← Spot

Spot Privacy Policy

Last updated: 2026-08-26. Version: 1.3.0.

This policy explains what personal data Spot collects, why, who can see it, and the rights you have over it. It is written to meet the disclosure requirements of the EU GDPR, the UK GDPR + Data Protection Act 2018, the CCPA/CPRA (California), and PIPEDA (Canada).

1. Who we are (Controller)

  • Spot is a shared, real-time grocery / to-do list app for two partners with a Manual Veto photo confirmation flow. The controller is Spot App (a trading name).
  • Privacy contact: privacy@spotgrocery.com. Email us for any privacy matter, including exercising any of your rights under this policy.

2. What data we collect

CategoryWhyWhereDeleted
Account credentials: your email and a password hash (never your plaintext password). Only if you create an account. Spot can be used without one.Sign-up, sign-in, partner invites.Our backend processor's authentication service (EU; see § 5).When you delete your account (§ 7), or after 36 months of inactivity.
Guest session: if you use Spot without an account, an anonymous session identified by a generated id, plus the display name shown in the app (Guest unless you change it). No email, no password.Letting you try Spot before deciding whether to sign up.Our backend processor's authentication service (EU; see § 5).When you delete it in the app (§ 7); unused guest accounts are also removed periodically.
List contents: list and item names, done state, who created what.The service itself: storing and syncing your lists.Our backend database (EU).31 days after the list is created (pinned Premium lists never expire), or the moment you delete it. Deletion is permanent. If a pinned list stops being pinned, for example when Premium ends, it keeps 31 more days from that point so you have time to act on it.
Verification photos: photos you take in the Manual Veto flow.Showing your partner the item you're verifying.Our backend photo storage (EU).Within 5 minutes of the item or list being deleted.
Invitation records: inviter and invitee emails.Delivering invites between partners.Our backend database (EU).When the invite is accepted or declined, or your account is deleted.
Tier metadata: which tier you're on (free or premium).Enforcing per-tier limits.Our backend database (EU).Not stored as a separate record: your tier is worked out from your purchase records each time it is needed, so it reverts to free as soon as a subscription ends.
Purchase records: if you buy Spot Premium, the store where you bought it (Google Play / App Store), an opaque purchase token, the plan you chose, the subscription’s state and expiry date, and, because one purchase covers both partners, which partner it covers. We never receive or store your payment card, bank details, or billing address. Google Play (or the App Store) is the merchant of record and processes all payment data under its own privacy policy.Knowing you have Premium and applying it on every device you (and your covered partner) sign into, regardless of store.Our backend database (EU).30 days after the subscription ends, or when your account is deleted, whichever comes first. We keep the record for those 30 days so that a refund or a chargeback can still be matched to it. The store retains its own transaction records per its policy.
Push token: a device token issued by Google's Firebase Cloud Messaging (FCM) if you enable notifications.Waking your device when your partner acts. The payload is opaque metadata (event type + record ids): names, list contents, and photos never transit Google; your device fetches details from our backend and composes the notification locally.Our backend database (registry) + Google FCM (transport).When you sign out, delete your account, or the token goes ~9 months unused.
Consent record: timestamp and version of this policy you accepted.Proving consent at sign-up (GDPR Art. 7(1)).Our backend processor's authentication service (user metadata).When your account is deleted.
Diagnostic logs: server error logs may include your user id. We do not log message bodies.Diagnosing bugs.Server logs (managed by our backend processor).≤ 30 days (automatic rotation).
Optional crash & error reports: only if you turn on Settings → Share diagnostics automatically (off by default): crash stack traces, handled-error reports, recent app activity with email addresses and tokens removed, and device/app metadata (model, OS version, app version, locale). Never message bodies, list contents, photos, or your account identity.To find and fix bugs faster.Our error-monitoring processor, EU data region; see § 4 and § 5.Error events are retained for 90 days. Turning the toggle off stops all new reports immediately.

Using Spot without an account. You can start with Get started and use Spot as a guest: no email, no password, nothing to remember. Your lists and items are stored exactly as any other account's, and you can set a display name if you want one. Two consequences are worth knowing before you choose it:

  • The session lives on this device only. There are no credentials, so if you uninstall Spot, sign out, or lose the device, that account and its lists cannot be recovered. Not by you, and not by us. Adding an email and password (Settings → Create account) makes it recoverable, and is also what lets you share a list with a partner.
  • Deleting is done in the app. A guest account has no email address, so we cannot verify an emailed request as yours. Settings → Delete my account erases it immediately and permanently. Unused guest accounts are removed periodically.

