Privacy Policy
Effective Date: July 18, 2026
Prodemy is a product of TECZENS INC
1. Introduction
TECZENS INC, doing business as Prodemy (“Prodemy,” “we,” “us,” or “our”), is committed to protecting your privacy and the privacy of your children. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information through our website (prodemy.app), mobile applications (iOS and Android), and related services (collectively, the “Platform”).
By creating an account or using the Platform, you acknowledge that you have read, understood, and agree to the practices described in this Privacy Policy. If you are a Parent or Guardian creating an account for a minor, you consent to the collection and processing of your child’s information as described herein.
This Privacy Policy should be read together with our Terms of Service and Data Deletion Policy.
2. Children’s Privacy
Prodemy takes children’s privacy seriously. We comply with the Children’s Online Privacy Protection Act (“COPPA”), as amended through April 2026, and applicable state laws governing children’s data.
2.1 Data Collection from Children Under 13
We do not knowingly collect personal information directly from children under 13. All information about children under 13 must be provided by a verified parent or legal guardian through the parent’s own account.
2.2 What We Collect About Children
When a Parent creates a child profile, we collect the following information about the child:
- Identity: First name or nickname, birth month and year (used for age-appropriate content and age group placement)
- Activity data: Class enrollments, attendance records, drill completion and skill progress, event registrations
- Media (with consent): Training videos uploaded for coach review, verification photos for drill completion
- Performance data: Mastery scores, streak counts, skill level assignments
2.3 Parental Consent
We obtain verifiable parental consent before collecting any personal information from children under 13. Consent is obtained through the parent’s authenticated account during the child profile creation process.
Separate consent for third-party disclosure: In accordance with updated COPPA requirements (effective April 22, 2026), we obtain separate parental consent before disclosing children’s personal information to third-party service providers for purposes beyond the internal operations of the Platform. Internal operations include maintaining and analyzing the functioning of the Platform, fulfilling transactions, and protecting security. Disclosure to third parties integral to the service (such as Stripe for processing a payment that the parent initiates) does not require separate consent beyond the initial parental consent.
2.4 Parental Rights
Parents and guardians have the right to:
- Review their child’s personal information by accessing the child’s profile in their account
- Request deletion of their child’s personal information by contacting us at hello@prodemy.app or using the data deletion process at prodemy.app/deletion
- Refuse further collection of their child’s data by contacting us at hello@prodemy.app
- Revoke consent for media sharing or AI data processing through account settings (note: revoking consent may limit certain features)
2.5 Data Retention for Children’s Data
We retain children’s personal information only for as long as reasonably necessary to fulfill the purpose for which it was collected or as required by law. See Section 10 for our complete data retention schedule.
3. Information We Collect
We collect different categories of information depending on your role on the Platform (Club Owner, Coach, Parent, or Student) and how you interact with our services.
3.1 Account and Profile Information
| Data Category | Who Provides It | Examples |
|---|---|---|
| Identity | All users | Full name, email address, date of birth, profile photo |
| Contact | All users | Phone number, mailing address (if provided) |
| Authentication | All users | Password (hashed), Google OAuth tokens, email verification status, phone verification status |
| Role | All users | Platform role (Club Owner, Coach, Parent, Student), role selection at registration |
3.2 Business Information (Club Owners)
| Data Category | Examples |
|---|---|
| Organization | Club name, club description, address, activity types offered |
| Tax and Legal | Tax ID / EIN (optional), business type |
| Financial | Stripe Connect account data (business legal name, business address, bank routing and account numbers, SSN or EIN for identity verification — collected by Stripe), payout history, platform fee agreement |
| Delegate Access | Names and email addresses of authorized delegates (Managers, Front Desk) |
3.3 Coaching Information (Coaches)
| Data Category | Examples |
|---|---|
| Professional | Coaching qualifications, certifications, specializations, biography, service area |
| Club Affiliations | Club memberships, class assignments, schedule availability |
| Financial | Stripe Connect account data (for independent coaches), session rates, package pricing |
| Performance | Coach reviews and ratings (posted by parents and students) |
3.4 Parent and Family Information
| Data Category | Examples |
|---|---|
| Children | Child profiles (name, birth month/year, activity selections, skill levels) |
| Consents | Media consent status, AI data processing consent status, consent timestamps |
| Family Links | Parent-child relationships, parent-student linking requests |
3.5 Payment and Financial Information
| Data Category | Examples |
|---|---|
| Payment methods | Last four digits and brand of saved cards, bank account type (checking/savings), billing address — full payment credentials are held by Stripe, not by Prodemy |
| Transaction history | Payment amounts, dates, descriptions, status (pending, paid, refunded, failed), payment type (class enrollment, tournament, coaching session, etc.) |
| Billing | Auto-pay preferences, billing cycle, coupon usage, late fees, access lock/unlock history |
