Privacy Policy
Last updated: 6 August 2026
1. Who we are
Spotter.fit is operated by Gustavo Serres, an individual sole operator based in Portugal ("we", "us"). For the purposes of the EU General Data Protection Regulation (GDPR), Gustavo Serres is the data controller for the personal data described in this policy.
For anything related to your personal data, contact privacy@spotter.fit.
2. What this policy covers
This policy covers the Spotter.fit marketing site (spotter.fit), the web application (app.spotter.fit) and the Spotter.fit mobile app. It explains what personal data we process, why, who can see it, how long we keep it, and the rights you have over it.
Cookie consent inside the application is managed separately — see the cookie policy in the app, where you can also change your consent choices at any time.
One distinction matters throughout: if you are a client of a personal trainer who uses Spotter.fit, your trainer decides what to ask of you (which check-ins, surveys and measurements to schedule), and we provide the platform that stores and processes those answers. This policy describes what the platform itself does with your data.
3. The data we process
Account and identity data
When you create an account we store your first and last name, email address and, if you choose to provide them, your gender and date of birth. You can sign in with an email and password, with a passkey, or through Google or Apple. If you use Google or Apple, we receive your name and verified email address from them — nothing more.
Health and fitness data
Spotter.fit is a training platform, so much of what it stores is data about your body and your training. Depending on how you and your trainer use it, this can include:
- body measurements — weight, body fat, and circumference measurements such as chest, waist, hips, arms, thighs and calves;
- check-in photos of your body, taken from up to four angles;
- training logs — the exercises, sets, reps, loads and effort you record, including sessions your trainer records for you in person;
- flags you raise on a session, including pain flags;
- your answers to surveys and questionnaires your trainer schedules;
- goals, and comments exchanged between you and your trainer;
- notes your trainer writes about you (see section 5).
Under the GDPR, data concerning health is a special category of personal data. We process it only because you knowingly and voluntarily enter it (or ask your trainer to record it for you) in order to receive the service — this is processing based on your explicit consent (Article 9(2)(a) GDPR). You can decline to fill in any measurement, photo or survey, and you can delete your account at any time.
Check-in photos are stored in private storage and are never publicly accessible; they are served only through short-lived signed links to you and to the staff of the workspace you train in.
Payments
Paid subscriptions are sold through Creem.io, which acts as Merchant of Record — Creem is the legal seller, handles the checkout, stores your card details and accounts for VAT. Your card number never reaches us. What we store is your subscription status and payment metadata: amounts, currency, dates and Creem's reference identifiers.
Usage and analytics
With your consent — and only with it — we collect technical telemetry through Amazon CloudWatch RUM: page load performance, JavaScript errors, page views and the timing of network requests. This telemetry is tied to your user identifier, role and workspace, never to your name or email. If you decline analytics in the consent banner, none of it is collected.
Support and feedback
If you send feedback through the app, we store your message, your verified email address and any screenshots you attach.
Push notifications
If you enable notifications in the mobile app, we store a push token for your device together with its platform and language, and use Expo's push service to deliver notifications.
4. Why we process your data (legal bases)
- To provide the service — storing your account, your training data and your workspace memberships, and showing them to the people described in section 5: performance of a contract, Article 6(1)(b) GDPR.
- Health data specifically — your explicit consent, Article 9(2)(a) GDPR, given by entering the data.
- Security and abuse prevention — server logs and monitoring: our legitimate interest in keeping the service secure, Article 6(1)(f) GDPR.
- Analytics — your consent, Article 6(1)(a) GDPR, which you can withdraw at any time in the app's cookie settings.
5. Who can see your data inside Spotter.fit
Spotter.fit is organised in workspaces run by personal trainers. Access follows workspace membership:
- The trainers and staff of a workspace you train in can see the training and health data connected to that workspace — your plans, logs, measurements, check-in photos, survey answers and comments.
- You can see your own data. One exception: trainers can keep private coaching notes about their clients, and those notes are never shown to the client.
- Members of one workspace cannot see data belonging to another workspace.
Your trainer is independently responsible for how they use the information you share with them, in the same way as in any off-platform coaching relationship.
If you connect an AI assistant (such as Claude or ChatGPT) to your account through our MCP connector, that assistant can read and act on your data with exactly your permissions, for as long as you keep the connection. You can revoke a connection at any time under Account → Connected apps.
6. Service providers
We use a small number of processors and recipients to run Spotter.fit:
- Amazon Web Services — all hosting and storage, in the eu-west-1 (Ireland) region: authentication (Amazon Cognito), database, file storage and monitoring.
- Creem.io — payments, as Merchant of Record (section 3).
- Google and Apple — only if you choose to sign in with them.
- Expo — delivery of mobile push notifications, if you enable them.
- AI assistants via MCP — only for connections you create yourself (section 5).
7. Where your data lives
Your data is stored in the European Union (AWS region eu-west-1, Ireland). Where a provider processes data outside the European Economic Area — for example when you sign in with Google or Apple, or when a connected AI assistant is operated from outside the EEA — the transfer is covered by an adequacy decision of the European Commission or by standard contractual clauses.
8. How long we keep your data
- While your account exists — we keep your data so the service can work.
- When you delete your account — deletion is self-service in the app. There is a 7-day grace period during which you can change your mind; after it, your data — database records and stored media, including check-in photos — is permanently and automatically erased.
- Deleted items — individual records you delete inside the app are retained in a soft-deleted state for up to about 180 days (so mistakes can be undone and references stay consistent), then removed.
- Feedback — feedback submissions, including the email address and screenshots, are kept for 180 days.
9. Cookies and data stored on your device
The application uses a small set of cookies and browser storage:
| Name | Purpose | Lifetime |
|---|---|---|
| spotter.consent | Remembers your cookie consent choices | 180 days |
| spotter.locale | Your language | persistent |
| spotter.tz | Your device timezone, so calendars render correctly | persistent |
| Sign-in cookies (Amazon Cognito) | Keeping you signed in | session-based |
| Active workspace | Remembers which workspace you last used | 1 year |
| cwr_* | Analytics session (only with your consent) | see cookie policy |
The app also uses your browser's local storage for drafts of workout logs you are filling in (so a lost connection does not lose your entries — this data stays on your device until the log is submitted) and for small interface preferences. The marketing site you are reading now sets no cookies at all.
You can review and change your consent at any time in the cookie policy page of the app.
10. Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you, and receive a copy;
- correct inaccurate data;
- erase your data ("right to be forgotten") — largely self-service through account deletion;
- restrict or object to processing;
- receive your data in a portable format;
- withdraw consent at any time, without affecting the lawfulness of processing before withdrawal.
To exercise any of these rights, email privacy@spotter.fit. We will respond within one month.
You also have the right to lodge a complaint with a supervisory authority — in Portugal, the CNPD (Comissão Nacional de Proteção de Dados, www.cnpd.pt), or the data protection authority of your own country of residence.
11. Children
Spotter.fit is not directed at children. You must be at least 16 years old to create an account.
12. Changes to this policy
When this policy changes in a way that matters, we will update the date at the top and, for significant changes, notify you in the app. Earlier versions are available on request.
13. Contact
Questions about this policy or about your data: privacy@spotter.fit.
See also our Terms of Service.