SpotWeave
FeaturesHow it worksPricingFAQ

Privacy Policy

Last updated 2026-07-31

[REVIEW BY COUNSEL] This document is a working draft. The facts in it describe how SpotWeave is actually built, but the wording is not legal advice and must be reviewed and approved by a qualified lawyer before launch. Passages we are least certain about are marked inline.

The short version

SpotWeave is a field notebook for your map. It is built offline-first, which means the copy of your Spots on your phone is the real one — everything else is a backup of it.

  • We collect the coordinates of Spots you deliberately save. We do not track where you go.
  • Your phone’s own position is used on your device to centre the map and to fill in a new Spot’s coordinate. It is never uploaded as a trail, a history, or a background location feed.
  • Photos are stripped of their metadata — including GPS — before they leave your device, and are stored in a private bucket that is only reachable through short-lived links we mint for you.
  • You can use SpotWeave without an account at all. Sign in only when you want your Spots on more than one device, or want to take part in the community.
  • No advertising, no tracking SDKs, no data sales, no profile-building. We have never sold data and have no plan to.

The rest of this page is the detail.

Who we are

SpotWeave is published by Stralion Pty Ltd (“Stralion”, “we”, “us”), a company registered in Australia (ABN 76 115 789 234, registered office PO BOX 277, Gosford NSW 2250, Australia). Stralion is the data controller for the personal information described here. You can reach us any time at privacy@spotweave.app.

What this policy covers

  1. The SpotWeave apps for Android and iOS.
  2. The web companion at app.spotweave.app (view and manage the same data in a browser).
  3. This website, spotweave.app.

What we collect

Account

Only if you choose to sign in. SpotWeave uses Supabase for authentication and supports:

  • Email and password — we store your email address and Supabase stores a hash of your password. We never see the password itself.
  • Sign in with Google, and on iOS Sign in with Apple — the provider tells us your email address and a stable identifier. We do not receive your contacts, calendar, or anything else from your Google or Apple account.

Profile

A username, and optionally a display name and an avatar. Your username is public wherever your content is: it appears on Community SpotSets you publish, on Spots you contribute to someone else’s set, and next to your comments and ratings.

Location

This is the part most people want to read carefully, so it is spelled out plainly.

  • Spot coordinates. When you save a Spot, we store the latitude and longitude you chose, plus an optional altitude and a “captured at” time. These are places you deliberately marked. If the Spot is in a private SpotSet, only you (and, once you sign in, our servers as your backup) can see it.
  • Your device’s position is read while the app is open, to show the blue dot, to centre the map, and to prefill a new Spot’s coordinate. It stays on the device. We do not record a track, a location history, or any breadcrumb trail, and we do not read your location in the background.
  • Map tiles are pre-downloaded by region, not requested per view, so panning the map does not send a stream of “where am I looking” requests to a server.
  • Choosing an offline region tells us which region file you downloaded — a country- or state-sized area, not a place you have been.

Photos

  • Photos you attach to a Spot are downscaled to a maximum of 2048 px on the long edge on your device.
  • All EXIF metadata is stripped before upload, including any GPS coordinates the camera wrote into the file. If the app offers to move a Spot to a photo’s location, that reading happened locally, before stripping, and only the coordinate you accept is ever stored — as a Spot coordinate, never as photo metadata.
  • Uploaded photos live in a private Cloudflare R2 bucket. The bucket has no public URLs; our API checks that you are allowed to see a photo and then mints a short-lived signed link.

Community content

Anything you publish — a Community SpotSet, a Spot contributed to one, a comment, a rating — is visible to other people using SpotWeave, along with your username. Reports you file are visible to our reviewers, not to the person you reported.

Purchases

SpotWeave does not sell anything yet. When Pro subscriptions ship, they will be sold only through the App Store and Google Play, and handled by RevenueCat on our side. We will receive your subscription status and a pseudonymous app-user identifier. We never receive your card number, billing address, or any payment detail — Apple and Google are the merchants of record.

This website

If analytics are enabled on spotweave.app, they are Plausible — cookieless, aggregate, no personal identifiers, no cross-site tracking. There is no advertising pixel, no session recorder, and no third-party tag manager on any SpotWeave page. Our hosting keeps standard server logs (IP address, user agent, path, timestamp) for security and abuse monitoring.

