Privacy Policy
In short
Spatchr stores the business records you enter — your customers, properties, jobs and photos — so they can sync between your devices and your crew. We do not sell them, we do not advertise, and you can export or delete everything. Two things worth knowing up front - if your business turns on time-tracking location, your location is recorded while you are clocked in, including in the background; and we keep assistant conversations for 90 days to improve the assistant, which you can switch off.
This policy explains what Spatchr does with information when you use the Spatchr Android app, the Spatchr web app at app.spatchr.com, or this website.
It is written to be read, not to be survived. Where something is genuinely unresolved, it says so rather than hiding behind a broad clause.
Who is responsible
Spatchr is operated by Jason Millis, at 5146 Carthage Avenue, Cincinnati, OH 45212. That entity is the data controller for the information described here.
For any privacy question, export request, or deletion request, write to privacy@spatchr.com.
What we collect
Information you give us
- Your account. An email address, and a display name if you provide one. If you sign in with Google we receive your email address, name and profile picture from Google.
- Your business records. This is the bulk of it, and it is information you type or capture: customers and their contact details, properties and their addresses, measured areas, jobs, visits, line items, prices, catalog services, expenses, time entries, notes, tasks and interactions.
- Photos and files you attach to jobs, along with the file’s own metadata.
- Crew members you invite, by email address, and the role you assign them.
Some of these records describe your customers, who are not our users. You are responsible for having a lawful basis to hold that information; we process it on your behalf.
Connecting your Google account
Signing in with Google gives us your identity and nothing else. Separately, you may choose to connect your Google account so Spatchr can act on your behalf. Every connection is optional, is off until you turn it on, and can be switched off at any time — in Spatchr’s settings, or at myaccount.google.com/permissions.
What we ask for, and why:
- Sending email as you — so the estimates, invoices, receipts and review requests you send reach your customer from your own address, land in your Sent folder, and have replies come back to you rather than to us. We cannot read your mail. Spatchr has no access to your inbox, your existing messages, your drafts, or any reply a customer sends you. We ask for permission to send, and nothing else.
- Your Google Business Profile — so you can read and reply to your Google reviews, see how your listing is performing, and keep your hours and business details current without leaving Spatchr.
- Your Google Calendar — so work you schedule in Spatchr can appear on your calendar. We read and write calendar events; we do not change your calendar’s settings.
- Files Spatchr creates in your Drive — used only for a backup you start yourself. This permission reaches only files Spatchr itself creates. It cannot see anything else in your Drive.
We use this access only to provide those features, when you ask for them. We do not use Google user data for advertising, we do not sell it, we do not use it to train AI models, and we do not pass it to anyone outside the processors listed below. When you disconnect, or delete your account, the access is revoked and what we held from it is deleted.
Spatchr’s use of information received from Google APIs follows the Google API Services User Data Policy, including the Limited Use requirements.
Information collected automatically
- Device and session data needed to keep you signed in and to sync — an authentication token, a device identifier, and timestamps of what changed so we know what to send. If you allow notifications we also store a push token for your device, so we can tell you about a new lead or an approved estimate.
- Location while you are using a map screen. Area measurement, property mapping and address lookup use your device’s location while you are on that screen. Nothing is stored unless you save it to a record.
-
Location while you are clocked in — including in the background, if your business turns it on. Time tracking has a location setting, chosen by the business owner, and it is off by default. When it is set to record at the start and finish of a shift, Spatchr takes one precise location fix as you clock in and another as you clock out. When it is set to record every 5 or every 15 minutes, Spatchr records your precise location on that schedule for as long as you are clocked in, including when the app is closed or not in use, and stores those points as a trail on the time entry.
This is employer-visible. The business owner, and anyone they have given permission to see all time entries, can see where you were while you were on the clock. It exists so a business can confirm attendance at a worksite and reimburse driven mileage.
Android will ask you for background location permission before any of this happens, and Spatchr shows you what it is for before Android asks. You can refuse, and you can withdraw the permission in your device settings at any time. When your business has location turned on, it is required to clock in: if you refuse, Spatchr will not clock you in, and it tells you so. Clocking out always works. While it is running, a notification stays in your tray for the whole shift.
- Voice recordings, when you talk to the assistant. Holding the assistant’s microphone button records audio and sends it to be turned into text. The recording is used for that and nothing else — it is not kept on our servers.
- Error and diagnostic information when something fails, so it can be fixed. This is technical information about the failure, scrubbed of personal details before it leaves your device, and there is currently no way to turn it off.
What we do not collect
We do not collect advertising identifiers, we do not run third-party analytics or advertising SDKs in the app, and we do not build behavioural profiles. We do not sell personal information, and we do not share it for cross-context behavioural advertising.
Payment card numbers never reach us. Payments run through Stripe’s hosted checkout, so card details go from you to Stripe directly.
