Uncommitted U

Strategic Framework and Privacy Architecture

Strategic Framework and Privacy Architecture

Advanced COPPA, MHMDA, and Student-Athlete Data Compliance for a College-Bound Platform

Uncommitted University · Effective Date: August 1, 2026 · Last Updated: August 1, 2026


Preface: Why This Document Is Public

Recruiting platforms have historically built their privacy architecture around one statute (COPPA) and treated everything since as an addendum. That was adequate when these platforms were digital bulletin boards. It is not adequate now that the sector routinely applies artificial intelligence, computer vision, and biomechanical inference to minors' bodies, in a legal environment that has moved considerably faster than the industry's disclosures have.

This document sets out the reasoning behind Uncommitted University's privacy architecture: which regimes we are subject to, which we have deliberately engineered ourselves out of, and why. It is published because the decisions in it are commitments, and a commitment nobody can read is not one.

It is not legal advice and it is not a warranty. It is a statement of design intent and current practice.


1. Overview and Applicability

UU operates a recruiting-support platform for baseball and softball athletes at high school, JUCO, NAIA, and transfer-portal level. Athletes build a profile, identify college programs that fit, draft outreach to coaches, and track the outreach they send.

The regimes bearing on that activity:

RegimeApplies to UU?Basis
COPPA (federal)Not triggeredWe operate a strict 13+ perimeter and knowingly collect nothing from under-13s
Washington MHMDARegulated entity; no covered dataWashington-headquartered, so we are a regulated entity by default. We collect no consumer health data
CCPA / CPRA (California)YesCalifornia residents use the Service
State comprehensive privacy lawsYesVA, CO, CT, UT, TX, OR, MT, DE, NH, NJ, NE, IA, IN, TN, MN, MD, KY, RI and others
State biometric statutes (IL BIPA, TX CUBI, WA)No covered processingWe extract no biometric identifiers or templates
FERPA / state student-data lawsNoUU is not a school or educational agency and receives no education records
NCAA NIL disclosure rulesNot as a platform obligationWe neither broker nor pay NIL compensation
CAN-SPAMYesWe send transactional and marketing email
FTC Act §5YesEvery representation in our published policies binds us

The last line is the one that governs all the others, and it is the organising principle of this framework: we do not claim a control or a practice we do not operate. An overstated policy is not a stronger position. In the United States it is the enforcement hook itself, and in Washington a privacy violation is a per se violation of the Consumer Protection Act, carrying a private right of action, attorneys' fees, and treble damages, with no statutory opportunity to cure before suit. Precision is the defensive posture.


2. The 13+ Perimeter

Design decision: UU does not knowingly collect personal information from anyone under 13.

COPPA obliges operators to obtain verifiable parental consent before collecting personal information from children under 13. The sector's common answer is to build consent machinery and admit under-13 users through it. We reached the opposite conclusion.

Why exclusion rather than consent:

  • Verifiable parental consent is a mechanism that can fail, and every failure is a federal violation involving a child.
  • Consent infrastructure creates a second, highly sensitive dataset (parent identity and verification records) that must then itself be protected.
  • The population under 13 is not commercially meaningful to a platform whose purpose is college recruiting. The cost of admitting it is high and the benefit is near zero.
  • Excluding it is simply better for the child.

How the perimeter is maintained:

  • The minimum age is stated in the Terms of Service and Privacy Policy as a condition of use.
  • We do not prepare pre-sign-up profiles for anyone under 13.
  • Where a graduation year or school implies an age under 13, that record is not used to create a profile.
  • On learning that we hold information from a child under 13, we delete it and close any associated account.
  • A parent or guardian may write to us at any time to review, correct, delete, or halt collection, with no account required and no charge.

The 13–17 population. Athletes between 13 and 17 are minors and are treated accordingly. For this group we categorically exclude sale, sharing for cross-context behavioural advertising, targeted advertising, and profiling with legal or similarly significant effects. Age verification occurs at sign-up. We do not segment or infer age from any pre-sign-up data, and we do not assert that any population is or is not composed of minors before we have asked.

Candour about a known limitation. Self-declared age is not verified identity. A determined minor under 13 can misstate their age on any consumer platform, ours included. We do not claim to have solved this, and we do not describe our age gate as verification. What we commit to is acting promptly whenever we learn of it. A platform claiming its age gate is airtight is making precisely the kind of representation this framework exists to avoid.


3. Washington MHMDA: Regulated Entity, No Covered Data

This is the most consequential analysis in this document, and the one where our position most sharply diverges from the sector's.

3.1 We are a regulated entity, and we say so. MHMDA reaches any entity that conducts business in Washington or targets products to Washington consumers and determines the purpose and means of processing consumer health data. Unlike CCPA, it carries no revenue or data-volume threshold. UU is headquartered in Washington. We are a regulated entity by default, and nothing about our size changes that.

