Privacy, in plain English
Your location history, your heart rate, your photos of family at the lake — Splashtag holds genuinely sensitive things. Here is how we treat them. (This is prototype copy; the reviewed policy ships with the app per docs/12.)
The promises
- We never sell your data. Not location, not health, not aggregated, not “anonymized.” There is no ad system for it to feed.
- Private by default. Every trip and photo starts visible to you alone. Sharing is always a deliberate act.
- Privacy zones. Areas around home clip your shared routes automatically. Originals stay intact and private.
- Photos shared publicly are scrubbed. EXIF GPS is stripped from every public variant.
- Health data is opt-in. Heart rate is read only after you explicitly connect a watch or Health Connect, and is never used for ads or sold — full stop.
- AI is opt-in. Trip text goes to our AI provider only when you press the button, and is not used to train models.
Your rights
Export everything (GPX + JSON + photos) from settings, free. Delete your account yourself — 30-day grace, then everything cascades: database rows, stored files, payment profile, analytics identity. No retention tricks, no guilt screens.
Who processes data for us
Supabase (database, auth, storage), Vercel (hosting), RevenueCat (subscriptions), PostHog (product analytics, cookieless on this site), Sentry (crash reports), Resend (email), Open-Meteo (weather — sees coordinates of forecasts you request, never your identity), Anthropic (opt-in AI drafts).