Privacy Policy
How Spotter handles your data. Short version: we collect the bare minimum, we don't sell anything, and you can delete it all at any time.
Controller
Gonçalo Matos, Rua Futebol Clube S. Francisco N523 M24, 2890-486 Alcochete, Setúbal, Portugal. Contact for data-protection enquiries: goncalomatos97@gmail.com.
Data Protection Officer
We are not required to appoint a Data Protection Officer under GDPR Art. 37. We are not a public authority; our core activities do not consist of large-scale systematic monitoring of data subjects; and we do not process Article 9 special-category data at scale. The data-protection contact above acts as our point of contact for data subjects and the supervisory authority.
What we collect
Your email (so you can sign in) and the workout data you log inside the app. If you use the wellness features, we also store what you actively log or set there: your water intake (each drink you record, with its time), the wellness goal targets you choose to aim for (a weekly-volume, sessions-in-30-days, estimated-one-rep-max, or daily-calorie target), and which daily suggested workout you mark as done. The wellness features are all optional and none of them is needed to run the app, so contract necessity (GDPR Art. 6(1)(b)) is not the basis for anything you log or set there. Your water intake and your daily-workout completions are not on that basis, and we do not claim they are: the app works without you ever logging a drink or marking a suggested workout as done, so contract necessity is the wrong test for them. We store them because you chose to log them, and that choice is your consent (GDPR Art. 6(1)(a)). Undoing a drink you logged, or un-marking a workout you marked as done, deletes it, and you can do either at any time. The three training targets (weekly volume, sessions in 30 days, and estimated one-rep max) are stored so the app can show them back to you, and they are on that same consent (GDPR Art. 6(1)(a)) for that same reason: the whole app works without you ever setting a goal, so contract necessity is the wrong test for them too. Removing a target at Profile then Goals deletes it, and you can do that at any time. A daily-calorie target is different again: it describes your diet rather than your training, so it is health information, and we hold one only if you have expressly agreed to it (GDPR Art. 6(1)(a), with your explicit consent under Art. 9(2)(a)). A bodyweight or a resting-heart-rate target would be health information too, and neither is available: the app does not offer them and our server refuses to store them, so we hold neither. The calorie calculator works a little differently: the weight, height, age, and sex you enter into it are used on your device to suggest a number, stored locally on your device (encrypted), and never sent anywhere. Those four are health information too, and we keep them only because you agreed to that on a screen that said so in those words. Saving the calculated calorie target to your account is a second question we ask separately, because that number is the one thing here that does leave your phone. You can see what you agreed to, when you agreed, and the exact words you agreed to, at Profile then Health data, and you can take it back there at any time. If you do, we delete the weight, height, age, and sex from your phone straight away, and we delete our copy of the calorie target the next time your phone is online. The calculator keeps working; it stops remembering anything. Separately, and only if you opt in, we process usage analytics and crash reports. Both analytics and crash reporting are off by default. Those analytics are not linked to your account: we never send your account ID to our analytics provider, so what they hold is a random device identifier and nothing that names you. One thing we should be straight about, because "anonymous" can be read as more than it is: like any request your phone makes over the internet, the connection to our analytics provider carries your device IP address, and they can use it to work out a rough country-level location. We do not use it to identify you, and because we never send them your account ID there is nothing on their side to tie that location back to your account.
Why we collect it
Your email and your workout data are required to run the app you signed in for (GDPR Art. 6(1)(b), contract necessity). The three training targets you can set (weekly volume, sessions in 30 days, and estimated one-rep max) are not, and we do not claim they are: the whole app works without you ever setting a goal, which rules contract necessity out for a goal target whether or not that target is health information. We keep them on your consent (GDPR Art. 6(1)(a)), which you give by setting a target and take back by removing it at Profile then Goals. Your water intake and your daily-workout completions are not required either, and we do not claim they are: the same test rules contract necessity out for these two, because the whole app works without you ever logging a drink or marking a suggested workout as done. We keep them on your consent (GDPR Art. 6(1)(a)), which you give by logging them and take back by deleting them in the app. The daily-calorie target and the weight, height, age, and sex in the calorie calculator are health information, so contract necessity is not the right basis for them either and we do not claim it: the whole app works without you ever setting a goal. We rely on your consent (GDPR Art. 6(1)(a)) together with your explicit consent for health data (GDPR Art. 9(2)(a)). Nothing there is pre-selected, the button you press is itself the statement of what you are agreeing to, and you can withdraw at any time from Profile then Health data, which deletes what we hold under it. Analytics and crash reports are processed only with your explicit consent (GDPR Art. 6(1)(a)) and can be revoked at any time from the in-app privacy settings.
