Privacy Policy
Last updated 24 September 2026 · Effective 24 September 2026
Anvil is scheduling software for college, high school, and club athletic programs. This policy explains what information Anvil holds about the people who use it — coaches, staff, athletic trainers, and the athletes on the roster — what it is used for, and who can see it.
It is written to be read by the people it describes, not only by their lawyers. Where something is a genuine limitation rather than a promise, it says so.
The short version.
Anvil holds your name, your email, your role on a team, and — if you are an athlete — the class schedule you enter, so that your coaches can build a practice week that does not collide with your classes. It also holds what you post in the app: announcements, messages, practice plans, and documents.
Anvil does not sell your information and does not show advertising. It carries no third-party analytics, tracking, or advertising software of any kind, so nothing here follows you to another website. The public website counts its signed-out visitors with Vercel's cookieless Web Analytics — see §2. Information is shared only with the vendors that run the service, listed in §7.
Most of what you do in Anvil is visible to your program's staff. Messages are the exception: only the people in a conversation can read it. §6 is the section to read if you want to know exactly who sees what.
1.Who is responsible for your information
Anvil is operated by Anvil Scheduling LLC ("Anvil", "we", "us"), a Colorado limited liability company at 604 19th Street, Golden, CO 80401.
Anvil is bought by athletic programs rather than by the athletes on them. A coach or an athletic department signs the program up — from the website or by talking to us — and from then on decides who is on the roster and what is recorded about them. For most of the information described here, and for student records in particular, your school or program directs what happens to it, and Anvil acts on its instructions. See §9 for what that means at a school, and §10 for a club side, where there is no school to direct anything.
If you want information corrected or removed and you are an athlete, the fastest route is usually your coach or your athletic department. You can also contact us directly at privacy@anvilscheduling.com and we will work with your program.
2.What Anvil collects
Anvil collects only what the product needs to do its job. There is no background collection: everything below is either typed into Anvil by you, typed in by a coach on your program, or created as a direct result of something you did in the app.
| What | Details | Why |
|---|---|---|
| Account | Email address, and a password if you set one. Sign-in is by emailed link or password | To sign you in and match you to your roster spot |
| Roster profile | Name, role (coach, athlete, trainer, observer), staff title, jersey number, playing position, and an optional profile photo | So the team knows who is who, and so the app shows you the right screens |
| Phone number | Optional. Entered by you or by a coach on your program. See §8 | To send text notifications, where a program enables them |
| Class schedule | For athletes: course names, meeting days and times, and exam times. Entered by hand, pasted from a timetable, or imported from a calendar file | The core of the product — it is how Anvil detects that a practice collides with your classes |
| Availability status | One of three values: healthy, rehab, or injured. No diagnosis, no notes, no dates | It tells the scheduler whether your classes should constrain the whole team's practice window |
| Readiness answers | Where a program uses the morning readiness form: your answer to each question on a 1–5 scale, the score Anvil calculates from them, and an optional comment of up to 500 characters in your own words. One row a day, kept as a series | So staff can see who is arriving tired or sore before practice is set. §6 says who reads it — every coach on your program does |
| Schedule activity | Practices and events you are scheduled for, open-hour sign-ups, meetings you book with a coach, and appointments you book with an athletic trainer | To run the schedule and to record countable hours |
| Content you create | Messages and the reactions on them, announcements, practice plans, checklist and survey answers, coach notes, team photos, and uploaded documents | It is the content of the product |
| Notification devices | If you switch on push notifications: the address your browser or phone hands over for that device, the two keys the message is encrypted against, and the device description you see beside the switch. Deleted when you switch them off | To deliver a notification to the device you asked for it on |
| Billing | For the person who signs a program up: the plan chosen, whether the subscription is current, and an identifier from Stripe. Card details are typed on Stripe's own checkout page and never reach Anvil | To take payment for the program's subscription |
| Technical | Server logs kept by our hosting vendors, containing IP address, timestamp, and request information | Security, abuse prevention, and diagnosing faults |
What Anvil does not collect
- No third-party analytics or tracking. The app contains no analytics package, no advertising identifier, no crash-reporting SDK, and no third-party tracking pixels. This is verifiable in the app bundle, not just a policy statement. We do keep our own count of how many programs have signed up, paid, or cancelled, read out of our own database on a page only we can open. That is a business record about programs, not a tracker, and it follows you to no other website.
- Visitor counts on the public website only. The pages at anvilscheduling.com that anyone can read without signing in — the home page, plans, the demo and the sign-up and sign-in pages — are counted with Vercel Web Analytics, which sets no cookies and keeps no identifier that lasts beyond a day. It records the page, the referring site, and a coarse country, device and browser. It never runs once you are signed in, and never in the iOS or Android app.
- No location. Anvil never reads your device's location. Practices carry a location because a coach typed one.
- No medical records. The availability status above is a scheduling flag with three possible values. Anvil is not a medical record system: it holds no diagnoses, no treatment notes, and no injury histories, and the athletic training room keeps its own records somewhere that is not Anvil. The readiness form is a wellness check a coach wrote rather than a clinical instrument — nothing is calculated from its comment box, and the box says on itself that every coach reads it and that medical detail belongs with your athletic trainer instead.