| Offline payments | Offline payment records (Zelle, cash, check, bank transfer reference numbers) as recorded by Club Owners |
3.6 Activity and Usage Data
| Data Category | Examples |
|---|---|
| Classes and Events | Class enrollments, schedule information, attendance records, tournament registrations, lane bookings, workshop registrations |
| Drill and Progress | Drill assignments, completion status, verification photos/videos, mastery scores, streaks, skill levels, weekly focus selections |
| Video | Training videos uploaded for coach review (title, skill category, coach assignments, privacy settings, file metadata) |
| Engagement | Feature interactions, pages visited, time spent, click patterns, session duration |
| AI Chatbot | Queries submitted to the support chatbot and AI-generated responses |
3.7 Device and Technical Information
| Data Category | Examples |
|---|---|
| Device | Device type, operating system, browser type and version, app version, screen resolution |
| Network | IP address, general location derived from IP (city/region level — not precise GPS) |
| Identifiers | Device identifiers for secure session management, session tokens |
| Diagnostics | Error reports, crash logs, performance metrics (collected by Sentry) |
3.8 Communications Data
| Data Category | Examples |
|---|---|
| Messages | Broadcast messages sent within clubs, notification content, contact form submissions |
| Support | Support ticket content (via Zoho Desk), email correspondence |
| SMS | SMS delivery status, opt-in/opt-out status |
4. How We Collect Information
4.1 Directly from You
We collect information that you provide directly, including during account registration, profile setup, onboarding, form submissions, content uploads, and communications with us.
4.2 Automatically
We collect certain information automatically when you use the Platform, including device information, usage data, IP addresses, and diagnostic data. We use the following technologies:
- Session cookies and tokens: Essential for authentication, maintaining your login session, and security. These are strictly necessary for the Platform to function and cannot be disabled.
- Local storage: Used to store your notification preferences, theme settings, and session data on your device.
- Server logs: Our hosting provider (Vercel) records standard server access logs including IP addresses, request timestamps, and request paths.
4.3 From Third-Party Services
We may receive information from third-party services you connect to your account:
- Google OAuth: If you sign in with Google, we receive your name, email address, and profile photo from Google.
- Stripe: We receive payment confirmation, transaction status, and Connected Account status information from Stripe.
- Twilio: We receive SMS delivery status reports from Twilio.
4.4 What We Do NOT Collect
- We do not collect precise GPS location data
- We do not collect biometric data (fingerprints, facial recognition, voiceprints)
- We do not use tracking pixels or third-party advertising cookies
- We do not collect information from social media profiles beyond Google OAuth
- We do not purchase data about you from data brokers
5. How We Use Your Information
We use the information we collect for the following purposes:
5.1 Providing the Platform
- Creating and managing your account
- Processing payments and facilitating marketplace transactions
- Managing class enrollments, schedules, and attendance
- Tracking drill progress, mastery, and skill development
- Facilitating video review between students and coaches
- Delivering notifications (email, SMS, push, in-app)
- Providing AI-powered support through the chatbot
- Enabling communication between platform roles (club broadcasts, coach feedback)
5.2 Platform Operations
- Maintaining, securing, and improving the Platform
- Monitoring for errors, performance issues, and security threats
- Analyzing usage patterns to improve features and user experience
- Enforcing our Terms of Service and preventing misuse
- Responding to support requests and contact form submissions
5.3 Communications
- Sending transactional emails (payment confirmations, enrollment confirmations, welcome messages)
- Sending transactional SMS alerts (payment failures, membership expiry, waitlist availability)
- Delivering push and in-app notifications based on your preferences
- Responding to your inquiries and support requests
5.4 Legal and Compliance
- Complying with applicable laws, regulations, and legal processes
- Enforcing our agreements and policies
- Protecting the rights, property, and safety of Prodemy, our users, and the public
- Maintaining audit logs for financial and regulatory compliance
6. How We Share Your Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. We share information only as described below:
6.1 Within the Platform (Role-Based Access)
The Platform is a multi-role system. Information is shared between roles as necessary to provide the service:
| Your Role | Who Can See Your Data | What They See |
|---|---|---|
| Student | Your assigned coaches | Name, activity data, drill progress, uploaded videos, attendance, skill level |
| Student | Your club owner(s) | Name, enrollment status, attendance, membership status, payment status |
| Student | Your parent/guardian | Full profile, all activity data, payment history, progress |
| Parent | Club owner(s) | Name, email, phone, children’s enrollment and payment status |
| Parent | Coaches | Name, in connection with their child’s coaching |
| Coach | Club owner(s) | Name, email, schedule, class assignments, session history |
| Coach | Students and parents | Name, profile, qualifications, reviews, availability |
| Club Owner | Platform admin | Club information, financial data, member counts, compliance status |
6.2 Third-Party Service Providers
We share information with third-party service providers who process data on our behalf to provide Platform functionality. We require these providers to use your information only for the purposes we specify and to protect it in accordance with applicable law.
