Safeguarding & privacy

Built for children’s data. Not retrofitted for it.

4CM holds information about children. That fact shaped the product before it had a first screen — and it is the reason some obvious features are missing on purpose.

The relationship

Your club is the data controller. 4CM is its processor.

Your club decides what is collected and why. We hold and process it on your club’s documented instructions, under a UK GDPR Article 28 agreement. We are not a joint controller, and we do not train AI models on identifiable data about your players.

Design decisions

Six choices that cost us features.

Anyone can publish a privacy policy. These are the places where protecting children actually changed what got built — or didn’t.

No coach-to-child messaging

The single clearest safeguarding lesson from youth sport is that unmonitored one-to-one adult-to-child channels are where harm happens. So we didn’t build one. Communication is squad-wide or goes through a parent. This costs us a feature every competitor has, and it is not up for discussion.

A closed platform, not a network

There are no public profiles, no discovery, no friend requests, no way for a stranger to reach a child. Players and parents join because their club invited them. Nobody arrives from a search result.

Player names never reach an AI model

Every AI request — session planning, video notes, the Brain — has player names replaced with pseudonyms before it leaves us. The model reasons about “Player 7”, and the name is restored on the way back. This is enforced at the point every request leaves the system, not remembered feature by feature.

Physical data always carries its context

A twelve-year-old can be two years ahead or behind in maturity, and a raw physical score hides that. So the product will not show one without its maturity context. Bio-band data is never used for selection, ranking, or release decisions.

Welfare signals go to adults, not children

If a child’s ratings drop sharply, or their wellbeing indicators slide, the coach is told. The child is not shown an alert about themselves, and neither is their parent. Wellness logs never appear in a ranked or comparative view.

No advertising, no profiling, no data sale

No ad SDKs, no marketing cookies, no third-party trackers, no selling data, and no marketing communications to anyone under 18 at all. Our own cookie policy commits to this as a rule rather than a setting.

The frameworks this is built against.

Not a badge wall. These are the specific regimes that apply to a UK service processing children’s data, and what each one means here.

UK GDPR & Data Protection Act 2018
The lawful basis for every kind of processing is written down and reviewed, and children’s data is treated as the higher-risk category it is.
ICO Children’s Code
All fifteen standards apply to every user under 18 — high privacy by default, data minimisation, no nudge techniques, transparency a child could actually follow.
Online Safety Act 2023
Assessed as an in-scope service. A risk assessment, published community standards, a reporting route on every screen and a complaints process that reaches a human.
FA safeguarding practice
Coaches evidence a current enhanced DBS check and FA safeguarding training. Clearance is tracked, warned about before expiry, and enforced when it lapses.
PECR
Nothing non-essential is stored on your device before you say yes, and rejecting is exactly as easy as accepting.
Equality Act 2010
WCAG 2.1 AA across the product and this site, tested rather than asserted.

Our data protection documentation — lawful basis register, data protection impact assessment, retention policy, breach procedure, sub-processor list — is written and under review by counsel ahead of general availability. If you are a club evaluating us, ask and we will send you the current set rather than a summary of it.

Under 13

Why children can’t have their own account yet.

An account for a child under 13 needs verifiable parental consent — not a tick-box, but one of a small number of methods the Information Commissioner accepts. Doing that properly means a third-party identity check, a commercial agreement, and a consent flow that a parent can actually complete.

We would rather ship that when it is genuinely right than approximate it now. So player accounts start at 13, the age gate fails closed below that, and no data is collected from a child who is turned away — we don’t even keep the date of birth they entered.

None of this reduces what a coach can do for a younger squad. U6–U12 players are planned for, rated and tracked by their coach, and their parents see it. The child simply isn’t a user.

If something is wrong, say so.

Every screen in the product has a reporting route, and it does not require an account. Reports reach your club’s welfare officer, and serious ones reach us as well.

If a child is at immediate risk, contact the police or your local authority children’s services first. Then tell us.