Public profile
Your profile is private by default. If you choose to make it public, other Spotter users who view your profile can see a slim public version of it: your handle, your display name, your profile initials (a photo avatar is not available yet), the month you joined, and your aggregate training totals (number of workouts, current streak, tonnage lifted this year, and count of personal records). Your bodyweight, body measurements, per-set data, workout dates, notes, and full workout history are never part of this public version. We rely on your consent for this public disclosure (GDPR Art. 6(1)(a)). Separately, and only if you turn on the optional Big 3 control, your public profile also shows your estimated one-rep max for bench, squat, and deadlift, estimated from your logged sets. Because that is a performance metric derived from your training, we treat your choice to publish it as explicit consent (GDPR Art. 9(2)(a)); it is off by default and never pre-selected. You can make your profile private again at any time from Profile → Public profile → Make private, and you can turn the Big 3 control off at any time from the same screen, which removes the estimated one-rep max from what others can see. Your public profile is shown only to signed-in Spotter users and is never shared with advertisers.
Sharing a plan
You can create a share link for one of your workout plans. When you do, we store the share: a link token, a note that the share belongs to you, and an expiry date 30 days out. Anyone who has the link can open a read-only copy of that plan, which shows the plan's name and its exercises with their sets, reps, and rest. It does not show your name, your notes, or any of your workout history. The link stops working on its own after 30 days, and you can turn it off sooner from the app. We do this to provide the plan-sharing feature you asked for (GDPR Art. 6(1)(b), contract necessity).
Reporting, blocking, and moderation
Spotter gives you tools to help keep the community safe. When another person has made their profile public, you can report it, for example for an offensive name or handle, an inappropriate photo, or spam or a scam. You can also block a person. Blocking works both ways: once you block someone, neither of you can see the other's profile. When you send us a report we keep a record of it, and we keep a short moderation log of any action we take, such as hiding a reported photo or putting a profile under review while we look into it. We do this to keep Spotter safe and respectful and to meet the user-generated-content rules that the App Store and Google Play require of apps like ours. The legal basis for this is our legitimate interest in a safe community (GDPR Art. 6(1)(f)). Reports are private: the person you report is never told who reported them. If someone reports you, we handle a report that contains information about you, which we received from the person who made the report (GDPR Art. 14). We use it only to review what was flagged, and we never tell you who filed it. We keep reports and any related moderation records for up to 12 months after a report is resolved, and records of the actions we take on an account for up to 24 months, and then we delete them. If you ever need to reach us about a report, a block, or anything objectionable in the app, email us at goncalomatos97@gmail.com, and we aim to review reports within 24 hours and act on them, which can include hiding content, putting a profile under review, or removing an account.
Who we share it with (sub-processors)
We rely on the following sub-processors. We do not sell your data and we do not share it with advertisers.
- Hetzner Online GmbH: server hosting for the self-hosted backend (database, Auth, and Edge Functions) on our own EEA server (Falkenstein/Nuremberg DE or Helsinki FI; hosting your account and workout data).
- Resend: transactional email (EU region; processes your email address solely to send one-time sign-in code emails).
- Cloudflare R2: off-site backup storage (EU jurisdiction; stores nightly backups only, which are client-side encrypted before upload, so R2 holds ciphertext it cannot read).
- PostHog Inc.: product analytics (EU region eu.i.posthog.com; consent-gated, off by default).
- PostHog Delete Persons API: the deletion endpoint we call when you delete your account, to remove the anonymous analytics profile held for the device you delete from. We never send your account ID to PostHog, so the request names that anonymous profile and nothing else.
- Sentry / Functional Software, Inc.: crash reporting (EU region sentry.io; consent-gated, off by default; configured with
sendDefaultPii: falseso per-user identifiers are not transmitted). - Google LLC: Play Store distribution (sub-processor when the V1.0 Android app ships; not yet active).
- Apple Inc.: Sign in with Apple identity provider (not enabled in the release you are using, so no Apple sign-in exists to process; when we do turn it on, Apple receives the authorization code when you sign in with Apple, holds the Apple refresh token for your linked account, and is the target of the token revocation we send when you delete your account).
Where your data is
Your account and your workout data are stored in the European Economic Area, on our own server in Germany or Finland. The sub-processors that hold or receive your data (Hetzner, Resend, Cloudflare R2, PostHog, and Sentry) are used in their EU regions, so what we send them is processed in the EEA too. Apple and Google are on the list above for a store listing and for a sign-in option that is not enabled in this release; neither holds your workout data, and Sign in with Apple has no EU region to choose.
Five of them are companies with a United States parent: PostHog Inc., Functional Software, Inc. (Sentry), Cloudflare, Apple Inc., and Google LLC. Using an EU region does not by itself rule out access from outside the EEA, for example by a support team at the parent company. Where that happens, we rely on the standard contractual clauses the European Commission has approved, where the provider's data-processing agreement includes them, or on the EU-US Data Privacy Framework where the company is certified under it (GDPR Art. 45 and Art. 46). Each of these providers publishes its data-processing agreement on its own website, which is where those clauses are set out. We are still confirming, provider by provider, which of the two applies to each of them, and we will name them individually here before release. In the meantime, if you want to know where any one of them stands, write to goncalomatos97@gmail.com and we will tell you what we have.
Your rights
Under GDPR you may exercise the following rights at any time:
- Access: request a copy of the personal data we hold on you.
