Privacy Policy
Last updated: 7 September 2026
Why Not I Ltd
1. Who we are
Why Not I Ltd (“Why Not I”, “we”, “us”) is a company registered in England and Wales. We provide a behavioural performance platform to sporting organisations.
Registered address: 1st Floor Cannon Mill, Gunco Lane, Macclesfield SK11 7JL
Company number: 15020809
Contact for privacy matters: privacy@whynoti.co.uk
We have not appointed a Data Protection Officer. Our processing is not carried out on a large scale within the meaning of Article 37(1)(c) of the UK GDPR, and we keep this under review as the number of organisations we work with grows.
2. Who this policy is for
This policy applies to:
- Athletes who use the platform through their club, academy or organisation
- Staff at those organisations who use the platform in their professional role
- Parents and guardians of athletes under 18
- Visitors to whynoti.co.uk
Where an organisation deploys the platform, that organisation will also have its own policies covering how it handles player information. This policy covers what we do. It does not replace anything your club tells you.
3. Our role
Our role is split.
We act as a processor, on the instructions of the client organisation, for the operational use of the platform — check-ins, journals, trends, staff visibility, support requests and welfare routing. The organisation decides to deploy the platform, decides who uses it, and decides what to do with what it sees.
We act as a controller for our own purposes — analysis and improvement of the behavioural model, security and service administration, research where separate agreement has been given, and our own business contacts and website.
Where we act as processor, the client organisation is the controller and its own privacy information applies alongside this policy. Where we act as controller, this policy governs.
4. What the platform does
Athletes complete two short structured check-ins a day. They can keep a private journal and raise a request for support.
The platform builds a picture of an individual athlete’s normal pattern over time and highlights movement away from it. Staff at the organisation see an indication of state and direction — whether someone might benefit from a conversation. Staff do not see numeric scores, rankings, or any comparison between athletes.
The platform is not a clinical or mental health service. It does not diagnose, assess, treat or provide care, and it is not a substitute for medical, psychological or safeguarding support. It surfaces behavioural signals and routes them to people who already hold responsibility within the organisation. Every decision about an athlete is made by a person, not by the platform.
5. The information we process
5.1 Account and profile information
Name, preferred name, date of birth, email address, mobile number, sport, club or team, role, notification and display preferences, acceptance of terms, and account status.
Profile photographs are not enabled and no images are stored.
5.2 Security information
Password (stored only as a cryptographic hash), records of failed sign-in attempts and account lockouts, invitation and password reset tokens, session tokens, and two-factor authentication settings.
5.3 Check-in and behavioural information
Responses to structured check-in questions, the dates and times of submissions, situational context an athlete chooses to record, requests for support and how they were resolved, individual baselines, derived measures and trends, and completion rates.
5.4 Journal entries
The text of entries, whether an entry is private or has been shared, and timestamps. See Section 7.
5.5 Organisation and system records
Records of support requests and welfare signals and where they were routed, notification records, organisation settings, and audit logs.
Staff cannot record free-text notes about athletes within the platform. This functionality does not exist.
5.6 Technical information
When the platform is used we automatically record the requested route and method, response status, response time, database query and error counts, and network metadata. Our website and hosting providers record IP addresses, request headers and access logs.
5.7 What we do not collect
We do not collect location or GPS data, advertising identifiers, or device fingerprints. We do not use tracking for advertising purposes and we do not sell personal information to anyone.
6. Special category information
Information about how someone is feeling and their psychological state is health information, which is treated as special category data under Article 9 of the UK GDPR and given additional protection in law.
We recognise this. The fact that the platform is not a clinical service does not change how the information is classified, and we treat check-in responses, journal entries and welfare-related records as special category information throughout.
7. Journal entries
This section describes a deliberate design decision and is stated in full because athletes are entitled to rely on it.
Private journal entries are inert. They are not read by staff. They are not read by us in the ordinary course of operating the platform. They are excluded from every trend, score, measure, insight, monitoring process and welfare signal. Nothing written in a private journal changes anything a member of staff sees, directly or indirectly.