| Provider | Purpose | Data Shared |
|---|---|---|
| Stripe, Inc. | Payment processing, marketplace payments, Connected Account management | Name, email, payment method details, transaction amounts, business information (for Club Owners), bank account details (for Connected Accounts) |
| Twilio, Inc. | SMS message delivery | Phone number, message content (transactional alerts only) |
| Resend | Transactional email delivery | Email address, name, email content |
| Cloudinary | Media file storage and processing | Uploaded videos and images, file metadata |
| Vercel, Inc. | Web application hosting and edge delivery | Server access logs (IP addresses, request data), application data |
| Neon, Inc. | Database hosting (PostgreSQL) | All Platform data (encrypted at rest and in transit) |
| Anthropic | AI chatbot response generation (Claude) | Chatbot query text (no personal account data, no children’s data used for AI model training) |
| Voyage AI | Text embedding for AI-powered search | Help article content and chatbot query text for semantic search |
| OAuth authentication | Authentication tokens, profile data (name, email, photo) | |
| Functional Software, Inc. (Sentry) | Error monitoring and performance tracking | Error reports, device information, anonymized usage context |
| Zoho Corporation | Customer support ticketing, email receiving | Support ticket content, contact form submissions, email correspondence at hello@prodemy.app |
For Stripe’s data practices, please review the Stripe Privacy Policy. For Twilio’s data practices, please review the Twilio Privacy Policy.
6.3 Legal Requirements
We may disclose your information if required to do so by law or in response to valid legal process, including court orders, subpoenas, or government requests. We may also disclose information if we believe in good faith that disclosure is necessary to: (a) comply with applicable law; (b) protect the rights, property, or safety of Prodemy, our users, or the public; (c) detect, prevent, or address fraud, security, or technical issues; or (d) enforce our Terms of Service.
6.4 Business Transfers
If TECZENS INC is involved in a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such transfer and any choices you may have regarding your information.
6.5 Aggregated and De-Identified Data
We may share aggregated or de-identified data that cannot reasonably be used to identify you, for purposes such as analytics, research, and Platform improvement.
7. AI Data Processing
7.1 How AI Is Used
The Platform uses AI technology to power a support chatbot that helps users find answers to questions about Platform features and usage. The AI system works as follows:
Text embeddings: Help articles and knowledge base content are processed through Voyage AI to create searchable text embeddings, which are stored in our database (pgvector). This allows the chatbot to find relevant help content for your question.
Response generation: When you submit a query to the chatbot, your query text (not your personal account data) is sent to Anthropic’s Claude API to generate a contextual response based on the relevant help content retrieved.
7.2 What Data Is Processed by AI
- Sent to AI providers: Your chatbot query text and relevant help article content
- NOT sent to AI providers: Your name, email, payment information, children’s data, activity data, or any other personal account information
7.3 AI Data Retention by Third Parties
Anthropic’s data usage policy governs how query data is handled. We use Anthropic’s API, which does not use API inputs to train models. Voyage AI processes text for embedding generation only and does not retain query data beyond the processing session.
7.4 AI Consent
AI data processing is subject to your consent, obtained during registration. You may view and update your AI data processing consent at any time in your account settings. Withdrawing consent disables the chatbot feature but does not affect other Platform functionality.
