Pocket Spotter

Privacy Policy

Effective October 4, 2026 · Tyler Hernandez

About this policy

Pocket Spotter is a workout and training app provided by Tyler Hernandez. This policy explains how information is handled in the app, its AI features, subscriptions, support, and the Pocket Spotter privacy website. Tyler Hernandez is responsible for Pocket Spotter’s handling of personal information. Contact: support@tyhdev.net.

You do not need a Pocket Spotter account to use the app. Your training records are stored on your device. Using online features sends certain information to service providers: AI requests pass through Cloudflare to Google’s Gemini API, and subscription information is processed through Apple and RevenueCat. Not using AI does not prevent subscription-related network activity.

Information stored on your device

Pocket Spotter stores the information you enter to plan and track training, including programs, exercises, sets, repetitions, weights, workout history, goals, sports, experience level, preferences, check-ins, recovery notes, injuries, body measurements, and progress photos. You may also enter a profile name and information about events affecting your training schedule.

The app uses local storage rather than a Pocket Spotter account-based cloud training database. Pocket Spotter does not synchronize its training database through CloudKit. Device backups and exported copies are separate from app synchronization and may be handled by Apple or another destination you choose. Do not assume deleting the app deletes those copies.

If you use the Apple Watch companion, training information is exchanged between your phone and watch. Copies on another device may need to be removed separately.

Progress photos are stored locally. For program imports, text is extracted from selected images or PDFs on the device; the extracted text, rather than the source image, is sent for AI processing. Extracted text can contain personal information present in your document.

AI features and the information they send

AI supports coaching conversations, workout recommendations, exercise changes, program tailoring, season planning, and program imports. Depending on the feature, a request may contain:

The optional name you enter can be included in the coach’s request. Using a nickname or leaving the name blank reduces that information. The app does not ask for an email address or telephone number to create an account, but anything you type into a message, note, or imported document can reach the AI service. Avoid including information you do not want processed there, including other people’s personal information.

Requests are sent over HTTPS to Pocket Spotter’s Cloudflare Worker, which forwards the prompt and relevant instructions to Google’s Gemini API and returns the answer. AI requests use Google Gemini. The Worker does not forward the installation-ID or incoming client-IP headers to Google as identifying fields. This does not make the prompt anonymous: its content may itself identify you.

The Worker’s application code does not save prompt or response content to its usage database. This is distinct from service-provider processing, caching, security records, and any operational logging configured outside that code.

Pocket Spotter uses the paid Gemini API. Under Google’s paid Gemini API terms, prompts and responses are not used to improve Google’s products, and Google may retain them for a limited period for safety, abuse prevention, and legally required disclosures. See Google’s Gemini API terms.

Apple Health and other health information

Connecting Apple Health is optional. The app requests permission to read steps, active energy, resting heart rate, heart-rate variability, body weight, sleep, and workouts. Pocket Spotter requests read access and does not write to Apple Health. These readings support training and recovery features, and some readings can become local records in Pocket Spotter.

Apple Health permission and sharing health information with the AI coach are separate choices. Profile → AI Coach → Share health data with the coach controls whether structured Apple Health readings, logged injuries, and body-composition information are included in AI requests. The app withholds these fields until permission is given and permits you to switch sharing off.

Turning that switch off does not remove information from a message, a check-in note, or a document you choose to submit. Energy, soreness, stress, and other check-in information may still be sent as part of the recommendation you request. Do not enter health details in free text if you do not want them sent. Switching sharing off also does not erase requests already processed.

You can manage Apple Health permissions in Apple’s Health or device settings. Removing permission prevents future access; it does not necessarily erase readings already copied into the app. Deleting Pocket Spotter does not delete the original records in Apple Health.

Pocket Spotter does not use health information for advertising or sell it. Our Consumer Health Data Privacy Notice provides additional detail about this information.

Subscriptions and purchase information

Apple handles App Store payments. Pocket Spotter does not receive your full payment-card details.

RevenueCat helps validate purchases, provide subscription and trial status, restore purchases, and manage access to paid features. It processes purchase history, subscription-related identifiers, and technical information necessary to provide its service. The app is configured to use RevenueCat’s generated app-user identifier rather than a Pocket Spotter login. That identifier is separate from the installation identifier used by the AI proxy.

The app does not send workout, health, or chat content as RevenueCat customer attributes. RevenueCat also provides subscription reporting and analytics; these reports help us operate subscriptions. See RevenueCat’s privacy disclosures.

Deleting the app does not cancel a subscription, remove Apple’s transaction records, or automatically delete RevenueCat’s records. Manage or cancel your subscription through Apple.

