The short version. We collect what it takes to run Spotter: your account, the clients and workouts you enter, what clients log, and the voice notes a trainer records during a session. To draft a workout, or turn a voice note into logged sets, we send the relevant details to an AI provider. Audio is transcribed and discarded, never stored. We don’t sell data, we don’t run ads, and the only measurement we run is cookieless page-view and performance counting. Write to contact@spottercoach.app and we will delete your data.
This policy covers the Spotter website and app (together, “Spotter”), which are run from Illinois, USA. Spotter is an invite-only beta for personal trainers and the clients they invite. “We” and “us” mean the team behind Spotter; “you” means anyone who uses the site or the app.
What we collect
When you request an invite
- Your name and email address.
- Your practice type, roughly how many clients you train, and what you write about how you program.
- The IP address the request came from, which we use to limit repeated or automated submissions.
When you have an account
- Account details: email address, display name, and whether you are a trainer or a client. Your password is handled by our authentication provider and stored only as a one-way hash.
- What trainers enter: a programming profile (philosophy, preferred splits, progression and substitution rules, excluded exercises), custom exercises, and workouts and their versions.
- Client records a trainer creates: the client’s name, and optionally their email, phone number, goals, experience level, available equipment, preferences, notes on limitations, and the trainer’s private notes.
- Training logs: sessions started and finished, and for each set the reps, load, RPE and notes; plus perceived difficulty, whether pain was reported, and written feedback.
- Voice notes a trainer records during a session: the transcript of each note, and the summary and per-exercise notes the AI writes from it. The audio itself is never stored (see “Voice notes” below). All of it is visible to the trainer only, never in the client’s app.
- Messages between a trainer and their client.
- Push notifications: if you turn them on, the subscription your browser gives us (an endpoint address and keys) and your browser’s user agent.
- Bug reports and feedback you send from the app: what you write, a screenshot if you attach one, and details captured when you open the report: the page you were on, the app version, your browser’s user agent, screen size, whether the app is installed, whether you were online, and the last ten error messages your browser recorded. The report is linked to your account email and role.
- AI requests: for each AI task (a workout draft, a substitution, a check-in message, a session opener, the profile interview, or turning voice notes into logged sets) a record of what was sent and what came back, so we can find problems and enforce usage limits. Transcription is the exception: for those we record only the size of the clip and the length of the text, never the audio and never the words.
Cookies and similar storage
Spotter uses cookies to keep you signed in, and your browser may store small display preferences. There are no advertising cookies and no tracking pixels, and nothing follows you to other websites.
We do measure how the site and app perform, using Vercel Analytics and Vercel Speed Insights, run by the same company that hosts Spotter. They record page views and page-load timings along with the kind of device, browser and country. They set no cookies, store nothing on your device, and do not build a profile of you or identify you across visits. We use it to see which pages trainers actually reach and which screens are slow.
Health-related information
Notes on limitations, pain flags, session feedback and anything spoken into a voice note can describe someone’s body and how they feel. Spotter is a training tool, not a healthcare service, and these notes are not medical records. Please don’t enter diagnoses, medications or other medical details beyond what a trainer needs to program safely.
Trainers: you enter information about your clients, so you are responsible for having their permission to do that, and for telling them you use Spotter.
How we use it
- To run Spotter: sign-in, drafting and assigning workouts, logging, messages and notifications.
- To draft workouts, suggest substitutions, turn a trainer’s voice notes into logged sets, and draft check-in messages and session openers a trainer can edit or discard (see the next section).
- To review invite requests and reply to them by email.
- To keep the service secure, prevent abuse, and enforce usage limits.
- To find and fix bugs, and to improve the product.
We don’t sell personal information, share it for advertising, or use it to train AI models of our own.
How the AI features use your data
When a trainer asks Spotter to draft a workout or suggest a substitution, we send an AI provider the trainer’s programming profile, the exercise library, what the trainer typed for that request (a brief, or the reason for a swap), and the client details the task needs: name, goals, experience level, equipment, preferences, notes on limitations, and a summary of their last few logged sessions (including pain flags). Client email addresses and phone numbers are never sent, and neither is anything the client has written to their trainer.
