@team

Privacy Policy

Last updated: July 21, 2026

1. Who we are

@team is a tool for sports teams and athletic organizations. It helps staff manage their roster, schedule events, message each other, track equipment, and create and publish posts to their own social media accounts on Facebook, Instagram, and X.

@team (the app at atteam.app) is operated by Tanner Monacoas an individual. In this policy, “we,” “us,” and “@team” all mean the same thing.

This policy explains what information we collect, why we collect it, who we share it with, and the choices you have, including how to delete your data or disconnect a social account.

2. Who this policy covers

Two kinds of people show up in @team, and it helps to keep them separate:

  • Account holders. Coaches, admins, and staff who create an account and sign in. They enter their own details and use the app directly.
  • People on a roster. Athletes and team members whose information is added by an account holder (usually a coach or admin). Many of these people are students, and some are minors. They do not sign in themselves; their information is entered on their behalf by the staff who run their team.

If you are on a roster and want to know what is stored about you or want it removed, contact your team’s coach or admin, or reach us at the address in the Contact section and we will help.

3. Information we collect

We collect the following, and nothing beyond what the app needs to work.

Account and sign-in information

  • Your name and email address.
  • Your password, which we store only as a scrambled “hash” (a one-way scramble). We never store or see your actual password.
  • If you turn on any of these ways to sign in: two-step codes (we store the secret in encrypted form), passkeys (we store the device’s public key, not any fingerprint or face data), and sign-in with Google or Microsoft (we store which provider you used and the account’s ID and email so we can recognize you next time; we do not keep any Google or Microsoft password or access token).
  • Your role, which organization and teams you belong to, and optional profile details you choose to add, such as a photo, a short bio, and your time zone.

Roster and team information

When staff build a roster, they may add details about athletes and team members, such as name, jersey number, position, class year, hometown, pronouns, birthday, height, injury or active status, tags, a photo, private notes, and social media handles. This is the core of what the app is for, so it is entered and controlled by the team’s staff.

Content you create

  • Posts you build: captions, hashtags, alt text (descriptions of images for accessibility), and the photos and videos you attach.
  • Messages you send in the app’s chat, including reactions and mentions. Edited and deleted messages keep a hidden history so the conversation stays consistent for everyone.
  • Events you schedule, equipment records, and notifications the app sends you.

Connected social accounts

When you connect a Facebook Page, Instagram Business account, or X account, we store an encrypted access token (a key that lets us post on your behalf), the account or Page ID, the username, the permissions you granted, and a snapshot of the account’s basic public profile. After we publish, we store the ID and link of each post we created. See the Facebook, Instagram, and X section for the details.

Technical information

  • A sign-in cookie so you stay logged in (see Cookies).
  • If you turn on push notifications, the subscription details your browser gives us so we can deliver them.
  • Basic, privacy-friendly traffic analytics from our hosting provider (Vercel) that count page views and performance. This does not use advertising cookies and does not track you across other websites.
  • For security, when a super-admin uses the “view as” support feature, we log who did it, when, and the IP address and browser used, so the action can be audited.

4. How we use your information

  • To run the app: sign you in, show your roster, schedule, chat, and equipment, and keep your organization’s data separate from every other organization’s.
  • To publish the posts you create to the social accounts you connect.
  • To send account emails, such as sign-up verification, invitations, and password resets.
  • To send notifications you have asked for.
  • To keep the app secure, prevent abuse, and fix problems.

We do not use your information for advertising, and we do not sell it.

5. AI features

@team has optional AI features that help write and check posts. To generate a description of a photo (alt text) and suggest captions, we send the relevant photo and some context (such as the roster names, sport, and team name) to our AI provider, Anthropic. Private admin-only notes on an athlete are never sent to the AI. Anthropic processes this to return the result and does not use it to train its models. If the AI feature is turned off, nothing is sent to Anthropic.

6. Facebook, Instagram, and X

You can connect your own social accounts so @team can publish for you. This is always your own account, connected by you.

  • What we ask permission for.For Facebook and Instagram, we request permission to see the list of Pages you manage, read your Pages’ basic info and engagement, publish posts to your Pages, and publish and manage comments on your Instagram Business account. For X, we request permission to read and post tweets on your behalf. We only ever access your own accounts and the content you create in @team.
  • What we send to them.When you publish, we send the post’s caption, the photos or videos, the alt text, and any tags you added, to the platform you chose.
  • What we store from them.An encrypted access token, the account or Page ID and username, the permissions you granted, a snapshot of the account’s basic profile, and, after publishing, the ID and link of the post we created. Access tokens are always stored encrypted.
  • You are in control.You can disconnect any social account at any time from the app’s social settings. When you disconnect, we delete the stored token for that account. You can also remove @team’s access from within Facebook, Instagram, or X directly. See Deleting your data.

Your use of Facebook, Instagram, and X is also governed by those companies’ own privacy policies.

