Legal · Privacy Policy

Privacy Policy

Effective August 26, 2026

Tessaira Golf is a directory of competitive golf tournaments and college golf programs, plus a free assessment, a free drill library, and a free round-and-practice tracker for junior golf families. We collect the minimum needed to run it: an email and password if you create a free account, an email if you sign up for a newsletter, roadmap, or quiz result, standard server logs, the details you enter into the assessment, and the rounds, practice sessions, and milestones you choose to log. If you fill in the Tessaira profile, we store the player details you enter there, including graduation year, boys or girls golf, optional academic details, optional player name, optional recruiting goal, and a U.S. state if you choose one. Free includes up to 8 Ace messages. Premium includes up to 50 messages in each UTC calendar month. Premium Unlimited has no monthly message ceiling, subject to reasonable anti-abuse safeguards. When you ask Ace a question, the question and the limited family context described below are sent to OpenAI. We keep a content-free allowance ledger with an account identifier, plan scope, counter, and request state. It does not store the prompt, answer, player record, provider payload, or hidden reasoning. We count public page views by default, storing a page category, a coarse source class, mobile or desktop, and a pseudonymous session identifier that rotates every day. Optional funnel and attribution analytics stay off unless you choose them. Global Privacy Control, Do Not Track, and Essential only stop all of it. and never include a location we worked out for you. No personal information is sold.

Who we are

Tessaira Golf (“Tessaira,” “we,” “us”), the service previously published as GolfNexus, operates tessaira.com, a directory of competitive golf tournaments, tours, rankings, and college golf programs in the United States, together with a free assessment (the “honest read” and “Tessaira”) and a free library of practice drills for junior golfers and their families (the “Service”). This policy explains what information we collect when you use the Service, why we collect it, and the choices you have. Questions or requests about this policy can be sent to angelo@tessaira.com.

Who Tessaira is for, and the question we ask first

Tessaira accounts are created by an adult: a parent or guardian setting up a family account for a player, or an adult player setting one up for themselves. Players under 18 participate through the family account. Before we create or operate an account, we ask which adult account-owner role applies.

What we ask. One question, with two choices: a parent or guardian, or an adult player. We do not ask for a date of birth, a child's email address, a country, or a precise location at this step. We ask whether the person creating the account is 18 or older and take that adult statement for it. We do not use country or location to decide whether an adult can create an account.

This is not verification, and it is not parental consent. It is what you told us. We do not check it against anything, and nothing on this site should be read as saying we did. It is also not verifiable parental consent under the Children's Online Privacy Protection Act — that is a different, formal process that Tessaira does not currently operate. What the question does is narrower and real: we do not create or operate an account until an adult has said they are the one setting Tessaira up.

If the player is under 18, a parent or guardian creates the family account with their own email and manages the player's file with them. We do not ask the player to make a child account, subscribe, or provide a direct email address in order to get started. (We never look up anyone's location — see Location.)

If you have not answered yet, we do not create or operate an account. That is deliberate: an unanswered question is not permission from an adult account owner.

What we keep from an answer we can accept. Two things, in two places. On our servers we record the exact wording you were shown, which option you chose, the version of that wording, when you answered, when the answer stops applying, the purpose it covers, and whether it has since been withdrawn. In your browser we set a cookie that points at that record: it holds the wording version, a random reference number that means nothing on its own, an expiry date, and a signature that lets us detect any change to it. The cookie says nothing about you — not your answer, not your role, not the time — so anyone reading your cookie jar learns nothing from it.

Why it is arranged that way. The reference number is what lets us withdraw an answer. Because the permission lives in our record rather than in your cookie, we can mark it withdrawn and it stops working immediately, everywhere, without needing anything to change on your device. It also means an altered or copied cookie does not work: if it does not match our record, we treat you as not having answered. Both last twelve months.

What we collect

Most of the Service is readable without giving us anything. When you do interact with it, here is everything we collect:

