Back to Atlea Atlea

Legal — Privacy

Privacy Policy

How Atlea handles the personal data of the people who use it — the players who answer each morning, the staff who read those answers, and the administrators who run a team — across the web app at atlea.ai and the Atlea Check-in app.

Effective: 17 September 2026 Applies to: atlea.ai and the Atlea Check-in app (iOS and Android) Contact: info@atlea.ai
01

Who we are

Atlea ("Atlea", "we", "us") is based in Stockholm, Sweden, and provides a daily readiness platform for sports teams of any sport, level and gender: a web application at atlea.ai used by team staff and administrators, and the Atlea Check-in app used by players to answer a short questionnaire each morning.

This policy explains what personal data we handle, why, who can see it, and what you can do about it. It is written in plain language on purpose. Where it refers to "the Terms", it means the Terms & Conditions that every account agrees to when it is created.

02

Who is responsible for your data

2.1 Your team. Atlea is used by a team — a club, an academy, a national programme or any other sports organisation — which decides who is on its squad, which questions are asked, and which members of its staff may see the answers. For everything a player or a member of staff enters into Atlea on behalf of that team, the team is the data controller under the EU General Data Protection Regulation (GDPR) and Atlea acts as its data processor, on the team's instructions and under the data-processing terms in the Terms.

2.2 Atlea. For the data needed to run the service itself — your login, your email address, the record of your agreement to the Terms, security logs, and communication with our support — Atlea is the data controller.

If you have a question about how your team uses Atlea, ask your team first. If you have a question about Atlea itself, write to info@atlea.ai.

03

What we collect

There is no sign-up form and no public registration. Every account is created by an invitation from a team, so the first thing we hold is what the team told us about you.

Account data
Your name and email address as entered by your team; a password you choose (stored only as a cryptographic hash by our authentication provider, never readable by us); your chosen language; the date and time you agreed to the Terms; and, for staff, the role your team gave you.
Morning check-in answers
Your answers to the questions your team asks — typically how your body feels, hours and quality of sleep, mood, how hard the previous session was, and whether you are ready to play, sick or injured. Teams can add their own questions; those answers are stored the same way.
Body chart and notes
If you point at a body area and rate how much it hurts, that area and rating are stored. Anything you write in the free-text note is stored as you wrote it and shown to your team's staff.
Data entered by staff about you
Training load and distances imported by staff, assessments and outcomes recorded after a conversation with you, rehabilitation records and clinical notes written by medical staff, and messages sent to you through the app.
Derived data
Readiness scores, baselines, workload ratios and flags computed from the data above. These are calculations, not diagnoses — see the Terms, which state that Atlea is not a medical device.
Technical data
A session cookie that keeps you signed in on the web; standard server logs (IP address, time, requested page) kept briefly for security and troubleshooting. Atlea contains no advertising, no analytics trackers and no third-party tracking of any kind, on the web or in the app.
On your phone only
The Check-in app keeps your reminder setting and, if you answer while offline, your unsent answer on the device until it can be delivered. Reminders are scheduled locally on your phone; they do not go through any notification service and nothing about them leaves the device.
04

Why we use it

4.1 To provide the service. Your answers exist so that your team's staff can read how you are each morning, notice when something has changed, and speak to you before training. That is the whole purpose of Atlea and the only purpose your answers are used for.

4.2 Health data. Answers about sleep, soreness, pain, illness and injury are health data, a special category under GDPR. They are processed on the basis of your explicit consent, given when your account agrees to the Terms, and — for the team — on the basis of its legitimate interest in the wellbeing and safe training of its players. You can withdraw consent at any time by asking your team to remove you; see section 8.

4.3 Running the platform. Account, security and log data are processed to keep the service working and secure (our legitimate interest and our contract with your team), and to meet legal obligations.

4.4 What we do not do. We do not sell personal data, we do not use it for advertising, we do not profile you for any purpose other than the readiness calculations shown to your own team, and we do not use your data to train models that are shared with other teams. Any statistics we derive to improve the product are aggregated and anonymised so that no person can be identified.

05

Who can see it

  • Your team's staff — the coaches, medical staff and administrators your team has given access to the squad you are on. They see your answers, your notes, your scores and everything staff have recorded about you. Staff of other squads or other teams cannot see you.
  • You — you can see your own answers in the app and download your own data from the web app.
  • Atlea — a small number of Atlea platform administrators can access data when needed to support a team or to investigate a fault, under confidentiality obligations. We do not browse team data otherwise.
  • Our processors — companies that host and run the service for us, bound by data-processing agreements: Supabase (database, authentication and file storage, hosted in the EU), Vercel (web hosting and server functions, running in the EU), and an email delivery provider used only to send invitation and password emails. App builds and updates are distributed through Apple and Google, who do not receive your team data.
  • Authorities — only where the law requires it.
06

Where it is stored

Your data is stored in the European Union (Ireland), and the servers that process it run there too. If a processor ever needs to handle data outside the EU/EEA, we rely on the European Commission's standard contractual clauses or another safeguard recognised under GDPR, and we will say so here.

07

How long we keep it

  • While you are on a squad — your answers and records are kept so that your team can read your history and compare today against it.
  • When your team removes you — your check-in history, messages and rehabilitation records are deleted with you. Your login remains only if you are still a member of another squad or team.
  • When a team's subscription ends — the team has thirty days to export its data, after which we permanently delete it, as set out in the Terms.
  • Server logs — kept for a short, fixed period for security, then discarded.
  • Backups — deleted data may persist in encrypted backups for a limited time before those backups expire.
08

Your rights

Under GDPR you can ask to access the data held about you, to have it corrected, deleted or restricted, to receive a copy in a portable format, to object to certain processing, and to withdraw consent at any time without affecting what was done before you withdrew it.

Because your team is the controller for your check-in data, the fastest route is to ask your team's administrator — they can correct your details, remove you from a squad, or export your data from the platform directly. You can also download your own data yourself from the web app. For anything concerning Atlea as a controller, or if your team does not respond, write to info@atlea.ai and we will answer within one month.

You also have the right to lodge a complaint with a supervisory authority. In Sweden that is the Swedish Authority for Privacy Protection (Integritetsskyddsmyndigheten, IMY), imy.se. You may instead complain to the authority in the country where you live.

09

Security

All traffic between your device and Atlea is encrypted in transit, and data is encrypted at rest by our hosting provider. Access is by invitation only — there is no public sign-up — and every request to the database is checked against row-level security rules, so an account can only ever read the rows its team has given it a right to. Passwords are never stored in readable form. If we ever become aware of a breach affecting your data, we will inform your team, and where required by law the supervisory authority and you, without undue delay.

10

Young players

Atlea is provided to teams, and it is the team that decides who is invited. Where a player is under the age at which they can consent to this kind of processing themselves (16 under GDPR, or the lower age set by their country — 13 in Sweden), the team must obtain the consent of a parent or guardian before inviting them, and must be able to show it on request. A parent or guardian may exercise the rights in section 8 on the player's behalf.

11

Changes & contact

If we change this policy in a way that matters, we will update the effective date above and tell teams through the platform before the change takes effect. Questions, requests and complaints go to info@atlea.ai, or by post to Atlea, Stockholm, Sweden.