier, so the product can show your data and enforce your plan's limits.
- Password reset tokens. A short-lived, single-use token if you request a password reset, sent to your account email. It expires after one hour whether or not it's used.
Athlete data (what the product looks up)
This is the core of the product, and the part most worth being precise about: the athletes you research through ScoutGlimpse are not our customers and have no account with us. We don't collect anything from them directly, and we never ask them to connect an account or grant us access. Everything we show about an athlete comes from data that's already public, pulled from these sources:
- YouTube. Public channel metadata and statistics — display name, thumbnail, subscriber count, lifetime view count — via the official YouTube Data API. We only request public read access; we never authenticate as the athlete or access anything requiring their login.
- ESPN and NCAA statistics. Publicly published season and career performance stats and national leaderboard rankings, matched to a watchlisted athlete by name.
- Sports news. Headlines from public sports-news RSS feeds, matched to a watchlisted athlete by name, so you're not the last to know about a brewing story.
What we don't do: we don't collect data from Instagram or TikTok, don't scrape private or login-gated pages, and don't request access to any athlete's own account, inbox, or private information. Name-based matching (for news and stats) can occasionally match the wrong person with a common name — we flag this as a known limitation rather than presenting every match as certain, and you should treat any single data point as a lead to verify, not a final answer.
We retain a rolling history of an athlete's public subscriber/view counts (snapshots) only for athletes actively on a customer's watchlist, so we can show real growth trends instead of a single point-in-time number. We don't build athlete profiles independent of customer watchlists, and we don't sell or license this data to anyone outside of showing it to the customer who watchlisted that athlete.
Billing
Subscription payments are processed by Stripe. We never see or store your full card number — Stripe handles that directly, under its own privacy policy. We store only your subscription status and tier.
Where data lives
Data is stored on Cloudflare's infrastructure (D1 database) and processed by our backend (Cloudflare Workers). Password-reset emails are sent via Cloudflare's own email-sending infrastructure. We do not operate our own physical servers.
How we protect data
- Encryption in transit. All traffic between the app, our backend, and any third-party source (YouTube, ESPN, Stripe) is encrypted via TLS/HTTPS.
- Password hashing. Account passwords are hashed with salted PBKDF2 before storage — never stored or logged in plaintext.
- Access control. There's no general-purpose admin panel with standing access to account data; access is limited to what the backend service needs at request time.
- Infrastructure security. Our backend runs on Cloudflare Workers and D1, covered by Cloudflare's own security program (including SOC 2 Type II and ISO 27001 certifications) — see Cloudflare's compliance resources.
Data sharing and disclosure
We do not sell, rent, or trade account data or athlete data to advertisers, data brokers, or any other third party for their own purposes. We disclose data only in these limited cases:
- Service providers acting on our behalf. Cloudflare (hosting, storage, email) and Stripe (payments), each processing data solely to operate ScoutGlimpse, under their own confidentiality terms.
- Legal requirements. If required by law, subpoena, or valid legal process, or to protect the rights, property, or safety of ScoutGlimpse, our users, or the public.
- Business transfer. If ScoutGlimpse is acquired or merges with another company, data may transfer as part of that transaction, subject to this policy.
If you're an athlete whose public data appears in ScoutGlimpse
If you're an athlete (or represent one) and believe your public data is being shown inaccurately, or you'd like to understand what a specific customer's watchlist entry contains, contact us at the email below. We can't control what's publicly published on YouTube, ESPN, or NCAA sites — that data lives with its original source, and correcting it there is the most effective fix — but we will review and, where reasonable, correct a name-matching error on our side, or remove an entry from active tracking on request.
Your controls
- Remove any athlete from your watchlist at any time from the dashboard.
- Request full account deletion by contacting us at the email below — we'll remove your account, watchlist, and associated snapshot history within 30 days.
- Reset your password at any time from the login screen if you suspect it's been compromised.
Children's privacy
ScoutGlimpse is a B2B tool built for sponsorship agencies and brands, not for personal or consumer use, and is not directed at children. We do not knowingly collect account data from anyone under 18.
Changes to this policy
If this policy changes materially, we'll update the "Last updated" date above and, for significant changes, notify active account holders by email.
Contact
Questions about this policy or your data: [email protected]
See also our Terms of Service.