  • Account information. If you create a free account, we collect your email address and a display name, and, if your sign-in method provides one, a profile image URL. These are handled by our authentication provider (Neon Auth) and also stored in our own database so we can recognize your account and provide the account features described below. Your password is created and stored only by Neon Auth, in hashed form; we never see or store it in plain text. Accounts let you save reads, schools, and drills. Premium unlocks coach email addresses and the other features listed on the Premium page.
  • Tessaira profile. The dashboard keeps one profile row per account, and it is stored on our servers until you change or delete it. It holds the graduation year and boys or girls golf you select, and three optional fields: a U.S. state (two letters, chosen from a list — see Location for what that is and is not), a grade-point band such as “3.5 to 3.7”, and a player name of up to 80 characters, which is used to fill in the coach-email templates. It can also hold an optional recruiting goal: whether you have set one, the division target, and the program tier you choose. Nothing checks what you type into the name field, so whatever you put there is stored exactly as you wrote it. This row is what the dashboard, the plan, and the recruiting tools read; it is a record about a minor in most cases, and it is disclosed here rather than folded into “account information”.
  • Ace conversation, allowance, and Season planning. Free includes up to 8 Ace messages for the account. Premium includes up to 50 Ace messages in each UTC calendar month. Premium Unlimited has no monthly message ceiling, subject to reasonable anti-abuse safeguards. Ace is an interactive AI assistant inside the player workspace. When you ask an interactive Ace question, Tessaira sends OpenAI the question, up to eight recent conversation turns, the workspace page you are using, and a limited summary of the family records that are relevant to that page. In Season, that limited context can include the account-entered graduation year, Handicap Index, and up to six recent family-confirmed tournament results (event, date, finish, field size, event class, and a qualifier outcome when entered). These are family-entered planning facts, not organizer verification, a Player Index, or proof of eligibility. Tessaira stores up to eight visible user and assistant turns for each workspace page so the signed-in family can continue the same conversation after a reload or in another tab. This record contains the text shown in the chat. It does not contain hidden reasoning or raw provider output. In Season, we separately store the closed planning choices you confirm, such as the date window, travel range, planning state, budget band, protected dates, and a compact family-confirmed Season brief about the goal and self-described competition point. We also store the organizer or catalog candidate you shortlist, decline, or save, together with that decision and an optional short reason. If you explicitly ask for current event dates, entry routes, exemptions, or a personalized event comparison, that question can send the bounded search focus to OpenAI and ask it to check public organizer pages. Tessaira can also keep up to 12 validated, family-visible Season event proposals across signed-in tabs until you review, remove, or restart them. A proposal can include the displayed event title, dates, location, explanation, public source, source-check time, and whether its dates were published or estimated. A proposal is not a saved calendar event. We do not store the raw provider response or hidden reasoning. To enforce the published plan allowance, Tessaira separately stores an account identifier, a lifetime or UTC-month scope, the plan category, a numeric count, and a short-lived request state. That ledger contains no question, answer, player record, provider payload, source result, or hidden reasoning.
  • Premium Beta feedback. If you choose Provide feedback inside the Premium workspace, we store the category, what you type, the current workspace page, the Tessaira release and build, a coarse browser and platform family, viewport size, and browser locale. You may separately enter a reply email or select one PNG, JPEG, or WebP screenshot. We never capture a screenshot in the background, and we do not automatically attach an Ace conversation, player record, school list, calendar, or inbox content. After the report is saved, we email a text-only copy and its release context to the Tessaira owner mailbox at angelo@tessaira.com so it can be reviewed; an attached screenshot remains in the stored report and is not emailed. Do not put information in the report that you do not want our product team to read.
  • Premium beta request. If you ask for Premium beta access from a Premium page, we store the adult account email you enter, the page focus you came from when one is present (Ace, Season, or Recruiting), the request date, and the review state of that request. This is a service request, not a newsletter signup, and it does not add you to any mailing list. The email address is stored encrypted, together with a one-way lookup value derived from it, so a repeat request on the same day updates the same record and an account deletion can find it. A text copy of the request is emailed to angelo@tessaira.com for review. We do not store your IP address, browser, referring page, campaign, or any player detail with the request.
  • Saved roadmap. The roadmap tool on the home page works without an account, and while it does, nothing you type reaches us. If you are signed in and choose to save, we store one row per account holding the five-digit ZIP code and player age you entered, and the development stage our server works out from that age. Saving again overwrites the previous one. Like the profile above, the age describes a minor in most cases, so it is named here rather than left inside a general description of account data. See Location for what the ZIP is used for and what is never done with it.
  • Coach outreach log. On Premium, when you mark a coach email as sent from the outreach composer we store which school and which coach it was addressed to, which template you used, the channel, the current state of that outreach, when it was sent and last updated, and an optional free-text note you keep about that specific attempt. We do not store the message body, and preparing an email writes nothing.
  • Assessment (“honest read”) information. If you use the assessment, we process the details you enter about a junior golfer, the player's age, gender, typical scoring range, the level of events they play, any ranking, and a few optional inputs (events per year, recent trend, academics, goals), to calculate the read. The assessment does not ask for the player's name, email, address, photo, or school. This calculation happens in your browser. An unsaved read stays on your own device in your browser's local storage. If you are signed in and save the read to Tessaira, we store a copy on our servers against your account. See Children's privacy and the honest read below.
  • Round and practice log (the “Tessaira” tracker). Logging is free and needs only a signed-in account. Everything you log is stored on our servers, tied to your account, and it is usually a parent's record of a minor. For each round we store the date you played, how many holes, the score, the course par, and whether it was a tournament round. If you fill them in, we also store an event or course name, the per-round statistics the form offers (fairways hit, greens in regulation, putts, up-and-downs, penalties, three-putts), and a free-text note of up to 500 characters. Nothing checks what you type into that note or that event name, so whatever you put there is stored on our servers exactly as you wrote it. We separately store your practice sessions (the date, which drills you did, and how many minutes if you enter it) and which skill milestones you have marked as cleared, with the date. See Children's privacy and the honest read below.
  • Email signups (newsletter, roadmap, quiz). If you sign up for the newsletter, download the roadmap, or complete the quiz, we store your email address and, if you pick one, a U.S. state preference. That signup can also include a small amount of context so the first email we send is relevant rather than generic: the recruiting stage you have been reading about, how many guides you have read, your quiz answers (age band, play level, and the question you picked as biggest), the page or campaign you signed up from, and your first-touch referrer or UTM tag. It does not include a location: we do not work one out. We also keep the state of your email sequence: which stage you were put on, which step you have reached, when the next message is due, whether you are still subscribed, and a log of which emails were sent to your address and when. See Email program below for how these emails work and how to stop them.
  • Saved drills. The drill library is free. If you save a drill, we store which drill you saved and when, tied to your account, so your saved list is there on your next visit. That record is the only thing we store about your use of the drill library. We do not record which drills you read, open, or watch.
  • Saved-school recruiting records. On Premium, each saved school can also carry the questionnaire state and completion time you record, the last contact time, a follow-up date you choose, the relationship state, camp interest, camp date, a verified official camp link, and your private contact note. Preparing an email does not create an outreach record. We record a sent-email time only after you explicitly mark the message as sent.
  • Planned tournaments. The verified tournament finder is free. If you save an event, we store which tournament you saved and when, tied to your account, so it remains in your Tessaira schedule. We keep that row if the organizer later withdraws the event from the verified finder, and label its current status rather than silently erasing your planning history.
  • Recruiting plan checklist. The checklist itself is generated from your profile and is never stored. What we store is the overlay you put on top of it: which items you have ticked off or dismissed, and, when you check off an event that has already happened, whether your golfer played it and the score you entered.
  • Saved Recruiting Readiness Scorecard. If you press “Save this recruiting plan” on the scorecard, we store the answers you gave: graduation year, boys or girls golf, scoring band, level of events, ranking status, academic band, the division and geography you are targeting, the state you are searching from if you narrowed it, and your answers about your school list, coach contact, player profile and swing video. One saved scorecard per account; taking it again replaces it rather than adding another. We do not store the result itself — the readiness band, the gap it named, or the next move. Those are recalculated from your answers each time you open the plan, so what you see always reflects our current scoring rather than a verdict frozen on the day you took it.
  • Parent-controlled public recruiting profile. If you choose to create one, we store a random public slug, whether the player is under 13, your adult/guardian attestation and consent time, the display name and visibility switches you selected, any parent contact email or allowlisted media link you explicitly chose to publish, and which organizer-verified saved tournaments you selected for the public schedule. Publishing is off by default. School interests, questionnaires, coach notes, outreach history, development notes, and raw score inputs are never included. For an under-13 profile, the server and database suppress full name, state, public rankings, and public media even if a browser attempts to send them.
  • Ranking snapshots. If you record one in My Player, we store the ranking system, rank, scope, official source URL, date shown by that source, and when you recorded it. A parent-entered snapshot stays labeled as parent reported and not independently verified. We do not infer a rank when one is missing or combine systems into a Tessaira national ranking.
  • College coach account applications. If you apply for a coach account, we store your institutional (work) email address, the program you say you coach for, the state of the application (pending, verified, or rejected), when you applied, any evidence link recorded during review, when it was reviewed and by whom, and whether you have turned the coach digest on and when one was last sent to you. We also keep a small audit trail of the actions taken on that application — what happened, when, and the institutional email address that acted. A personal address is rejected: the point of the field is that it belongs to the institution.
  • Private coach prospect lists. A verified coach can save a published player profile to a private shortlist. For each saved profile we store which profile it is, the relationship stage the coach selected, an optional private note of up to 2,000 characters, and when the entry was created and last changed. The note is free text about a junior golfer written by somebody other than that golfer's family, so we describe it exactly: nothing checks what is typed there, it is stored as written, it is visible only to the coach account that wrote it, and it is never shown to the player, to their family, or to any other coach. A coach can export that shortlist as a spreadsheet, which contains the same private notes and relationship stages alongside the fields the player's parent chose to publish — display name, graduation year, boys or girls golf, state, scoring summary, ranking evidence and the public profile address. Publishing a profile is what makes it visible to coaches at all; see Your rights and choices for how to unpublish.
  • Demonstration videos. Some drills include a video hosted on YouTube. Nothing is sent to Google unless you click to load one. See Demonstration videos below.
  • Premium payment. If you subscribe to Premium, our payment processor, Polar, handles your card details. We never see or store your full card number. What we keep is the subscription status, the exact paid product, the amount charged, the date the current period ends, and the customer and subscription identifiers Polar gives us, so we can unlock your account and keep it accurate.
  • Analytics. See Analytics below.
  • Location — we do not work one out. We resolve no location from your IP address and infer none from any substitute signal. Separately from that, a few fields let you tell us a U.S. state yourself, and those we do store. See Location below, which sets out exactly which fields those are and what the difference is.
  • On-device personalization. See Cookies and local storage below.
  • Logs and security data. Like nearly every website, our servers record request logs that include IP addresses and basic request metadata. We use these for rate limiting, abuse prevention, and keeping the Service running.

