SpotCue is a location-based reminder app. It reminds you about something when you arrive at, leave, or come near a place you chose. This policy explains exactly what the app collects, where it goes, and what it never does.
The short version. SpotCue does not record where you go. It watches only for the specific places you attached a reminder to, using the operating system's geofencing, and it keeps no trail of your movements. Analytics never receive your coordinates or address.
You need an account to use SpotCue. You can sign in with Apple, sign in with Google, or use an email magic link. We store your email address and, if your sign-in provider supplies one, a display name.
During onboarding you may optionally provide a date of birth and gender (including a self-described value). These are optional. If you skip them, they are never stored.
We store your time zone, locale, and whether you prefer miles or kilometres, so reminders and distances display correctly.
SpotCue stores the content you create so it can sync across your devices and survive reinstalling the app:
If you use the SpotCue widget or a Live Activity, the next reminder's details are written to a storage area shared between the app and its widget on your device. That sharing is local to your device only.
That last item is a history of your reminders firing. It is linked to the place you already saved and it contains no coordinates. It is not a record of everywhere you have been.
SpotCue requests “While Using the App” location first, so it can find places near you and set up a reminder. It asks for “Always” location separately, and only after the first permission is granted.
A place-based reminder is useless if it only works while the app is open. “Always” permission lets iOS monitor a small number of geofences — invisible circles around the places you chose — and wake SpotCue when you cross one. Everything else stays off.
If a reminder can match any location of a chain or category — “any pharmacy” rather than one specific shop — SpotCue also asks iOS for low-accuracy background location updates. iOS only reports these when you have moved a meaningful distance, and SpotCue uses them to re-point its geofences at the nearest matching places for wherever you now are. The position is used in memory for that calculation and is not stored on your device or sent to our servers. These updates stop when no such reminder is active.
Your position is sent out only at the moment it is needed to answer something you asked for:
These are one-off lookups tied to an action you took. Results are cached briefly to reduce repeat requests.
Reminders are delivered as local notifications, scheduled and fired on your device. SpotCue does not register for remote push notifications and does not hold a push token for your device, so we cannot send you anything from a server.
You can dictate a reminder instead of typing it. When you do, SpotCue uses the microphone and Apple's speech recognition to convert speech to text. Depending on your device and settings, Apple may process that audio on its servers under Apple's own privacy policy. The microphone is active only while you are dictating, and SpotCue does not store audio recordings.
SpotCue uses PostHog to understand which features are used and where people get stuck. Before any event is sent, the app strips properties whose names look like location or identity data — latitude, longitude, address, coordinates, email, name, user ID, tokens, and similar. IP-based geolocation is explicitly disabled on every event, so PostHog cannot infer even your city from the request.
SpotCue uses Sentry to capture crashes and errors. Sentry's “send default personally identifiable information” setting is turned off, and every event passes through a sanitiser before it leaves the device.
SpotCue requires a subscription. Purchases are processed by Apple through the App Store. SpotCue never sees or stores your payment card, billing address, or Apple Account credentials.
We use RevenueCat to check whether your subscription is active. RevenueCat receives an app-specific account identifier and the purchase information Apple provides, and tells the app whether you are entitled to premium features. We keep a cached copy of your subscription status so the app works briefly offline.
| Service | What it handles | What it receives |
|---|---|---|
| Supabase | Accounts and data sync | Account details, reminders, saved places, SpotRuns, trigger history, settings |
| Apple | Sign in with Apple, purchases, notifications, speech recognition | Sign-in identity, purchase transactions, dictated audio |
| Sign in with Google | Sign-in identity | |
| Google Maps Platform | Place search, distances, routing | Search text, your position, destination coordinates |
| RevenueCat | Subscription status | App-specific account identifier, purchase information |
| PostHog | Product analytics | Feature usage events with location and identity fields removed |
| Sentry | Crash reporting | Crash and error diagnostics, sanitised |
Each of these providers handles data under its own privacy policy.
Your reminders, places, and settings are kept while your account exists, so the app works across your devices.
You can delete your account from inside the app: Settings → Delete account and data. This removes your account and the data attached to it — reminders, saved places, SpotRuns, trigger history, settings, and your profile. Deletion cascades automatically, so nothing is left orphaned on the server.
Deleting your account does not cancel your subscription, because Apple manages billing. Cancel in your Apple Account settings.
Backups and crash logs may persist for a short period in our providers' systems before rotating out.
Depending on where you live, you may have the right to access, correct, export, or delete your personal data, to object to or restrict certain processing, and to complain to a data protection authority. The in-app delete described above satisfies the deletion right immediately and without needing to contact anyone.
SpotCue is not directed to children and is not intended for use by children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
Traffic between the app and our services uses HTTPS. Session credentials are held in the device's secure storage. Server-side, every table carrying user content is protected by row-level security policies so one account cannot read another's data.
No system is perfectly secure, and we cannot guarantee absolute security.
If this policy changes materially, we will update the date at the top of this page and, where appropriate, tell you in the app.
SpotCue does not yet publish a support email address. A contact address will be added to this page when SpotCue's website launches. Until then, account deletion and data removal are available directly in the app under Settings → Delete account and data, without needing to contact anyone.