SpotPast Privacy Policy

Privacy Policy

SpotPast is built on a single principle: your location history is yours alone. Everything the app records stays on your device. We have no servers that store your data, no accounts that hold your information, and no way to see where you've been.

Last updated: July 4, 2026 Product: SpotPast (Android) Package: com.mzz.spotpast Country: United Kingdom

1. Summary (Plain English)

  • Your location data never leaves your device. SpotPast records where you go and stores it locally — no uploads, no cloud, no accounts.
  • Photos are scanned on-device. When you enable photo scanning, SpotPast reads location metadata from your photos directly on your phone. The images and their metadata are never sent anywhere.
  • We collect anonymous crash reports via Firebase to help us fix bugs. No location data is ever included.
  • Subscriptions are handled entirely by Google Play. We never see your payment details.
  • We do not sell your data and cannot access your location history under any circumstances.
Your location history is stored only on your device. SpotPast does not have a backend server that stores personal data. When you uninstall the app, your data is gone. There is no account to delete, no data request to make — because we never had it.

2. What We Collect

2.1 Location Data

  • SpotPast uses your device's GPS and network location to record the places you visit.
  • Location is collected periodically in the background when you enable tracking.
  • All location records are stored only on your device in a local database.
  • Location data is never transmitted to any server or third party.

2.2 Photo Location Metadata (EXIF)

  • If you enable photo scanning, SpotPast reads the location coordinates embedded in your photos (EXIF data).
  • This scanning happens entirely on your device — your photos are never uploaded or transmitted.
  • Only the location coordinate and timestamp are extracted; image content is never read or stored.

2.3 Crash Reports (Firebase Crashlytics)

  • Device model and Android version
  • App version at time of crash
  • Stack trace of the error
  • No location data, no personal information, no diary content

2.4 Anonymous Usage Analytics (Firebase Analytics)

  • Which features are used (e.g. "calendar viewed") — no location content
  • App session duration
  • Device type and OS version (aggregated)
  • All data is anonymised — individual users cannot be identified

2.5 Subscription Status (Google Play)

  • SpotPast verifies your SpotPast Plus subscription status with Google Play.
  • Google Play handles all payment processing. We never receive or store payment information.
  • Only your subscription state (active/inactive) is checked — no financial data is processed by us.

2.6 Data We Do NOT Collect

  • Your name, email address, or any account information
  • Your contacts, messages, or browsing history
  • Photo image content (only GPS coordinates from EXIF metadata)
  • Payment or billing details
  • Any data from other apps on your device

3. How We Use Data

  • Location data: to build your personal diary and display your history in the calendar and map views. Stored and used entirely on-device.
  • Photo metadata: to add photo-derived locations to your diary. Processed and stored entirely on-device.
  • Crash reports: to detect and fix bugs that cause the app to crash or misbehave.
  • Analytics: to understand which features are useful so we can improve the app.
  • Subscription status: to unlock SpotPast Plus features for paying subscribers.

We do not use any data for advertising, profiling, or selling to third parties.

4. Third-Party Services

4.1 Firebase (Google)

We use Firebase Crashlytics and Firebase Analytics for anonymous crash and usage data. See Firebase Privacy Policy.

4.2 Google Play Billing

SpotPast Plus subscriptions are processed by Google Play. Your payment details are handled entirely by Google. See Google Payments Privacy Notice.

5. Data Retention and Deletion

  • Location visits and diary data: stored on your device indefinitely until you delete individual entries or uninstall the app.
  • Favourite places: stored on your device until you delete them within the app.
  • App settings and preferences: stored on your device until you uninstall the app.
  • Crash reports: retained by Firebase for 90 days per Firebase's standard policy.
  • Analytics: aggregated and anonymised — retained per Firebase Analytics standard policy.

Because all personal data is stored only on your device, uninstalling SpotPast permanently removes all your diary data. We have no copies to delete on your behalf.

6. Data Sharing

We do not sell your data. We share data only as follows:

  • Firebase (Google): anonymous crash and usage analytics as described above.

No location data, diary content, or personally identifiable information is ever shared with any party.

7. Children's Privacy

SpotPast is a general-purpose location diary intended for adults. As described in this policy, we do not collect personal data from anyone — including children. All diary data stays on the user's device and is never transmitted to us.

8. Your Rights

Because your diary data is stored only on your device and we hold no personal information, most traditional data rights are exercised directly on your device:

  • Access and deletion: view or delete any diary entry within the app at any time.
  • Full deletion: uninstall SpotPast to permanently remove all data.
  • Location permission: revoke location access at any time in Android Settings → Apps → SpotPast → Permissions.

9. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top will reflect any changes. Continued use of SpotPast after changes constitutes acceptance of the updated policy.

10. Contact

For questions about this Privacy Policy:
Email: pocket.tools26@gmail.com