Privacy Policy
Last updated: July 20, 2026
Who is responsible for your data
Spody is published and operated by Forge & Co SAS, a French simplified joint-stock company (société par actions simplifiée) with a share capital of €1,200, registered with the Brive-la-Gaillarde Trade and Companies Register under number 993 661 453, whose registered office is at 503 route de Ménoire, 19490 Sainte-Fortunade, France (intra-EU VAT number FR 62 993 661 453). Forge & Co SAS is the data controller for the personal data described here. For any question or request about your data, write to contact@spodyapp.com or to the postal address above. We have not appointed a Data Protection Officer, as we are not required to.
Spody is for adults only
Spody is reserved for people aged 18 or over. We ask for your date of birth during sign-up solely to enforce this rule; the check runs on our servers and an account that does not meet it cannot be completed. Your date of birth is never displayed on your profile and is never shown to other users. We do not knowingly process the data of anyone under 18 — if you believe a minor has created an account, tell us and we will delete it.
What data we collect
We only collect what Spody needs to work. In practice:
- Account — your email address and password, or the identifier, email address, name and profile picture provided by Apple or Google if you sign in with them; your display name; your date of birth (age check only); an optional profile photo.
- Sports — the sports you practice and, optionally, your level for each.
- Activities and participation — the activities you propose or join, with their title, description, sport, meeting point (place name, address and coordinates you choose), start and end times, level, capacity and join mode; join requests, approvals, declines, departures and attendance confirmations.
- Messages — the messages you send in an activity’s group chat.
- Meet-up coordination — an optional short note describing how to recognize you, and, if you add one, a phone number. Sharing your phone number is off by default: it is only revealed if you turn it on, only to people who joined the same activity, and only around the time of the meet-up.
- Objectives — the training objectives you join, with the area, level, availability and target date you set, and any note you write.
- Sport sessions and health data — sessions you log yourself and, only if you explicitly enable the import, workouts read from Apple Health or Android Health Connect (activity type, date, duration, distance). See the dedicated section below.
- Location — your device location, if you allow it. See the dedicated section below.
- Safety and moderation — users you block, reports you send or that concern you (including the free-text details), and the decisions our moderators take.
- Devices and notifications — for push notifications: a device token, the platform (iOS, Android, web), a device name so you can recognize it in your session list, and the last-used date; plus the in-app notifications generated for you.
- Technical data — the authentication, security and abuse-prevention data needed to run the service (for example, sign-in events and rate-limiting counters). For password resets we store only a hash of the email address, never the address itself.
Location: what is used and what is stored
Spody uses location in the most limited way we could design. Your device’s position is requested only while the app is open and only when you allow it — there is no background tracking, and refusing never blocks sign-up or the use of the app.
- Your device position is used live, on your device, to center the map, sort activities by distance and bias address search. We never store it on our servers.
- The locations that are stored are the meeting points you deliberately enter when you create an activity or set the area of an objective. Choose a public meeting point rather than your home address.
- On public pages — the activity pages on this website, visible without an account — the meeting point is deliberately blurred: it is shifted by 100 to 400 meters and shown as an approximate zone. The exact point is only revealed to signed-in users.
Health data
If — and only if — you enable the import, Spody reads your workouts from Apple Health or Android Health Connect to fill in your sport history. We read the activity type, date, duration and distance. We never read or store GPS routes, and we never write anything back to Health. This data is health data within the meaning of Article 9 GDPR, so we process it solely on the basis of your explicit consent, which you can withdraw at any time in your device settings or by deleting the imported sessions. Turning the import off, or never turning it on, leaves every other Spody feature fully usable.
Why we use your data, and on what legal basis
Under the GDPR, each use rests on a legal basis:
- Performing our contract with you — creating and managing your account, showing activities near you, letting you propose, join and organize them, running activity chats, and delivering the notifications tied to those actions.
- Your consent — device location, push notifications, importing workouts from Health, revealing your phone number to co-participants, and any future newsletter. You can withdraw any of these at any time, without affecting the lawfulness of what came before.