We do not sell your personal information, run advertising, or use advertising identifiers. We also do not derive your location: we collect neither precise (GPS-level) location nor an approximate estimate worked out from your IP address, and we do not infer one from any other signal. That is a claim about what we work out, not a claim that no place name is ever stored — the U.S. state fields listed above are ones you fill in yourself, and those we keep. See Location, which draws the line precisely.

How we use your information

  • To operate the Service and keep you signed in.
  • To calculate your assessment read from the details you enter, in your browser.
  • To gate coach contact details behind Premium, which limits bulk harvesting of those addresses.
  • To keep the schools, drills, and tournaments you saved available on your account.
  • To keep the rounds, practice sessions, and milestones you log available on your account, and to calculate what the tracker shows you from them: the scoring average, the trend, the streak, the weakest statistic, and what to practice next. Those figures are recalculated from your log every time the page loads and are not stored separately.
  • To send you the stage-appropriate emails described under Email program: the recruiting-stage content and deadlines relevant to you, and nothing else. Every message includes an unsubscribe link. We never send marketing on behalf of anyone else.
  • To process your Premium payment through Polar and keep your subscription status accurate.
  • To understand traffic and how well pages and the funnel work, using the first-party analytics described below, so we can fix what is not working.
  • To make email more relevant, using the U.S. state you pick for the weekly digest — a preference you choose, not a location we work out. See Location.
  • To protect the Service: rate limiting, abuse detection, and security investigation.
  • To respond when you contact us.

We do not sell your personal information, share it for advertising, or use it to build advertising profiles.

Email program

If you sign up for the newsletter, the roadmap, or a quiz result, you may receive a short sequence of emails matched to the recruiting stage you signed up from (for example, getting started, evaluating level, or recruiting) rather than one generic blast. Emails are sent through Resend, our email delivery provider (see Service providers).

  • Unsubscribe. Every email we send you includes a working one-click unsubscribe link, and the header your mail app uses for its own unsubscribe button. Using either stops all future emails; we keep no separate marketing list you have to hunt down.
  • Stage switcher. Every email we send you includes a link to the recruiting-journey page, where you can pick the stage that fits your golfer if the one we picked is not the right fit.
  • Reply-to. You can reply directly to any email and it reaches the owner, not a no-reply inbox.

We only send what you signed up for. We do not send marketing on behalf of anyone else, and we do not sell or share your email address.

Cookies and local storage

Cookies we set. Tessaira sets only first-party cookies. There are no advertising cookies, no cross-site tracking cookies, and no cookies from ad networks anywhere on the Service. The only thing that can put another company's storage on your device is a drill demonstration video, and only if you click to load it. See Demonstration videos.

  • Session cookie: keeps you signed in to your account. Set only if you sign in; expires when your session ends or you sign out.
  • tsa_audience: set only after an adult chooses the parent/guardian or adult player account-owner role. It holds the version of the wording you were shown, a random reference number for the record of your answer, an expiry date, and a signature. It does not contain your answer, your role, or the time — those live in the record it points at, which we can withdraw. First-party, HttpOnly, one year. See the question we ask first.
  • Opening the account-owner screen does not set this cookie. It is written only after an adult chooses an account-owner role; reading the guides or arriving at the setup screen does not create an account-owner record. See the question we ask first.
  • gn_vid: a random identifier, not tied to your name or email, that lets us recognize a returning visitor across separate visits so our analytics is not just counting the same person as a new visitor every day. We set it only after you choose site analytics. It is first-party, HttpOnly (a script on the page cannot read it), and lasts up to 90 days. Choosing Essential only removes it. It does not follow you to other sites, and no third-party ad network can read it.
  • tsa_analytics: remembers the version of your analytics choice — Essential only or Allow site analytics — for up to 90 days. It is first-party and HttpOnly. It does not contain an account role, a name, email, age, page history, or visitor identifier. Choosing Essential only also removes gn_vid.
  • gn_signup_checked: an account-specific one-way hash that says which signed-in account this browser last checked for the sign-up milestone, so switching accounts cannot suppress the second account and the site stops re-checking a successful result on every poll. It does not contain the raw account ID. First-party, HttpOnly, one year.
  • gn_internal: set only on the owner's own accounts, so our visits are excluded from our own traffic numbers. It carries no identity, just that marker, and is never set on a visitor's browser. First-party, HttpOnly, one year.
  • Cloudflare Turnstile cookie: a short-lived cookie Turnstile may set to run its bot check on the sign-in, sign-up, and password-reset pages. See Service providers.

Local storage on your device. Some features store information in your browser rather than on our servers. This data stays on your device unless you take an action that sends it to us, such as submitting your email or saving a read to a signed-in account:

  • Saved assessment reads: a read you have not saved to an account stays in your browser's local storage. If you have Premium access and choose Save assessment, the selected answers are stored on our servers against your account. A pending save is held in this tab's session storage for up to 24 hours so a failed request can be retried without creating another read. See Children's privacy and the honest read.
  • gn_stage_affinity: records which recruiting-journey stages (for example, “getting started” or “recruiting”) you have spent time reading, so the site can lead with content relevant to you on your next visit. Stays on your device unless you submit your email, at which point the current stage is included in that signup (see What we collect).
  • gn_first_touch: records the referrer or campaign (UTM) tag from your first visit to the site, so we know what brought you here if you later sign up. It is stored only after you choose site analytics, and is removed when you choose Essential only.
  • gn_audience_path: records whether you explicitly chose the golfer, parent, or coach path so that choice can remain consistent on your device. It contains no name, email, score, or profile information, is not sent to another company, and can be removed with the “Clear saved path” control on any audience page.
  • tsa_shortlist: if you save a college program without being signed in, the program's directory ID is kept here so the list is still there when you come back. It holds up to three program IDs, a version number, the dates the list was created, last changed, and expires, and one date recording that we have shown you the “keep these” message once. That is the whole contents. It contains no name, email, account ID, ZIP code, note, score, player information, or anything that identifies you or signs you in. Nothing in it is sent to us at any point while you are signed out. It is deleted automatically 30 days after you last change the list. If you sign in, we ask whether to add those schools to your account and do nothing until you answer — we never move them across on our own, and choosing “Not mine” erases the list from this browser without touching your account. No answer you give to that question is recorded on this device. Choosing “Not now” closes it only for the account you are signed in as, and only until you leave the page — so if somebody else signs in on this browser, we ask them too rather than treating your answer as theirs.
  • gn_entry: the first page path of the current tab, kept in session storage rather than local storage, so it is gone when you close the tab. It is created only after you choose site analytics and is sent with the site-analytics funnel milestones described under Analytics so we can tell which kind of page a visit started on. Choosing Essential only removes it.

Submitting your email copies the current gn_stage_affinity and gn_first_touch values into that signup record. It does not erase them from your device; they stay in your browser until you clear them. You can clear any of this at any time through the app's controls (the “Tessaira” clear control, or account settings) or by clearing your browser's cookies and site data.

Demonstration videos (YouTube)

Some drills in the free drill library include a short demonstration video. Those videos were made by other people and are hosted on YouTube, which is owned by Google. We do not host them, we did not make them, and we are not affiliated with the channels that did. Each one is credited on the page with its title, its channel, and a link to the original.

Nothing loads from Google until you click. The video area starts as a still placeholder drawn by our own site. No request goes to YouTube or Google while it sits there, and we do not even fetch the thumbnail image from them. If you never click, Google is never told you were on the page.

