Trust

How we protect your account and data

Learn about how SunSpotters handles security and privacy. This information reflects controls we have enabled today; it is not an independent certification or audit.

EU-basedGDPR alignedHTTPS everywhere

Shared responsibility

Security in SunSpotters is a shared effort. Our hosting platform provides the underlying infrastructure controls. The SunSpotters team configures the app, access rules, and how data flows. You are responsible for keeping your login credentials safe and only sharing content you have the right to share.

Authentication & access

  • Sign-in options: Google OAuth and atproto OAuth (Eurosky, Bluesky, or another PDS).
  • Passwords are never stored by SunSpotters — we delegate to OAuth providers.
  • Sessions are managed with short-lived tokens and automatic refresh.
  • Sensitive actions (moderation, admin) use role-based checks operating in trusted infrastructure.

Hosting & platform

  • The app runs on a managed edge platform with TLS for every request.
  • The database is a managed instance with row-level security enabled.
  • Secrets and API keys are stored in the server and never visible in the client.
  • Backups and platform-level patching are handled by the hosting provider.

Spotter privacy

  • All profile, feed, leaderboard and location pages are behind sign-in and marked noindex — nothing is exposed to search engines or the public web.
  • Other members only ever see your chosen handle. Your email and sign-in name are stored encrypted and never shown to anyone else.
  • You can change your handle at any time from your profile — pick a random spotter-style handle for extra privacy.
  • Locations shared inside the app are coarsened to H3 level-7 cells (roughly 5 km across); precise GPS coordinates are never shown, even to other members.
  • If you link a Bluesky (atproto) account, your DID, handle and PDS URL are stored encrypted in a segregated PII schema — moderators and admins cannot read them.
  • Push notification tokens (endpoint URL and browser keys) are treated as credentials and stored encrypted at rest; only the notification dispatcher decrypts them in memory when it delivers a message.

Data handling

  • We only collect what's needed to run the app: account identifiers, content you upload (sunset/sunrise spots, photos, metadata), and basic usage data.
  • Row-level security policies restrict every table so users can only view and change data that they are authorised to do so, unless content is intentionally public (e.g. published spots).
  • Admin content is stored separately and with additional controls.

Subprocessors

  • Lovable — application platform and hosting.
  • Supabase — database, authentication, and file storage.
  • Google — OAuth sign-in.
  • atproto PDS providers (e.g. Eurosky, Bluesky) — OAuth sign-in when you choose them.

All providers operate in the EU or under EU-approved data transfer safeguards. See the Privacy Policy for details.

Retention & deletion

  • You can delete your account at any time from the profile page.
  • Account data is removed within 12 months of closure (sooner on request).
  • Uploaded content is removed when you delete it or close your account.
  • Usage and device data is anonymised or deleted within 26 months.

Your privacy rights

Under GDPR you can access, correct, export, or delete your data, and you can withdraw consent at any time. See Your Rights for the full list and how to exercise them.

Report a security issue

If you believe you've found a vulnerability, please email security@sunspotters.net. Responsible Disclosure: Please don't publicly disclose the issue before we've had a chance to investigate and fix it. We aim to acknowledge reports within 5 working days.

For privacy-specific requests, contact privacy@sunspotters.net.