Version 2026-08-24. Before your team can connect its own software to xcathletes.org, an
operator on your team accepts this agreement once. It covers how we protect your athletes'
data, what the connection is for, and what happens if it ever needs to end.

## What connecting means

A token lets your team's own system read and write your athletes' training data on
xcathletes.org, the same data your coaches and athletes already see on this site. A token is
a real credential, so we ask an operator to read this page and accept it first.

## How we protect it

We never store a token in a form anyone, including us, can read back to the original
credential. If a token leaks, revoke it from your team's tokens page and it stops working
immediately. The old credential can never be reused. We log every token created, revoked, or
renewed, so there's a record of who connected what and when.

## What the connection is for

Use the connection to run your own team's tools against your own athletes' training data.
It isn't for pulling data to resell, to hand to a recruiting service, or to share with anyone
outside your coaching staff. If you're not sure whether a use fits, ask us before you build
it.

## We don't pass it along

We don't sell athlete data or share it with advertisers, and we don't hand it to a third
party beyond what your own team's connection does with it. Once your system has the data,
protecting it is your team's job. We ask you to hold it to the same standard this agreement
holds us to.

## Ending a connection

Revoke any token from your team's tokens page whenever you want. It takes effect right away.
Ask us to remove records tied to a specific token, and we will, the same way we handle any
other deletion request.