- No contacts, photos library, camera, or microphone access. If you set a profile photo, you choose a single file; Anvil does not have access to your photo library.
- No card numbers. A program's subscription is paid for on Stripe's own checkout page, which is Stripe's and not ours. Anvil is told which plan was bought and whether the subscription is current. It never sees, and could not store, a card number.
3.Where the information comes from
- From you, when you sign up and use the app.
- From your program's staff. A coach puts you on the roster by entering your name and email address before you have an account, and can set your jersey number, position, availability status, and phone number.
- From a file you import. If you import your class schedule from a calendar file or paste a timetable, Anvil reads the course times out of it. Anvil shows you what it found and imports nothing until you confirm.
4.How Anvil uses it
Information in Anvil is used to:
- run your program's schedule and detect conflicts with classes;
- calculate and record countable athletically related activity hours against the limits your program configures;
- deliver announcements, messages, practice plans, and documents to the people your program has addressed them to;
- let athletes sign up for open hours and book time with staff;
- send notifications about schedule changes and bookings — in the app, to a device you turned push on for, and by text where your program has enabled it (§8);
- show your program's staff the morning readiness answers, where a program collects them;
- take payment for your program's subscription and tell the coach who bought it when it needs attention;
- keep the service secure, available, and working correctly;
- comply with law.
Anvil does not sell personal information, does not share it for advertising, and does not use it to train machine learning models. There is no advertising in the product and no plan for any.
5.Automated decisions
Anvil flags scheduling conflicts and warns when a practice week is over a configured hour limit. These are calculations shown to a coach, not decisions made about you: a human decides what the schedule is, and Anvil supplies none of the limits — your program enters its own.
6.Who can see what
This is the section most worth reading. Anvil is a team tool, and the honest summary is that your program's staff can see nearly everything you do in it. Three specific things are worth stating exactly.
Messages are read only by the people in them
A conversation in Anvil can be read only by the people in it. A coach, athletic trainer or observer who is not in a conversation cannot read it. Anyone in a conversation can add another member of your program to it; the person added can read everything already said, and everyone in the conversation sees them on its member list. A coach in a conversation can remove people from it and can delete any message in it, or the whole conversation. The app tells you who can read a conversation when it is created and again inside it.
This is a rule about who in your program can read a conversation, not a promise of secrecy: messages are stored by Anvil like the rest of your data, and anyone in a conversation can add somebody else to it.
Athletic training room appointments are private from coaches
Appointments you book with an athletic trainer are visible to you and to your program's athletic trainers, and not to your coaches. This is enforced in the database rather than in the interface: coaches have no permission to read the appointments table at all. An athlete who believes a coach is watching will not book the treatment they need, which defeats the purpose of the feature.
Meetings you book with a coach are a different thing and are not private from coaches.
Read receipts are private from everyone
Anvil records what you have read so it can show you what is new. Nobody — staff included — can ask Anvil who has read a given message or announcement. There is no interface for it and no permission that would allow it.
Everything else
- Other athletes on your team see your name, photo, jersey number, position, and availability status on the roster, and the practices you are both scheduled for. They cannot see your class schedule, and they cannot see your readiness answers — those go to staff and to you, and to nobody else on the roster.
- Your coaches see your class schedule, because that is what the product is for, along with everything else in §2 — your readiness answers and the comment you wrote with them included. The readiness page is read by every member of staff on your program, not only by the coach who wrote the questions.
- People on other programs see nothing. Every request is checked against your membership before any data is returned, and a roster is invisible to anyone not on it.
- Observers — a read-only seat used by athletic directors and compliance officers — see the schedule and roster and can change nothing.
7.Who Anvil shares information with
Anvil uses a small number of vendors to run the service. They process information on our instructions and are not permitted to use it for their own purposes.
| Vendor | What it does | What it holds |
|---|---|---|
| Supabase | Database, sign-in, and file storage | Everything in §2 except server logs |
| Vercel | Web hosting, storage for encrypted backups, and visitor counts for the public website | Server logs, and cookieless page counts for the signed-out website. Backups are encrypted before they leave our machines, so Vercel holds only ciphertext |
| Stripe | Subscription payments and the checkout page | The name, email address and card details of the person paying, typed on Stripe's own page. Anvil is handed back the plan and the subscription's status, and never the card |
| Resend | Delivering the email Anvil sends — sign-in links and invitations | The address it is being sent to and the text of that one message |
| Apple, Google, Mozilla | Delivering a push notification to the device you switched it on for — whichever of them made your browser or phone | That device's address, and a payload encrypted against the device's own keys, which they carry and cannot read |
We may also disclose information if required by law, to enforce our agreements, or to protect the rights and safety of users — and if Anvil is ever acquired or merged, information may transfer as part of that transaction, subject to this policy.
Information is stored and processed in the United States.
8.Phone numbers
Anvil does not send text messages. It has no text provider and no text message has ever been sent from it. Everything the app notifies you about — a published week, an announcement, a booking — arrives as a notification from the app itself, which you control on the Notifications page (§7).
