Privacy Policy
Last updated: March 3, 2026
Your privacy is important to us. This Privacy Policy explains how Spotbo, Inc. ("we," "us," or "our") collects, uses, and protects your information when you use our social meetup platform. By using Spotbo, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
Account Information
We collect information you provide directly when you create an account, including your name, email address, username, profile photo, city, and interests. When you use Spotbo, we also collect information about your activity, such as meetups you attend, posts you create, and interactions with other users.
Phone Number
If you enable two-factor authentication, we collect your phone number to send verification codes via SMS. Your phone number is stored securely and is only used for account security purposes.
Technical Information
We automatically collect certain technical information, including your device type, operating system, browser type, IP address, and usage patterns within the app. This helps us improve the Spotbo experience and troubleshoot issues.
Device Information
To protect your account security, we collect device-level information including IP address, user agent, and a device fingerprint. This data is stored in our systems and used to detect unauthorized access, prevent fraud, and let you manage your active sessions.
Location Data
Spotbo uses your location to show you nearby meetups and display distance information. We collect your approximate location based on your city selection during onboarding. If you grant permission, we may access your precise location to improve meetup recommendations and map features. You can revoke location permissions at any time through your device settings.
Behavioral Data
To personalize your feed and improve content recommendations, we collect behavioral signals such as dwell time on posts, scroll patterns, video engagement metrics, and interaction signals (likes, RSVPs, shares). This data is used by our recommendation algorithm to surface content that is relevant to you.
Push Notification Data
If you enable push notifications, we store your notification subscription data (such as push tokens) to deliver timely updates about meetups, messages, and other activity. You can disable push notifications at any time through your device or app settings.
Direct Messages
Spotbo offers end-to-end encrypted direct messaging. When end-to-end encryption is active, message content is encrypted on your device before being sent and can only be decrypted by the intended recipient. We cannot read the content of end-to-end encrypted messages. The following metadata is accessible to Spotbo even when end-to-end encryption is active: sender identity, recipient identity, and message timestamps. This metadata is necessary to deliver messages and provide the messaging feature. The actual message content (text, images, and other media) is not accessible to Spotbo when end-to-end encryption is active.
Please note that GIF searches performed within the messaging feature are powered by Tenor (Google) and are not end-to-end encrypted. Your GIF search queries are sent to Tenor's servers to retrieve results and are subject to Tenor's privacy policy.
2. How We Use Your Data
We use your information to provide, maintain, and improve Spotbo's services. This includes personalizing your feed, recommending meetups near you, connecting you with people who share your interests, and sending you relevant notifications about upcoming events in your city.
We may also use your information to communicate with you about service updates, respond to your requests, and enforce our Terms of Service and Community Guidelines. We never sell your personal information to third parties.
Content Moderation
To maintain a safe community, user-generated text content (such as post text, meetup descriptions, and profile bios) is analyzed by automated moderation systems, including third-party AI services, to detect content that violates our Community Guidelines. User-uploaded images may also be analyzed for prohibited content using AI-based image classification. These processes are automated and are used solely for safety and compliance purposes.
AI and Machine Learning
Your content may be used to train and improve our internal content moderation and safety systems. This means we may use patterns detected in user-generated content to make our automated moderation more accurate and effective at identifying policy-violating content. To be clear: your content will NOT be used to train generative AI models and will NOT be sold or licensed to third parties for AI training purposes. This use is limited strictly to improving the safety and integrity of the Spotbo platform.
3. Third-Party Services
Spotbo relies on trusted third-party services to operate. Each of these providers has their own privacy policies governing how they handle data. We share only the minimum information necessary for each service to function:
Infrastructure & Hosting
- Supabase — authentication, database, and backend services
- Vercel — application hosting and performance analytics
- Cloudflare R2 — media file storage (photos, images uploaded to the platform)
- Upstash Redis — rate limiting and abuse prevention (stores anonymized request identifiers and IP addresses temporarily)
AI & Content Safety
- OpenAI — text content moderation (user-generated text is sent to OpenAI's Moderation API to detect policy-violating content)
- HuggingFace / ONNX Runtime — image safety classification (uploaded images are analyzed server-side using machine learning models sourced from HuggingFace to detect prohibited visual content)
- Google Gemini — AI-powered vision analysis for content understanding and moderation
Maps & Location
- Mapbox — interactive maps, geocoding, and location features
- Nominatim / OpenStreetMap — reverse geocoding (converting coordinates to human-readable addresses)
- Overpass API — geographic data queries for location-based features
Communications
- Google Gmail SMTP — transactional emails (account verification, password resets, notifications)
- OpenPhone — SMS delivery for two-factor authentication codes
Other Services
- DiceBear — default avatar generation for new accounts
- Tenor (Google) — GIF search within the messaging feature
- QR Server — QR code generation for sharing profiles and meetups
We will never sell, rent, or trade your personal data to advertisers or data brokers.
We may disclose your information if required to do so by law, such as in response to a subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, investigate fraud, or respond to a government request.
4. Cookies & Local Storage
Spotbo uses cookies and browser local storage to provide and improve the Service. For full details, please see our Cookie Policy. A brief summary:
- Essential cookies — required for authentication and session management. These cannot be disabled as the Service would not function without them.