What happens if you click. Clicking loads YouTube's player into the page. At that moment Google receives your IP address, your browser's user agent, and the address of our site, and it can set its own storage on your device. That happens under Google's privacy policy, not this one. We do not control what Google does with it, and none of it comes back to us.

We use the privacy-enhanced player. The player loads from youtube-nocookie.com rather than youtube.com, which is Google's own privacy-enhanced mode. We send only our site address with the request, not the full page path. Nothing on the page can start a video on its own.

If you would rather Google receive nothing, do not click to load the video. The drill works without it: the written steps, the diagram, and everything else on the page are ours and load normally. Parents should know that a child who clicks play is the person whose information reaches Google. See Children's privacy and the honest read.

Analytics

We count public page views by default. Optional funnel and attribution analytics stay off unless you choose them. This part of the policy takes effect August 28, 2026. Essential services still run without any choice, including sign-in, security, and the account-owner step. That account-owner step is separate: it decides who may create an account; it does not turn analytics on.

What a default page view stores. The time, a normalized public page path from a fixed list of public sections, a coarse source class (search, social, referral, direct, or unknown), mobile or desktop, the collection basis, the measurement series it belongs to, and a pseudonymous session identifier that changes every day. Nothing else.

What never becomes a record at all. Requests from recognized search and AI crawlers, from anything that does not identify itself as a browser we know, and from our own staff browsers are refused before a page view is counted. They are not stored and then filtered out of our reports; no row is written for them, which is why this measurement is described as external human page views rather than as all traffic.

What a default page view does not store. No cookie is set and nothing is written to your browser's local storage or session storage. Your IP address and your browser's user agent are used while the request is being handled, to enforce abuse limits, to classify device and traffic, and to derive that day's identifier. Neither raw value is written into the analytics record. We do not store the referring site's hostname, any location, your email, your account, your player details, or any identifier that links one day to another.

We do not call these records anonymous, and here is why. The daily identifier is a pseudonym: within a single day, two page views from the same browser carry the same value, which is how we count sessions rather than raw hits. It is derived with a random key created for that day and stored on our server, and that key is destroyed after two days, so once it is gone the day's identifiers cannot be recomputed from anything in our live database. One qualification we would rather state than leave out: deleting the key removes it from that live database, and our hosting provider's automated backups and point-in-time recovery keep a copy of the database as it was until that copy ages out on their schedule. The rows themselves are still records stored on a server, and we keep them for a bounded period described under How long we keep information.

What is only ever done for these records. Measuring and improving this site. They are never used for advertising, sold or shared, joined to an account, joined to a player, used to personalize what you see, or used in any pricing or eligibility decision. They are structurally kept out of every per-session view in our own reporting: they contribute to grouped counts above a minimum group size and to nothing else.

How to stop it. Choose Essential only from the privacy control available on every page. If your browser sends a Global Privacy Control or Do Not Track signal, we treat either one as a full analytics stop and no page view is counted, even if you previously allowed analytics. Refusing changes nothing about what the site does for you. Because a request that reaches our server produces an ordinary infrastructure log before any of our code runs, an opted-out visit can still appear in that log, which is described under How long we keep information.

What choosing Allow site analytics adds. Choosing it separately turns on the optional layer: the gn_vid cookie described above, which recognizes a returning browser across days, the gn_entry session key, first-touch attribution, funnel milestones, and account acquisition reporting. None of that happens under the default.

You can choose Essential only or Allow site analytics from the privacy control available on every page. Both choices are first-party settings recorded in the versioned tsa_analytics cookie for up to 90 days. Choosing Essential only removes the analytics identifier and browser-side analytics keys. If your browser sends a Global Privacy Control or Do Not Track signal, it takes priority: analytics stay off even if you previously allowed them.

We measure traffic with our own first-party page analytics. Records created after you choose Allow site analytics carry the coarse source class, page path, device class, browser word, daily session identifier, internal-visit flag, and the gn_vid value described above, which lets us recognize the same browser across days. No location is recorded; see Location. Records created before August 2026 also carry the referring site's hostname, and some carry an approximate location from a lookup we have since removed. We have not altered or deleted those older records, and no new record carries either field. There is no cross-site tracking, and analytics data is never shared with third parties or used for advertising. Your IP address is used elsewhere for rate limiting and security, as described under What we collect and How long we keep information.

The one word about your browser. A large share of web traffic is now automated, and we could not tell how much of ours was, because we do not keep the header that would say. So from July 2026 each pageview also stores a single word for what the visitor identified itself as: human, search-crawler, ai-crawler, or unknown. It is worked out from the browser's user agent at the moment the pageview arrives, and only that word is kept. The user agent itself is never written to our database. It is present in the ordinary server request log, which, like nearly every website's, records the address, the user agent, the path and the status of each request; that log is described under How long we keep information and is kept for 30 days. We are separating those two things deliberately: an analytics record is something we built and can promise about, and a request log is infrastructure that every site has. We chose a single word rather than storing the header because four words cannot describe a person or a device, and the header can. Pageviews recorded before this shipped have no value here and never will: their user agent was already discarded, which is the point.

That word is now always human on a new record. The other three used to be stored and then excluded from our reports. A request that classifies as a search crawler, an AI crawler, or an agent we do not recognize is now refused before any record is written, so it is not measured, not retained, and not counted in any total. Records created earlier still carry the value they were written with, and we have not altered them.

Alongside page views, we record a small number of first-party site funnel milestones so we can measure how well the site works overall. These cover: a sign-up or profile being completed, coach contact details being revealed, a sign-up or upgrade prompt being shown, a checkout being started, reaching halfway or near the end of a guide, and the steps of the assessment (opened, started, read delivered, save clicked). Each milestone is stored with the same daily-rotating session hash described above and a coarse category for the page the visit started on. These records contain no name, email, IP address, or user agent, are not linked to your account or identity, and carry none of the answers you entered into the assessment.

When our authentication provider confirms that you are signed in and you have chosen Allow site analytics, we also mark that day's rotating session hash as authenticated. This keeps automated-traffic cleanup from discarding real signed-in browsing. The marker stores no account ID, name, email, IP address, or user agent, and a public analytics event cannot create it. It used to be written for every signed-in visit regardless of your analytics choice, which contradicted the promise on this page that Essential only creates no analytics record. It is now gated on that choice, so an Essential only or privacy-signal browser creates no marker.

If you create an account, we also keep one account acquisition record so we can measure whether search and other channels produce accounts and paid subscriptions. It stores a coarse source category (organic search, social, referral, direct, or unknown), the first Tessaira page resolved transiently from the browser's gn_vid, and the times the account was created, a checkout was successfully created, and a paid subscription was first confirmed. It does not store your IP address, browser user agent, search query, or a history of pages. The gn_vid itself is discarded and is never stored on the account-linked record. The record is linked to the account so a later server-to-server payment confirmation can be attributed without pretending a daily rotating session hash still identifies the same visitor. It is deleted with the account.

Location

We do not work out where you are. Your IP address is not sent to any location service, before or after you answer the question about who is setting up Tessaira. There is no such service in the product for us to send it to.

This used to be different, and the change is worth stating plainly. Every page view previously sent your full IP address to an outside company to turn it into a country, region, and city. That company was a free service we had no contract with, so we could not tell you what it did with the addresses it received. We removed the lookup rather than keep describing it.

We also do not guess. A few things about a request hint at location — your browser's language setting, the network you arrive on, your device's time zone. We do not read any of them to estimate where you are, and we do not fill in a location from the state you pick for the weekly email. A guess stored in a record that says “location” is worse than no record at all, because nobody reading it later can tell the difference.

