Privacy Policy
Last updated: September 5, 2026
This Privacy Policy explains how Spotter (“Spotter,” “we,” “us,” or “our”) collects, uses, shares, and protects information when you use the Spotter mobile application and related services (collectively, the “App” or “Service”).
By creating an account or using Spotter, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the App.
1. Who We Are
Spotter is a gym-accountability app that helps you and a small group of friends (“Squad”) track workouts, stay consistent, and celebrate progress together.
Contact: hello@spotter.fit
Company: Spotter
2. Information We Collect
2.1 Information you provide directly
- Account information: email address, username, display name, password (or Google/Apple sign-in identifiers), unit preference (imperial/metric), timezone.
- Profile information: avatar/profile photo, display name.
- Workout data: exercises logged, sets, reps, weights, cardio sessions (distance, duration, activity type), workout notes, timestamps, and any custom exercises you create.
- Squad information: squads you create or join, squad names, invite codes you generate or use, membership role.
- Social content: notes attached to workouts, “Spot” reactions and comments you give or receive, nudges sent between squad members (limited to preset templates — we do not collect free-text nudge content because none exists).
- Gym information: gyms you register (name, address, or coordinates), whether a gym is marked as your home gym.
- Communications: messages you send us for support requests.
2.2 Information collected automatically
- Location data: if you enable geofencing/auto check-in, we collect precise device location to detect when you arrive at a registered gym. This creates a check-in record tied to your account only — arrival at a gym is never shared with your squad automatically. Only the act of logging a workout is visible to your squad. You can decline location access entirely and use manual check-in with no loss of core functionality.
- Wi-Fi network identifiers: if you enable Wi-Fi -assisted home-gym detection, we store a hashed (not raw) version of your home network’s SSID to assist check-in detection.
- Device and usage information: device type, operating system version, app version, crash logs, general usage analytics (e.g. , which screens are used), and push notification token.
- Log data: IP address, access times, and similar technical metadata generated through normal use of the Service.
2.3 Information from third parties
If you sign in using Google or Apple, we receive basic profile information (name, email address, and a unique identifier) from that provider, subject to your settings with them.
2.4 Information we do NOT collect
- We do not collect precise location unless you explicitly enable geofencing/auto check-in.
- We do not store raw Wi-Fi network names — only a one-way hash.
- We do not request push notification permission during onboarding, and only ask for it contextually.
- We do not read your contacts, messages, or other apps.
3. How We Use Your Information
We use the information we collect to:
- Create and maintain your account and authenticate you.
- Provide core features: logging workouts, joining/managing squads, computing weekly quotas, detecting personal records (PRs), and rendering your activity history and contribution matrix.
- Detect “Synced” workouts (sessions logged close in time to a squad member’s) to award in-app recognition.
- Enable geofence-based check-in prompts, if you opt in, and process confirm/cancel actions.
- Send push notifications you’ve opted into (e.g., Spots received, PRs, squad invites), subject to your notification preferences and quiet hours.
- Maintain security, detect abuse, and enforce our Terms of Service.
- Diagnose technical issues, improve performance, and develop new features.
- Comply with legal obligations.
We do not use your workout or health data to build advertising profiles, and we do not sell your personal information.
4. How Information Is Shared
4.1 With your Squad
When you log a workout and share it to a squad, the following becomes visible to other members of that squad:
- Your display name/avatar, workout title, notes, exercise/cardio summary, and any PR or Synced badges.
- Spots and comments you or others leave on that workout.
Your precise location, home gym address, check-in history, and un-shared/private workouts are never visible to other users, regardless of squad membership.
4.2 Service providers
We share information with third parties that help us operate the Service, under contractual confidentiality and data-protection obligations, including:
- Supabase (database, authentication, and backend infrastructure hosting).
- Google and Apple (sign-in authentication, if you use those options).
- Push notification delivery providers (e.g., Expo Push Service, APNs, FCM) — solely to deliver notifications to your device.
- Geocoding services — to convert a gym address you enter into map coordinates.
4.3 Legal and safety
We may disclose information if required by law, subpoena, or legal process, or if we believe in good faith it’s necessary to protect the rights, property, or safety of Spotter, our users, or the public.
4.4 Business transfers
If Spotter is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy or a policy at least as protective.
4.5 We do not sell your data
We do not sell or rent your personal information to third parties for their own marketing purposes.
5. Your Choices and Controls
- Location: Toggle geofencing/auto check-in on or off anytime in Settings → Location. Declining or disabling it does not lock you out of any feature — manual check-in and logging remain fully available. We do not re-prompt you after a decline.
- Push notifications: Configure which notification types you receive, and quiet hours, in Settings → Notifications.
- Profile editing: Update your display name, username, avatar, and unit preference anytime.
- Squad membership: Leave a squad at any time; your historical workouts remain yours, but posts already shared to that squad’s feed may remain visible to former squad members unless deleted.
- Account deletion: You may request deletion of your account and associated personal data from within the App (Settings → Account → Delete Account) or by emailing hello@spotter.fit. Some information may be retained where required for legal, security, or fraud-prevention purposes, or in anonymized/aggregated form.
- Access and correction: You may request a copy of the personal data we hold about you, or ask us to correct it, by contacting hello@spotter.fit.
6. Data Retention
We retain your information for as long as your account is active or as needed to provide the Service. If you delete your account, we delete or anonymize your personal data within 30 days, except where retention is required for legal compliance, dispute resolution, or fraud prevention.
Check-in records are retained only as long as necessary to support Synced detection and your personal history; expired/cancelled pending check-ins are not broadcast anywhere and are retained solely in your own account history.
7. Data Security
We use industry-standard safeguards, including encryption in transit, database-level Row Level Security (so other users’ data is not directly accessible), and hashed storage of sensitive identifiers like Wi-Fi SSIDs. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
8. Children’s Privacy
Spotter is not directed to children under 13 (or the applicable minimum age in your jurisdiction), and we do not knowingly collect personal information from children under that age. If we learn we have collected such information, we will delete it. If you believe a child has provided us information, contact us at hello@spotter.fit.
9. International Data Transfers
Spotter’s infrastructure may process and store data in the United States or other countries. By using the Service, you consent to the transfer of your information to countries that may have different data protection laws than your country of residence.
10. Your Regional Privacy Rights
10.1 California residents (CCPA/CPRA)
You have the right to know what personal information we collect, request deletion, and opt out of the “sale” or “sharing” of personal information (we do not sell or share personal information as defined by the CCPA). To exercise these rights, contact hello@spotter.fit.
10.2 European/UK residents (GDPR)
If you are in the EEA, UK, or Switzerland, our legal bases for processing include: performance of a contract (providing the Service), consent (e.g., location and push notifications), and legitimate interests (security, fraud prevention). You have rights to access, rectify, erase, restrict, or port your data, and to object to certain processing. Contact hello@spotter.fit to exercise these rights.
10.3 Other jurisdictions
We aim to honor equivalent rights for users in other jurisdictions with applicable privacy laws. Contact us with any request.
11. Health and Fitness Data
Workout, exercise, and cardio data you log is fitness/wellness information you choose to enter — Spotter is not a medical device and does not provide medical advice. This data is treated with the same security and access controls as other personal data described in this Policy, and is never shared with third-party advertisers.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the App or by email before the changes take effect. Continued use of the Service after changes take effect constitutes acceptance of the revised Policy.
13. Contact Us
Questions or requests regarding this Privacy Policy or your data can be sent to:
Email: hello@spotter.fit
Mail: Spotter, Attn: Privacy