8. Cookies and Tracking Technologies
8.1 What We Use
The Platform uses only essential cookies and technologies necessary for its operation:
- Authentication cookies: Maintain your login session across pages
- Session tokens: Secure your authenticated session with encrypted tokens
- CSRF tokens: Protect against cross-site request forgery attacks
- Local storage: Store user preferences (theme, notification settings)
- Cloudflare Turnstile: Used on the public chatbot for bot detection (does not use traditional cookies — uses browser signals to assess whether a visitor is human)
8.2 What We Do NOT Use
- We do not use third-party advertising or tracking cookies
- We do not use analytics cookies that track you across other websites
- We do not use retargeting or remarketing technologies
- We do not participate in advertising networks
- We do not respond to “Do Not Track” browser signals because we do not engage in the type of cross-site tracking that such signals are intended to address
8.3 Managing Cookies
Because we use only essential cookies, there is no cookie preference banner — all cookies we use are strictly necessary for the Platform to function. If you disable cookies in your browser settings, the Platform may not function properly.
9. Data Security
9.1 Security Measures
We implement industry-standard security measures to protect your personal information, including:
- Encryption in transit: All data transmitted between your device and our servers is encrypted using TLS (HTTPS)
- Encryption at rest: Data stored in our database is encrypted at rest
- Password security: Passwords are hashed using industry-standard algorithms and are never stored in plain text
- Payment security: We are PCI DSS compliant through Stripe’s hosted payment elements (SAQ A). Full payment credentials are held by Stripe and never touch our servers
- Access controls: Role-based access controls limit data access to authorized users and personnel
- Authentication: Email verification, secure session management, and optional OAuth authentication
- Monitoring: Error monitoring (Sentry) and structured logging for security event detection
9.2 No Guarantee
While we use commercially reasonable efforts to protect your information, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee the absolute security of your information.
10. Data Retention
We retain personal information for the periods described below, or for as long as reasonably necessary to fulfill the purpose for which it was collected, comply with legal obligations, resolve disputes, and enforce our agreements.
10.1 Retention Schedule
| Data Category | Retention Period | Basis |
|---|---|---|
| Account profile data | Until account deletion is requested, plus 30 days (soft-delete period) | Service performance, account recovery |
| Payment and transaction records | Seven (7) years from the date of the transaction | Financial record-keeping, tax compliance, dispute resolution |
| Audit logs | Permanent (entries are anonymized after account deletion) | Financial compliance, fraud prevention, regulatory requirements |
| Drill and activity history | Until account deletion (anonymized, not deleted, for aggregate analytics) | Service performance, progress tracking |
| Uploaded videos | Until deletion by user, then 30 days in trash before permanent destruction | User control over content |
| Chatbot conversation data | Ninety (90) days, then automatically purged | Service improvement, abuse prevention |
| Support tickets | Three (3) years after resolution | Service quality, dispute resolution |
| SMS delivery records | Two (2) years | Compliance with telecommunications regulations |
| Server access logs | Thirty (30) days (managed by Vercel) | Security monitoring |
| Error reports and diagnostics | Ninety (90) days (managed by Sentry) | Platform stability |
| Session and authentication tokens | Until logout or expiration (session-based) | Security |
| Children’s data | Same as above categories, subject to parental deletion rights at any time | COPPA compliance |
10.2 Deletion Process
When you request account deletion (via prodemy.app/deletion or hello@prodemy.app):
- Verification: We verify your identity and account ownership
- Cool-off period: Club accounts have a 14-day cool-off; Coach accounts have a 7-day cool-off; other accounts begin processing immediately
- Soft-delete: Your profile is hidden, login is disabled, and your data is no longer accessible through the Platform (within 7 days of a verified request for non-club/coach accounts)
- Hard-delete: Personal information is permanently removed 30 days after soft-delete. Payment records and audit logs are retained as required by law (see retention schedule above) but are disassociated from your identity
- Third-party notification: We notify applicable third-party providers to delete your data from their systems
11. Your Privacy Rights
11.1 Rights for All Users
Regardless of your location, all Platform users have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete personal information
- Deletion: Request deletion of your personal information, subject to legal retention requirements
- Data portability: Request your data in a commonly used, machine-readable format
- Withdraw consent: Withdraw consent for optional data processing (media sharing, AI features) at any time
To exercise these rights, contact us at hello@prodemy.app or use the tools available in your account settings.
11.2 California Residents (CCPA/CPRA)
If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”):
- Right to know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we have shared it.
- Right to delete: You may request that we delete your personal information, subject to certain exceptions.
- Right to correct: You may request that we correct inaccurate personal information.
- Right to opt out of sale or sharing: We do not sell your personal information or share it for cross-context behavioral advertising. No opt-out is necessary.