MHMDA also applies extraterritorially: it protects Washington residents and any individual whose consumer health data is collected in Washington. An athlete in Florida would receive its protection if covered data about them were processed here.

3.2 The definition is deliberately broad. MHMDA defines consumer health data as information linked or reasonably linkable to a consumer that identifies their past, present, or future physical or mental health status. It expressly extends beyond clinical data to bodily functions, vital signs, symptoms, biometric data, and, critically, health data derived, inferred, or extrapolated from non-health information. Commentary has applied it to fitness applications tracking steps, heart rate, and training load.

3.3 Our position: UU collects no consumer health data. We do not collect, derive, or infer diagnoses, symptoms, medications, treatment, injury history, recovery status, fatigue, training load, vital signs, heart rate, sleep, bodily functions, reproductive or sexual health information, gender-affirming care information, biometric identifiers, or precise location suggesting an attempt to obtain health services.

The three genuinely arguable categories, addressed directly:

Athletic performance statistics: exit velocity, fastball velocity, batting average, ERA. These are competitive results, of the same character as a box score or a line in a game programme. They record what happened in a game, not the state of the athlete's body. They are self-reported by the athlete for the express purpose of being shown to college coaches. We draw no health inference from them and combine them with nothing that would.

Height and weight: roster attributes published in every college and high school programme in the country and requested by every recruiting questionnaire. We collect them because coaches ask, display them as entered, and infer nothing from them.

Highlight video: the sharpest line we draw. MHMDA classifies biometric data as a subset of consumer health data and defines it to include imagery from which an identifier template can be extracted. This is materially broader than statutes that regulate templates only when used to identify a person. Under that language, a platform applying pose estimation to a minor's highlight video to derive joint angles, stride length, or sprint mechanics is processing biometric health data about a child.

UU performs no such processing. Video is stored and displayed as video. We run no pose estimation, no kinematic extraction, no biomechanical inference, no facial recognition, and no identifier-template extraction of any kind. This is an architectural commitment, not a current gap.

3.4 The "sale" analysis, and why our business model resolves it. MHMDA imposes a near-embargo on selling consumer health data: a sale requires a written, signed, dated authorisation retained for six years, entirely separate from terms of service. "Sale" is defined broadly enough to capture exchange for any valuable consideration.

The exposure this creates for competitors is structural: a platform that charges college recruiters for access to athlete performance data is arguably selling consumer health data about minors. Clickwrap terms would not cure it.

UU's model inverts this. Coaches pay us nothing. The directory is free to browse. We charge no one for access to athlete data. Our revenue is athlete subscriptions: athletes paying for their own tools. There is no exchange of athlete data for consideration anywhere in our business, so the sale analysis does not engage even if the data classification were contested.

3.5 If this ever changes. Introducing biomechanical analysis, wearable integration, injury tracking, or any recruiter-paid access to athlete data would require, before any collection: separate prior opt-in consent to collect; distinct separate consent to share; a standalone Washington Consumer Health Data Privacy Policy linked separately from our homepage per Washington Attorney General guidance; and a signed authorisation regime for anything constituting a sale. We will not introduce any of it quietly.


4. What We Deliberately Do Not Build

Stated as architecture, because absence of a capability is the only fully reliable control.

CapabilityCommon in sectorUUConsequence
Pose estimation / kinematic modellingIncreasingly yesNoNo biometric health data under MHMDA; no BIPA/CUBI exposure
Facial recognition / identifier templatesYesNoNo biometric identifier processing
Injury, fatigue, recovery trackingYesNoNo clinical-adjacent health data
Wearable / heart-rate integrationYesNoNo vital signs
Precise geolocationYesNoNo location-derived health inference
Recruiter-paid access to athlete dataYesNoNo "sale" analysis engages
Advertising trackers / ad identifiersYesNoNo targeted advertising or cross-context sharing
Under-13 usersVariesNoCOPPA consent machinery not required
NIL brokerage or paymentGrowingNoNo NCAA reporting obligation as a platform

Each row is a category of liability that cannot materialise, because the data does not exist. This is the framework's central strategy: minimisation is the only control that does not fail.


