This page is in English only.
Privacy Policy
spotops · Last updated 28 September 2026
spotops (“the app”) is operated by ON Aspect ApS (CVR 46552091), Denmark, which is the data controller for your personal data. This policy explains what the app collects, why, the legal basis for it, and your rights. Questions: [email protected].
What we collect
| Data | Why | Required? |
|---|---|---|
| Email address | Account sign-in and password recovery | Yes — to create an account |
| Password | Authentication (stored hashed by our auth provider; we never see it) | Yes |
| Spot locations (GPS coordinates) | The core feature — saving and mapping the places you shoot | Only when you save a spot or use the map |
| Photos you attach | Reference images for your spots | Optional |
| Display name / profile | Shown to people you share spots or collections with | Optional |
| Push notification token | To notify you when conditions match a watched spot. The alert may include the name of the space and is shown on your device's lock screen; it never contains a spot's location or your photos. | Only if you enable match notifications |
| Crash & diagnostic data | Fixing crashes and bugs (via Sentry; no personal identifiers attached) | Automatic |
| Device information | Basic technical details about the device you use Spotops on — the device model, operating-system version, the app's version and build number, and when the app was last opened on it (so we can tell which devices are in active use). We use this to reproduce problems you report and to understand how widely an issue affects our users. It is a single current snapshot per device, not a history of your activity; we do not collect any identifier that uniquely singles out your device, and we do not use it to track you across apps or services. | Automatic |
| Improving our forecasts | When you log the conditions at a place against one of our built-in templates, we add what the weather actually was there to a combined dataset we use only for analytics, in aggregate, to make our built-in forecasts more accurate for everyone. While your account exists this includes the exact location and time you logged — the point you recorded the conditions at, which the app already stores to build your own condition history; if you delete your account, these entries are made approximate and their link to you removed, and kept only as anonymous statistics. Those anonymous statistics keep the approximate area, the month and hour, the light conditions, and which way the coast there faces the sea — never the exact point. It is never used to profile or advertise to you, and never shared or sold. | Automatic when you log against a built-in template; you can turn it off at any time in Settings |
| Feature requests & votes | If you post an idea on the in-app feature-request board or upvote one, we store the text you write and which requests you upvote. Requests are shown publicly to other users but never with your name; we keep an internal link to you only for handling abuse and grouping duplicates, and it is never displayed. See Feature requests & voting below. | Only if you post or vote on the board |
| Subscription & purchase data | To run your free trial and any paid subscription: the date your trial started, whether a paid or complimentary entitlement is active, the plan (monthly / annual / complimentary / lifetime), which app store and product it came from, and the current period's expiry. The payment itself is handled entirely by Apple or Google — we never receive or store your card number or payment details. To validate purchases and keep this status in sync we use RevenueCat (see Who processes your data), which receives an app-specific account identifier and your store purchase/receipt data — never your email address or card details. | The trial is automatic with your account; purchase data only if you subscribe |
| Record of a used free trial | When you delete your account, we keep a one-way, keyed fingerprint (a hash) of your email address, and of the address you signed up with if you changed it — never the addresses themselves — for 12 months. It lets us recognise the same email address, or a variation of it such as an added +tag or, for Gmail, added dots, if it is used to sign up again, so deleting and re-registering doesn't start a new free trial. You can still sign up again and subscribe; you just don't get a second free trial. It is used for nothing else. | Automatic when your account is deleted, by you or by us after an unpaid trial |
Legal basis for processing
We process your personal data under the following legal bases (GDPR Article 6):
- Performance of a contract (Art. 6(1)(b)) — your account, authentication, spots, locations, photos, profile, and sharing, and running your free trial and any subscription you take out (keeping track of your entitlement and its expiry). This is the data we need to provide the service you signed up for.
- Consent (Art. 6(1)(a)) — push notifications for matching conditions, and optional product-news or marketing emails. You give these by opting in and can withdraw at any time (see Your rights). Essential service emails — such as password resets, security notices, and important changes to your account or these policies — are sent under our contract with you, regardless of these settings.