There is no monitoring of journal content. There is no automated flagging, no distress detection, and no scanning of entries for words or themes. This applies equally to adult athletes and to athletes under 18.
Entries are private unless the athlete chooses otherwise. An athlete may choose to share an individual entry with staff. Sharing is always an explicit, entry-by-entry decision. Nothing is shared automatically or by default. A shared entry can be read by staff at the organisation, but even a shared entry does not feed any trend, score or measure.
Private entries do not appear to staff in any form. Staff are not shown the content, the fact that an entry exists, when it was written, or whether an athlete keeps a journal at all. Nothing about a private entry is communicated to staff, directly or indirectly.
Athletes can see their own journalling streak. This counts only whether an entry was written, never anything about what it says, and it is visible to the athlete alone. It is not shared with staff and it is not compared against other athletes.
Because journal entries are not monitored, the journal must not be relied upon as a route for raising something urgent. If an athlete needs help, the platform provides a support request, and the organisation’s own welfare and safeguarding routes remain available at all times.
8. Our lawful basis
We process on the basis of legitimate interests under Article 6(1)(f) — the organisation’s interest in supporting the welfare and performance of its athletes — together with the athlete’s explicit consent under Article 9(2)(a) for the special category element.
We are aware that consent given within an employment or academy relationship can be questioned on the grounds that it may not be freely given. Our response is to make the consent genuinely free in practice:
- Athletes who decline are not enrolled, and non-participation carries no consequence for selection, contract or standing. This is written into our agreement with the organisation
- Withdrawal is available in the app, takes effect immediately, and requires no conversation with anyone at the club
- Consent to research is sought separately and declining it changes nothing
The following are settled and will not change:
- An athlete’s participation is voluntary and an athlete may stop at any time
- An athlete may withdraw their agreement to welfare routing at any time, and processing for that purpose will stop
- Withdrawal is available from within the app and does not require the athlete to ask anyone’s permission
- For research, agreement is sought separately and specifically. It is never bundled with agreement to use the platform, and declining it has no effect on an athlete’s access to anything
9. What we use the information for
| Purpose | What this involves |
|---|---|
| Providing the platform | Creating accounts, delivering check-ins, storing responses, showing athletes their own information |
| Producing insight for the organisation | Generating individual trends and state indicators for staff, within the visibility limits in Section 10 |
| Routing welfare signals | Directing indications that an athlete may need support to the appropriate staff, as described in Section 11 |
| Notifications and reminders | Prompting athletes to complete check-ins |
| Support and administration | Responding to requests, managing accounts, maintaining the service |
| Security | Detecting and preventing unauthorised access, maintaining audit records |
| Improving the platform | Analysis of usage and of the behavioural model, using aggregated information |
| Research | Only with separate, specific agreement |
We do not use personal information for advertising, and we do not use athlete information to train AI models.
10. Who can see what
Athletes see everything held about them, including full numeric detail of their own responses, measures and trends, and their own journal.
Staff see information only for athletes at their own organisation, and only within their role. Staff never see:
- Numeric scores of any kind, for any athlete or team, including on chart axes
- Any single combined or composite score — none is calculated or stored anywhere in the platform
- Rankings or comparisons between athletes
- The structure of the underlying behavioural model
- Private journal entries, in any form — including their existence, their timing, or whether an athlete journals at all
Staff do see indications of state and direction, check-in completion, situational context an athlete has recorded, journal entries the athlete has expressly chosen to share, and support requests.
Organisation administrators manage users and settings for their own organisation only.
Why Not I administrators have technical access to the platform for support, security and maintenance. This access is limited to named individuals, is recorded in audit logs, and is used only where necessary to operate the service.
11. Welfare routing
Where check-in responses indicate that an athlete may benefit from support, the platform routes an indication to the appropriate staff at the organisation — typically player care, welfare, or the organisation’s safeguarding lead. It does not appear on a coaching dashboard.