Two features send more than that. When a trainer drafts a check-in message, we also send the trainer’s own last three typed messages to that client, so the draft sounds like them instead of like us; the client’s side of the conversation is not sent. When a trainer records a voice note, the audio goes to our transcription provider, and the resulting text is sent on to be turned into logged sets and a trainer-only summary.
Which provider handles a request depends on the task. Workout drafts, substitutions, check-in drafts, session openers and voice logging go to Anthropic (the Claude models) by default, or to Google (the Gemini models) if the trainer’s account is set to one. Transcription always goes to Google, whichever model the account is set to. Under Anthropic’s commercial terms and Google’s paid API terms, what we send is not used to train their models. AI output is a draft: a trainer reviews it before any client sees it.
Voice notes
A trainer can record short voice notes during a session by holding a button, so a recording only happens when they choose to start one. Each clip is sent to Google, transcribed, and discarded in the same request: Spotter never writes audio to a disk, a file store or a log. What we keep is the text, and it stays on the trainer’s side of the app.
A microphone on a gym floor picks up whatever is audible, which can include the client speaking and other people nearby. Trainers are responsible for telling their clients that they use voice notes, and for not recording where people expect privacy, such as a changing room.
Who else processes it
We use these service providers to run Spotter. Each one gets only what its job requires.
- Vercel hosts the website and app, handles web requests, and provides the cookieless page-view and performance measurement described above.
- Supabase provides the database, sign-in and file storage (bug report screenshots).
- Anthropic, and Google when a Gemini model is selected, generate workout drafts, substitutions, check-in drafts, session openers and voice logs. Google also transcribes every voice note, whichever model the account is set to.
- GitHub receives bug reports, filed as issues in a private repository.
- Push services run by your browser’s maker (such as Google, Apple or Mozilla) deliver notifications if you turn them on. They see the notification, not your account.
- Have I Been Pwned checks new passwords against known breaches. Only the first five characters of a hash of the password leave our server, never the password itself.
We may also disclose information if the law requires it, to protect someone’s safety, or as part of a sale or transfer of Spotter, in which case this policy continues to apply to it.
These providers store and process data in the United States.
Who can see what inside Spotter
A trainer sees their own clients, those clients’ logs and their messages with them. A client sees the sessions their trainer assigned, their own logs and their messages with their trainer. A trainer’s private notes are never shown to the client. Database access rules enforce this for every request.
How long we keep it
- Account data and training history stay while the account exists.
- When a client record is deleted, that client’s sessions, logs and messages are deleted with it.
- If you ask us to delete your account, we delete it and the data tied to it within 30 days. Copies in our providers’ backups expire on their normal schedule.
- Invite requests are kept until the beta ends, or deleted sooner if you ask.
Your choices
You can ask to see the information we hold about you, correct it, get a copy of it, or have it deleted. Email contact@spottercoach.app from the address on your account and we will reply within 30 days. You can turn off push notifications from your profile or your browser settings at any time.
If you are a client and want something changed or removed, you can ask your trainer, or write to us directly.
Children
Spotter is not meant for children under 13, and we don’t knowingly collect their information. Trainers should not invite a client under 18 without a parent or guardian’s permission. If you believe a child’s information is in Spotter, write to contact@spottercoach.app and we will delete it.
Security
Connections are encrypted, passwords are hashed, and every table is protected by access rules checked in the database. No system is perfectly secure, so we can’t promise that data will never be exposed. If a breach affects your information, we will tell you as the law requires.
Changes to this policy
When this policy changes, we update the date at the top. If a change is significant, we will tell account holders by email or in the app before it takes effect.
Contact
Questions or requests about your data: contact@spottercoach.app. The Terms of Service cover the rest of how Spotter works.
See also the Terms of Service.