- Legitimate interests (Art. 6(1)(f)) — crash and diagnostic data, and basic device information, used to keep the app stable, fix bugs, provide support, and understand how widely an issue affects our users. This is coarse, technical data that does not uniquely single out your device, and we balance its use against your privacy. This basis also covers improving our forecasts — using the conditions you log against built-in templates, in aggregate, to make the built-in forecasts more accurate for everyone. The result is only ever an improved recipe, never a decision about you; you can stop contributing future logs at any time by turning it off in Settings (entries already contributed stay in the aggregate dataset and become anonymous when you delete your account). It also covers operating the feature-request board — storing the requests you post, the votes you cast, and any reports you make, so the community can shape what we build next. Finally, it covers preventing abuse of the free trial — keeping a keyed hash of your email address for 12 months after you delete your account, so that deleting an account and signing up again with the same email doesn't give a new free trial. The hash can't be turned back into your address, but it is still personal data: we can check whether a given address matches it. We use it only to check new signups against it and erase it after 12 months.
Location — we don't track you
spotops does not track your location in the background. We use your device's GPS only at the moment you choose to — when you save a spot, or to centre the map and show your position while you're using it. We don't build a history of your movements.
When you import photos to create spots, spotops can read each photo's own capture location (from the photo's metadata) to place the new spot on the map automatically. How this works differs by platform:
- iOS: the system photo picker gives us the capture location of only the photos you pick, without any photo-library permission.
- Android: automatic capture-location is off by default. By default you use the system photo picker (which does not share location) and place spots on the map manually. Reading a photo's location on Android is only technically possible with broader access to your photos, so it is an opt-in feature: you can turn on “automatic photo location”, which asks for permission to access your photos. You can decline, or turn it off again at any time in Settings — the setting always reflects the permission you've actually granted your device.
Either way, we read the location only of the photos you choose to import, only at that moment, to position the spot — we never scan, browse, or upload the rest of your photo library, and a photo's capture location is used to place the spot and then discarded, not stored.
A note on what you add
Please don't put personal information — about yourself or others — into free-text fields such as spot notes. We can't control what you type, and you remain responsible for it. Photos can also contain embedded location metadata (EXIF); if you attach a photo, that metadata may be stored with it. Only share spots and photos with people you trust.
What we do NOT do
- We do not sell or rent your data.
- We do not use it for advertising or cross-app tracking.
- Map usage telemetry is disabled.
- We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
How sharing works
Spots and collections are private by default. When you create a share link or accept one, the people you share with can see the shared content (and, depending on the permission you grant, edit parts of it). They never see your email address — only your display name. You can revoke access at any time from within the app.
Shared content, ownership and deletion. The photos you add are yours — including photos you add to a spot someone else has shared with you. When you delete a photo, or delete your account, your photos are deleted, and any you added to other people's shared spots are removed from those spots too, so nobody is left with them. Other things you contribute to a spot owned by someone else — for example a note or an edit to a shared detail — become part of that owner's spot and remain with them; deleting your account does not automatically remove them, because the spot is the owner's. In the same way, content other people contribute to spots you own stays with your spots and is removed for everyone when you delete the spot or your account (the owner keeps control). If you need specific text you contributed to someone else's spot removed, ask the spot's owner, or contact us at [email protected] and we will help (see Your rights).
Feature requests & voting
Spotops has a public feature-request board where you can suggest ideas, upvote other people's requests, and report content.
- Public, but anonymous. Requests are shown to other users, but never with your name — the board is about ideas, not people. We keep an internal link between a request and its author only for handling abuse and grouping duplicates; it is never displayed. We never show who voted for what.
- Requests are permanent. Because other people rely on and vote for public requests, a request stays on the board even if you delete your account — at that point it is fully anonymised, with the link to you removed. Your votes and reports are deleted with your account. The app reminds you of this when you post.
- Taking a post down. If you want a specific request you made removed, contact us at [email protected] and we'll remove it.
Who processes your data
We use a small set of processors to run the service:
- Supabase — database, authentication, and photo storage.
- Cloudflare — website hosting and encrypted backups of photos and database (R2).
- Sentry — crash reporting.
- Resend — sending account emails such as password-reset codes.
- Mapbox — map tiles.
- Geoapify — place-name search (geocoding), using OpenStreetMap data, processed on servers within the EU (Finland and Germany). Search runs through our own servers, so Geoapify does not receive your device's IP address; we send only your search text and an approximate location.
- Open-Meteo — weather and marine forecasts, and the weather at the time of conditions you log. Our servers request it for places near your spots: a spot’s own position when you save it, otherwise one point per area about 5 km across (the average position of the spots in it), and for a logged condition, the place and date you logged. Only coordinates and dates are sent — no account, email or device information, and the request comes from our servers, not your device.
- RevenueCat — subscription management and purchase validation. It receives an app-specific account identifier and your store purchase/receipt data to tell us whether your subscription is active; it never receives your email address, and never your card or payment details (those stay with Apple / Google).