A phone number is contact information for your coaches and nothing more: it is stored so a coach can reach you the ordinary way, from their own phone. It is entered either by you in Settings or by a coach on your program, it is visible to the staff on that program, and nothing in Anvil sends to it. You can clear it in Settings at any time, or ask a coach to clear it, and nothing else about your account changes.
What changed. Until 22 September 2026 this section described text notifications Anvil intended to send, with Twilio as the provider. That feature was removed from the product before it ever sent anything, and Twilio has been removed from the list of services in §7. Numbers entered while it was described are still stored, and are still only contact information.
9.Student records and FERPA
This section is about school programs — a college, a high school, or a district. A club or travel team is not a school and holds no education records, so none of what follows applies to one; §10 is the section for those.
Class schedules, exam times, and roster information about student-athletes are education records belonging to the school, and are protected by the Family Educational Rights and Privacy Act (FERPA).
Anvil holds these records on behalf of the school, under the school official exception — as a contractor performing a function the school would otherwise perform itself, under the school's direct control over how the records are maintained and used. Anvil does not use education records for any purpose other than providing the service to that school, and does not re-disclose them except as the school directs or the law requires.
Requests about education records go to your school. FERPA gives eligible students the right to inspect and to seek correction of their records, and that right is exercised through the institution, not through us. We will support any such request the school makes of us.
10.Minors, high schools, and club teams
Anvil supports high school and club programs, so some of the people on a roster are minors. Anvil is not directed to children under 13 and we do not knowingly collect information from them. If we learn that we have, we will delete it.
At a school, the school or district decides what is entered into Anvil and is responsible for obtaining any parental consent its own policies and applicable state student-privacy laws require. Anvil uses student information only to provide the service to the school, and never for advertising, profiling, or any commercial purpose unrelated to it.
At a club or travel team it is different, and the difference is worth stating rather than leaving to be inferred. There is no school behind a club side, so no school is directing what happens to the information and §9 does not apply to it. A club program must not put a child under 13 on an Anvil roster. That is a rule about who this product is for and not a formality: Anvil is not built to obtain and record verifiable parental consent, so a coach who enters a child under 13 is asking Anvil to hold information it has said plainly it will not hold. A parent or guardian who believes a child under 13 has been entered can write to privacy@anvilscheduling.com and we will delete the account and everything attached to it, without asking the club first.
For a club athlete who is 13 or older but under 18, the club decides what goes on the roster in the same way a school would, and a parent or guardian can ask us for a copy of what Anvil holds about their child, or ask for it to be deleted, at the same address.
11.How long information is kept
Information stays in Anvil for as long as your program keeps using it. When a program's subscription ends, the program turns read-only and stays that way for 90 days — long enough to ask for an export, or to come back — and is then deleted. A program that asks us to delete it sooner is deleted sooner. §6 of the terms states the same 90 days from the program's side, and the two are meant to be read together.
Stated plainly, because it is a real limitation. Anvil does not currently expire old content automatically. Practices, messages, announcements, and uploaded documents from previous seasons remain until someone deletes them. If your program wants a retention schedule enforced, that is a conversation to have with us rather than something the product does on its own today.
Encrypted backups are retained on a rolling basis and may hold deleted content until they age out.
12.Security
- All traffic between the app and our servers is encrypted (HTTPS).
- Access is enforced in the database itself, on every row and every request, rather than only in the interface — so a request for data you are not entitled to returns nothing, regardless of how it is made.
- Uploaded documents are held in private storage and served through short-lived links; a coach decides whether a document is visible to athletes, and the storage rules read that same setting.
- Backups are encrypted before they leave our systems.
- Passwords are stored hashed, and we never see yours.
No system is perfectly secure, and we do not claim otherwise. If we discover a breach affecting your information, we will notify affected programs and users as required by law.
13.Your choices
- See and correct your information. Most of it is visible and editable in the app — your profile, your class schedule, your availability, your phone number. Your name, email, and role are set by your program; ask a coach to change them.
- Clear your phone number. In Settings, at any time. Nothing in Anvil sends to it — see §8 — but it is yours to remove.
- Stop push notifications. Switch them off on the Notifications page. Anvil deletes that device's subscription when you do, rather than keeping it and declining to use it.
- Delete your account. Email privacy@anvilscheduling.com and we will delete your account and the personal information attached to it. Content you posted to your team — an announcement, a message in a conversation — may remain visible to your program unless the program deletes it, in the same way that a sent message is not unsent by closing an account.
- Take your information with you. Ask us and we will provide a copy of the information Anvil holds about you.
Depending on where you live, you may have additional rights — to access, correct, delete, or restrict use of your information, and to be free from discrimination for exercising them. Anvil does not sell or share personal information as those terms are used in state privacy laws, so there is nothing to opt out of. To exercise any right, contact privacy@anvilscheduling.com. Where the information is an education record, §9 applies and your school is the right first stop.
14.Changes to this policy
If we change this policy we will update the date at the top. If a change materially affects what we collect or who we share it with, we will tell affected programs directly rather than relying on you to re-read the page.
15.Contact
Anvil Scheduling LLC
604 19th Street, Golden, CO 80401
privacy@anvilscheduling.com