LEGAL

Privacy Policy

This policy explains how SpotRank handles information to provide its car-spotting, social, ranking, event, safety, account, and notification features.

Last updated July 27, 2026

1. Who operates SpotRank

SpotRank is operated by Sidhvik Bokka. Privacy questions and requests may be sent to spotrank.support@gmail.com.

2. Account and authentication information

SpotRank processes your email address, Supabase authentication user ID, username, display name, biography, avatar, authentication-provider information, and session credentials. Session tokens are stored in the iOS Keychain. Usernames, display names, biographies, and avatars are part of the social profile and may be visible to other authenticated users who are not blocked.

You may use email and password authentication. If you choose Sign in with Apple or Sign in with Google, that provider processes the sign-in under its own terms and sends SpotRank the information needed to establish your account and session.

3. Photos, posts, and social activity

SpotRank stores car photos you upload, car brand and model, captions, location descriptions, comments, replies, likes, comment likes, rarity votes, follows, blocks, reports, notification events, and moderation records. Post images are served through public Supabase Storage object URLs.

4. Location information

SpotRank may request precise location while the app is in use when you choose a verified capture, Weekly Draft, Spot Globe, or current-location event feature. For a verified post, exact coordinates are retained in an owner-only record linked to your account. Separate post coordinates rounded to three decimal places—approximately neighborhood-level—may be shown publicly. Event coordinates may also be stored. SpotRank does not request background location access.

5. Permissions and on-device image validation

Camera access lets you capture post images. Photo Library access lets you select existing images. Location supports the contextual features described above, and notification permission enables supported alerts. You can change these permissions in iOS Settings, although related features may stop working.

Images selected for posting are checked on your device with Apple Vision and a bundled automotive-detail Core ML classifier to determine whether automotive content can be verified. A failed check prevents publishing. This validation is not a guarantee that every inappropriate or inaccurate image will be detected. Approved images are uploaded only when you publish the post.

6. Push notifications and device information

After you opt in, SpotRank stores an Apple Push Notification service token associated with your user ID, platform, APNs environment, and an IDFV-derived device identifier. This supports notification delivery, preference handling, and token cleanup. Apple processes delivery through APNs.

7. How information is used

  • Create, authenticate, secure, and restore accounts.
  • Display profiles, posts, maps, rankings, events, and social activity.
  • Process likes, votes, comments, follows, reports, and blocks.
  • Verify eligible captures and deliver requested notifications.
  • Moderate content, enforce community rules, and prevent abuse.
  • Respond to support, privacy, and safety requests.
  • Maintain service integrity and comply with applicable obligations.

8. Service providers

Supabase processes authentication, PostgreSQL database records, file storage, and server functions for SpotRank. Apple and Google process authentication when you choose their sign-in options. Apple processes push delivery when notifications are enabled. Their own privacy policies apply to the services they operate.

SpotRank does not sell personal information and does not use information for third-party advertising or cross-app tracking. The app currently includes no third-party analytics, advertising, attribution, or crash-reporting SDK.

9. Local data and security

SpotRank stores notification preferences and limited cached state in UserDefaults, stores session credentials in the iOS Keychain, and may cache feed data in the iOS Caches directory. SpotRank uses authenticated server requests and platform and service-provider safeguards. No internet-connected service can promise absolute security.

10. Retention and account deletion

Account content remains while your account is active unless you remove individual content or moderation requires action. You may permanently delete your account from Settings. The deletion process authenticates the request, removes owned upload objects and the Supabase Auth user, and removes related records where database relationships provide for deletion. The app clears its local session and cache after server deletion succeeds.

Limited security, abuse-prevention, dispute, legal, operational, backup, or moderation audit records may be retained for as long as reasonably necessary for those purposes and then deleted or anonymized where appropriate.

11. Your choices and requests

You can edit profile information, manage iOS permissions, remove content where the app provides that control, block users, and request account deletion in Settings. Depending on where you live, you may also have rights to request access, correction, deletion, or restriction. Send requests from the email connected to your account when possible so SpotRank can verify them.

12. Children

SpotRank is not intended for children under 13. You must also meet any higher minimum age required where you live. If you are not legally able to consent yourself, a parent or legal guardian must approve your use.

13. Updates and contact

This policy may be updated as SpotRank, applicable requirements, or service providers change. Material updates will be published with a revised date.

Privacy questions or requests: spotrank.support@gmail.com