A ZIP code used to travel a worse way, and that history is worth stating plainly. A free tool on an earlier version of this site took a five-digit ZIP code to suggest events near you. A ZIP code is a location: it travelled in the web address, so it reached the ordinary request logs, it was counted against your network address, and it was sent to an outside postal-code service, all before you had answered the question about who is setting Tessaira up. We removed that tool entirely rather than rework it, because it was not part of this launch and there was no version of it that collected less.

That retired tool is not the roadmap tool on the homepage today, and the two do not work the same way. The retired tool put your ZIP code in the web address itself, sent it to an outside postal-code service, ran before you had answered the audience question, and was counted against your network address. The homepage roadmap tool sends a ZIP code in the body of a request, never in a web address. It does not contact any postal-code service or any other outside company. Previewing a roadmap happens entirely in your browser and sends nothing to us. Saving one requires a signed-in account that has already answered the audience question, and the request is counted against your account, not your network address.

If you choose to save a roadmap to a signed-in Tessaira account, we store the five-digit ZIP code and player age you provide, together with the development stage calculated from that age. We use those values only to keep that roadmap available and up to date. We do not infer your location from your IP address or send your ZIP code to a postal-code lookup service.

Home base & travel is separate and optional.A signed-in account can save a home postal code and country for Tessaira travel checks. Before the first use, we show a separate consent notice. Only after you ask for a travel or nearby-support check do we send that saved postal code and the selected destination or home area to Google Maps. We do not send your IP address, Player Index, recruiting activity, or a browser-derived location. The result is shown for that request and is not saved as a Google route, review, photo, or provider profile. A route based on a city centre is labelled as an estimate, not an exact campus or venue route.

Course search is separate from Home base & travel.While logging a round, entering a course name does not send a request. After you enter at least three characters, only choosing Search Google Maps or pressing Enter sends that course name to Google Maps to suggest matches. After you select a match, we request its exact display name, Google Place ID, formatted address, and coordinates. We do not send your Player Index, recruiting activity, home postal code, or scorecard details. Google does not supply the golf Course Rating, Slope Rating, tee, or yardage; those remain information you enter from the scorecard.

Home base is optional. It never controls whether you can create an account, whether an event is open to you, or how Player Index is calculated. You can change or remove it in Tessaira settings at any time; it is deleted with your account.

What you can tell us yourself, and why that is a different thing. Everything above is about what we would have to work out about you: from your network address, your browser, or a code you typed that we sent somewhere else to be turned into a place. None of that happens. What does happen is that a few optional fields let you tell us something about yourself directly, either a U.S. state you pick from a list or, on the homepage roadmap tool, a ZIP code and player age you type in, and when you do we store it, because the feature does not work otherwise. Those fields are:

  • the state on your Tessaira profile, used to place a golfer in their state's recruiting context;
  • the optional home postal code and country in Tessaira Home base & travel, used only after a signed-in family requests a Google Maps travel or nearby-support check and gives the separate consent described above;
  • the state on a saved Recruiting Readiness Scorecard, stored only when you narrow the search to a region rather than leaving it as “anywhere”;
  • the state preference on a newsletter signup, which decides which state's events the weekly email leads with;
  • the state shown on a published public recruiting profile, which is the profile state above and appears only if you switch it on, and which the server and database suppress outright for an under-13 profile. When a verified coach saves that profile to a shortlist or exports it, the state travels with the rest of what you published;
  • the five-digit ZIP code and player age you type into the homepage roadmap tool, stored only if you save that roadmap to a signed-in account, together with the development stage we calculate from that age.

A state you typed is not a location we determined, and we do not treat it as one: it is never written into an analytics record, never compared against your network address, and never used to decide what the site shows a visitor who has not filled it in. Where it is stored, it is stored because you entered it, and you can change or clear it in the same place you entered it.

Connected Gmail in Tessaira

Gmail is optional and user-controlled. Connecting Gmail first asks Google for read-only Gmail access. Tessaira uses that access only when you press Check for new messages. The server builds the search from schools you saved and email contacts you already linked to those schools; the browser cannot nominate an arbitrary mailbox query. We request only message metadata needed to show a candidate match: sender and recipient headers, subject, date, and Gmail's short preview snippet. We do not request a received message's full body or attachments, change mailbox content, run background scans, or import anything automatically.

If you explicitly import a result, we keep its Gmail message ID, sender name and address, subject, date, short preview snippet, and the school/review choices you make. That record remains separate from correspondence you type yourself. Choosing a suggested school never confirms a recruiting relationship or a program's interest.

Sending requires a second permission. The read-only connection cannot send. If you choose Enable drafting and sending, Google separately asks you to approve the narrow gmail.send permission. Every message shows the From address, one To address, linked school, subject, body, and attachment state, then requires a separate final confirmation. We do not request gmail.modify or full-mailbox access, and we do not send automatically, in bulk, by BCC, or as a follow-up sequence.

After Google confirms a message in Gmail Sent, Tessaira keeps the provider message ID and sent status, recipient, subject, body, sent time, and linked school as recruiting activity. Disconnect asks Google to revoke the credential and removes the encrypted local credential. Imported and sent correspondence already kept in the player file remains until it is removed or the account is deleted.

Automated processing and AI

The assessment is generated automatically. The “honest read” is produced by an automated formula (an algorithm) that runs in your browser on the inputs you enter. No person at Tessaira reviews your inputs or the result. The read is informational only: it does not make any legally or similarly significant decision about you or a junior golfer, and it does not determine eligibility, admission, financial aid, or any recruiting outcome. See the assessment section of our Terms of Use for its limits.

How interactive Ace works. Ace runs only after you ask a question or accept a clearly labeled research action. An explicit question for current event facts or a personalized event comparison can itself start the bounded public-source check; a second research click is not required. The question, up to eight recent conversation turns, and limited account-owned context relevant to the workspace page are sent from Tessaira's server to OpenAI. Ordinary conversation has no web-search tool and cannot save, send, register, or change anything. In Season, an explicit research action may also send the organizer and date focus and inspect current public pages. The returned visible chat text and validated Season event proposals can remain available to the signed-in account across reloads and tabs. A proposal remains separate from the calendar until you review and save it. The raw provider response and hidden reasoning are not stored.

Provider data use. Tessaira sets OpenAI's response request to store: false, so we do not ask OpenAI to persist the response object as application state. OpenAI states that API data is not used to train or improve OpenAI's models by default unless the customer opts in. OpenAI also states that its API abuse-monitoring logs can contain prompts and responses and are kept by default for up to 30 days, or longer where legally required. Tessaira has not represented that it has an approved Zero Data Retention arrangement, so we do not promise one here. We do not use your information to train a Tessaira model, opt this API data into provider training, sell it, or share it for advertising.

Plan allowances. Tessaira enforces the Ace limits described above with a content-free account ledger. It records the account identifier, plan category, lifetime or UTC-month scope, numeric count, and a short-lived request reservation. It does not contain the question, answer, player record, source result, provider payload, or hidden reasoning.

How the site is built. Tessaira is built using AI and automated software-development tools, and some site content and parts of the assessment are generated or assisted by automated systems. We review this content, but automated systems can produce errors or omissions, so please verify anything you rely on (tournament dates, coach contacts, scholarship or aid figures, and NCAA, NAIA, or NJCAA eligibility rules) with the official source.

