The fine print, in plain language
Privacy Policy
Effective September 17, 2026
The short version
We collect what we need to run the platform, we don’t sell your personal information, and we don’t run third-party advertising trackers. Phenomenal exists so parent groups, clubs, leagues, and districts can run their year — your data is used for that, and not for anything else.
What we collect
Account information: your name and email address, and the passkey credential your device creates when you register. A passkey gives us only a public key — we never see or store a password or your biometrics.
Organization content: the pages, events, products, and communications an organization publishes, and your memberships, signups, and roles within it.
Transaction details: what you bought or donated, the amount, and — for physical orders — the shipping name and address you provide. Payments are processed by Stripe; your full card number goes to Stripe, not to us.
Technical information: logs, approximate location derived from your IP address, and the cookies described below.
How we use it
To provide the service: signing you in, rendering your organization’s site, processing orders and donations, sending the emails the service needs (sign-in links, receipts, order updates), and keeping organizations’ records accurate.
To keep the platform safe and working: security, fraud prevention, debugging, and aggregate analytics about how the platform performs. We don’t use your personal information to train advertising profiles, and we don’t sell it — to anyone.
Imported organization knowledge may be used to power in-product AI features for that organization, as described in the Google user data and Limited Use sections.
Cookies
We use a small number of first-party cookies that the service needs: one keeps you signed in, and one remembers preferences like which organization you’re managing.
Analytics: an organization can connect its own Google Analytics property to its site, and we may run one for the platform. Where either is turned on, Google Analytics sets first-party cookies that count visits and pages viewed. When an organization uses its own property, that information goes to that organization’s Google account, and the organization decides what to do with it. We switch off Google’s advertising and cross-site identity features — Google Signals and ad personalization — so analytics cookies are not used to build advertising profiles and are not shared across other sites. An organization that has connected no property, on a site where the platform runs none, sets no analytics cookies at all.
There are no third-party advertising or cross-site tracking cookies on Phenomenal.
Who sees your information
The organization you interact with: if you join, volunteer, pay dues, buy, or donate through an organization’s site, that organization sees the information it needs — your membership details, order, or donation — because it is the merchant and community you’re dealing with. If that organization has connected its own Google Analytics property, it also sees the visit statistics for its own site.
Service providers who help us run the platform: Stripe for payments, our print fulfillment partner for shipping spirit-wear orders (they receive the shipping details for your order), our email provider for the messages the service sends, Google Analytics where analytics is turned on (it receives page, referrer, and device information — not your name or email address), and the cloud infrastructure that hosts the platform. Each receives only what its job requires.
Legal reasons: we may disclose information if required by law, or to protect the rights, safety, or property of our users, the public, or Phenomenal.
For Google user data specifically, see Google user data — who we share it with.
Children
Phenomenal is built for adults — parents and guardians, members, volunteers, coaches, teachers, staff, and administrators. The service is not directed to children under 13, and we do not knowingly collect personal information from them. If you believe a child has provided us personal information, contact us and we will delete it.
How we protect your data
We use safeguards to protect personal information, including sensitive information received from Google Drive, against unauthorized access, disclosure, alteration, and destruction. We encrypt data in transit using HTTPS/TLS and use database and object-storage providers that encrypt stored data at rest.
Google Drive refresh tokens, which let us maintain your authorized connection, receive an additional layer of encryption before they are stored: AES-256-GCM authenticated encryption. Encryption keys are managed separately from the stored connection records. Google access and refresh tokens are handled on our servers and are not returned to your browser by the Drive integration.
We require authenticated access and enforce role-based permissions for private organization data. Database row-level security restricts access to organization records, and Drive connection checks restrict use of a connection to the person who authorized it. Another administrator cannot use your connection to browse your Drive. Content you choose to import is available according to your organization’s permissions and the visibility you choose. We limit internal access to what operating the service requires. No method of transmission or storage is completely secure.
Google Drive access and your choices
Connecting Google Drive to Phenomenal is optional. We request Google’s drive.file permission. That permission lets us access Google Drive files you select with Google’s file picker (and files our app creates, if any) — not blanket read access to your entire Drive. It does not let us create, change, or delete files in your Google Drive except as Google’s drive.file rules allow for app-created files. We do not use an in-product folder browser over your whole Drive.
