Privacy Policy
Effective Date: June 24, 2026
Privacy is important to RecSpot. This Privacy Policy explains how RecSpot Corporation ("RecSpot," "we," "us," or "our") collects, uses, and shares information when you use www.therecspot.com, the RecSpot mobile app, and related services (collectively, the "Service").
By using the Service, you agree to the collection, use, sharing, and storage of information as described in this Privacy Policy. This Privacy Policy supplements and is incorporated into our Terms of Service.
Information We Collect
Account Information
When you sign in with Apple or Google, we receive your name if you authorize it and an email address. We do not receive your Apple ID or Google password. When you set up your profile, we also store your chosen @handle, display name, optional avatar image, optional location such as city or region, and your profile privacy preference.
Content You Create
We store the recommendations ("recs") you create, including titles, ratings, notes, photos, dates, locations, external URLs, and any RecLists you organize them into. We also store bookmarks, comments, likes, and other content you choose to create or share through the Service.
Social Graph
We store who you follow and who follows you. For users with private profiles, we also store pending follow requests until they are approved, ignored, or deleted.
Contacts
If you grant Contacts permission to find friends on RecSpot, your device hashes each contact's email address using SHA-256 before sending it to us. We never receive plaintext email addresses from your contacts. Hashes are matched against existing user emails, also hashed, to help surface mutual connections.
Location
If you grant location permission, we may use one-time GPS readings to reverse-geocode a "City, Region" label for your profile or rec creation. We do not continuously track your location and do not store latitude/longitude for this purpose. We store only the human-readable location label you confirm.
Device, Push, and Diagnostics
To deliver push notifications, we store your iOS push token. We may collect basic device information, such as iOS version, device model, and app version, to diagnose crashes and improve app reliability.
Usage Analytics and Logs
We use Firebase Analytics to measure product events such as sign-up, rec creation, rec sharing, push taps, and recap views. These events may be associated with your user ID so we can deduplicate events and understand aggregate product usage.
Our backend records timestamped request metadata, such as operation name, user ID, IP address, and response latency, for abuse detection, security, and performance debugging. We generally retain these server logs for up to 30 days.
Website Analytics and Cookies
When you visit our website, we may collect information through cookies, pixels, and similar technologies, including device, browser, IP address, pages visited, and interactions with the website. We may use third-party analytics and advertising tools to understand website usage and improve our marketing and product experience.
How We Use Information
We use the information we collect to:
- Operate and improve the Service, including feeds, recs, profiles, notifications, RecLists, maps, and recaps.
- Authenticate you across devices using session tokens.
- Send push notifications you opt into, such as likes, comments, follows, follow requests, and monthly recaps.
- Surface friends-on-RecSpot suggestions when you sync contacts.
- Deliver search results, including web search and place search.
- Generate optional AI-assisted draft notes for new recs.
- Measure product usage, diagnose crashes, detect abuse, and improve performance.
- Communicate with you about the Service.
Sharing Information
We do not sell your personal information.
We share information with service providers and technology partners that help us operate, protect, and improve the Service. These include providers for authentication, hosting, push notifications, analytics, crash reporting, maps and place search, web search, AI-assisted drafting, website analytics, and marketing measurement.
Current examples include Apple, Google, and Anthropic.
When you use search or AI-assist features, the information needed to complete that request may be sent to the relevant provider. For example, place searches may be processed through Google services, and text submitted for AI-assisted drafting may be sent to Anthropic.
Claude (optional connector, by Anthropic). Only if you choose to connect your RecSpot account to Claude. Claude can then read what you ask it about: your recs — including your own private notes — your reclists and bookmarks, and the recs and public reviews of people you follow. It never receives anyone else’s private notes. If you allow it when connecting, Claude can also add to your account: rate things (rated recs are public, like recs made in the app), update your ratings, save bookmarks, build reclists as drafts, and import items into your private To rate list. It asks you before each change. It cannot delete anything or tag anyone. Once shared, that information is handled under Anthropic’s Privacy Policy and your Claude settings. You can disconnect at any time from Claude’s Settings > Connectors, or from Connected apps inside the RecSpot app, which also revokes access on our side.
Your information may also become visible to other users when you interact with the Service, such as when you create a public profile, post a rec, share a RecList, comment, like, or follow another user.
We may disclose information if required by law, legal process, or government request; to enforce our Terms of Service; to investigate fraud, abuse, or security issues; or to protect RecSpot, our users, or others.
If RecSpot is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, user information may be transferred as part of that transaction.
We may also share information with your consent or at your direction.
How Long We Keep Information
- Your content. Recs, reclists, bookmarks and comments are kept for as long as your account exists.
- Recs you delete. Deleting a rec hides it immediately, everywhere. The underlying record is permanently removed 30 days later. The delay exists so a mistaken deletion can be recovered if you contact us within that window.
- Deleting your account. Edit Profile > Delete Account removes your account together with your recs, reclists, bookmarks, comments, likes, follows, contact hashes, push tokens, notifications, your private To rate list, and any access previously granted to a connected AI assistant. Entries for shared things — a restaurant, a film — remain, because other people have rated them too, but they are no longer attributed to you.
- Server logs. Generally up to 30 days.
- Connector access. If you connect RecSpot to Claude, the access it uses expires about an hour after it is issued and the longer-lived credential after 60 days unless you keep using it. Disconnecting revokes it immediately.
- Backups. Our database is backed up continuously and those backups are kept on a rolling 10-day window. Anything you delete disappears from the live service straight away, but can remain in a backup until it ages out of that window, after which it is gone.
Your Choices
You can control or delete certain information through the Service and your device settings:
- Account deletion: Edit Profile > Delete Account permanently removes your account and associated recs, bookmarks, RecLists, comments, likes, follows, contact hashes, and push tokens within 24 hours.
- Push notifications: Toggle notification types in Edit Profile, or revoke notification permission in iOS Settings > Notifications > RecSpot.
- Contacts sync: Revoke Contacts access in iOS Settings > RecSpot > Contacts. Existing contact hashes can be cleared through Edit Profile.
- Location: Revoke location access in iOS Settings > RecSpot > Location.
- Profile privacy: Switch your account between Public and Private in Edit Profile at any time.
- Website cookies: You can adjust cookie and tracking preferences through your browser settings or device controls.
Children
The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13.
Changes to This Policy
We may update this Privacy Policy from time to time. If changes are material, we will notify you in-app or by another reasonable method before the update takes effect.
Contact Us
If you have questions, comments, or concerns about this Privacy Policy, contact us at support@therecspot.com.