What we deliberately do not collect

Advertising identifiers, contacts, calendars, microphone audio, health data, background location, and browsing behaviour on other sites or apps. The apps ship with no advertising SDK and no third-party analytics or crash-reporting SDK. If that ever changes, this policy is updated — with the change described — before the code ships.

Where your data lives

  • On your device first. The local database is the source of truth. Create, edit, and browse Spots with no network at all; nothing is sent anywhere until you sign in and sync.
  • On our servers, if you are signed in. Sync copies your SpotSets, Spots, photo records, and subscriptions to a Supabase Postgres database, protected by row-level security policies that scope every read and write to your own account (plus whatever the community rules explicitly allow).
  • Photo files are the exception to “in Postgres”: those bytes sit in the private R2 bucket described above.

How we use it

Purpose What it uses
Show your Spots on your device Everything you saved, locally
Sync across your devices and back you up Account, SpotSets, Spots, photo records
Run the community (publish, browse, follow, contribute, comment, rate) Username, published content
Keep the community usable — moderation, reports, bans Reports, published content, account status
Support Whatever you send us in an email
Prevent abuse and keep the service up Server logs, rate-limit counters
Sell and restore Pro subscriptions (when they ship) Subscription status from Apple/Google via RevenueCat

For users in the EEA and the UK, our legal bases are performance of a contract (running your account, sync, community features, purchases), legitimate interests (security, abuse prevention, moderation, aggregate website analytics), consent where we ask for it, and legal obligation where the law requires us to keep or produce something. In Australia the same activities are handled under the Australian Privacy Principles. [REVIEW BY COUNSEL] — confirm this mapping, and whether saved Spot coordinates should be treated as sensitive information in any jurisdiction we ship to.

Community visibility and moderation

Publishing is a deliberate act, and it is not private:

  • A Community SpotSet and the Spots in it are readable by anyone using SpotWeave, with your username attached.
  • Comments and ratings are attributed to your username.
  • Moderators — our staff and trusted community reviewers (“Rangers”) — can read published community content, act on reports, hide comments, take down Spots or photos, and freeze a set. Rangers see community content only; broader access is limited to administrators, and moderation actions are recorded in an internal audit log.
  • Unpublishing later does not un-see it. Other people may already have downloaded a community set for offline use. Treat publishing as permanent, especially for locations you would not want a stranger to find.

Who else processes your data

Provider Where What for What they get
Supabase United States (region configurable) Authentication and the Postgres database Account email, profile, your synced rows
Cloudflare (R2) Global edge Private photo storage and public basemap tiles Photo files (metadata already stripped)
Railway United States Hosts our API and our websites Standard server logs; API traffic in transit
Apple / Google Global App distribution, and payments when Pro ships Purchase and store account data we never see
RevenueCat United States Subscription entitlements (when Pro ships) Pseudonymous app-user id, subscription status
Plausible Analytics European Union Cookieless website analytics, if enabled Page, referrer, country — no identifiers

Each acts as a processor under a data-processing agreement or the equivalent Australian Privacy Principle 8 arrangement. We do not disclose your personal information to anyone else, and we do not sell it.

International transfers

Several processors are outside Australia and the EEA — Supabase, Railway and RevenueCat are in the United States, and Cloudflare serves from a global edge network. For transfers out of the EEA/UK we rely on the European Commission’s Standard Contractual Clauses and equivalent UK mechanisms; for transfers out of Australia, on the contractual safeguards Australian Privacy Principle 8.1 requires. [REVIEW BY COUNSEL] — confirm the actual mechanism in each processor’s current DPA before publication, and whether a UK Addendum or an EU representative appointment is needed for the markets we launch in.

How long we keep it

  • Your content stays until you delete it. Deleted rows are tombstoned first (so the deletion reaches your other devices), then purged.
  • Your account: delete it and we remove your account data and content. Content you contributed to someone else’s Community SpotSet may remain, with attribution removed, because it is part of a shared map others rely on.
  • Photo files: deleting a photo makes it unreachable immediately — no signed link is ever minted for it again. Photos removed as part of deleting your account are purged from storage during account deletion (see below). For a photo deleted on its own, the file itself is purged from the bucket by a separate sweep. [REVIEW BY COUNSEL] — that sweep is currently an operator task, not an automated job; either it ships or this sentence has to keep saying so plainly.
  • Server logs are kept for a short window for security and abuse monitoring, then deleted or anonymised.
  • Moderation records — reports and the audit log — are kept longer than the content they concern, because they are the record of a decision.

