Privacy Policy
Effective Date: To be set on public launch
Last Updated: 2026-08-26
1. Introduction and Scope
This Privacy Policy describes how Spot LLC, a Delaware limited liability company (in formation) ("Spot," "we"), collects, uses, retains, discloses, and protects information when you use the Spot mobile application and related services (the "Service"). It applies to all users of the Service in the United States. By creating an account or otherwise using the Service, you agree to this Policy. If you do not agree, you must not access or use the Service.
This Policy is incorporated by reference into our Terms of Service and forms a binding part thereof.
2. Information We Collect
2.1 Account Information
Phone number (primary credential), username, display name, date of birth (for age gating), optional profile photo, optional university affiliation, and account-recovery information.
2.2 Content
Photographs, notes, captions, stickers, doodles, and other content you submit through Photo, Note, and Presence Ping Spots (each a "Spot"); the content of one-to-one and group chat messages, including text, links, reactions, and media attachments; and the category, risk level, and location associated with each Safety Report you submit. Safety Reports do not contain photographs or free-text descriptions.
2.3 Friend Graph
Your friend connections (including incoming and outgoing requests, accepted Mutual Friend relationships, blocks, and mutes) and the per-friend permission selections you make through the five-question Privacy Form. With your permission, we may access your device contacts solely to help you find existing connections; we do not retain or repurpose your full address book for advertising.
2.4 Location Information
We collect location in three distinct modes:
- Per-event location. A single latitude/longitude captured at the moment you post a Spot or Safety Report.
- Continuous live location. Real-time location data transmitted to a counterpart during an active Mutual Live-Location Share session, which is capped at 24 hours and may be terminated by either participant at any time.
- Pinned Area coordinates. A Pinned Area is a user-designated geographic zone (such as Home, Campus, or Other) used to surface Safety Reports relevant to that area. A Pinned Area is a zone you choose, not a record of where you have been; we do not log your presence within a Pinned Area.
All location collection requires operating-system-level permission, which you may revoke at any time.
2.5 Device and Technical Information
Device model and manufacturer, operating system and version, app version, language and locale, time zone, mobile carrier, IP address, resettable mobile advertising identifiers (subject to your OS-level controls), and crash and diagnostic data.
2.6 Usage and Inferred Information
Information about how you use the Service (features used, screens viewed, sessions, timing) and limited inferences derived from such usage. We do not infer sensitive characteristics (health, religion, sexual orientation, immigration status) for advertising or sensitive profiling.
2.7 Biometric Carve-Out
We do not generate, collect, store, or sell biometric identifiers (such as faceprints or voiceprints) derived from content you upload, and we do not use facial recognition to identify you to other users. If we ever introduce face-detection technology for trust and safety purposes, we will update this Policy and obtain any consent required under applicable law before doing so.
2.8 Information From Third Parties
Limited fields from single-sign-on providers you choose to use; signals from service providers performing functions on our behalf (crash reports, geocoding lookups, fraud signals); publicly available emergency and weather feeds overlaid on the Safety Map; and information other users may provide about you (for example, by tagging you in a Spot or submitting a report concerning your conduct).
3. How We Use Information
We use the information described in Section 2 to: (a) operate the Service, including delivering Spots to the recipients you designate, routing Safety Reports by geography, running Mutual Live-Location Share sessions, and delivering chat messages; (b) maintain safety, integrity, and trust, including investigating and responding to abuse, harassment, fraud, threats to life, and other violations of these Terms or applicable law; (c) provide essential service communications (login codes, security alerts, material policy updates); (d) comply with legal obligations and respond to lawful process as described in Section 13; and (e) understand how the Service is used and improve it. You may opt out of optional product analytics at any time in Settings > Privacy > Analytics; baseline diagnostic and security telemetry necessary to operate the Service may not be fully disabled.
We do not use Safety Report content, the content of your chats, Pinned Areas, precise location, or your Spots to serve advertising.
4. The Safety Map
The Safety Map is designed to permit users to flag a safety condition without disclosing their identity to other users. Reporter anonymity is implemented as a structural property of the feature.
A published Safety Report shows only the fixed category selected, the risk level (High, Medium, or Low), the location of the reported incident, and the time of posting. It does not contain photographs, free-text descriptions, or any identifier that is visible to other users on the client. The reporter's identity is stored only on our servers, in access-controlled systems, and is not displayed on any client surface, including the moderation and trust-and-safety tooling used by our staff in the ordinary course of review.
We will not disclose the identity of a Safety Report reporter to a third party outside Spot in response to a subpoena alone. We require a court order or equivalent judicial process, except in a bona fide emergency involving imminent risk of death or serious physical injury. Where lawful, we will provide the affected reporter with advance notice and a meaningful opportunity to object before any disclosure. Internally, we operate a narrowly scoped abuse-review lane that allows designated staff to access reporter identity to investigate documented patterns of misuse (for example, repeated false reporting); internal access is logged and audited.