Service providers

We use a small number of infrastructure providers that process data on our behalf, under their own security and privacy commitments:

  • Neon: database and authentication (United States). Stores account records, hashed credentials, newsletter signups, and operational data.
  • DigitalOcean: primary hosting (United States). Runs the servers that serve the site and produce the request logs described above.
  • Netlify: standby hosting (United States). If our primary host is unavailable, the site can be served from Netlify, which would then process the same request data.
  • Cloudflare: bot protection. On the sign-in, sign-up, and password-reset pages we use Cloudflare Turnstile to tell humans from bots. To do this, Cloudflare receives your IP address and basic browser signals. Turnstile does not use tracking cookies for cross-site advertising.
  • OpenAI: provides the language model used for interactive Ace answers and explicitly accepted public-event research. OpenAI receives the limited question, recent-turn, workspace-context, or research-focus data described under Automated processing and AI. The request is server-to-provider, uses store: false, and is not made merely because you opened Ace.
  • YouTube (Google): hosts the demonstration videos in the drill library. Nothing is requested from Google until you click to load a video; once you do, Google receives your IP address and browser user agent and may set its own storage on your device. Unlike every other provider on this list, Google is not processing anything on our behalf and does not act on our instructions. It handles that information under its own privacy policy. See Demonstration videos.
  • Resend: email delivery. Sends the account, newsletter, and stage-based emails described under Email program. Resend processes your email address and the message content to deliver it, and is not permitted to use it for its own marketing.
  • Google Gmail API: optional, account-authorized recruiting correspondence checks and one-at-a-time sends. See Connected Gmail in Tessaira for the exact metadata, separate permissions, and user controls.
  • Google Maps Platform: optional course identity, travel, and nearby-support lookups requested from Tessaira. See Location for the inputs, outputs, and consent boundary.
  • Polar: payment processing for Premium subscriptions. Handles your card details directly; Tessaira never sees or stores your full card number. Polar shares back only what we need to run your subscription (payment status, the amount charged, when the period ends, and its own customer and subscription identifiers).

Apart from YouTube, which is described above and which you have to click before it receives anything, these providers act only on our instructions and are not permitted to use your information for their own purposes. We do not give any other company access to your personal information, and we do not sell or share it.

Things that are not on this list, because they receive nothing. The coach map draws from a map file stored on our own server: there is no map or tile company involved, no key, and no request from your browser to one. We load no images from anyone else's server — your browser is not permitted to fetch one. We do not display tour, conference, or event logos, because we have not recorded permission to republish them, so those appear as text instead. And there is no advertising network, no cross-site tracking, and no behavioural analytics company anywhere in the product.

One that used to be on this list. An IP geolocation service received a complete IP address on every page view and every email signup, so that we could record an approximate city. It was a free service with no contract and no agreement with us, which meant we could not tell you what it did with the addresses it received — and that is not a footnote to disclose, it is a reason not to send them. The lookup has been removed and no location service receives an IP address or inferred location. See Location.

And one more. A free postal-code service received the ZIP code entered into a local-events tool, in order to turn it into a city and state. That was worse than the geolocation lookup above: no contract, and it ran before the visitor had answered the question about who is setting Tessaira up. That tool has been removed from the product entirely. The homepage roadmap tool does ask for a ZIP code today, but it does not send that ZIP code to a postal-code service or to any other outside company; it only reaches our own database, and only if you save it to your account. See Location.

Directory data

The Tessaira directory aggregates publicly available information about college golf coaches published by their schools and institutions, such as institutional email addresses on athletics websites. Event and rankings coverage is editorial and links parents to the relevant official organizer where appropriate. This is information about public programs and roles, not private individuals' personal lives, and coach contact details are gated behind Premium to discourage bulk collection.

Coach and institution listing removal

If you are a coach or represent an institution listed in our directory and your listing is inaccurate, or you would prefer not to be listed, email angelo@tessaira.com from an institutional address and we will correct or remove the listing.

How long we keep information

Two different things are described below, and we have tried to keep them plainly apart. Some of these periods are enforced by the software: the deletion happens because you did something and the code carries it out. Others are periods we have committed to and carry out by hand — they are real commitments, but there is no automatic job behind them yet, and we are not going to describe them as if there were.

  • Default page view records and their daily identifiers: 30 days. Deleted by a daily job, not by hand. Row-level detail is only needed for the recent operational window.
  • Daily identifier keys: 2 days, then destroyed. After that, the identifiers on any older record cannot be recomputed from anything in our live database. Deleted by the same daily job. As with every period on this page, that describes deletion from the live database; a provider backup or point-in-time snapshot keeps a copy until it ages out.
  • Daily totals: 25 months, which allows one year-over-year comparison and no more. These are counts by day, page category, source class, and device. They contain no session identifier, no visitor identifier, no full page path, and no time of day, so a single visit cannot be picked out of them. Deleted by the same daily job.
  • Analytics recorded before August 2026 and funnel milestones: 25 months. Carried out by hand today, not automatically.
  • Server request logs (IP address, user agent, path, status): 30 days. Carried out by hand today.
  • Rate-limiting records: 24 hours. These are the counters that stop one machine hammering a form; the key is derived from a network address, so we do not keep them past the day they were counting. Deleted by a daily job, not by hand.
  • Your answer to the question about who is setting Tessaira up: the answer stops being usable after 12 months, enforced by the record itself and by the cookie. We then keep the record of what you agreed to, and when, for a further 365 days — a total of 730 days from the day you answered — so that if anyone asks what we were relying on when we emailed you last March, we can answer. Deleted by the same daily job. If you delete your account or unsubscribe, the link between you and that record is removed straight away; what stays is an anonymous record with no subject attached to it.
  • Subscription and payment records: kept for seven years after the subscription ends, because they are financial records. This is the one category that deliberately outlives account deletion.
  • Unsubscribe records: kept indefinitely, on purpose. If we deleted the record that you unsubscribed, the next signup or import would email you again. It is a short record — your address and the fact that you opted out.

What “deleted” means here. Every period above, including the analytics periods, describes deletion from the live database. Our database provider keeps automated backups and a point-in-time recovery window, and we have not yet confirmed how long a deleted row can persist inside one. Until we can state that period, treat “deleted” as deleted from the live database and still present in a provider backup until that backup ages out on the provider's own schedule.

When you delete your account, the account-scoped items below are deleted with it, subject to the same backup limitation.