5. Data Categorisation

CategoryData pointsGoverning regimeRisk
Standard PIIName, email, phone, school, graduation year, city/stateCCPA/CPRA, state comprehensive lawsModerate: standard rights apply
Athletic performanceExit velo, fastball velo, batting average, ERA, innings, bats/throwsState comprehensive lawsLow: self-reported competitive results
Physical attributesHeight, weightState comprehensive lawsLow: roster attributes, no inference drawn
AcademicGPA, SAT/ACT, core-course status (all optional)State comprehensive laws. Not FERPA: self-supplied, not an education recordModerate: treated as sensitive in practice
MediaHeadshot, highlight video linksCopyright, publicity rights. Not biometric: no template extractionLow as processed
EligibilityNCAA/NAIA eligibility number, transfer-portal statusState comprehensive lawsModerate: identifier, access-controlled
Digital exhaustHashed IP, device/browser, session analytics, click eventsCCPA, state lawsLow: IP stored only as irreversible hash
Pre-sign-up profileCamp registration records; public search-summary informationState comprehensive laws; FTC §5Highest sensitivity: see Section 6
Biometric / kinematicN/AN/ANot collected
Health / wellnessN/AN/ANot collected
NIL financialN/AN/ANot collected

6. Pre-Sign-Up Profiles: The Most Sensitive Thing We Do

We treat this as the highest-scrutiny processing on the platform, and we describe it rather than burying it.

What it is. For some athletes we assemble a draft profile before they have an account, so we can offer them a working profile to claim free of charge.

The two sources, and only two:

  1. Camp and event registration records belonging to UU: name, graduation year, school, location, position, and a parent or guardian contact address. Our founder ran the registration systems and athlete profiles for a baseball and softball camp operation, and these records are UU's own data. UU does not operate camps or events.
  2. Publicly available information, obtained by submitting the athlete's name to a commercial search-results service returning the summary panel a public search engine displays, which we read.

What it explicitly is not. We do not crawl, scrape, log into, or extract data from recruiting platforms or any other third-party website. We read a public search summary. We do not fetch, parse, or harvest anyone's pages.

We note this precisely because the sector's disclosures on the point are not always reliable. Ours is a verifiable technical statement about how our system works, and we would rather be held to a narrow accurate description than a broad comfortable one.

The controls, which are the point:

  • Unclaimed profiles carry instructions telling search engines not to index them, and appear in no public directory on our site
  • They are reachable only through the direct link sent to that athlete
  • Provenance is recorded per field, and disclosed to the athlete on request
  • One-click deletion from that link: no account, no login, no correspondence, no retention offer, no verification step. We consider friction in front of a removal request to be the defect, not the safeguard
  • On deletion we remove the profile and its account, retaining only a minimal suppression record so we neither recreate the profile nor contact the athlete again
  • None are prepared for anyone under 13
  • A parent or guardian of any athlete under 18 may require correction or removal

On unverified matches. Automated matching produces some records whose confidence is moderate: a name match without corroborating detail. We treat these as leads requiring human confirmation, not as facts about a person. A record we are not confident about is not a record we should be publishing or acting on, and the deletion path above applies to it identically.


7. NCAA NIL

NCAA Division I rules effective August 1, 2024 require student-athletes to disclose non-institutional NIL agreements exceeding $600 within 30 days, with institutional reporting obligations and eligibility consequences for failure.

These obligations attach to compensation an athlete receives. UU pays athletes nothing. Money flows from athletes to UU for software access. We do not broker, facilitate, host, or pay NIL compensation; we are not a collective, agent, marketplace, or booster. Use of the Service does not itself create a reportable agreement.

Our commitment: we will never obstruct an athlete's ability to meet a disclosure obligation. On request we provide a complete export of account data, including transaction history and outreach records, in a portable format, for submission to a compliance office.


8. Rights Architecture

Every right below is extended to every user, regardless of residence, not only where mandated.

RightHow exercisedResponse
AccessEmail supportWithin 45 days
CorrectionAccount settings or emailPromptly
DeletionAccount settings or emailPromptly; within statutory period
PortabilityEmail supportMachine-readable export
Opt out of sale/sharingNot required: we do neithern/a
Opt out of targeted advertisingNot required: we do nonen/a
Opt out of profilingNot required: we do nonen/a
Delete unclaimed profileOne click from the link sentImmediate
Guardian access for a minorEmail support, no account neededPromptly, no charge
Appeal a denialReply to our responseExplained in writing, with AG contact details

We honour Global Privacy Control universally. We do not discriminate for exercising any right. We ask for no more verification information than verification requires.


9. Governing Principles

  1. Minimisation over protection. Not collecting is the only control that cannot fail.
  2. Accuracy over strength of claim. Every representation is enforceable against us. We would rather publish a narrow true description than a broad flattering one.
  3. Exclusion over consent, where a population is not needed. Better for the person; removes a class of risk entirely.
  4. Deletion without friction. A removal path with obstacles is not a removal path.
  5. Explicit refusals. Saying what we will never do is a stronger and more auditable commitment than describing what we currently do.
  6. No quiet expansion. Materially broadening use of information we already hold requires consent, not a revised date at the top of a page.

10. Review

This framework is reviewed when the platform's data practices change, and specifically before introducing any capability in the Section 4 table. Questions:

Uncommitted University · Seattle, WA · support@uncommittedu.com

Companion documents: Privacy Policy, Terms of Service, Security, Privacy, and Personal Information Protection Framework.

Pin It on Pinterest