Published pins expire 24 hours after submission or upon resolution, whichever is sooner. The server-side reporter-identity record is retained for 90 days after pin expiry and is then deleted from primary systems, subject to the retention windows described in Section 11.
5. Spots, Chat, and the Mutual-Friends Layer
Spots and Safety Reports are removed from user-facing map surfaces within 24 hours of posting, or sooner if deleted or, in the case of Safety Reports, marked resolved. Direct and group chat messages remain visible to their participants until explicitly deleted or until the associated account or conversation is deleted. Saving a chat message bookmarks it for saved-content views, is visible to all members of the chat, and does not change its retention period.
A user identified as the subject of, or principal person depicted in, a Spot (a "Tagged Friend") may delete that Spot at any time during its 24-hour life. Deletion is platform-wide and removes the Spot from every recipient's surface; the user who posted the Spot (the "Sender") is notified that the Spot has been deleted.
Mobile operating systems generally permit recipients to capture screenshots or screen recordings of content displayed on their devices, and external cameras can photograph any screen. We attempt to detect in-app screenshots where the operating system supports detection, but we cannot guarantee detection and cannot prevent capture. Our Terms of Service prohibit non-consensual capture and redistribution.
A Mutual Live-Location Share session requires affirmative opt-in by both participants, is capped at 24 hours, and may be terminated by either participant at any time. After the session ends, location coordinates are deleted from user-facing systems; limited session metadata (participants, start/end times, duration) is retained for up to 90 days for safety and dispute resolution.
6. How We Share Information
We share information only as described below.
- With other users. Spots and Presence Pings are delivered only to the Mutual Friends you authorize through the Privacy Form. Forwarding rules: a Tagged Friend may forward a Spot of themselves to any user, with the Sender shown as "Anonymous" to recipients who are not Mutual Friends of the Sender; a Sender may forward a Spot only to users who are Mutual Friends of both the Sender and the Tagged Friend. Published Safety Reports are visible to other users in the relevant geography subject to the structural anonymity described in Section 4.
- With service providers. We share information with vendors that process it on our behalf under written contracts limiting use to providing services to us, including providers of cloud hosting, push notification delivery, transactional email and SMS, product analytics and crash reporting, customer support tooling, fraud and trust-and-safety detection, mapping and geocoding, and (if and when introduced) age-assurance or identity-verification services. A current list of our key subprocessors and SDKs will be maintained on our website on or before public launch.
- For legal reasons. As described in Section 13.
- In a business transfer. In connection with a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, subject to the protections of this Policy.
- With your consent or at your direction.
7. Advertising and Analytics
We do not sell personal information for monetary consideration and do not share personal information for cross-context behavioral advertising as those terms are defined under California law. We do not serve targeted advertising to any user known to be between 13 and 17 years of age and do not build advertising profiles based on sensitive inferences. We do not use Safety Report content, Pinned Areas, precise location, Spots, or the content of your chats to serve advertising.
8. Minors (Users 13 to 17)
The Service is available to users 13 and older. We collect a self-attested date of birth at sign-up and may apply additional age-assurance signals over time. For users identified as being between 13 and 17, we apply the following defaults: a default-private friendship graph; restricted Mutual Live-Location Share defaults (off by default, with in-app reminders before a session is started); no targeted advertising or sensitive-inference profiling; and no sale or sharing of the user's information for cross-context behavioral advertising. A parent or legal guardian may contact us at privacy@[domain].com to make a rights request on behalf of a minor child or to request termination of a minor's account.
We do not knowingly collect personal information from children under 13. If we learn that we have inadvertently collected information from a child under 13, we will delete it consistent with the Children's Online Privacy Protection Act and applicable state minor-protection statutes (including the California Age-Appropriate Design Code Act and analogous statutes in Utah, Florida, and other states).
9. Your Rights, Choices, and Controls
You may, at any time within the Service: edit your per-friend Privacy Form; add, rename, or delete Pinned Areas; manage push notifications and in-app notification categories; block or mute another user; opt out of optional product analytics; and request deletion of your account, subject to the cooling-off period described in Section 11.
Subject to applicable law, you may also have the right to confirm whether we process personal information about you and to obtain a copy; to correct inaccurate personal information; to request deletion of personal information about you, subject to legal exceptions; to receive certain personal information in a portable, machine-readable format; and to opt out of the sale or sharing of personal information or of certain profiling, in each case as applicable. To exercise a right, submit a request through Settings > Privacy > Your Rights or to privacy@[domain].com. We will take reasonable steps to verify your identity. If we deny a request in whole or in part, you may appeal by replying to our response. California residents may use an authorized agent. We will not discriminate against you for exercising your privacy rights.
