Privacy Policy
Effective date: August 6, 2026
Sweet Spot ("we," "us") is a free iOS app that helps you understand how alcohol affects your next day. Privacy isn't a compliance afterthought for an app like this — it's the product's foundation. This policy explains exactly what we collect, why, and what we will never do with it, in plain English.
1. What we collect
- Account information. When you sign in with Apple, we receive a unique identifier and, if you choose to share it, your name and email address (Apple lets you hide your real email; that works fine with us).
- Check-in data you enter. Your daily check-ins: the date, the number of drinks you logged, and your feeling score (0–10).
- Sleep data (optional, only with your permission). If you connect Apple Health, we read sleep analysis data through Apple's HealthKit framework: how long you slept, how long you were in bed, the stage breakdown (core, deep, REM, awake) where your device records one, and the overall shape of the night — when sleep began and ended, how many times it was interrupted, and your longest unbroken stretch. We only read; we never write to Apple Health. You can revoke this access at any time in iOS Settings, and the app works fully without it.
- Recovery signals from Apple Health (optional, only with your permission). If you connect Apple Health, we also read the daily recovery measurements your device records: resting heart rate, heart rate variability, respiratory rate, and wrist temperature. These exist to answer the question the app is for — whether drinking affects how your body recovers overnight — and they are used for nothing else. Most require an Apple Watch, and each is independent: if your device doesn't record one, or you decline it, everything else in the app works exactly as before. We only read; we never write to Apple Health. You can revoke this access at any time in iOS Settings.
- Workout data from Apple Health (optional, only with your permission). If you choose to use Apple Health as your training source, we read workout summaries through the same HealthKit framework: the activity type, the date and start time, the duration, and the distance where your device recorded one. We do not read routes or GPS traces. We only read; we never write to Apple Health. You can revoke this access at any time in iOS Settings, and the app works fully without it.
- Activity data (optional, only with your permission). If you connect Strava, we receive summaries of your activities through Strava's official API: activity type, date and start time, duration, distance, pace and speed, elevation gain, relative effort, and — where your device recorded them — heart rate (average and maximum), cadence, and power. We do not access your Strava followers, messages, or precise GPS routes. You can disconnect Strava at any time, and the app works fully without it. When you disconnect, we stop syncing and delete the Strava access tokens we hold for you; activity summaries already synced remain until you delete your account.
- Waitlist email. If you signed up for early access on our website, we store the email address you provided, solely to contact you about Sweet Spot.
- Basic technical data. Standard technical information required to operate the service (such as authentication tokens and timestamps).
- Usage analytics. We record basic, first-party usage events — for example that you opened the app, completed a check-in, or connected Apple Health — so we can understand which parts of Sweet Spot people actually use. These events are never your drink counts, feelings, sleep, or workout data — only the fact that an action happened. This data is stored only in our own database, is linked to your account, and is deleted permanently when you delete your account. We do not use any third-party analytics or advertising SDKs.
2. What we deliberately do not collect
No location data. No contacts. No advertising identifiers. No browsing behavior. No precise GPS routes — not from Strava, and not from Apple Health. No data about you from third-party data brokers — ever.
Within Apple Health, we read only the categories named in section 1 — sleep, workout summaries, and the four recovery signals. We do not read your medical records, medications, lab results, reproductive health, mental-health logs, nutrition, blood glucose, ECG, or anything else Health can hold. HealthKit requires apps to ask for each category individually, so this is not merely a promise: the app has no way to read a category it never requested, whatever you grant it.
A note on heart rate. An earlier version of this policy said we collected no heart-rate data. That was true then and is no longer, so we have changed it rather than leave a comfortable sentence standing: as of August 6, 2026 we read heart rate from workouts you sync with Strava, and resting heart rate and heart rate variability from Apple Health, both only with your permission and both solely to compute your own insights. The commitments that surround this data — never sold, never used for advertising, never shared, deleted with your account — are unchanged and apply to it in full.