Three things follow from this:
- The routing uses check-in responses only. It never uses journal content.
- It requires the athlete’s agreement, given at onboarding and withdrawable at any time. Where an athlete has not agreed, or has withdrawn, the platform is not used for this purpose in relation to them.
- It ends with the organisation. A signal is passed to a person at the organisation, who acts under the organisation’s own welfare and safeguarding policies. Why Not I does not assess risk, does not make decisions about any athlete, and does not hold a duty of care towards athletes.
The platform does not use clinical language and does not make clinical statements about anyone.
12. Automated processing
The platform processes information automatically in order to produce what athletes and staff see. It calculates measures from check-in responses, builds an individual rolling baseline for each athlete from their own history, and identifies where current responses differ from that individual baseline.
This is profiling under data protection law, and we describe it plainly because athletes are entitled to understand it:
- Baselines are individual. An athlete is compared against their own normal pattern and never against other athletes
- No indication is produced until the platform has enough of an athlete's own history to be meaningful, so there is a period at the start during which the platform produces no signal at all
- No indication is ever produced from a single response
- No combined score is calculated at any point
The platform also runs internal checks on data quality — for example, identifying where responses appear to have been submitted without being considered. These checks affect how much weight the platform gives to the information internally. They are never shown to staff and are not a judgement about the athlete.
No decision about an athlete is made by the platform. Every output is a prompt for a human being to have a conversation. Decisions about selection, participation, medical care, welfare and safeguarding are made by people at the organisation, using their own judgement and their own processes. We do not carry out automated decision-making producing legal or similarly significant effects within the meaning of Article 22.
13. Artificial intelligence
The platform uses an AI service provided by Anthropic to generate short written reflections back to the athlete on their own check-in responses.
What is sent. A constructed summary containing labelled check-in values and recent trends from the last fourteen days.
What is not sent. Names, athlete identifiers, dates of birth and organisation details are not sent. The information sent is pseudonymised.
Journal entries are never sent. Journal text does not leave the platform. This is enforced in the platform’s own database logic rather than by a setting.
The reflection produced is stored alongside the check-in and kept for the same period. Athletes can turn reflections off for themselves at any time.
We use Anthropic’s standard commercial terms, under which the information we send is not used to train AI models and is retained by Anthropic only for a limited period for operational and safety purposes. A data processing agreement, including standard contractual clauses, forms part of those terms.
If we later introduce any feature that involves AI processing of journal content, it will require fresh, specific agreement from athletes and an update to this policy. It will not be introduced by changing a setting.
14. Who we share information with
We do not sell personal information and we do not share it for advertising.
We share information with the athlete’s own organisation, as described in Section 10, and with the service providers we rely on to operate the platform:
| Provider | What they do | Where |
|---|---|---|
| Railway | Hosting, database and storage | Amsterdam, Netherlands |
| Vercel | Web application hosting | London, United Kingdom |
| Lovable | Website hosting and enquiry form storage | See provider’s terms |
| Cloudflare | Network and content delivery | Global network |
| Resend | Invitation and password reset emails | United States |
| Anthropic | AI reflections (Section 13) | United States |
| Apple | Push notifications to iOS devices | United States |
| Push notifications to Android devices | United States |
Each is bound by a written contract requiring them to process information only on our instructions and to keep it secure.
Push notifications contain only a device token and generic text such as a reminder to complete a check-in. No personal or behavioural detail is sent to Apple or Google. Any detail is retrieved from our own systems after the app is opened.
We may also disclose information where we are required to do so by law, or where it is necessary to protect someone’s vital interests.
15. Information held outside the UK
Our primary hosting is in the Netherlands. Some of our providers operate in the United States. Where information is transferred outside the UK, we rely on the appropriate safeguards provided for in data protection law, including UK adequacy regulations where they apply and the International Data Transfer Addendum to the European Commission’s standard contractual clauses where they do not.
