Privacy Policy

Last updated: August 8, 2026

The short version

  • We store your email, username, handle, avatar, zipcode, and a one-way hash of your phone number.
  • Location is “When In Use” by default. Automatic visit detection is a separate, optional “Always” permission you have to grant on purpose — and can revoke at any time. We never keep a continuous trail of where you go.
  • We store a GPS point for each check-in you make (100m-verified), not for browsing the map.
  • Contact matching hashes your contacts on your device. Raw phone numbers never leave your phone, and we never message anyone in your address book.
  • We send push notifications for friends, plans, and your own content. Every category has an off switch.
  • We use PostHog for product analytics (screen views and in-app actions). No ad SDKs, no cross-app tracking, no IDFA, no session recording.
  • Uploaded photos are scanned automatically by OpenAI’s moderation API before they go live.
  • You can delete your account in the app. Note that spots and events you posted stay on the map, unlinked from you — see Deleting your account.

Who we are

SideQuestr is built and operated by Samuel Schoettker as a solo developer in Palm Beach, Florida (“we”, “us”). We are the controller of the data described below. Questions go to sidequestr.support@gmail.com.

Data we collect

WhatWhyWhere it’s stored
EmailSign-in and account recoverySupabase (encrypted at rest)
Username, handle, avatar, home zipcodeProfile, search, and local recommendationsSupabase
Hashed phone numberContact-matching only — never used to contact youSupabase (one-way hash with a secret pepper)
XP and who invited youProgress and referral creditSupabase
Spots you addPut places on the map for you and othersSupabase (data) + Supabase Storage (photos, pin icons)
Events you create or submitList events on the mapSupabase
Visits and event check-insLog that you actually went thereSupabase — lat/lng at the moment of check-in, how it was recorded, and a confidence score
Navigation intentsConfirm a visit when you head to a spot in-app; expires after 4 hoursSupabase — the destination lat/lng
Reviews, thumbs, and reactionsRatings and votes on spots, events, and other people’s reviewsSupabase
Spot and event attributesCrowd level, parking, vibe and similar crowd-sourced detailsSupabase
Saved spotsYour private saved listSupabase (only you can read it)
Plans you commit toShow friends who’s goingSupabase (visible to accepted friends)
FriendshipsShow you friends’ visits, plans, and spotsSupabase
BlocksKeep blocked accounts out of your experienceSupabase (only you can see your block list)
Reports you fileReview the reported content — includes a snapshot of it at report timeSupabase
Spots and events shared to you in-appDeliver the share and mark it seenSupabase (sender, recipient, item)
Private invite accessRemember that you unlocked someone’s private spot or eventSupabase
Push token and notification settingsDeliver notifications and respect your togglesSupabase + Apple (APNs)
Notification historyAvoid sending you the same thing twice and enforce daily capsSupabase
In-app feedbackYour rating, optional written quote, and whether you let us share itSupabase
Photos and pin icons you uploadShow your spots, events, and reviewsSupabase Storage — see Photos
Product analyticsUnderstand which features get used and where people get stuckPostHog (United States) — see Analytics
Hashed contact digestsServer-side matching — then discardedSupabase (ephemeral; see below)

We do not collect your precise home address, your payment details (SideQuestr is free and there is nothing to pay for), your health data, or your browsing activity outside the app.

Location, in detail

SideQuestr asks for location in two separate steps, and the second one is entirely optional.

“When In Use” — the default. This powers centering the map on you, showing what’s nearby, and verifying that you’re within about 100m of a spot when you check in. We only store the lat/lng at the moment you confirm a check-in. We do not record where you went while the app was open, and we do not store the location updates that drive the map.

“Always” — opt-in, for automatic visits. If you turn on automatic visit detection, SideQuestr asks iOS for background location so it can log a visit when you actually arrive somewhere — including when you navigated there in Apple Maps rather than in our app. Under the hood this uses Apple’s visit monitoring and geofences around specific spots: iOS does the watching and only wakes the app when you arrive at or leave a place. Even then, we store a single point for the visit we record. We never build or store a location trail, and we do not sell, share, or use location data for advertising.

You can revoke either permission at any time in iOS Settings → SideQuestr → Location. Dropping back to “When In Use” turns off automatic visits; everything else in the app keeps working.

Contact matching, in detail

When you choose to find friends from your contacts, SideQuestr reads your address book on your device only. For each phone number, we normalize it and compute a SHA-256 hash, mixed with a client-side pepper (a secret constant compiled into the app). Only those hashes are sent to our server.

The server then compares those hashes against the hashes of SideQuestr users’ phone numbers and returns a list of matched profile IDs. We never receive or store raw contact phone numbers, names, emails, or any other field from your address book. We never send SMS, email, or any other communication to people in your contacts.