  • Account data: kept until you delete your account or ask us to delete it.
  • Saved assessment reads: an unsaved read stays on your own device and lasts until you clear it (through the app's controls or your browser storage). A read you save to a signed-in Tessaira account is also stored on our servers and is kept until you delete the entry, reset dashboard data, or delete your account. After entry deletion or a reset, we retain an account-scoped request key, a hash of the submitted answers, reset counter, and removal timestamps to stop an old save request from restoring the removed entry. These receipts do not retain the answers themselves and are removed with the account.
  • Round and practice log: kept until you clear it or delete your account. There is no automatic expiry — a round logged today is still there in five years unless you remove it. You can delete any single round from the tracker itself, which removes that round and its statistics and note immediately. Reset dashboard data in Tessaira settings deletes every logged round (with its statistics and note), every practice session, and every cleared milestone on the account, and deleting your account deletes them too. All three are available to any signed-in account, free or Premium.
  • Email signup data (newsletter, roadmap, quiz): kept until you unsubscribe or ask us to remove you.
  • Saved drills, saved schools, saved-school recruiting records, and planned tournaments: kept until you remove them from your saved lists. All three are also removed when you delete your account and cleared by Reset dashboard data in Tessaira settings.
  • Public recruiting profile: the selected fields remain public until you unpublish. After unpublishing, we keep the private configuration and reserve its random URL until you publish again, clear dashboard data, or delete your account. Reset and account deletion remove the profile, its selected public schedule, and the profile-view analytics association.
  • Tessaira profile: the graduation year, boys or girls golf, optional U.S. state, optional grade-point band, optional player name, and optional recruiting goal (including division target and program tier) are kept until you change them, clear dashboard data, or delete your account. There is no expiry; the row is overwritten in place each time you save it.
  • Coach outreach log: the school, coach, template, channel, state, timestamps and your optional note are kept until you clear dashboard data or delete your account.
  • College coach account application: the institutional email address, the program claimed, the verification state, the review record and the digest settings are kept for as long as the coach account exists, and are deleted when that account is deleted. The audit trail of what was done to the application — including the institutional address that acted — is deleted with it.
  • Private coach prospect list: a saved profile, its relationship stage and its private note are kept until the coach removes that entry or their coach account is deleted, and are removed automatically if the player's family deletes the published profile the entry points at. A spreadsheet a coach has already downloaded is a file on their own device and is outside anything we can delete; that is a limit of an export, and we state it rather than implying otherwise.
  • Player ranking snapshots: kept as a dated history until you remove an entry, clear dashboard data, or delete your account.
  • Recruiting-plan checkmarks: the items you have ticked off or dismissed on your plan, and — when you check off an event that has already happened — whether your golfer played it and the score you entered, are kept until you clear them with Reset dashboard data or delete your account.
  • Coach email reveals: an older version of the site recorded which school's coach contacts an account had unlocked, and when. We no longer write those records. One row from that period still exists and is deleted when that account is deleted; nothing new is added. If we start keeping this record again, to spot bulk collection of coach addresses, we will say so here first.
  • Analytics (page views and funnel milestones): the daily session hash cannot be linked across days by design; the underlying records are kept in aggregate for reporting. A public profile view is labeled with that profile's random slug so its owner can receive an aggregate view count later; it never identifies a coach or visitor, and deleting the profile removes that slug association.
  • Authenticated-session analytics marker: the daily rotating session hash and the times it was confirmed as signed in are retained with analytics reporting. It carries no account identifier and cannot be linked across days.
  • Account acquisition record: the coarse source, first Tessaira entry page, and signup, checkout, and first-paid timestamps are kept until you delete your account. They are used only for Tessaira conversion reporting, not advertising.
  • gn_vid cookie: lasts 90 days from when it is set unless you clear your cookies sooner. This entry previously said one year, which never matched the cookie the code actually writes; 90 days is the real period and matches the description under Cookies.
  • gn_stage_affinity and gn_first_touch: stay in your browser's local storage until you clear them. Submitting your email copies the relevant snapshot into that signup record but does not remove the keys from your device.
  • tsa_shortlist: 30 days from the last time you added or removed a school, after which your browser's copy is discarded the next time the page reads it. It never reaches our servers unless you sign in and explicitly choose to add those schools to your account; if you do, what is stored is the same saved-schools list a signed-in save would have created, and it is covered by the account periods above.
  • Approximate location: no longer collected at all. The columns that held it on older page views and signup records are now always empty, and nothing writes to them. Values recorded before the lookup was removed are covered by the page-view and signup-record periods above and age out with those records.
  • Anonymous roadmap preview: the ZIP code and player age you enter to preview the homepage roadmap tool stay in your browser. They are not sent to us at all unless you sign in and choose to save the result.
  • Saved roadmap preference: kept until a newer save replaces it, until you ask us to delete it, or until you delete your account. See Location.
  • Home base & travel preference: the optional postal code, country, consent version, and consent time are kept until you remove Home base or delete your account. Google Maps travel and nearby-support responses are not stored. See Location.
  • Ace conversation and Season planning: the visible Ace thread is kept as a bounded eight-turn account record for each workspace page. Season can also keep up to 12 validated, family-visible event proposals. The thread, proposals, family-confirmed Season brief, closed planning choices, and candidate decisions are kept until you restart the relevant Ace thread or Season plan, use Reset dashboard data, or delete your account. A saved event then follows the planned-tournament period above. Provider-side handling of a live Ace request is described under Automated processing and AI.
  • Ace message allowance ledger: the account, plan category, lifetime or UTC-month scope, and numeric count are kept until account deletion. A request reservation is normally settled or released when the request finishes; stale reservations stop counting after 15 minutes. Reset dashboard data does not erase this ledger because a reset must not restore messages that were already used. Account deletion removes both counters and reservations.
  • Premium Beta feedback: kept for no more than 90 days and deleted by the daily retention job. An explicitly attached screenshot is stored in the same report and is deleted with it. Deleting the account removes its reports immediately. The text-only owner-mailbox copy is separate from this 90-day product-support record and follows the mailbox's operating retention. Reset dashboard data does not delete a report that was already submitted, because it is a product-support record rather than part of the player workspace.
  • Premium beta request: kept while the request is open. Once the request is closed, the record is deleted by the daily retention job 90 days after the close date. Deleting your account deletes the request immediately when the request is linked to that account or when the account email matches the request email. The text copy emailed to angelo@tessaira.com follows the mailbox's operating retention.
  • Retired ZIP lookup tool: an earlier version of the site had a free tool that took a five-digit ZIP code to suggest local events and sent that code to an outside postal-code service before you had answered the question about who is setting Tessaira up. That tool has been removed from the product entirely; it is history, not a current data flow. See Location.
  • Rate-limiting records: to enforce request limits we keep a counter keyed to an IP address or an account. The limit window itself is an hour or less. We use these records only to slow abuse, never for analytics, profiling, or advertising.
  • Server and security logs: 30 days, the same period given under How long we keep information. They record the request address, the browser user agent, the path and the status. Carried out by hand today, not by an automatic job — this bullet used to say “a short period, then rotated out”, which is not a period and was not the number stated elsewhere on this page.

Your rights and choices

You can access, correct, or delete your information at any time:

  • Account deletion: delete your account yourself anytime from account settings (Danger zone), which removes every record we hold against your account — your profile, saved schools and their recruiting records, public recruiting profile and its selected schedule, saved drills, planned tournaments, ranking snapshots, saved reads, outreach history, recruiting-plan checkmarks, Ace conversation settings, the Ace message allowance counters and request reservations, the saved Season brief and candidate decisions, Home base, connected-Gmail credentials and correspondence records, any saved Recruiting Readiness Scorecard, your newsletter subscription and any record of emails we have sent you, any legacy coach-unlock row still held from the older version of the site, and your whole tracker log, meaning every round with its statistics and note, every practice session, and every cleared milestone — and cancels any Premium subscription immediately. You can also email angelo@tessaira.com from the address on your account and we will delete it for you.
  • Clearing your data without deleting your account: Reset dashboard data, in Tessaira settings, wipes the player profile, its public recruiting page, ranking snapshots, saved reads, saved schools and their recruiting records, saved drills, planned tournaments, outreach history, recruiting-plan checkmarks, readiness items, calendar items, imported Gmail message metadata and Inbox records, Coach Loop records, the family-confirmed Season planning brief and candidate decisions, Home base, and the entire tracker log from our servers. It leaves the account, email, and subscription in place. It also preserves a few account-level safety and operating controls: the player age-band confirmation used to protect optional provider features; the Gmail connection, which you remove with Disconnect; the technical Gmail send receipts that prevent an accidental resend; the completed tutorial marker; and the content-free AI spend and Ace message allowance ledgers; and the assessment request receipts and reset counter described above. Your saved Recruiting Readiness Scorecard also remains until you retake it or delete your account. A legacy row from an older version of the site recording that an account had unlocked a school's coach contacts is no longer written and is also left alone. Deleting your account removes these account-scoped records. See how long we keep information, above.
  • Saved reads: a read you never saved to an account is on your device — clear it in the “Tessaira” screen or by clearing your browser storage. A read you saved while signed in is also on our servers; remove that copy by deleting the entry in Tessaira, by using Reset dashboard data, or by deleting your account.
  • Email signups: use the unsubscribe link in any email to stop all future messages, or the journey link in the same footer to pick a different stage. You can also email us and we will remove you.
  • Cookies and local storage: clear any of the cookies or on-device keys listed under Cookies and local storage at any time through your browser's cookie and site-data settings. This does not affect your account or email subscription, which are stored separately.
  • Access and correction: email us and we will tell you what we hold about you and fix anything that is wrong.

