Where we actually are
AthleteFlow is founder-led and early. As of 7 September 2026 it runs one school and one team: 19 athletes who have logged 2,847 sets across 157 training sessions since 6 July 2026. That is a real team of real athletes using it every week — and it is also the entire body of evidence.
There are no other customers, no pilot logos, and no case studies. A second organisation has never existed, which means every assumption about running more than one is untested by use rather than proven by it. We would rather you knew that from us.
What we hold, and where
Names and email addresses, training data (sessions, sets and weights, tests, conditioning), optional daily wellness check-ins, an optional college target level, and team membership. The full list is in the privacy notice.
It lives in the United States — Amazon Web Services in Northern Virginia — with Supabase. Five other companies touch it, each for one job: Netlify serves the app, Resend sends sign-in and invitation email, Apple delivers push notifications if an athlete turns them on, Google sees a device's network address when an exercise video loads, and Sentry receives crash reports. All six are named on the privacy notice with what each receives.
No analytics or behavioural tracking runs anywhere, on any surface. That is enforced by the site's content-security policy rather than by intention: the browser is not permitted to load a script from anywhere but us.
Who can see it
Access is enforced by the database, not by the interface — every table has row-level security, and the test suite signs in as a real athlete, a real coach and a real parent and asserts what each can and cannot read. A parent linked to one athlete reads that athlete and returns zero rows for every other.
Teammates see a leaderboard with a first name, last initial and best results — never a full training history. Profile photos are visible only to their owner.
Getting a copy out, and deleting a person
Coaches can export a team's training data and roster as CSV from inside the app. There is no athlete-facing or parent-facing export button: a request for a copy is answered by a person, at hello@athlete-flow.com. You never need a coach's permission to make one.
Deletion is real and shows its work before it runs. It removes what is about the person — their sessions, sets, maxes, test results and check-ins — and disowns rather than destroys what they merely authored, so a departing coach does not take a team's programming with them. One case is refused on purpose and says so: an athlete still holding a multi-block season plan must have it cancelled or reassigned first, because cascading there would delete a coach's whole season.
How long we keep it
Indefinitely. There is no automatic deletion and no retention schedule — six scheduled jobs run and not one of them deletes a row. Data goes when someone asks for it to go.
That is a decision nobody has made yet rather than one that was made, and it is on the list for legal review. We would rather say so than describe a policy we do not operate.
Accessibility, as measured
Every release is scanned with axe-core against the WCAG 2.1 A and AA rule set — every page a signed-out visitor can reach, plus the main athlete and coach screens, at a 375-pixel wide screen, the narrowest size the design targets. Serious and critical findings block the release; as of 7 September 2026 there are none. A page added to the site without being added to that scan fails the build, so the list cannot quietly fall behind.
A separate check tabs through every interactive control on three screens and requires each to take focus and visibly show it, since a focus ring is painted rather than declared and no scanner can see one. Primary controls are held to a 44-pixel touch target, and the athlete-facing screens are exercised on WebKit as well as Chrome, because the athletes using this are on iPhones.
This is a measurement, not a conformance claim. No third party has audited it, and no VPAT exists. If a specific need is not met, write to us and say which — that is a more useful answer than a badge.
When something breaks
Anyone signed in can report a problem from Help, and the report carries the diagnostics that make it fixable: build, screen, role, device, and how much unsynced work is waiting. Severity levels, escalation and recovery steps are written down and rehearsed rather than improvised.
Sessions logged without signal are kept on the device and sync when it returns, so a dead gym Wi-Fi loses nothing. The database is backed up weekly. Errors go to Sentry; behaviour does not.
What we have not done yet
The privacy notice and terms are careful drafts that describe exactly what the app does — but no lawyer has reviewed them, and the question of who is the data controller in a school setting is open. Both are prepared for review, not finished.
We have not committed to a response time, because committing to one we cannot consistently meet is worse than not having one. One person currently holds every operational credential; naming a second is on the list and should matter to you. There is no billing, no invoice has ever been raised, and the terms are silent on payment, renewal and cancellation.
None of that stops a team using the product. It does mean that if you are a district running a procurement process, the honest answer today is that we are not through it yet.