Legal
Privacy Policy
What Spotary is
Spotary is a discovery game: you photograph things you encounter, an AI model identifies the main subject, and the result is added to your private collection. Spotary is operated from the European Union and designed with GDPR principles in mind. Spotary is intended for users aged 13 and over and is not directed at children.
Data we process
- Account data. Sign-in is handled by Clerk (our authentication provider). We store your authentication subject ID, and optionally a display name and username you choose.
- Photos. Photos you capture are uploaded to a private storage bucket. They are visible only to you; there is no public feed. GPS metadata is stripped from images before upload.
- AI analysis. To identify a photo, we send it to OpenAI with storage disabled (
store: false) together with a pseudonymous identifier. We never send your name, email, or precise location. - Location (opt-in only). If you explicitly enable it, we store a coarse (~10 km) location with your sightings. This is off by default.
- Gameplay data. Discoveries, sightings, XP, and level.
- Feedback. Reports you submit about incorrect identifications.
What we never do
- No face recognition; people in photos are never identified.
- No reading or storing of license plates.
- No selling of personal data; no advertising SDKs.
- No precise GPS collection.
Your rights
From the app's profile screen you can export your data as JSON and delete your account, which removes your database records immediately and reliably deletes your stored photos. EU users additionally have the GDPR rights of access, rectification, erasure, restriction, portability, and objection — contact us to exercise them.
Retention
Uploaded photos that never become a scan are automatically deleted after 48 hours. Account data is retained until you delete your account.
Processors
Clerk (authentication), Cloudflare (hosting, storage, queues), PlanetScale (database), OpenAI (image identification, storage disabled).