3. How we use your data
- To show you your own insights: how your drink count relates to your next-day feeling, sleep, recovery, and training — computed from your own history, on your own data, and never compared against anyone else's.
- To operate the app: authentication, syncing, notifications you've enabled.
- To compute anonymous, aggregated statistics (see section 4).
- To respond when you contact us.
That's the complete list. We do not use your data for advertising, and we do not sell or rent it to anyone, in any form.
Apple Health data (special commitment): data obtained through HealthKit is used solely to provide you with your own insights inside the app. Consistent with Apple's requirements, we never use HealthKit data for advertising or marketing, and we never share it with third parties.
Strava data: activity data obtained through the Strava API is used solely to show you your own training-related insights, consistent with Strava's API Agreement.
4. Anonymous aggregate statistics
Sweet Spot may show fun, anonymous benchmarks — for example, how your weekly drink count, or how you tend to feel in the mornings, compares with other people using Sweet Spot. A nightly job on our own servers reads check-ins in bulk and writes out group statistics only; the records it produces contain no user identifiers of any kind. A benchmark is only calculated, stored, or shown when the underlying group is at least 25 people — large enough that no individual could be singled out — and where a group is smaller than that, the statistics are never calculated in the first place.
Sweet Spot may also compare your numbers with published statistics from public research — for example a national survey of drinking habits. Those figures are fixed, public, and cited in the app; making that comparison sends nothing anywhere, because the published numbers ship inside the app itself. We do not know where you live, and a comparison against any national figure is offered as general context, not as a claim about your own country or region. Your individual check-ins are never visible to any other user, and never will be.
5. Where your data lives and how it's protected
Your data is stored with Supabase, our database provider, on servers located in the United States. Data is encrypted in transit and at rest. Access to individual records is restricted by database-level security rules so that your data is readable only by you. Our administrative tooling does not expose individual drink or feeling data beyond what is strictly necessary to provide support you have requested.
No system is perfectly secure, and we cannot guarantee absolute security — but we designed this app so that the sensitive data it holds is minimal in the first place.
6. How long we keep data, and how to delete it
We keep your data for as long as you have an account, so your insights can be computed from your history.
Export: you can export all of your check-in data as a CSV file from the app's settings at any time.
Deletion: you can permanently delete your account and all associated data from the app's settings at any time. Deletion is complete and irreversible — check-ins, sleep records, recovery signals (resting heart rate, heart rate variability, respiratory rate, wrist temperature), activity records including their heart-rate and power data, Strava tokens, usage-analytics events, and account information are all removed, and your Strava authorization is revoked at Strava. Waitlist emails are deleted on request or when no longer needed.
7. Your rights
Depending on where you live (including under GDPR in the EU/UK and CCPA in California), you may have rights to access, correct, export, delete, or restrict the processing of your personal data, and to lodge a complaint with a supervisory authority. The app's built-in export and deletion tools cover most of these directly; for anything else, contact us and we will help.
We do not "sell" or "share" personal information as those terms are defined under the CCPA.
8. Age requirement
Sweet Spot is intended for adults of legal drinking age in their location and is rated 18+ on the App Store. We do not knowingly collect data from anyone under 18 (or under the legal drinking age where they live, if that is higher). If you believe a minor has created an account, contact us and we will delete it.
9. What Sweet Spot is not
Sweet Spot is not a medical device and does not provide medical advice. Insights describe patterns in your own logged data; they are not health guidance. If you are concerned about your drinking, please talk to a doctor or a qualified professional.
10. Changes to this policy
If we make material changes, we will update this page and note the new effective date, and — for significant changes — tell you in the app before they take effect. We will never change the fundamentals quietly: no ads, no selling data, no sharing individual data.
11. Contact
Questions, requests, or concerns: privacy@findsweet.spot
Operated by the Sweet Spot team, New York, USA.