Pocket Spotter
Privacy Policy
Pocket Spotter is a training app. It is built to keep your data on your phone, and to send off it only what the AI coach needs to answer you. This policy explains exactly what that is, who handles it, and what your rights are.
The short version
- No account. Pocket Spotter never asks for your name, email or phone number.
- Your training log stays on your phone. Workouts, programs, progress photos and check-ins are stored on your device.
- The AI coach is the only thing that sends data off your phone. When you use it, the parts of your training data it needs go through my server to Google's Gemini API, which writes the answer.
- Health data is only sent if you allow it — injuries and body measurements you log, and Apple Health readings — and you can switch it off any time.
- Google does not use your data to train its AI, and my server doesn't keep what you send.
- No ads, no tracking, and your data is never sold.
Consumer health data is also covered by a separate Consumer Health Data Privacy Policy, as Washington and some other US states require.
Who is responsible for your data
Pocket Spotter is published by Tyler Hernandez, an individual developer, who decides how your data is used (the "controller" under laws such as the GDPR). "I", "me" and "my" in this policy mean Tyler Hernandez. Contact: support@tyhdev.net.
Who this app is for
Pocket Spotter is intended for adults aged 18 and over. It is not directed to anyone under 18, and I do not knowingly collect data from anyone under 18. It is rated 18+ on the App Store. If you believe someone under 18 is using the app, contact me and I'll help remove what I can.
What stays on your phone
Everything you log in Pocket Spotter is stored on your device: workouts and sets, programs, check-ins, injuries, body measurements, progress photos, and your name if you enter one. If you use Pocket Spotter on Apple Watch, the watch and phone talk to each other directly.
I do not copy any of this to my own servers, and the app does not sync it to iCloud.
Photos you use to import a program are read on your phone. Only the text found in the photo is sent to the AI, never the photo itself. Progress photos never leave your phone.
What the AI features send, and when
The coach, exercise swaps, the daily brief, program tailoring, the season planner and program import all use AI. Each time you use one of them, Pocket Spotter sends the information that feature needs:
- Your training: your program and current phase, today's session, recent training history and training-load trends.
- What you tell it: your messages to the coach, check-in answers (energy, soreness, stress, time available, notes), your sport and goals.
- Program documents you import: the text of the document.
- Health data — only if you allow it:
- injuries you've logged, and your body weight, body-fat and lean-mass readings;
- from Apple Health: last night's sleep, resting heart rate and HRV, today's steps and active calories, and workouts recorded by other apps or your watch.
The app asks before sending any health data, and you can change your answer in Profile → AI Coach. If you say no, the coach still works from your logged training, and it is told your health details weren't shared so it won't assume you have no injuries.
It does not send your name, photos, contacts or location.
Who handles it
| Service | What it does | Where |
|---|---|---|
| Cloudflare, Inc. | Runs my small server that passes each request to Google and returns the answer. It stores no content. | Cloudflare's global network |
| Google LLC — Gemini API (paid service) | Generates the answer | Google's infrastructure, which may be outside your country |
| Apple Inc. | App Store, purchases, Apple Health, TestFlight | Under Apple's own privacy policy |
| RevenueCat, Inc. | Checks whether your subscription or free trial is active (see Purchases) | United States |
- My server does not store what you send. It keeps no message content and no logs of it.
- Google does not use your requests or its answers to improve its products or train its AI. Under the paid Gemini API terms, Google keeps them for a limited time only to detect and prevent misuse of its service.
- My server does not send Google anything that identifies you or your device.
What my server does keep
To keep the AI affordable and to stop automated abuse, my server keeps a few numbers — never the content of anything you send:
| What | Why | How long |
|---|---|---|
| A random ID for your installation of the app, with this month's AI usage cost and number of program imports | Fair-use limits and abuse prevention | 40 days |
| The same ID, with a count of your requests in the last few minutes | Rate limiting | Up to 20 minutes |
| Your IP address, with a count of today's requests | Daily limit against automated abuse | 2 days |
The installation ID is a random code the app creates. It isn't your name, your Apple ID or Apple's advertising identifier. It is stored in your phone's keychain so that usage limits can't be reset by reinstalling, which means it may remain on your phone after you delete the app. Your IP address is never used to work out your location.
Emails, TestFlight feedback and crash reports
Three other things can reach me, only if you send them:
- Emails to support@tyhdev.net. I receive your email address and whatever you write, and use them only to answer you. I delete support emails within 12 months of your question being resolved.