- Rectification: correct anything inaccurate.
- Correcting a logged set: fix the numbers on a set you already logged, from inside the app.
- Erasure: delete your account and all associated data.
- Portability: export your data from Profile → Export your data. The JSON file holds your profile and settings, your workouts including the ones you discarded, every set in them, your templates, plans, goal targets, water log, workout-of-the-day history, and the exercises you created yourself; a sets-only CSV spreadsheet sits alongside it for Excel, Google Sheets, or Numbers. That list describes what the file holds; it is not everything we have about you. The weight, height, age, and sex you may have typed into the calorie calculator stay on your device and are not in the file, your subscription record is not in it, and there are other records we hold that it does not carry. Ask us and we will send you anything the file does not cover, and anything else you think is missing.
- Restriction (GDPR Art. 18): ask us to pause what we do with your data instead of deleting it, for example while you are disputing that something we hold is accurate, or while we are considering an objection you have made. While a restriction is in place we keep the data but stop using it, apart from storing it.
- Objection (GDPR Art. 21): object to processing we do on the basis of our legitimate interests. The processing that runs on that basis is the safety work described above: handling a report about a public profile, keeping a moderation log, and putting a profile under review. We will stop unless we can show compelling legitimate grounds that override your interests, or we need the records to establish or defend a legal claim.
- Withdraw consent: take back any consent you have given us, at any time. Each consent has its own route. Analytics and crash reporting come off from the in-app privacy settings. The health data consents come off at Profile → Health data, which deletes the weight, height, age, and sex from your phone straight away and deletes our copy of your calorie target the next time your phone is online. Your goal targets come off by removing them at Profile → Goals. Your water log and your daily-workout completions come off by deleting what you logged, in the app. The public-profile consents come off at Profile → Public profile, where you can make your profile private again and turn the Big 3 control off. Withdrawing a consent does not undo what was lawful before you withdrew it. This is a different thing from objecting, and it is simpler: you do it yourself and you do not need to ask us.
You can correct the numbers on a set you already logged at any time from History → open the workout → Fix a set, and the set itself is corrected straight away. Your training totals and your personal records are worked out from your sets, and correcting a set does not update them yet, so if a total or a record is still wrong after you correct a set, email us at the address above and we will put it right.
You can delete your account at any time from Profile → Delete account. To exercise restriction, objection, or any other right, email us at goncalomatos97@gmail.com.
If we cannot do what you asked
If we do not act on a request you make about your data, we will tell you why, and we will do that without undue delay and in any event within one month of receiving the request (GDPR Art. 12(3) and Art. 12(4)). We will tell you at the same time about the two routes below, and you can use either of them, or both, whether or not you come to us first.
- Complain to a supervisory authority (GDPR Art. 77). You can complain to the data-protection authority in the EU or EEA country where you live, where you work, or where you think the problem happened. In Portugal, where we are established, that authority is the Comissão Nacional de Proteção de Dados (CNPD): www.cnpd.pt, geral@cnpd.pt.
- Go to court (GDPR Art. 78 and Art. 79). You have the right to an effective judicial remedy against us, and also against a supervisory authority if it does not handle your complaint. You can bring a claim in the courts of the country where you live.
You do not have to contact us first, but it is usually the fastest way to fix something: write to goncalomatos97@gmail.com.
Account deletion
You can request full erasure of your account from our delete-account page or from inside the app (Profile → Delete account). That removes your account and every record attached to it on our servers, and the app deletes everything it can reach on your phone. There is one thing on your phone it cannot reach. If you imported a workout file into an older version of Spotter, a fingerprint of that file can stay in your phone's secure storage where the app cannot reach it to delete it. It holds no workout data, only that an import happened, when, and how many workouts were in it. Email us at goncalomatos97@gmail.com if you want to know more about it. If you had analytics turned on, we also ask PostHog to delete the anonymous analytics profile held for the device you delete from, using their Delete Persons API. Analytics is off by default, and we never send your account ID to PostHog, so there is no analytics profile linked to your account for us to delete. If you used Spotter on more than one device, the anonymous profile for a device you did not delete from carries no link to your account and we have no way to identify it. Crash-report data on Sentry contains no per-user identifiers (we configure sendDefaultPii: false) and is purged on Sentry standard retention.
Data retention
We retain your workout data until you delete your account or ask us to erase it. Erasure requests are completed within 30 days. We keep nightly off-site backups, client-side encrypted before they leave our server and stored in the EU, for 30 days; a deleted account rolls off those backups within that window, after which the data is gone. Crash reports and analytics events are retained according to the standard retention windows of the respective processors.
Cookies
Contact
For any data-protection enquiry, write to goncalomatos97@gmail.com.
Updates
If this policy changes materially we'll notify you in-app on next launch and ask you to review the new version. So that we show you that notice once rather than every time you open the app, we keep a note on your device of the policy version you were last shown. That note stays on your device, is never sent to us, and is removed when you sign out or delete your account. You can read this policy at any time from Profile → Privacy Policy.