Privacy Policy
Effective: May 17, 2026
Who we are
Recruit is a baseball recruiting intelligence platform operated by Kaifecta Inc. ("we", "us"). Contact: team@kaifect.com.
What we collect
- Account data — email, password (hashed by Supabase), name.
- Player profile — graduation year, location, high school, travel ball, GPA/SAT/ACT (optional), physical metrics, position, video links, bio.
- Performance metrics — exit velocity, fastball velocity, 60-yard dash, etc., that you enter yourself or that we import from PG/PBR when you connect those profiles.
- Recruiting activity — programs you target, coaches you interact with, notes and email content you log.
- AI usage — counts of recommendations and drafts generated, used for fair-use enforcement.
- Technical data — IP address, browser type, page views (via Vercel Analytics, anonymous and aggregated).
How we use it
- Compute fit scores between your profile and college programs.
- Power AI recommendations and outreach drafts (sent to OpenAI — see below).
- Send transactional emails (account verification, password reset).
- Operate the service, prevent abuse, and improve features.
We do not sell your personal data. We do not sell or rent player data to recruiting services, scouts, or coaches.
Third parties we share with
- Supabase — our database and authentication provider. Data is encrypted at rest and in transit.
- OpenAI — when you request an AI recommendation or outreach draft, your profile context is sent to OpenAI's API. OpenAI does not use API data to train models (per their data usage policy as of 2026).
- Vercel — our hosting provider. Standard server logs.
Age & COPPA
Recruit is intended for users 13 and older. We do not knowingly collect data from children under 13. If a parent believes their child under 13 has created an account, contact us at team@kaifect.com and we will delete the account.
Users between 13 and 18 should have parental awareness of this service. Parents may request deletion of a minor's account at any time.
Your rights
You can:
- Access and edit your profile from your profile page.
- Export your data — email us and we'll send you a JSON dump within 14 days.
- Delete your account — email us and we'll erase your data within 30 days (some logs retained for legal purposes).
Security
Row-level security is enforced on every database table — you can only read and write your own data. Service-role credentials are server-side only and never exposed to the client. We use HTTPS everywhere. We do not store payment information; payments (when launched) are handled by Stripe.
Changes to this policy
We'll post any changes here and update the effective date. Material changes will trigger an email to all account holders.