7. Who we share information with

We do not sell your information. We share it only with the service providers that make the app run, and only as needed for them to do their job for us:

  • Meta (Facebook and Instagram) and X — to publish the posts you create to the accounts you connect, and to read your own connected accounts.
  • Vercel — hosting and basic traffic analytics.
  • Neon — the database that stores your data.
  • Cloudflare R2 — temporary, private storage for photos and videos while a post is being prepared and published.
  • Anthropic — the AI features described above, when you use them.
  • Resend — sending account emails such as verification, invitations, and password resets.
  • Railway — the server that powers live chat.
  • Your browser’s push service (for example Apple, Google, or Mozilla) — to deliver push notifications, if you turn them on.

We may also share information if the law requires it, or to protect the safety and rights of our users and the app.

8. Photos and videos

When you add a photo or video to a post, it is uploaded to private cloud storage (Cloudflare R2) so the post can be published. This storage is not public. Files there can only be reached through a temporary signed link that expires. For Instagram, we hand Meta a temporary link so its servers can fetch the image to publish it.

We do not keep your photos and videos long-term. Temporary working files are deleted automatically within about a day, and media for scheduled posts is cleared within about 35 days. Once a post is published, the live copy lives on the social platform, not on us. If you delete a published post on the platform, that copy is gone.

9. Cookies

We use a small number of cookies, and none of them are for advertising:

  • A sign-in cookie that keeps you logged in. It lasts up to 30 days and is protected so it cannot be read by scripts.
  • A small cookie that remembers which sign-in method you used last, so we can show a “last used” hint.
  • Short-lived security cookies used only during the sign-in handshake for social login and passkeys. These expire within minutes.

We do not use advertising or cross-site tracking cookies.

10. How long we keep your data

We keep your account and your organization’s data for as long as the account is active, so the app works day to day. Some items have shorter lives on purpose: sign-up and password-reset links expire (typically within 24 hours), the temporary photo and video files described above are deleted on the schedules listed there, and in-app notifications are deleted after six months.

When someone leaves an organization.If an admin removes you from their organization, your access ends immediately: you can no longer sign in, and your saved password, passkeys, and two-step setup are deleted right away. Your name and the record of what you did there stay with that organization. That means things like the messages you sent in a team chat, the equipment you checked out, and the events you were assigned to. We keep these because they are the organization’s working records, not only yours: removing one person should not erase a shared conversation or the log of who last had a piece of equipment. An admin can restore your account later, and everything comes back.

If you would rather your personal details were removed as well, you can ask, and an organization owner (or we) can erase them. Your name, email address, photo, and bio are cleared permanently, and the organization’s records stay without your name attached. Section 11 explains how to ask, and how to get a copy of your data first if you want one.

11. Deleting your data

You have a few ways to remove your information:

  • Disconnect a social account.Go to the app’s social settings and disconnect any Facebook, Instagram, or X account. We delete the stored access token for that account right away. You can also remove @team’s access from inside Facebook, Instagram, or X:
    • Facebook: Settings → Business Integrations, then remove @team.
    • Instagram: Settings → Apps and Websites, then remove @team.
    • X: Settings → Connected apps, then revoke @team.
  • Delete your account and data. Email us at privacy@atteam.app from the address on your account and ask us to delete it. We will delete your account and the personal data tied to it, except anything we must keep by law. We will confirm when it is done.
  • If you are on a rosterand want your information removed, ask your team’s coach or admin, or email us and we will help coordinate the removal.
  • Get a copy of your data first.Before you ask us to erase anything, you can ask your organization’s owner for a copy of what they hold about you, or email us at privacy@atteam.app. Owners can download it from the app as a file, and it covers your profile, teams, event history, equipment history, and the messages you sent. Parents and guardians can make this request on behalf of a student.

12. How we protect your information

  • Passwords are stored as one-way hashes, never in plain text.
  • Social access tokens and two-step secrets are encrypted before they are stored.
  • Traffic to the app is protected in transit with HTTPS.
  • Each organization’s data is kept separate, and access is limited by role.

No system is perfectly secure, but we work to protect your information and to fix problems quickly.

13. Children and student data

@team is a tool for adults who run teams (coaches, admins, and staff). It is not meant to be used directly by children, and people under 13 should not create an account.

Because @team manages sports rosters, staff may enter information about athletes who are minors, such as a name, photo, and team details. That information is entered and controlled by the team’s staff, who are responsible for having the right to share it. If you are a parent or guardian and want a minor’s information reviewed or removed, contact the team’s staff or email us at privacy@atteam.app and we will help.

14. Your choices and rights

You can view and update your profile in the app, choose which notifications you receive, connect and disconnect social accounts, and ask us to delete your account. Depending on where you live, you may have additional rights to access, correct, or delete your personal data. To make any of these requests, email us at privacy@atteam.app.

15. Where your data is stored

Our service providers may store and process data in the United States and other countries. By using @team, you understand that your information may be handled in these locations.

16. Changes to this policy

If we change how we handle your information, we will update this page and change the “last updated” date at the top. Significant changes may also be announced in the app.

17. Contact

Questions about this policy or your data? Email us at privacy@atteam.app.