Privacy Policy
Last updated: August 23, 2026
Spot is a community platform where creators and their communities own their content and their relationships. That ownership principle applies to your data too: we collect what we need to run the service, we don't sell it, and we don't build advertising profiles from it. This policy explains, in plain language, what we collect and why.
1. Who we are
Spot is operated by [PLACEHOLDER: company legal name, registered address, and company number] ("Spot", "we", "us"), and is available at spot.com. We are the data controller for the personal data described in this policy. You can reach us about anything privacy-related at privacy@spot.com.
2. What we collect
Account information
Signing in to Spot uses your email address and a one-time code — there is no password. Verifying your email creates your account. We store your email address and the technical session data needed to keep you signed in. Authentication is handled through our infrastructure provider, Supabase (see section 5).
Profile information
You choose a username (your handle, which is the same everywhere on Spot), a display name, and optionally an avatar, banner, bio, and social links. You can hold more than one profile (for example a personal profile and a separate creator profile). Profile information is public by default; you can set a profile to private so only approved followers see your posts, spots, and collections.
Content you create
Posts, comments, reactions, votes, images and other files you upload, collections, and saved posts. Uploaded files are stored in our storage infrastructure and count toward your storage quota. Who can see a post depends on the read rules of the topic and spot it was posted in — from fully public to members-only.
Messages
Direct messages between members, and messages to a community (which go to that community's shared inbox, visible to its admins). Messages are private to their participants but are not end-to-end encrypted — like most web platforms, they are stored on our servers so we can deliver them across your devices.
Membership information
Which spots (communities) you've joined, your roles in them, and — where a spot requires it — whether you agreed to share your email address with that community and accepted its rules when joining. See section 6 for how shared emails are used.
Moderation and safety data
Reports you file about posts, moderation decisions applied to your content or membership (such as pending, approved, rejected, or banned statuses), and blocks or mutes you set. Moderation records are kept so decisions can't be silently erased (see section 8).
Technical data
Standard server logs (IP address, browser type, timestamps) generated when you use the service, used for security, debugging, and abuse prevention — including the posting rate limits that protect communities from spam.
3. Cookies and local storage
We use strictly necessary cookies to keep you signed in (your authentication session). We do not use advertising cookies or third-party tracking cookies.
We also use your browser's local storage for on-device conveniences — such as remembering which posts you've already read and your recent viewing history. This data stays in your browser: it is not transmitted to our servers and disappears if you clear your browser data.
4. How we use your data
- To provide the service — showing your posts to the people allowed to see them, delivering messages, applying community permissions and roles.
- To sign you in — sending one-time codes to your email.
- Transactional email — service messages like sign-in codes and important account notices.
- Safety and moderation — operating report queues, post approval, rate limits, and age-gating of sensitive content.
- Improving Spot — aggregate, non-identifying usage patterns to understand what's working.
We do not sell your personal data, and we do not use it for behavioral advertising.
Where GDPR applies, our legal bases are: performance of our contract with you (providing the service), our legitimate interests (security, abuse prevention, service improvement), your consent (community email sharing, optional features), and legal obligations. [PLACEHOLDER: legal counsel to confirm legal-basis mapping]
5. Who can see your data
Other people on Spot
- Your profile and public posts are visible according to your profile visibility setting and each topic's read rules.
- Admins and moderators of a spot you join can see your membership, your roles, your standing in that spot, and content you post there — including content awaiting approval.
- If a spot required or requested your email at join and you agreed, that spot's admins can see and use your email address (section 6).
Service providers
We use a small number of infrastructure providers to run Spot — currently Supabase for authentication, database, and file storage, our hosting provider, and an email delivery provider for sign-in codes and notifications. [PLACEHOLDER: finalize and list hosting + email providers once chosen] These providers process data on our behalf under data-processing agreements and cannot use it for their own purposes.
Legal requirements
We may disclose data where required by law, or where necessary to protect the safety of our users or the integrity of the service.
6. Email and community communications
Spot never gives your email address to a community without your consent. Some spots require or request your email as a condition of joining — when that happens, the join screen tells you, and your agreement is recorded on your membership. Only members who opted in can be emailed by that community (for example, newsletters). You can stop receiving a community's emails at any time, and leaving a spot ends its access to email you.
7. Community data export
Data portability is a core Spot commitment: communities are not locked in. A community owner can export their community's data, which includes the posts, comments, and membership records within that community — including your contributions to it and, if you consented to share it, your email address. In other words, content you post into a spot becomes part of that community's record, in the same way an email you send to a mailing list belongs to that conversation. Your private messages and your activity in other spots are never part of a community's export.
8. Retention and deletion
- Deleting content: when you delete a post or comment, it is immediately hidden from everyone. It is first soft-deleted (retained briefly in our systems for integrity and abuse-prevention purposes) and then permanently removed after [PLACEHOLDER: retention window, e.g. 30 days].
- Moderation records: content removed by moderators is retained as a moderation record and cannot be erased by deleting it, so that moderation decisions stay auditable.
- Leaving a spot: ends your membership; if you rejoin later, your previous standing in that spot is restored.
- Account deletion: you can request deletion of your account and personal data by emailing privacy@spot.com. We will remove your personal data except what we must keep for legal, safety, or moderation-integrity reasons.
9. Your rights
Depending on where you live (and always if you're in the EU/EEA or UK), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data — most profile data you can edit yourself in settings.
- Delete your data (see section 8).
- Export your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent at any time where processing is based on consent (such as community email sharing).
- Complain to your local data protection authority.
To exercise any of these rights, email privacy@spot.com. We'll respond within the timeframe required by applicable law.
10. Age requirements
You must be at least [PLACEHOLDER: minimum age — 13 in the US, up to 16 in some EU countries; needs a legal decision] to use Spot. Some content on Spot is marked as sensitive (18+); it is only shown to members who are over 18 and have chosen to see it. We use your age information solely for this gating.
11. International transfers
Your data may be processed in countries other than your own, depending on where our infrastructure providers operate. [PLACEHOLDER: name data-hosting regions and the transfer mechanism (e.g. SCCs) once hosting is finalized]
12. Changes to this policy
If we make material changes to this policy, we'll notify you — by email or by a prominent notice on Spot — before the changes take effect. The "Last updated" date at the top always reflects the current version.
13. Contact us
Questions, concerns, or requests: privacy@spot.com, or write to [PLACEHOLDER: postal address].