- Our legitimate interests — keeping Spody safe and usable: preventing abuse and spam, handling blocks and reports, moderating content, securing accounts, and fixing bugs. We have balanced these against your rights and limited the data accordingly.
- Compliance with our legal obligations — responding to lawful requests from authorities and keeping records where the law requires it.
What other users can see
Spody is a social app, so part of your data is visible to others — but the scope is deliberately narrow.
- Your display name, your sports and your public sport record are visible to signed-in users.
- Your profile photo is only visible to people who have joined the same activity as you.
- Your date of birth and email address are never shown to other users.
- Your phone number is never shown unless you explicitly turn on sharing, and then only to co-participants of the activity concerned, around the meet-up time.
- What you write — activity descriptions, chat messages, meet-up notes — is visible to the people concerned by that activity. Please treat those spaces as public.
Who we share your data with
We never sell your personal data and we never share it with advertisers. We do use a small number of service providers, which act as our processors under contracts meeting Article 28 GDPR:
- Supabase — database, authentication, file storage and backend, hosted in the European Union (West EU region). This is where your Spody data lives.
- Mapbox — maps, address search and reverse geocoding. Mapbox receives the map and search requests your device makes, along with the technical data inherent in them.
- Google (Firebase Cloud Messaging) — delivery of push notifications on mobile. Receives your device token and the notification content. Push notifications never contain the body of a chat message.
- Apple and Google — only if you use “Sign in with Apple” or “Sign in with Google”.
- Resend — sending our transactional emails (verification code, password reset, moderation notices).
- OVH SAS — hosting of this website in France.
What we do not do
No advertising, no sale or rental of your data, no resale to data brokers. Spody contains no advertising SDK and no analytics or tracking SDK, and does not build advertising profiles. This website sets no cookies and runs no audience-measurement or tag-management script — which is why you are not seeing a cookie banner. No decision producing legal effects concerning you is taken by purely automated means.
Transfers outside the European Union
Your Spody account data and this website are hosted in the European Union. Some of the providers listed above (Mapbox, Google, Apple and Resend) are established in the United States or may process data there. Those transfers are covered by the appropriate safeguards required by Chapter V GDPR — the European Commission’s Standard Contractual Clauses and/or certification under the EU–US Data Privacy Framework.
How long we keep your data
We keep your data for as long as your account is open, then:
- When you delete your account, your profile, activities, participations, messages, sports, objectives, blocks and reports are permanently deleted, along with your profile photo. This is a real deletion, not a deactivation.
- Content you delete inside the app (an activity, a message) is first hidden from everyone and then removed as part of our routine clean-ups. A deleted chat message is shown as “Message deleted” and its content is no longer displayed.
- Moderation and safety records may be retained after your account is deleted, de-identified where possible, for as long as needed to protect other users and to defend legal claims.
- Technical and security logs are kept for a limited period, not exceeding twelve months.
Your rights
Under the GDPR you have the right to access your data, to have it corrected, to have it erased, to restrict or object to its processing, to receive it in a portable format, and to withdraw your consent at any time. You can exercise several of these directly in the app: edit your profile, delete your content, manage your linked devices, and delete your account permanently from your settings. For anything else, write to contact@spodyapp.com — we reply within one month. If you believe your rights have not been respected, you may lodge a complaint with your national supervisory authority; in France, the CNIL (3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07 — cnil.fr).
Security
Data is encrypted in transit (HTTPS/TLS) and at rest at our host. Access is controlled row by row in the database, so a user can only read the data they are entitled to. Passwords are never stored in plain text, email-verification codes are stored hashed, and you can review your linked devices and sign them out remotely at any time. No system is perfectly secure, but should a breach occur that is likely to result in a high risk to your rights, we will notify you and the CNIL as required by law.
Changes to this policy
We may update this policy to reflect changes to the app or to the law. The new version is published on this page with an updated date, and any significant change is announced in the app before it takes effect.
Questions about this policy? Contact us at contact@spodyapp.com.