16. How long we keep information
| Information | Retention |
|---|---|
| Athlete account and behavioural information | For the duration of the organisation’s contract, and for twelve months after an athlete leaves the organisation. Then deleted. |
| Journal entries | As above, and deleted immediately if the athlete deletes them |
| Email delivery records (Resend) | 30 days |
| Security and audit logs | 12 months |
| Aggregated information | Retained indefinitely, where it can no longer identify anyone |
| Website enquiries | 24 months from last contact |
We treat information generated at pilot scale as pseudonymised rather than anonymised, and therefore as still within the scope of data protection law. A small squad at a single named organisation, with dates attached, is plausibly re-identifiable to anyone holding a team sheet, and we do not claim otherwise. We do not describe information as anonymised — in this policy, in club material, or in any research output — unless a dataset is large enough that the claim genuinely holds.
17. Security
- All information is encrypted in transit using HTTPS/TLS
- Stored information is encrypted at rest by our hosting provider
- Passwords are stored using bcrypt hashing and are never stored in readable form
- Session tokens on mobile devices are held in the device’s secure storage
- Two-factor authentication is required for all staff accounts and available to athletes
- Access is restricted by role, and administrative access is recorded in audit logs
No system can be guaranteed completely secure, but we take these measures seriously and review them as the platform develops.
18. Deleting an account
An athlete can request deletion of their account from within the app, in account settings.
Deletion removes the account and the personal information held in it, including check-ins, trends and journal entries. We may ask the athlete to confirm their identity and confirm the request, to protect against accidental or unauthorised deletion.
Where we are required by law to retain particular information, we will retain only what is required and only for as long as it is required.
19. Your rights
Under UK data protection law you have the right to:
- Be informed about how your information is used — this policy
- Access the information held about you
- Have inaccurate information corrected
- Have information erased in certain circumstances
- Restrict how your information is used
- Object to certain processing
- Receive your information in a portable format
- Withdraw agreement at any time, where processing relies on it
- Not be subject to decisions made solely by automated means with legal or similarly significant effects
Athletes can see all of their own information within the app at any time. To receive a copy of your information in a portable format, contact us at privacy@whynoti.co.uk.
Where we are acting as processor for an organisation, we will pass the request to that organisation and support them in responding. We will acknowledge within five working days and a response will follow within one month.
20. Athletes under 18
The platform is used by athletes aged 16 and over. It is not offered to anyone under 16.
Where an athlete is under 18:
- A parent or guardian must give their agreement before the athlete takes part, and the athlete must also agree themselves
- A separate information sheet is provided to parents and guardians explaining what the platform does in plain terms
- A parent or guardian may withdraw their agreement at any time, and the athlete may withdraw their own agreement at any time
- The protections in Section 7 apply in full — journal entries are not monitored, and this does not change because an athlete is a minor
We have regard to the Information Commissioner’s Age Appropriate Design Code in designing the platform, including keeping settings private by default, collecting no more information than is needed, and explaining what happens in language a young person can understand.
21. Our website
whynoti.co.uk sets no cookies of its own and uses no analytics or tracking of any kind. There are no third-party trackers, advertising scripts or embedded content on the site.
Our hosting provider may set essential security cookies necessary for the site to operate. These are strictly necessary and require no consent under the Privacy and Electronic Communications Regulations.
When you use the enquiry form on our website we store your name, email address, organisation, role and message so that we can respond to you. This information is held in our own systems and is not shared with any third party. We keep it for 24 months from our last contact with you, and you can ask us to delete it sooner at any time.
22. Changes to this policy
We will update this policy when the platform changes. Where a change is significant — particularly any change affecting journal entries, welfare routing or AI processing — we will tell athletes and organisations directly and, where the change requires it, seek fresh agreement. We will not make a material change by adjusting a setting.
The date of the current version appears at the top of this policy.
23. Complaints
If you are unhappy with how we have handled your information, please contact us first at privacy@whynoti.co.uk so we can try to put it right.
You also have the right to complain to the Information Commissioner’s Office:
Information Commissioner’s Office
Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF ico.org.uk