The hashed digests you send during a contact sync are used for that match request and not retained long-term. Your own phone number is stored only as the same kind of one-way hash, so that friends can find you the same way.

Photos

Photos and pin icons you upload land in Supabase Storage. New uploads go to a private staging area first, get scanned (see below), and are then promoted to a public bucket so they can render on the map and in the app. Once promoted, a photo is served from a public URL — anyone with that link can view the image, the same as with most photo-sharing services. Photos on a private spot are gated in the app, but treat any uploaded photo as something that can be seen if a link is passed around.

We strip nothing from your judgment here: don’t upload a photo you wouldn’t want a stranger to see, and don’t upload photos of other people without their say-so.

Deleting a photo in the app removes both the database row and the stored file.

Automated content moderation

Every image uploaded to SideQuestr is scanned automatically before it goes live. We send it to OpenAI’s moderation API (omni-moderation-latest), which returns a verdict on categories like sexual content, violence, and self-harm.

The image is handed over as a short-lived signed link and nothing else — no account, handle, caption, or location travels with it, so the scan is anonymous on their end. Per OpenAI’s published API data policy, moderation requests are not used to train their models and are not retained after the scan.

We also run report-driven moderation: reviews and other content that reach three reports are hidden automatically pending a look from us, and accounts can be suspended or banned for repeated violations. Reports store a snapshot of the reported content so it can be reviewed even if the author edits or deletes it afterward.

Push notifications

SideQuestr sends push notifications through Apple’s Push Notification service (APNs). To do that we store a device push token tied to your account, which is removed when you sign out or delete your account.

Notifications fall into three categories, each with its own toggle in Settings → Notifications:

The app also schedules local reminders (about 30 minutes before an event you committed to). Those are created and fired on your device and never leave it.

We keep a log of what we sent you so we don’t send duplicates and so we can enforce a daily cap. You can turn all notifications off at the system level in iOS Settings at any time.

Analytics

We use PostHog to understand how the app is actually used — which features people find, where a flow breaks down, whether a change helped. PostHog captures:

Events are associated with your SideQuestr user ID so we can tell one person’s session apart from another’s. Session replay is off — we do not record your screen. We do not send your email, phone number, contacts, precise location, or photo content to PostHog. When you sign out or delete your account, we reset the analytics identity so later activity isn’t attributed to you. Data is processed on PostHog’s US cloud.

You may see a promoted spot or a deal card in the feed above the map. These are curated by us and served from our own database. There is no third-party ad network in the app, no advertising SDK, no IDFA, and no ad targeting based on your personal data, your location history, or your behavior. We don’t share your data with advertisers, and a promoted card doesn’t know who you are.

Who your data is visible to

Access rules are enforced at the database level with row-level security, not just in the app.

Third parties

We don’t sell, rent, or trade your data to anyone. We may disclose data if we’re legally required to, or where it’s necessary to investigate a safety issue or a violation of our Terms.

What we do not do

Children

SideQuestr is for users aged 13 and over. We don’t knowingly collect data from children under 13. If you believe a child under 13 has created an account, email us at sidequestr.support@gmail.com and we’ll remove it.

Your rights

You can access, export, correct, or delete your data at any time, wherever you live.

We won’t discriminate against you for exercising any of these rights, and we don’t charge for them.

Deleting your account

Deleting your account removes your personal data: your profile, your email and login, your hashed phone number, your visits and check-ins, your reviews and votes, your saved spots, your attributes, your friendships, your blocks, your push tokens, and your notification settings. We also reset your analytics identity.

Spots and events you posted stay on the map. They are unlinked from your account — no longer attributed to you, no longer editable by anyone — because deleting them would punch holes in the map for every other user who has visited, saved, or reviewed them. If you want a specific spot or event removed rather than orphaned, delete it in the app before you delete your account, or email us and we’ll take it down.

Retention

Your data lives in Supabase while your account is active. After deletion, a brief tail remains in our provider’s backups and ages out on its normal schedule. Product analytics in PostHog are retained on PostHog’s standard schedule and are no longer tied to your identity after deletion. Moderation records — reports, snapshots of reported content, and enforcement actions — are kept as long as needed for safety and abuse prevention, since deleting them would let a banned account come straight back.

Security

Data is encrypted in transit and at rest. Access rules are enforced by row-level security policies in the database, so a client can only read what it’s entitled to even if the app were modified. We’re a small operation and can’t promise perfection — if you find a security issue, email us and we’ll take it seriously and fast.

International users

SideQuestr is operated from the United States and your data is stored and processed there. If you use the app from outside the US, you’re consenting to that transfer.

Changes

If we update this policy we’ll bump the date at the top of the page. Material changes will be called out in-app.

Questions about privacy?

Privacy questions, data requests, or anything else: sidequestr.support@gmail.com.

Contact

Replies usually within a day or two. For account deletion requests, please include the email on your account.