- Analytics cookies — Vercel Web Analytics may set cookies to collect anonymized performance data. These are only used with your consent where required by applicable law.
- Local storage — we use your browser's local storage to remember your preferences, such as cookie consent status, map view state, theme preference (light or dark mode), and end-to-end encryption key material for direct messaging.
We do not use any third-party marketing or advertising cookies. You can manage or delete cookies through your browser settings. Note that disabling essential cookies will prevent you from using the Service.
5. Data Security
We take the security of your data seriously and implement industry-standard measures to protect it, including encryption in transit (TLS) and at rest, regular security audits, and access controls. Direct messages use end-to-end encryption so that message content cannot be read by anyone other than the sender and recipient — including Spotbo. However, no method of electronic storage or transmission is 100% secure, and we cannot guarantee absolute security.
6. Data Retention
We retain different types of data for different periods, depending on their purpose:
| Data Type | Retention Period |
|---|---|
| Account & profile data | Until you delete your account |
| Posts & media | Until you delete them + 30 days for cleanup |
| Direct messages (encrypted) | E2E encrypted; server cannot read content |
| Notifications | 90 days |
| Audit logs | 90 days |
| Device tracking data | Until you manually remove the device |
| Behavioral data (raw signals) | 7 days |
| Behavioral data (aggregated) | 90 days |
If you delete your account, we will remove your personal information within 30 days, except where we are required to retain it for legal or legitimate business purposes (such as fraud prevention or compliance with legal obligations). Deleted messages are purged from our servers within 30 days of deletion.
7. International Data Transfers
Spotbo is operated from the United States. If you are accessing or using the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States and other countries where our service providers operate.
If you are located in the European Economic Area ("EEA"), the United Kingdom, or Switzerland, we rely on appropriate legal mechanisms to transfer your personal data, including Standard Contractual Clauses ("SCCs") approved by the European Commission, where applicable. By using the Service, you acknowledge that your data may be transferred to countries that may not provide the same level of data protection as your home country. We take reasonable steps to ensure that your data is treated securely and in accordance with this Privacy Policy regardless of where it is stored or processed.
8. Your Rights
You have the right to access, correct, or delete your personal information at any time. Here is how you can exercise these rights:
- Edit your profile — update your information directly within the app at any time.
- Delete your account — go to Settings → Delete Account to permanently remove your account and associated data. You will be required to confirm your password before deletion. Upon deletion, your profile, posts, and media are removed, and associated files are cleaned up from our storage. This action is irreversible.
- Export your data — use the in-app data export feature to download a copy of your personal data in a portable JSON format (GDPR data portability). The export includes your profile information, posts, meetups, and associated data.
- Contact us — for any privacy request you can also email us at info@spotbo.com. We will respond within 30 days.
You also have the right to:
- Access — request a copy of the personal data we hold about you.
- Rectification — ask us to correct inaccurate or incomplete data.
- Data portability — receive your data in a structured, machine-readable format.
- Object to profiling — you may object to the use of your behavioral data for algorithmic feed personalization. Contact us to opt out, and we will serve you a chronological feed instead.
9. Do Not Sell My Personal Information
Spotbo does not sell, rent, or trade your personal information to third parties for monetary or other valuable consideration. We do not share your personal information for cross-context behavioral advertising. This applies to all users, regardless of location.
State-Specific Privacy Rights
Depending on where you live, you may have additional privacy rights under state law:
- California (CCPA/CPRA) — California residents have the right to know what personal information we collect, the right to delete it, the right to correct inaccurate information, the right to opt out of the sale or sharing of personal information (which we do not do), and the right to non-discrimination for exercising your privacy rights. To submit a request, email info@spotbo.com with the subject line "California Privacy Request." We will verify your identity before processing your request.
- Virginia (VCDPA) — Virginia residents have the right to access, correct, delete, and obtain a copy of their personal data, and to opt out of the processing of personal data for targeted advertising, sale, or profiling. To appeal a decision regarding your privacy request, email us with the subject line "Virginia Privacy Appeal."
- Colorado (CPA) — Colorado residents have similar rights to access, correct, delete, and port their personal data, and to opt out of targeted advertising, sale of personal data, or certain profiling. You may designate an authorized agent to make a request on your behalf.
- Connecticut, Utah, and other states — If your state has enacted consumer privacy legislation, we will honor the rights afforded to you under that law. Contact us at info@spotbo.com to exercise your rights.
European Economic Area & United Kingdom
If you are a resident of the European Economic Area or the United Kingdom, you may have additional rights under GDPR / UK GDPR, including the right to data portability, the right to restrict or object to certain processing of your data, and the right to lodge a complaint with your local supervisory authority.
10. Children's Privacy
Spotbo is not intended for users under 18 years of age. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete that information promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting a notice within the app or sending you an email. Your continued use of Spotbo after changes are posted constitutes your acceptance of the revised policy.
12. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us at info@spotbo.com. We are committed to addressing your concerns promptly.
Spotbo, Inc.
1111B S Governors Ave STE 29027
Dover, DE 19904