Privacy Policy

Last updated: 2026-04-28

Draft. This is a working draft prepared by NILifi and reviewed by legal counsel before public launch. Athletes and parents using the platform during the pilot period should emailprivacy@mw-creative.comwith any questions.

Who we are

NILifi is operated by MW Creative LLC (“NILifi,” “we,” “us”). Our platform helps college and high-school athletes learn the financial side of NIL — taxes, budgeting, contracts, investing.

What we collect

We collect the minimum information needed to provide our service:

  • Account data: email, display name, school, sport, position, graduation year.
  • Course activity: which lessons you’ve completed, quiz answers and scores, time spent, XP earned, daily streak.
  • Certification: when issued, the unique certificate number, and the lesson versions you saw at the time.
  • Audit and security logs: actions you take in the app (sign-in, lesson completion, content publish, etc.), IP address, and user-agent string.

FERPA

When NILifi is used through an educational institution (a school, a district, a college athletic department), the activity records that we hold may be considered “education records” under the Family Educational Rights and Privacy Act (FERPA). In those cases:

  • We act as a school official with a legitimate educational interest, under the direct control of the institution.
  • We do not sell, rent, or share student data with any third party for any purpose other than delivering our service.
  • We delete student data within 30 days of a written request from the student or institution.
  • Institutions can request a complete data export at any time.

COPPA

NILifi is not directed at children under 13. Athletes must be 13 or older to create an account. Parents who believe a child under 13 has created an account should contact us immediately and we will delete the account.

How we use data

  • To deliver lessons, quizzes, and certifications.
  • To track progress and show personalized dashboards.
  • To enable parents (with athlete approval) to see linked athletes’ progress.
  • To enable institutional staff to see completion rates and at-risk athletes within their own institution.
  • To send transactional emails (sign-up confirmation, certification, occasional reminders).
  • To monitor security and audit access for compliance purposes.

We do not use student data for advertising or to train third-party AI models.

Who we share with

Only the subprocessors listed at /legal/subprocessors, each bound by a Data Processing Agreement, and only to the extent needed to operate the platform.

Your rights

You can:

  • Download a complete export of your data via our in-app export endpoint.
  • Request deletion of your account and data via privacy@mw-creative.com or the in-app deletion-request flow.
  • Correct inaccurate data by editing your profile.
  • Withdraw parent-account links at any time, from either the parent or athlete side.

Retention

We retain account data for the life of the account. Audit log entries are retained indefinitely as required by SOC 2 and FERPA compliance. After deletion, data is removed from production systems within 30 days; backup retention follows our backup rotation schedule, after which deletion is final.

Security

We encrypt data in transit (TLS 1.2+) and at rest. Access controls are role-based and scoped to institutions. Every meaningful action is recorded to an append-only audit log. We are pursuing SOC 2 Type II certification.

Contact

Email privacy@mw-creative.com with any privacy-related question or request.