- Right to limit use of sensitive personal information: We use sensitive personal information (such as payment information and children’s data) only as necessary to provide the Platform. We do not use it for purposes beyond what is necessary.
- Right to non-discrimination: We will not discriminate against you for exercising your privacy rights.
To submit a verifiable consumer request, email hello@prodemy.app with the subject line “CCPA Request.” We will verify your identity before processing the request and will respond within 45 days.
11.3 Virginia, Colorado, Connecticut, and Other State Residents
If you reside in a state with a comprehensive privacy law (including but not limited to Virginia, Colorado, Connecticut, Utah, Indiana, Iowa, Tennessee, Montana, Oregon, Texas, Delaware, New Hampshire, New Jersey, Nebraska, Minnesota, Maryland, Kentucky, and Rhode Island), you may have rights similar to those described above, including the right to access, correct, delete, and obtain a portable copy of your data, and the right to opt out of targeted advertising, sale of personal data, and profiling.
We do not engage in targeted advertising, do not sell personal data, and do not profile users for decisions that produce legal or similarly significant effects.
To exercise your rights, contact us at hello@prodemy.app. If you are unsatisfied with our response, you may have the right to appeal our decision. Instructions for filing an appeal will be provided with our response to your initial request. You may also contact your state’s Attorney General.
12. Phone Numbers and SMS Communications
12.1 How We Use Your Phone Number
If you provide a phone number during registration or in your account settings, we may use it to:
- Deliver time-sensitive transactional SMS alerts (payment failures, account lockouts, membership expiry, waitlist availability, session reminders, attendance notifications)
- Send account security notifications
- We do not use your phone number for marketing or promotional messages
- We do not sell or share your phone number with third parties for their marketing purposes
12.2 SMS Delivery Provider
We use Twilio, Inc. (twilio.com) as our SMS delivery provider. Your phone number is transmitted to Twilio solely for message delivery. Twilio’s privacy practices are governed by the Twilio Privacy Policy.
12.3 Opt-Out
You may opt out of SMS notifications at any time by:
- Replying STOP to any message from us
- Toggling off SMS in your notification preferences at prodemy.app/dashboard/settings
- Emailing us at hello@prodemy.app
Opting out stops SMS delivery but does not delete your phone number from your account or affect other notification channels.
12.4 Data Retention
Your phone number is retained as part of your account profile until you delete your account or remove it from your profile settings. SMS delivery records are retained for two (2) years.
13. Data Breach Notification
13.1 Our Commitment
In the event of a data breach that compromises the security of your personal information, we will:
Investigate the breach promptly and take steps to contain it and mitigate harm
Notify affected individuals within the timeframes required by applicable law (including within 30 calendar days for California residents under SB 446, and as otherwise required by applicable state breach notification laws)
Notify applicable regulatory authorities as required by law
Provide information about what data was affected, what steps we are taking, and what steps you can take to protect yourself
13.2 How We Will Notify You
Breach notifications will be sent via email to the address associated with your account. If email contact is not possible, we may use alternative methods such as posting a notice on the Platform or sending SMS notifications.
14. International Data
14.1 Data Location
The Platform is hosted in the United States. Our database, application servers, and primary service providers process and store data in the United States.
14.2 International Users
If you access the Platform from outside the United States, you understand and consent to the transfer of your information to the United States for processing and storage. We will take reasonable steps to ensure your information is treated securely and in accordance with this Privacy Policy and applicable law.
15. Do Not Track Signals
The Platform does not track users across third-party websites and therefore does not respond to “Do Not Track” (DNT) browser signals. We do not engage in the type of cross-site tracking that DNT signals are intended to address.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will:
Post the revised Privacy Policy on the Platform with an updated “Last Updated” date
Notify you via email or in-app notification at least fifteen (15) days before the changes take effect
Where required by COPPA, obtain new parental consent before materially changing how we collect, use, or disclose children’s personal information
Your continued use of the Platform after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.
17. Contact Us
If you have questions about this Privacy Policy, want to exercise your privacy rights, or have concerns about how we handle your data, please contact us:
TECZENS INC dba Prodemy
838 Walker Road, Suite 21-2 Dover, Delaware 19904
Email: hello@prodemy.app Website: https://prodemy.app
For privacy-specific requests, please email hello@prodemy.app with the subject line “Privacy Request.”
For data deletion requests, visit prodemy.app/deletion or email hello@prodemy.app.
Version 1