User-initiated problem reports. Settings → Report a problem (or the prompt after a crash) prepares an email to support@spotgrocery.com with an on-device diagnostics file (recent app activity with email addresses removed) plus any screenshot you choose to attach. You send it from your own mail app; nothing leaves your device unless you send it.

Optional automatic diagnostics (off by default). If, and only if, you enable Settings → Share diagnostics automatically, the app uploads crash reports and handled-error reports as described in the table above. Reports are redacted on your device before upload: email addresses and authentication tokens are removed. While the toggle is off (the default), the error-reporting component is never even initialized: nothing is collected, transmitted, or fingerprinted. You can turn it off at any time, which takes effect immediately.

What we do NOT collect: plaintext passwords · location data (no location permission) · advertising identifiers (IDFA/AAID; Spot ships no advertising or analytics SDKs) · payment card or bank details (purchases are processed entirely by the app store) · contact lists · browsing history · biometric data.

3. How we use your data

Processing purposes and lawful bases (GDPR Art. 6):

PurposeLawful basis
Run the service (sign-in, sync lists, deliver invites, show verification photos)Contract (Art. 6(1)(b)).
Enforce tier capsContract.
Apply your Premium subscription across your and your covered partner’s devicesContract (Art. 6(1)(b)).
Diagnose bugs and abuseLegitimate interests (Art. 6(1)(f)).
Optional automatic diagnostics (§ 2)Consent (Art. 6(1)(a)): the Settings toggle; withdrawable there at any time.
Respond to privacy requestsLegal obligation (Art. 6(1)(c)).
Send transactional emails (invites, password reset)Contract.
Mandatory CSAM reporting (§ 9)Legal obligation.

We do not use your data for advertising, sell it, or profile you for automated decisions with legal effects.

4. Who can see your data

RecipientWhat and why
Your partner(s) on a shared listList and item names, done state, and the verification photos on that list; this is the service. Because a shared list is between two people who invite each other, each member can also see the other member's display name and account email address, so you can confirm who you're sharing with.
Our backend hosting processor (§ 5)They host the database, storage, and auth under a Data Processing Agreement, only on our instructions. What they cannot read: item and list names, brands, your notes, and your photos. Those arrive already encrypted on your device, and the keys are not ours to give (§ 8). What they do hold: everything else in § 2's table, including your email address, quantity, unit, price, done state, expiry dates, timestamps, and technical records.
Our error-monitoring processor (§ 5)Only if you enable the optional diagnostics toggle: the crash & error reports described in § 2. Processed under a Data Processing Agreement, only on our instructions, in its EU data region.
Google LLC (FCM push transport)Your push token and opaque event metadata only, never names, emails, list contents, or photos; notifications are composed on your device.
Google LLC (device backup)Your encryption key only, inside the device backup Google encrypts under your screen lock and states it cannot read (§ 8). Never list contents.
Law enforcement / regulatorsSpecific records when legally compelled, and proactive CSAM reports (§ 9) where the law requires them.
A successor entity (hypothetical merger/acquisition)The same data, bound by the same commitments.

We do not share your data with advertising networks, data brokers, or cross-service analytics platforms.

If your partner’s purchase covers you, the app shows each of you that the coverage exists (“You have Premium via your partner”), never any payment details.

5. International transfers

Our backend is hosted by our processor in the European Union (Frankfurt, Germany). From the EU/EEA/UK, your data stays in the EEA; from anywhere else, it is processed in the EU with the same protections.

Any onward transfer of EU/UK personal data outside the EEA (e.g. a sub-processor engaged by our backend processor) is covered by the EU Standard Contractual Clauses in our data-processing agreements with our processors, including, if you enable optional diagnostics, our error-monitoring processor (EU data region). You may request a copy of the SCCs, and the identity of our processors, by email.

6. How long we keep your data

§ 2's "Deleted" column is authoritative. In short: account data until deletion or 36 months of inactivity; lists 31 days after creation, or immediately when you delete them; photos within 5 minutes of deletion; logs ≤ 30 days; reported CSAM 90 days per the applicable preservation statute, or longer under a law-enforcement preservation order.

7. Your rights

These apply to all users, using the strictest (GDPR) wording; CCPA/PIPEDA equivalents share the same paths. Unless noted, invoke by emailing privacy@spotgrocery.com from your account email; we respond within 30 days (extendable by 60 for complex requests, with notice).