10. State Privacy Disclosures (United States)
California (CCPA/CPRA). In the 12 months preceding the Last Updated date, we collect the categories of personal information described in Section 2 (including identifiers, customer records, commercial information, internet or other electronic network activity, geolocation data, audio and visual information, inferences, and sensitive personal information such as precise geolocation and account credentials), from the sources described in Section 2, for the purposes described in Section 3. We disclose categories of information to service providers as described in Section 6 and for legal reasons as described in Section 13. We do not sell personal information for monetary consideration and do not share personal information for cross-context behavioral advertising. We honor browser-based opt-out preference signals, including the Global Privacy Control, where technically feasible. We do not offer financial incentives in exchange for personal information.
Other states with comprehensive privacy laws. Residents of Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Delaware, Iowa, Indiana, Tennessee, New Hampshire, New Jersey, Minnesota, Maryland, Kentucky, and Rhode Island, and of other states with comprehensive consumer privacy laws as they take effect, may have rights of access, correction, deletion, portability, and opt-out of targeted advertising, sale, and certain profiling, in each case as defined and limited by the applicable state law. Exercise of these rights and the appeal of any adverse decision is described in Section 9.
Washington and Nevada Consumer Health Data. Because the Safety Map and Pinned Areas involve precise geographic information, location data we process may relate to your visits to or proximity to a reproductive- or sexual-health facility, a gender-affirming-care facility, a mental-health or addiction-services provider, a domestic-violence shelter, a place of worship, or another sensitive location. For users protected by the Washington My Health My Data Act, the Nevada Consumer Health Data Privacy Law, or analogous laws: we do not sell consumer health data and do not share consumer health data for advertising; we do not use Safety Report content, Pinned Areas, or precise location to infer health conditions; you have a separate right to confirm, access, withdraw consent regarding, and request deletion of consumer health data about you, exercised through the channels described in Section 9 and identified as a "consumer health data" request.
11. Data Retention
- Account information: until account deletion, then up to 30 days (cooling-off period).
- Spots (Photo, Note, Presence Ping): up to 24 hours from posting.
- Direct and group chat messages: until explicitly deleted or the associated account or conversation is deleted, subject to the backup window below. Saving a message bookmarks it but does not change its retention period.
- Safety Reports (published pins): up to 24 hours, or until resolved.
- Safety Report reporter identity: 90 days after pin expiry.
- Pinned Areas: until you delete them.
- Mutual Live-Location Share location: not retained after session ends; session metadata up to 90 days.
- Operational and security logs: up to 90 days.
- Encrypted backups: up to 30 days (disaster recovery only).
- Inferred data (non-sensitive): up to 12 months from last activity.
Following the 30-day account-deletion cooling-off period, account-level information is deleted or de-identified on the schedules above. We may retain information beyond these periods to the extent required by law, by a legal hold issued in connection with actual or reasonably anticipated litigation or investigation, or as necessary to protect against fraud or imminent harm.
12. Security
We use administrative, technical, and physical safeguards designed to protect personal information, including TLS 1.2 or higher for data in transit, AES-256 for data at rest, access controls and least-privilege provisioning, network segmentation, logging and monitoring, vendor security review, and a documented incident response process. The Service is not end-to-end encrypted. Content is encrypted in transit and at rest, but we hold the keys and can access content on our servers when necessary to operate the Service, respond to abuse, or comply with legal process. In the event of a security incident affecting your personal information, we will provide notice as and to the extent required by applicable law.
13. Government Requests, Law Enforcement, and Legal Process
We require legal process appropriate to the type of information requested. For non-content account information we generally require a subpoena; for content of communications and other sensitive information we generally require a search warrant or equivalent. As described in Section 4, we do not disclose Safety Report reporter identity to a third party outside Spot in response to a subpoena alone; we require a court order or equivalent judicial process, except in a bona fide emergency. We may voluntarily disclose information without legal process if we have a good-faith belief that an emergency involving imminent risk of death or serious physical injury requires disclosure without delay. Where lawful and not otherwise prohibited, we will provide affected users with notice of legal requests for their information and a meaningful opportunity to object. We will publish a semiannual transparency report beginning no later than the first full reporting period after public launch.
14. International Users
The Service is offered only in the United States and is not directed to, marketed to, or intended for users in the European Economic Area, the United Kingdom, Switzerland, or other jurisdictions outside the United States. If you access the Service from outside the United States, you do so at your own initiative, and you understand that your information will be transferred to, stored in, and processed in the United States, where data-protection laws differ from those of your home country.
15. Changes to This Policy
We may update this Policy from time to time. For material changes, we will provide notice through the Service and, where we have your email address, by email, at least 14 days before the changes take effect. The "Last Updated" date at the top of this Policy reflects the most recent change. Continued use of the Service after the effective date of an updated Policy constitutes acceptance to the extent permitted by law.
16. Contact
Privacy questions, requests, or accessibility-format requests may be sent to privacy@[domain].com. A physical mailing address will be provided upon entity formation and published in the Service.
