Privacy Policy
Last updated August 2026
Overview
GuardNIL is a professional development partner for athletic programs, covering career readiness, financial literacy, and mental performance for student-athletes. This policy explains what we collect through guardnil.com, what we handle when an institution engages us, how long we keep it, and who it is shared with.
Which GuardNIL service this covers
This policy covers guardnil.com and the professional development services we deliver to institutions. GuardNIL University (guardnilu.com) is a separate consumer service for families, with its own privacy policy, its own parental consent flow, and its own data. Nothing collected under this policy is combined with GuardNIL University data. For any institutional engagement, the written agreement between GuardNIL and the institution names which party controls which records, and that agreement governs where it is more specific than this page.
Information we collect through this website
We collect what you type into a form: your name, email address, organization, role, and the contents of your message. We also receive standard server request logs from our hosting provider. This site runs no analytics product, no advertising trackers, and no third-party marketing pixels, so there is nothing here that follows you to another site.
Information we handle under an institutional agreement
When an athletic program engages GuardNIL, we may handle athlete contact details, roster and eligibility status, program enrollment and attendance, session notes, and completion records for the modules an athlete works through. The specific categories are set out in the written agreement rather than chosen by us. We use that information only to deliver the program the institution has asked for. We do not sell it, we do not use it for advertising, and we do not use it to train machine learning models.
Student education records and FERPA
Where an institution shares student education records with us, we act as a school official with a legitimate educational interest under FERPA, 34 CFR 99.31(a)(1). That means we work under the direct control of the institution with respect to those records, we use them only for the purpose the institution designated, we do not re-disclose them to anyone else without the institution's written authorization or the student's consent, and we return or destroy them when the engagement ends or when the institution asks. An institution that needs these commitments restated in contract language should ask; we will put them in the agreement.
How we use information
To respond to your inquiry, to deliver and improve the programs an institution has engaged us for, to meet our legal and contractual obligations, and to communicate with you about GuardNIL. We do not sell personal information and we do not share it for cross-context behavioral advertising.
Who we share information with
We use a small number of service providers to run this site and reach you: Vercel hosts the website, and Resend delivers the email generated when you submit the contact form. Each is bound to use the information only to provide that service to us. Beyond those, we share information only where an institutional agreement directs us to, or where the law requires it.
How long we keep information
- Website inquiries and contact form submissions: 24 months from our last exchange with you, then deleted.
- Server request logs: retained by our hosting provider on its standard schedule and not separately archived by us.
- Information handled under an institutional agreement: for the term of that agreement, then returned or destroyed within 30 days of the institution's written request or of termination, whichever comes first.
- Records we are required to keep by law or to resolve a dispute: for as long as that requirement lasts, and no longer.
How we protect information
Traffic to this site is encrypted in transit. Information is stored with providers that encrypt it at rest, and access is limited to the people who need it to do the work. GuardNIL has not yet completed an independent security audit or certification; we would rather say so here than let a prospective partner assume otherwise. An institution evaluating us should ask for our current security documentation, and we will send what we have.
Reporting a security issue
If you believe you have found a vulnerability in this site or in a GuardNIL service, please tell us at contact@guardnil.com. Our disclosure contact is also published at /.well-known/security.txt. We will acknowledge a report and tell you what we find.
Children
This website is intended for athletic program staff, student-athletes of college age, and their families. It is not directed to children under 13 and we do not knowingly collect information from a child through it. GuardNIL University is the service built for families with younger athletes, and it handles children's information under its own policy and its own verifiable parental consent process.
Your choices
You can ask us what we hold about you, ask us to correct it, or ask us to delete it, and we will do so unless a law or an institutional agreement requires us to keep it. If you are a student-athlete whose information reached us through your institution, the fastest route is usually your institution, because those records stay under its control. Email us either way and we will help.
Changes to this policy
When this policy changes materially we update the date at the top of this page. An institution under a written agreement is notified directly rather than being expected to notice a website change.
Contact
For any privacy question or to request that we update or delete your information, email us at contact@guardnil.com.