RightHow
Access: get a copy of your dataEmail.
ErasureIn-app: Settings → Delete my account. To remove lists but keep the account, use Settings → Delete my lists; a single list can also be erased from its delete dialog. No account (guest)? Use Settings → Delete my account. Without an email address we cannot verify an emailed request. Uninstalled? See spotgrocery.com/legal/delete-account or email.
RectificationAccount fields are editable in-app; email for anything else.
Portability (machine-readable copy, JSON)Email.
Restriction: pause processing during a disputeEmail.
Objection: to legitimate-interests processingEmail; we stop unless an overriding basis exists.
Withdraw consentDiagnostics: the Settings toggle, instant. Anything else: email. Withdrawal doesn't affect prior processing.
Complain to a regulatorYour national DPA (EU), the ICO (UK), the CPPA (California), or the OPC (Canada).
Non-discrimination (CCPA)Automatic; exercising rights never degrades your service.

8. Security

Encryption in transit (TLS 1.2+) and at rest (AES-256), on our backend processor's infrastructure. Access is enforced server-side: Row-Level Security on every table, and all state changes flow through server-side functions a modified client cannot bypass.

End-to-end encryption of list content (not switched on yet). Spot is built so that item and list names and brands, the notes you write on an item, and the verification photos you take are encrypted on your device before they are sent to us, with keys that exist only on the devices of the people on that list. That is not active yet. Until we switch it on, this content is stored in our EU database in a form we can read, protected by the transit and at-rest encryption described above. We will change this section, and the date at the top of this page, when it is on. Even then these fields will not be encrypted, because the app needs them to work: quantity, unit, price, done state, expiry dates, and timestamps.

Your encryption key, and how it is backed up. Your key is generated on your device and protected by the device's hardware keystore. Two optional backups exist so a new phone can read your lists:

  • Google Block Store, on by default. Spot asks Android to include your key in the device backup that Google encrypts under your screen lock, and which Google states it cannot read. Per Google's documentation, that backup is restored when you set up a new Android device with the same Google account. It is not a replacement for the recovery code: the backup arrives during device setup, so reinstalling Spot on the same phone does not bring the key back.
  • A recovery code, which you can generate in Settings. We store a copy of your key that only that code can decrypt. We cannot decrypt it, and we never see the code. You can also save the code to a file of your choosing.

What this means if you lose access. This describes how it will work once end-to-end encryption is switched on. If you lose your device and have neither a Block Store backup nor your recovery code, content on a list only you are on cannot be recovered, by you or by us. That is a consequence of encryption we cannot read, not a fault. A list you share works differently: your partner's device gives you access to that list again once you are both online, so a shared list does not depend on the code. Keep the code for the lists that are only yours.

In the event of a personal-data breach we will notify the supervisory authority within 72 hours (GDPR Art. 33) and you directly where the breach is likely to put your rights at high risk (Art. 34).

9. Mandatory CSAM reporting

If we discover child sexual abuse material on the service, via a user report (§ 10) or operator review, we report it to the designated authority in the applicable jurisdiction (for example, NCMEC's CyberTipline in the United States, per 18 U.S.C. § 2258A). We preserve the reported content for 90 days (or longer under a preservation order) so investigators can secure legal process. We do not notify the uploader: the statutes impose a non-disclosure obligation that overrides this policy's transparency commitments for this class of report. We do not proactively scan uploads with hash-matching tools; the law does not require monitoring, and we rely on user reports and operator review.

10. Reporting other unlawful or objectionable content

For non-CSAM content you believe violates our terms or the law (harassment, hate speech, IP infringement, …), use the in-app Report affordance on the affected item. EU users: we treat an in-app report as a notice under Art. 16 of the Digital Services Act. We act on substantiated reports promptly; where we remove content, the uploader receives a statement of reasons (DSA Art. 17) unless disclosure is legally prohibited.

11. Children

Spot is not intended for users under 13 (US) or under 16 where EU member states set a higher digital-consent age, and we do not knowingly collect children's data. If you believe a child has created an account, email privacy@spotgrocery.com; we will investigate and delete accounts that we determine belong to children.

12. Changes to this policy

We update this policy as Spot evolves. Material changes increment the version number at the top. A change that adds an optional practice (like automatic diagnostics) applies only if you opt in; any other material change will be presented in-app for renewed consent before it applies to you. Non-material edits (clarifications, typo fixes) update only the "Last updated" date. If you do not accept a new version, you can delete your account (§ 7).

13. Contact

privacy@spotgrocery.com for all privacy matters.