When you choose Pick files from Google Drive (or the equivalent picker on members import), Google’s picker opens so you can select the files to import. We then read metadata and contents for those selected files so we can import them into your organization’s knowledge library, asset library, or members import — as the feature you used requires.
You can disconnect Google Drive in the product or revoke access in your Google Account’s third-party connections settings. Disconnecting in the product deletes the stored connection credential and attempts to revoke the Google authorization. Neither action deletes files from Google Drive or automatically removes copies already imported into your organization’s records.
If you previously connected under an older, broader Drive permission, reconnecting upgrades the connection to the current drive.file + picker model. Until you reconnect, an older connection may still reflect the permission you granted at connect time.
Imported content is retained as part of your organization’s records under the retention policy below. To request access to or deletion of imported content or other Google user data, contact us at hi@phenomenal.org.
Google user data — who we share it with
Google user data means information we receive through Google authorization — for example OAuth tokens for a Drive connection, and the contents or metadata of Google Drive files you choose to import into Phenomenal.
We share, transfer, or disclose that data only as follows.
Your organization. Content you import from Google Drive becomes part of that organization’s records on Phenomenal. People with access in the organization can see it according to the roles and visibility settings for that organization.
Cloudflare. We run Phenomenal on Cloudflare. Cloudflare provides hosting, storage (including vector search indexes), database connectivity, and AI inference infrastructure. Google user data — including imported file contents, derived embeddings, and prompts — is processed on Cloudflare systems as needed to operate those features.
AI processors (inference). When someone in your organization uses AI features that draw on imported knowledge or other Google-derived content, relevant passages may be sent for inference (for example to generate an answer, embedding, or image-derived text) to Cloudflare Workers AI (including models Cloudflare hosts or routes) and, where a partner model is used for a feature, xAI via Cloudflare (Cloudflare AI Gateway / Workers AI partner routing), as needed to run that feature. We do not list individual model names on this page; those processors are who may receive Google-derived content for inference.
We use that processing to run the feature you asked for. We do not sell Google user data. We do not use Google user data for advertising. We do not claim Zero Data Retention. Retention and training rules of Cloudflare and any partner model provider are governed by their terms and our Cloudflare configuration. In production, our named AI Gateway (ptopro-ai) is configured not to collect request logs. Non-production traffic uses a separate gateway (ptopro-ai-dev) that may collect logs for testing and optimization.
Google Analytics is not one of those processors. It never receives Google Drive tokens or imported file contents; it receives only the visit information described under Cookies.
We do not share Google Drive tokens or Drive file contents with Stripe, our print fulfillment partner, or our email provider. Those providers receive only what their jobs require for payments, shipping, or service email — not your Google Drive connection.
Legal. We may disclose information if required by law, or to protect the rights, safety, or property of our users, the public, or Phenomenal.
Google Workspace API data — Limited Use
The use of raw or derived user data received from Google Workspace APIs will adhere to the Google User Data Policy, including the Limited Use requirements.
We use Google user data only to provide or improve user-facing features that are prominent in the Phenomenal interface. We do not sell Google user data. We do not use Google user data for serving advertisements. We do not allow human reading of Google user data except (a) with your permission, (b) for security/compliance investigation, (c) when required by law, or (d) where use is limited to aggregated/anonymized data that cannot be associated with an end user — and only as allowed under Google’s Limited Use rules.
Retention
We keep personal information for as long as your account or your organization’s records need it, and as required for legal, tax, and financial-audit obligations — organizations’ financial records are, by design, durable.
Your choices
You can update your account information in the product, and unsubscribe links are included in non-essential email. To access, correct, or delete your personal information — or to ask what we hold about you — write to us and we will respond. Deleting your account removes your personal information, except records we are required to keep (like an organization’s transaction history).
Most browsers let you block or delete cookies, and Google publishes a browser add-on that opts you out of Google Analytics on every site that uses it. Blocking analytics cookies does not affect your ability to use Phenomenal.
Changes to this policy
When this policy changes, we will update the effective date above, and give notice on this page, in the product, or by email if the change is material.
Contact
Questions, requests, or concerns about your data? Write to us at hi@phenomenal.org and a human will get back to you.