Pocket Spotter
Consumer Health Data Privacy Notice
This notice explains Pocket Spotter’s handling of consumer health data and supplements our Privacy Policy. Pocket Spotter is provided by Tyler Hernandez. Contact support@tyhdev.net.
Data and sources
Health-related information includes workouts and exercise performance; training goals and preferences; body measurements and composition; injuries; recovery, energy, soreness, stress and sleep check-ins; and health details in messages, notes or imported program text. You supply these records, and the app derives training and recovery recommendations from them. Progress photos are stored locally.
If you connect Apple Health, Pocket Spotter requests read access to steps, active energy, resting heart rate, heart-rate variability, body weight, sleep and workouts. It does not write to Apple Health. Training information may also pass between your phone and the Apple Watch companion.
Purposes and disclosures
This information supports workout tracking, progress views, recovery guidance and the recommendations you request. Training records are stored on your device. When you use AI features, relevant information is sent through Cloudflare to Google’s Gemini API to generate responses. Your optional profile name, check-ins, messages and imported text may be included. This content may identify you.
Cloudflare processes AI requests as our infrastructure provider and Google processes their content as our AI provider. We do not send workout, health or chat content to RevenueCat as customer attributes. Apple handles HealthKit, device services and feedback you choose to share. If you send health details in support email or beta feedback, the developer and the relevant email or feedback provider receive them. We do not disclose consumer health data to corporate affiliates; there are no Pocket Spotter affiliates receiving it.
We do not sell consumer health data or use it for advertising. We disclose it to the providers needed for the functions described here and may disclose information when legally required. Providers may process information outside your country. The main Privacy Policy explains subscriptions, technical counters and provider processing in more detail.
Consent and controls
Connecting Apple Health is optional. A separate switch, Profile → AI Coach → Share health data with the coach, controls inclusion of structured Apple Health readings, injuries and body-composition information in AI requests and is off until you enable it.
Turning this switch off does not remove health information from messages, notes, imported text, or check-in answers such as energy, soreness and stress that may accompany the recommendation you request. Avoid submitting details you do not want processed by AI. Turning sharing off does not erase previously processed requests. You can stop using AI and revoke Apple Health read permissions through Apple’s settings.
Retention and deletion
Local training records remain until you remove them or delete the app’s local data. Removing the app does not erase Apple Health originals, device backups, exported files, Watch copies, keychain identifiers or information already held by providers. Offloading is different from deleting an app.
The AI proxy does not save prompt or response content in its usage database. Its technical counter entries expire between two minutes and 40 days after their latest write, depending on the counter; this is not a retention promise for provider records. Paid Gemini API content is not used to improve Google’s products under Google’s terms, but limited safety, abuse-prevention and legal retention can apply.
We retain resolved support email for one year after resolution and saved TestFlight feedback for one year after collection. We manage these periods manually. Longer retention may apply where required by law or necessary for a specific legal claim. Verified deletion requests are also handled manually; we coordinate applicable requests with providers.
Your rights and requests
Where applicable, you may confirm and access health data, obtain recipient information, withdraw consent and request deletion. Email support@tyhdev.net; no Pocket Spotter account is required. We may reasonably verify your identity and need help locating your records. Do not send a full health history to identify yourself.
For Washington requests, we respond within 45 days, with a permitted 45-day extension and notice when necessary. You may appeal a refusal by replying to our response; we respond to appeals within 45 days. You can complain to the Washington Attorney General. Applicable deletion requests include processor notification and archived or backup copies; legally permitted backup delays may be up to six months. We will not unlawfully discriminate for exercising these rights.
Contact
Tyler Hernandez, developer of Pocket Spotter. support@tyhdev.net.