Pocket Spotter

Privacy Policy

Effective 4 October 2026 · Tyler Hernandez · support@tyhdev.net

Pocket Spotter is a training app. It is built to keep your data on your phone, and to send off it only what the AI coach needs to answer you. This policy explains exactly what that is, who handles it, and what your rights are.

The short version

Consumer health data is also covered by a separate Consumer Health Data Privacy Policy, as Washington and some other US states require.

Who is responsible for your data

Pocket Spotter is published by Tyler Hernandez, an individual developer, who decides how your data is used (the "controller" under laws such as the GDPR). "I", "me" and "my" in this policy mean Tyler Hernandez. Contact: support@tyhdev.net.

Who this app is for

Pocket Spotter is intended for adults aged 18 and over. It is not directed to anyone under 18, and I do not knowingly collect data from anyone under 18. It is rated 18+ on the App Store. If you believe someone under 18 is using the app, contact me and I'll help remove what I can.

What stays on your phone

Everything you log in Pocket Spotter is stored on your device: workouts and sets, programs, check-ins, injuries, body measurements, progress photos, and your name if you enter one. If you use Pocket Spotter on Apple Watch, the watch and phone talk to each other directly.

I do not copy any of this to my own servers, and the app does not sync it to iCloud.

Photos you use to import a program are read on your phone. Only the text found in the photo is sent to the AI, never the photo itself. Progress photos never leave your phone.

What the AI features send, and when

The coach, exercise swaps, the daily brief, program tailoring, the season planner and program import all use AI. Each time you use one of them, Pocket Spotter sends the information that feature needs:

The app asks before sending any health data, and you can change your answer in Profile → AI Coach. If you say no, the coach still works from your logged training, and it is told your health details weren't shared so it won't assume you have no injuries.

It does not send your name, photos, contacts or location.

Who handles it

ServiceWhat it doesWhere
Cloudflare, Inc.Runs my small server that passes each request to Google and returns the answer. It stores no content.Cloudflare's global network
Google LLC — Gemini API (paid service)Generates the answerGoogle's infrastructure, which may be outside your country
Apple Inc.App Store, purchases, Apple Health, TestFlightUnder Apple's own privacy policy
RevenueCat, Inc.Checks whether your subscription or free trial is active (see Purchases)United States

What my server does keep

To keep the AI affordable and to stop automated abuse, my server keeps a few numbers — never the content of anything you send:

WhatWhyHow long
A random ID for your installation of the app, with this month's AI usage cost and number of program importsFair-use limits and abuse prevention40 days
The same ID, with a count of your requests in the last few minutesRate limitingUp to 20 minutes
Your IP address, with a count of today's requestsDaily limit against automated abuse2 days

The installation ID is a random code the app creates. It isn't your name, your Apple ID or Apple's advertising identifier. It is stored in your phone's keychain so that usage limits can't be reset by reinstalling, which means it may remain on your phone after you delete the app. Your IP address is never used to work out your location.

Emails, TestFlight feedback and crash reports

Three other things can reach me, only if you send them:

Apple Health

Pocket Spotter reads Apple Health data only with your permission, which you give or remove in the Health app and in Pocket Spotter. It is used only to give you better training recommendations. It is never used for advertising or marketing, never sold, never shared with anyone except as described above to answer your coach requests, and never stored in iCloud. If the company that processes it ever changes, the app will ask for your permission again before sending any.

Purchases

Purchases and subscriptions are handled by Apple through the App Store. I don't receive your payment details.

To know whether your subscription or free trial is active, the app uses RevenueCat, Inc. RevenueCat receives your purchase and subscription history from Apple, linked to a random identifier the app creates (not your name, email or Apple ID), plus basic device details such as the app version, operating system and IP address. It receives none of your training, health or chat data.

What I don't do

Your choices

Your rights, wherever you live

You can ask me to confirm what I hold about you, to access it, correct it, delete it, restrict or object to its use, or receive it in a portable format, and you can withdraw consent at any time. Email support@tyhdev.net; I'll reply within 30 days. I may ask you to confirm details before acting on a request, so I don't act on someone else's behalf by mistake.

Because I don't keep your content and have no account for you, the only data about you on my server is the counters above, stored against a random ID that I can't connect to you. The training data itself is on your phone, where you control it completely. If you send me your installation ID, I'll delete its counters straight away; otherwise they expire within 40 days.

European Economic Area, United Kingdom and Switzerland

The legal bases I rely on under the GDPR and UK GDPR:

ProcessingLegal basis
Sending your training data and messages to generate the AI answer you asked forPerformance of a contract — providing the feature you requested (Art. 6(1)(b))
Sending injuries and body measurements you've loggedYour explicit consent, given in the app (Art. 6(1)(a) and 9(2)(a))
Sending Apple Health readingsThe same explicit consent (Art. 6(1)(a) and 9(2)(a))
Installation ID and IP countersLegitimate interests — keeping the service affordable and preventing abuse (Art. 6(1)(f))

International transfers: Cloudflare and Google may process data outside the EEA, UK or Switzerland, including in the United States. Google processes it under its data processing terms for paid Gemini API use, which rely on the EU–US Data Privacy Framework and Standard Contractual Clauses; Cloudflare's data processing terms rely on Standard Contractual Clauses.

You also have the right to complain to your local data protection authority.

California and other US states

I don't sell or share personal information, including for cross-context behavioral advertising, and I don't use sensitive personal information to infer characteristics about you. The categories involved are those listed above: health and fitness information, the content you submit, and an installation identifier. You won't be treated differently for exercising any right in this policy.

I'll disclose the little data I hold only if the law requires it. If Pocket Spotter is ever sold or transferred, this policy would continue to protect any data that moves with it, and I'd tell you before it changed.

Security

Data between the app, my server and Google is encrypted in transit (HTTPS). The provider key that talks to Google lives only on my server, never in the app. Data on your phone is protected by your device's own security.

Changes

If I change what Pocket Spotter sends or who processes it, I'll update this policy and the effective date above. If a change affects your health data, the app will ask for your permission again before sending any.

Contact

Tyler Hernandez — support@tyhdev.net