Where your data lives, and who processes it
Spatchr is offline-capable on Android: after your first sign-in, your records live in a database on the phone itself and the app keeps working with no connection. When you have signal, that data syncs to our cloud so it reaches your other devices and your crew. The web app has no local database — it reads and writes your data live over the network.
We use these processors, each for one purpose:
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database hosting | United States |
| Application hosting provider | Runs the Spatchr backend | United States |
| Cloudflare | Website and app hosting, object storage | Global edge network |
| Stripe | Subscription billing and payment processing | United States |
| Sign-in, maps and address lookup, delivering notifications — and, if you connect your Google account, sending mail as you, your Business Profile, and your calendar | United States | |
| OpenRouter | Routing the in-app assistant to a language model, when you use it | United States |
| Cloudflare Workers AI | Speech-to-text for the assistant’s microphone, when you use it | Global edge network |
| Resend | Sending transactional email, such as a crew invitation | United States |
Data is stored and processed in the United States. If you use Spatchr from outside the United States, your information is transferred there.
About the assistant
When you ask the assistant something, Spatchr sends your message, the recent conversation, and the records needed to answer it to a language model through OpenRouter. If you ask about a job, that job’s details go with the question — and if that job belongs to one of your customers, so do their name and address. If you use the microphone, the audio goes to a speech-to-text service first.
We do not permit the assistant to be routed to any model provider that trains on what we send. Every zero-priced model is excluded from Spatchr for exactly this reason: those endpoints are free because the provider may train on, or publish, the prompts.
We keep a copy of assistant conversations, and we read them. This is how we find out where the assistant is getting things wrong — a question it misunderstood, an action it took that you did not ask for. The copy is verbatim, so if you asked it to “book Dale Whitfield at 12 Maple Drive”, that is what we see.
We use it to improve the assistant, and for nothing else. We do not sell it, we do not use it for advertising, and we do not train an external company’s model on it.
You can turn this off. It is in Settings → Assistant → Share Conversations, and turning it off also discards anything still waiting to be sent. In the United States it starts on and we tell you so when you first sign in. In the UK and the European Economic Area it starts off, and stays off unless you turn it on.
Conversations are deleted 90 days after they are recorded, and immediately if you delete your account.
We may, in future, use conversations to train or tune a model of our own for the in-app assistant. We are not doing that today. If that changes, this policy changes with it before it starts.
How your data is separated from everyone else’s
Each business’s records are isolated at the database level by row-level security keyed to membership, not by application code alone. A signed-in user’s queries can only return rows belonging to a business they are a member of. This is enforced by the database on every request.
How long we keep it
- Active accounts: for as long as the account exists.
- Deleted records: items you delete go to a recoverable trash first, then are purged.
- Assistant conversations: 90 days, then deleted automatically. Immediately, if you delete your account.
- Voice recordings: not retained. The audio is transcribed and discarded.
- Error and diagnostic records: 30 days.
- Cancelled or lapsed subscriptions: your data is retained, not destroyed, so you can return to it. Access may become read-only.
- After an account-deletion request: removed within 30 days, except where we must keep something (for example, billing records required by tax law).
- After you delete a business: access ends immediately — for you and for everyone who worked in it — and the records are erased from our production systems and our provider’s storage within 30 days. For a short part of that window the person who deleted it can undo the deletion from Settings → Account → My Account, so that an accidental deletion is survivable. We keep the data for no other purpose, and once the window closes it is gone.
Your choices
- Export everything. The app can produce a complete backup of your data, including attached media, to a file you keep.
- Delete your account and data. The process, and what it does and does not remove, is written out at /data-deletion/.
- Correct or access your information. Most of it you can edit directly in the app. For anything you cannot reach, write to privacy@spatchr.com.
- Location. Revoke the location permission in your device settings at any time. Area measurement, map centring and clock-in location will stop; nothing else will. Background location can be withdrawn on its own, without giving up the rest.
- Assistant conversations. Turn off Settings → Assistant → Share Conversations and we stop keeping them, including anything not yet sent.
- Notifications. Turn them off in your device settings; we stop using your push token.
Depending on where you live, you may have additional rights — to access, correct, delete, or port your information, and to complain to a supervisory authority. We apply these requests to everyone regardless of location. We do not charge for them and we will not degrade your service for making one.
Children
Spatchr is a tool for running a business and is not directed at children. We do not knowingly collect information from anyone under 13. If you believe a child has provided us information, write to privacy@spatchr.com and it will be removed.
Security
Data is encrypted in transit. Access to production systems is limited to those who need it. Credentials for third-party services are held server-side and are never included in the app you download.
No system is perfectly secure, and we are not going to pretend otherwise. If a breach affects your information, we will tell you and the relevant authority as required by law.
Changes
If this policy changes materially, the “last updated” date at the top will change and we will notify you in the app before the change takes effect. Continuing to use Spatchr after that means the new version applies.
Contact
privacy@spatchr.com — Jason Millis, 5146 Carthage Avenue, Cincinnati, OH 45212