← NIL Kit

Privacy Policy

Last updated August 17, 2026

This policy explains what information NIL Kit collects, why, and how it's used. We collect the minimum we need to run the Service, and we don't sell your data.

1. Information We Collect

When you use NIL Kit, we may collect:

  • Account info: your email address and a hashed (never plaintext) password.
  • Profile info you provide: name, sport, level, school, position, personal traits, goals, and social handles, used to generate your brand kit.
  • Payment info: if you subscribe to Pro, billing is handled entirely by Stripe. We never see or store your full card number.
  • Sponsor responses: if someone submits the sponsor response form on your public link, we store the name, business, email, and message they enter so we can pass it along to you.
  • IP addresses: used briefly to enforce rate limits and prevent abuse (e.g. spam signups or bulk generation). Not used to track you across the web.
  • Usage analytics: page views and product-usage events via PostHog, only after you accept analytics cookies in the cookie banner. You can decline, or change your choice anytime from “Cookie Preferences” in the footer.

2. How We Use AI

The profile information you submit (name, sport, school, traits, goals, and similar details) is sent to Anthropic's Claude API to generate your bio, content pillars, sponsor pitch, and related materials. We don't use your data to train any AI model, ours or a third party's.

3. Third Parties We Use

To run the Service, we share the minimum necessary data with:

  • Anthropic: generates your brand kit content from the profile info you provide.
  • Stripe: processes Pro subscription payments and billing.
  • Resend: sends account emails (verification, password reset, billing notices).
  • PostHog: product analytics, only if you've accepted analytics cookies.
  • Cloudflare Turnstile: a CAPTCHA-free bot check used to keep automated abuse off the Service.
  • Vercel and Neon: host the Service and its database.

Each of these providers processes data under their own privacy policy and only for the purpose of providing their service to us. We don't permit them to use your data for anything else.

4. Children & Minors

NIL Kit is built for student athletes, including high school athletes who may be under 18. If you're under 18, you should have a parent or guardian's permission before creating an account or entering into any sponsorship arrangement, consistent with your state's NIL rules for minors.

We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us at support@nilkit.org and we'll delete it.

5. Public Pages

Pro users can optionally enable a public “link in bio” style page showing their bio, sport, and content pillars. This is off by default and only visible to others once you turn it on. A separate sponsor-response link (included on your downloadable PDFs) is always reachable by anyone who has the direct link, but is excluded from search engine indexing.

6. Sponsor Marketplace

College athletes can optionally opt into a marketplace where businesses browse for sponsorship candidates. This is off by default and currently limited to the college level. Until a business requests a connection and you approve it, they only see non-identifying details: sport, general region (city/state, never a precise address), class year, and sponsorship-interest categories. Your name, school, and social handles are only shared with a business once you've approved that specific connection.

Businesses go through a review process before they can use the marketplace, including an automated plausibility check and, where that's inconclusive, a manual review. This doesn't guarantee every business is who they claim to be, so use the same judgment here you would with any unfamiliar sponsor.

7. Data Retention & Your Rights

We keep your data for as long as your account is active. You can request a copy of your data, ask us to correct it, or request deletion of your account and associated data at any time by emailing support@nilkit.org. We'll act on deletion requests within a reasonable time, except where we're required to keep certain records (e.g. billing history) for legal or tax purposes.

8. Security

Passwords are hashed, never stored in plain text. All traffic to the Service is encrypted in transit. Sessions are stored server-side and can be revoked at any time by logging out. No system is perfectly secure, but we take reasonable, industry-standard measures to protect your information.

9. Changes to This Policy

We may update this policy from time to time. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.

10. Contact

Questions about this policy, or requests about your data, can be sent to support@nilkit.org.