If you live in California or another U.S. state with a consumer privacy law (such as Virginia, Colorado, Connecticut, or Texas), you have rights over your personal information, including the right to know or access what we hold, the right to correct it, the right to delete it, the right to data portability, and the right not to be discriminated against for exercising these rights. To exercise any of them, email angelo@tessaira.com from the address associated with your information; we may ask you to confirm a few details to verify the request before we act on it, and we honor these requests regardless of the state you live in. You may use an authorized agent. For clarity under these laws: we do not sell your personal information, we do not share it for cross-context behavioral advertising, and we do not offer financial incentives for your data. We do not use or disclose sensitive personal information, including a minor's information, beyond what is necessary to provide the Service.

Children's privacy and the honest read

Tessaira is built for parents, guardians, and junior golfers. The parts that involve a specific child are used through a family account owned by a parent or guardian. A player under 18 can build their file with that adult; they do not create a direct child account. See the question we ask first — including what it is not.

We do not operate verifiable parental consent. The question described above is a self-declaration, not verification, and no checkbox or notice on this site is verifiable parental consent under the Children's Online Privacy Protection Act. We do not allow a child under 13 to create an account, subscribe, or directly submit information. A parent or guardian who is setting Tessaira up provides and manages player information under their own account, and can remove it at any time.

The journey quiz and a young player's age. The quiz asks roughly how old the player is so it can point you at the right guidance, and two of its answers describe a child under 13. On the page, that answer is just guidance and never leaves your browser. We only attach it to an email address or an account when an adult has answered the question above; otherwise it is discarded rather than stored beside anything that identifies a person.

What the assessment collects. The honest read asks a few questions about a junior golfer so it can produce an estimate: the player's age (10 to 18), gender, typical scoring range, the level of events they play, and any ranking, plus a few optional details. It does not ask for the player's name, email, address, photo, school, or any other direct identifier, and it never asks for free-text input. If you ask for the read as a PDF, that separate form asks for your own email address, not the player's.

Where the read is stored. The read is calculated in your browser. If you do not save it to an account, it stays on your own device in your browser's local storage and never reaches us. If you are signed in and save it to Tessaira, we store a copy on our servers, tied to your account, so the tracker can show progress over time. That copy contains the answers you gave the assessment: the player's age and gender, their scoring band, the level of events they play, and any ranking you entered. It does not contain their name, photo, school, or any other direct identifier, because the assessment never asks for those. You can remove it by deleting the entry in Tessaira or by deleting your account, which erases the saved reads with it.

What the tracker stores, and where. The “My Player” tracker keeps a log of rounds and practice. Logging is free: any signed-in account can do it, and there is no Premium requirement to write to it or to delete it. Every round you log is stored on our servers, tied to your account — the date, the score, the course par, how many holes, whether it was a tournament, any of the per-round statistics you choose to enter (fairways, greens in regulation, putts, up-and-downs, penalties, three-putts), an event or course name if you add one, and a note if you write one. Practice sessions (date, drills, minutes) and the milestones you mark as cleared are stored the same way. Put together, that is a running record of a specific child's competitive results over time, held on our servers against a parent's account. We are telling you that plainly because it is more than the assessment holds and it accumulates.

The note is free text and we do not filter it. Unlike the assessment, which only ever offers fixed choices, the note and the event name accept anything you type, and we store it exactly as written. If you type your golfer's name, their course, their coach, their school, or how they were feeling that day, that is what sits in our database. Nothing in the product requires it — a round needs only a date, the holes, a score, and a par — so if you would rather we held none of that, leave the note and the event name blank. The log works the same either way.

We do not knowingly permit a child under 13 to create a direct account or directly submit information. The Service is directed to parents and guardians, not to children. We do not ask children to create accounts. Accounts and email signups (newsletter, roadmap, quiz) are intended for adults, not children. Where information about a child is provided, the adult account owner is responsible for providing and managing it.

No profiling or advertising to children. We do not use any information about a minor to build advertising or behavioral profiles, we do not serve targeted advertising, and we do not sell or share a minor's information. There are no third-party advertising trackers anywhere on Tessaira.

Videos, and what reaches Google. Some drills include a demonstration video hosted on YouTube. Nothing is sent to Google while the page sits there. If your golfer clicks to load one, Google receives their IP address and browser user agent at that moment and may set its own storage on the device, under Google's privacy policy rather than ours. We do not control that and we receive nothing back from it. If you would rather that not happen, the drill works without the video. See Demonstration videos for the full description.

Parental review and deletion. A read you never saved to an account is on your device: review it in the “My Player” screen and delete it instantly with the clear control there, or by clearing your browser's storage. Everything held on our servers — the saved read, the profile, and the whole tracker log with its statistics and notes — is shown back to you in My Player. Any single round can be deleted from the tracker on its own, and you can erase everything yourself in two ways: Reset dashboard data in Tessaira settings, which wipes that data and leaves the account standing, or deleting the account, which removes it and cancels any subscription. Both work on any signed-in account, free or Premium — removing a minor's data is not a paid feature. To review or delete any information we hold about a minor, including an account created for a junior golfer or an email in our newsletter list, email angelo@tessaira.com and we will respond promptly and without charge. If you believe a child under 13 has given us information directly, contact us and we will delete it.

Security

We take reasonable measures to protect your information: traffic is encrypted in transit, passwords are stored only in hashed form by our authentication provider, and the Service enforces rate limits to slow abuse. No website can promise perfect security, but we keep the amount of data we hold small on purpose. The best protection for data is not collecting it: the assessment runs in your browser, a read you do not save never leaves your device, the assessment never asks for a player's name, and the tracker requires only a date, the number of holes, a score, and a course par — every statistic, event name, and note is optional. What you do save to an account is on our servers, described above, and deletable by you at any time.

Changes to this policy

If we change this policy, we will post the updated version here with a new effective date. If a change meaningfully affects what we collect or how we use it, we will make that clear rather than bury it. That includes changes we should have written down sooner: this page previously said a saved assessment read stayed on your device and never reached our servers, which was wrong once saving a read to a signed-in account began storing a copy against it. We corrected that in July 2026 and described exactly what the copy contains, rather than quietly softening the old wording, and we disclosed the My Player tracker's round and practice log the same way. We would rather tell you more than we strictly have to than leave something out.

Contact

Privacy questions, requests, and listing-removal requests: angelo@tessaira.com. See also our Terms of Use.

Privacy Policy | Tessaira