Usage counters and technical records

The AI proxy uses a random installation identifier and IP-based counters to limit excessive usage and protect the service. Its current source sets the following expiry periods for its own Cloudflare KV entries:

RecordPurposeExpiry after the entry’s latest write
Monthly AI cost and program-import counters associated with an installation IDUsage limits and cost control40 days
Short-term request counters associated with an installation IDRate limiting2 or 20 minutes, depending on the counter
Daily request count associated with an IP addressAbuse prevention2 days
Daily aggregate count of AI safety blocks, without an installation identifierService monitoring40 days

These are entry-expiration settings, not a promise that an active installation disappears from all systems after 40 days. Later requests can update or create entries. They do not describe Google, RevenueCat, Apple, or Cloudflare’s separate operational records.

The installation identifier is stored in the device keychain and may survive uninstalling the app. It is not an advertising identifier. The Worker does not perform IP geolocation; network providers necessarily process connection information to deliver and secure requests.

Support, diagnostics and the website

If you email support, the recipient receives your email address, message, and any attachments. Send only the information needed to explain the issue. TestFlight feedback or crash information you choose to share through Apple can include comments, screenshots, device information and technical details.

The app contains no dedicated third-party advertising or general-purpose crash-reporting SDK. This does not rule out Apple-provided diagnostics, local device logs, RevenueCat subscription reporting, or hosting-provider technical records.

The Pocket Spotter policy site is hosted on Cloudflare Pages. The website contains no analytics script or third-party embedded content. Cloudflare handles website requests and associated network information to serve and secure the pages.

Resolved support email is retained for one year after resolution. TestFlight feedback saved by the developer is retained for one year after collection. These periods are managed manually. Saved beta feedback can include a shortened comment, feedback identifier, device/OS/build information and limited crash frames. Shortening text is not removal of personal information. Apple controls copies retained in its own systems. We may retain records longer where required by law or necessary for a specific legal claim.

Cloudflare Workers Logs and Traces and Pages Web Analytics are disabled for these services. Optional Gemini GenerateContent logging is disabled. Providers may still keep their own security, abuse-prevention and legally required records under their terms.

Service providers and other disclosures

The principal services involved are Cloudflare for website hosting and the AI proxy; Google for AI processing; RevenueCat for subscription services; and Apple for app distribution, purchases, HealthKit, device services and optional beta feedback. These services may process information outside your country.

Pocket Spotter’s current design does not include advertising, data brokers, or cross-app advertising tracking. Personal information is not sold or rented or shared for targeted advertising. Providers receive information for the functions described above; that is not the same as saying no information is disclosed to third parties.

Information held by the developer may also need to be disclosed to comply with applicable legal requirements or protect the service and its users.

Retention, deletion and your choices

You can review and change training records in the app and export workout history as CSV from History. A CSV workout export is not necessarily an export of every category of information, such as photos or purchase records.

Local records remain until you remove them or remove the app’s local data. Uninstalling is different from offloading an app. Neither operation should be relied on to erase Apple Health records, backups, shared exports, Watch copies, keychain identifiers, provider records, or messages sent to support. Delete those copies through their respective controls or request help where appropriate.

You can stop using AI features, turn off structured health sharing, revoke Apple Health access, manage subscriptions through Apple, and ask about information held outside your device. AI usage entries expire as described above.

Requests concerning support, saved beta feedback, subscription records or identifiable AI usage counters are handled manually through support@tyhdev.net. After reasonable verification, we will remove records we control or arrange deletion with the relevant provider as applicable, subject to legal requirements and technical limits. Provider records are retained as needed to operate the service and satisfy applicable obligations; the counter expiry periods above do not apply to every provider. Deleting subscription data does not cancel an Apple subscription.

Privacy rights

Depending on where you live, you may have rights to request access, correction, deletion, a portable copy, restriction or objection to processing, withdrawal of consent, and appeal or complaint to a privacy regulator. Contact the privacy address above to make a request. The response will follow the rules and deadlines that apply to your request; deadlines vary by location and request.

Reasonable verification may be necessary to protect your information. Because the app has no account system, the developer may need help identifying records associated with your installation or subscription. Do not send a full health history merely to identify your request. Exercising privacy rights will not result in unlawful discrimination.

Age, security and changes

Pocket Spotter is intended for adults aged 18 or older. If you believe a child has provided personal information, contact support so the situation can be investigated.

Network requests to the AI proxy use HTTPS, and the provider API credential is kept on the server rather than embedded in the app. Device storage relies on the device’s security protections. No system can guarantee absolute security.

This policy will be updated when relevant practices change, with an effective date shown at the top. Where a change requires additional consent or notice, that must be obtained or provided before the new processing begins.

Contact

Tyler Hernandez, developer of Pocket Spotter support@tyhdev.net