[REVIEW BY COUNSEL] — these windows are deliberately described qualitatively. Fixed retention periods (in days) need to be set, implemented as an actual job, and stated here before launch.

Deleting your account

You can delete your account in the app — no email required. On Android or iOS, open the You tab and choose Delete account. It’s permanent, so we ask you to confirm before it happens.

Once you confirm:

  • You’re signed out everywhere. Sign-in for that account is permanently disabled, and any other device where you’re still signed in loses its session and behaves as signed-out from then on.
  • Your content is removed from sync, so the deletion reaches your other devices the normal way, and the copy in our database is scrubbed: your profile (username, display name, avatar) is cleared, and SpotSets you own are removed — unless someone else has contributed to them (see below).
  • Your photos are deleted from storage, both the ones in your own SpotSets and any you added to someone else’s.

A few things deliberately do not disappear, because they are shared with other people or because we are required to keep a record:

  • Spots you contributed to someone else’s Community SpotSet stay in that set, with your attribution removed — they become part of the shared map other people rely on, the same way the rest of this policy already describes for contributed content.
  • A Community SpotSet you own that other people contributed to stays published, just without your name on it, rather than being deleted along with your account — that protects the contributors’ work and keeps it under moderators’ control.
  • Comments and ratings you left are removed, not kept under an anonymous label.
  • Purchase records are kept, because we have financial and audit obligations to retain them, and reports and moderation records involving your account are kept, for the same reason community moderation records are kept generally (see “How long we keep it”).

Your account and the rest of your data are then fully purged from our systems after a short retention window that gives the deletion time to propagate to every device before the underlying account row disappears. This mirrors the tombstone-then-purge process described above.

Deleting your account does not cancel a store subscription. If you have a Pro subscription when Pro ships, cancel it separately in Google Play or the App Store — Apple and Google are the merchant of record and only they can stop a subscription from renewing.

If you would rather ask us to do it for you, or you want to exercise any of the other rights below, email privacy@spotweave.app — see “Your rights”.

Security

Traffic is TLS-encrypted end to end. Access to your rows is enforced by row-level security in the database, not only by the app. Photo links are short-lived and minted only after a permission check. The photo bucket is private with no public URLs. Access to production systems is limited to the people who operate them. No system is perfectly secure, but the offline-first design means the copy that matters most is the one on your own device.

If a data breach occurs that is likely to cause serious harm, we will notify affected users and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and the relevant supervisory authority within 72 hours where the GDPR applies.

Children

SpotWeave is not directed at children and is intended for people 16 or older. We do not knowingly collect personal information from anyone younger. If you believe a child has given us personal information, email privacy@spotweave.app and we will delete it. [REVIEW BY COUNSEL] — confirm the age threshold against each launch market (13 in the US under COPPA, 13–16 depending on EU member state, and the store age-rating declarations must match whatever we choose).

Your rights

Under the Australian Privacy Principles, the GDPR, the UK GDPR and similar regimes you can ask us to: give you access to what we hold, correct it, delete it, give you a portable copy, restrict or object to processing carried out under legitimate interests, and withdraw consent where processing relies on it. We do not use your data for automated decision-making with legal or similarly significant effects.

Email privacy@spotweave.app. We will respond within the time the applicable law allows (one month under the GDPR, extendable by two months for complex requests).

If you think we have mishandled your information, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au), to your national data protection authority in the EEA, or to the ICO (ico.org.uk) in the UK. We would like the chance to fix it first.

Changes

We will post material changes on this page and update the date at the top. If a change affects your rights or relies on your consent, we will tell you in the app or by email before it takes effect.

Contact

The data controller is:

Stralion Pty Ltd
ABN: 76 115 789 234
Registered office: PO BOX 277, Gosford NSW 2250, Australia
Privacy: privacy@spotweave.app
Support: support@spotweave.app

SpotWeave
FeaturesPricingFAQSupportPrivacyTermsWeb app
Coming soon to theApp StoreComing soon toGoogle Play

© 2026 Stralion Pty Ltd · ABN 76 115 789 234 · support@spotweave.app

Liability limited by a scheme approved under Professional Standards Legislation.