- Apple — app distribution, push notification delivery, and processing App Store purchases and subscriptions (iOS).
- Google (Firebase Cloud Messaging) — push notification delivery, and (Google Play) processing purchases and subscriptions (Android).
- Expo — app builds, over-the-air updates, and relaying match notifications to Apple (iOS) and Google (Android) for delivery.
- Google Workspace — email and correspondence (e.g. support and privacy requests you send us).
- GitHub — running our automated backup jobs.
Where your data is processed & international transfers
Your account, content, and backups are hosted in the European Union (database, authentication, photo storage, and backups). Some of our providers are US-owned or operate services in the United States — for example Mapbox (maps), Apple (iOS app distribution and push), Google (Android push delivery), Expo (relaying match notifications), RevenueCat (subscription management), and as the parent companies of providers such as Supabase and Cloudflare. Where this involves a transfer of personal data outside the EEA, or access to it from outside the EEA, it is governed by appropriate safeguards — primarily the European Commission's Standard Contractual Clauses and each provider's Data Processing Agreement (and, where applicable, EU–US Data Privacy Framework certification).
Security
We protect your data with encryption in transit (HTTPS/TLS) and at rest, access controls, and reputable infrastructure providers. No online service is perfectly secure, but we take reasonable measures to keep your information safe.
Retention & deletion
We keep your data for as long as your account exists. You can delete your
account from Settings → Account in the app, or on the web at
spotops.io/delete-account.
Spaces & Trash. Moving a space to Trash hides it and
its contents; you can restore it from Settings at any time. A
space left in Trash is permanently deleted after 30 days,
including its underlying data such as its spots, photos and collections.
When you delete a photo, a space, or your account, it is removed from our live systems immediately (except as described below) and you lose access to it right away. For disaster-recovery reasons, copies remain in our encrypted, time-limited backups (file backups and database snapshots) for up to 30 days after deletion, after which they are permanently and automatically erased. We do not use these backups to restore deleted accounts.
Device information. The basic device details described above are kept as a current snapshot per device (each update replaces the last) for the life of your account, and are erased when you delete your account.
Subscriptions & trials. Your trial start date and subscription status are kept for the life of your account and erased when you delete it, with one exception: to stop the free trial being reset by deleting and re-registering, we keep a keyed hash of your email address (never the address itself) for 12 months after deletion, then erase it automatically. If you sign up again with the same email within that time, you can still create an account and subscribe, but you won't get a second free trial. The payment records themselves are held by Apple or Google, not by us. If your free trial ends and you don't subscribe, we'll email you a reminder, and if the account stays unsubscribed we may delete it and its data after a grace period (currently around 90 days after the trial ends). We'll always warn you by email before doing so, and subscribing at any point stops this.
Improving our forecasts. The conditions you log against built-in templates are pooled with other users' logs into a combined dataset we use only for analytics — in aggregate — to improve our built-in forecasts. It is internal — not made public, and never shared with third parties or sold. While your account exists, an entry is linked to you only through an internal key (not your name, email, or account) and includes the exact location and time you logged; when you delete your account, those exact details are removed and the entry is kept only as coarse, anonymous statistics no longer linked to you — the approximate area (about a kilometre), the month and hour, the light conditions, and which way the coast there faces the sea, never the exact point. Anything you log against your own custom templates is never added to this dataset.
Feature requests & votes. A feature request you post is public community content, so it remains on the board after you delete your account, anonymised — the internal link to you is removed. Your votes and any reports you made are deleted with your account. You can ask us to remove a specific request you posted at any time (see Feature requests & voting).
Children
spotops is not directed at children. You must be at least 16 to use it, and we do not knowingly collect data from anyone under 16.
Your rights
Under the GDPR you may request access to, correction of, export of (portability), or deletion of your personal data, and you may object to or restrict certain processing. Where we rely on your consent (notifications, marketing email) you can withdraw it at any time — turn off notifications, switch off the email toggle, or use the unsubscribe link — without affecting the lawfulness of processing before withdrawal. Contact [email protected]; we respond within one month. You may also lodge a complaint with the Danish Data Protection Agency (Datatilsynet).
Changes
If this policy changes materially we will update the date above and, where appropriate, notify you in the app.
Contact
ON Aspect ApS (data controller), CVR 46552091, Denmark.
[email protected]
ON Aspect ApS · CVR 46552091 · Denmark