- TestFlight feedback, if you test a beta version. Apple passes me the comment you write, any screenshot you attach, and your device model, iOS version and app build. I keep the comment, the device details and a short excerpt of any crash report in my development notes to fix problems. I do not keep your name, email address or screenshots from TestFlight.
- Crash reports and app statistics from Apple, if you've turned on sharing with app developers in your iPhone's settings. Apple provides these to me in a form that doesn't identify you; I use them only to fix bugs.
Apple Health
Pocket Spotter reads Apple Health data only with your permission, which you give or remove in the Health app and in Pocket Spotter. It is used only to give you better training recommendations. It is never used for advertising or marketing, never sold, never shared with anyone except as described above to answer your coach requests, and never stored in iCloud. If the company that processes it ever changes, the app will ask for your permission again before sending any.
Purchases
Purchases and subscriptions are handled by Apple through the App Store. I don't receive your payment details.
To know whether your subscription or free trial is active, the app uses RevenueCat, Inc. RevenueCat receives your purchase and subscription history from Apple, linked to a random identifier the app creates (not your name, email or Apple ID), plus basic device details such as the app version, operating system and IP address. It receives none of your training, health or chat data.
What I don't do
- No advertising, and no advertising or analytics SDKs.
- No tracking across other companies' apps or websites.
- No selling or renting of your data, and no "sharing" of it for targeted advertising.
- No data brokers.
- No automated decisions with legal or similarly significant effects on you. The coach's suggestions are suggestions; you decide what to train.
Your choices
- Turn off health data sharing (logged injuries, body measurements and Apple Health) any time in Profile → AI Coach.
- Don't use the AI features, and nothing leaves your phone.
- Export your workout history as a spreadsheet (CSV) any time from the History screen.
- Delete your data by deleting the app. Because I don't keep your content on my servers, there's nothing else to delete. The usage counters above expire on their own.
Your rights, wherever you live
You can ask me to confirm what I hold about you, to access it, correct it, delete it, restrict or object to its use, or receive it in a portable format, and you can withdraw consent at any time. Email support@tyhdev.net; I'll reply within 30 days. I may ask you to confirm details before acting on a request, so I don't act on someone else's behalf by mistake.
Because I don't keep your content and have no account for you, the only data about you on my server is the counters above, stored against a random ID that I can't connect to you. The training data itself is on your phone, where you control it completely. If you send me your installation ID, I'll delete its counters straight away; otherwise they expire within 40 days.
European Economic Area, United Kingdom and Switzerland
The legal bases I rely on under the GDPR and UK GDPR:
| Processing | Legal basis |
|---|---|
| Sending your training data and messages to generate the AI answer you asked for | Performance of a contract — providing the feature you requested (Art. 6(1)(b)) |
| Sending injuries and body measurements you've logged | Your explicit consent, given in the app (Art. 6(1)(a) and 9(2)(a)) |
| Sending Apple Health readings | The same explicit consent (Art. 6(1)(a) and 9(2)(a)) |
| Installation ID and IP counters | Legitimate interests — keeping the service affordable and preventing abuse (Art. 6(1)(f)) |
International transfers: Cloudflare and Google may process data outside the EEA, UK or Switzerland, including in the United States. Google processes it under its data processing terms for paid Gemini API use, which rely on the EU–US Data Privacy Framework and Standard Contractual Clauses; Cloudflare's data processing terms rely on Standard Contractual Clauses.
You also have the right to complain to your local data protection authority.
California and other US states
I don't sell or share personal information, including for cross-context behavioral advertising, and I don't use sensitive personal information to infer characteristics about you. The categories involved are those listed above: health and fitness information, the content you submit, and an installation identifier. You won't be treated differently for exercising any right in this policy.
If the law requires it, or the app changes hands
I'll disclose the little data I hold only if the law requires it. If Pocket Spotter is ever sold or transferred, this policy would continue to protect any data that moves with it, and I'd tell you before it changed.
Security
Data between the app, my server and Google is encrypted in transit (HTTPS). The provider key that talks to Google lives only on my server, never in the app. Data on your phone is protected by your device's own security.
Changes
If I change what Pocket Spotter sends or who processes it, I'll update this policy and the effective date above. If a change affects your health data, the app will ask for your permission again before sending any.
Contact
Tyler Hernandez — support@tyhdev.net