Privacy Policy
Tailspot is a free plane-spotting game. This policy explains what information the app collects, why, and what happens to it. It is written to be read, not lawyered around.
What changed on July 11, 2026 (from the June 11, 2026 policy): (1) the app now embeds the PostHog analytics SDK, including session replay — recordings of the app's screens; your catch photos and the live camera view are masked out of those recordings (see §3); (2) we now describe location use accurately: the app uses your location continuously while it is open, to fetch nearby aircraft — not only at the moment of a catch; (3) catch records are now stored on our server and can be restored after a reinstall (photos cannot — see §5); (4) two minor processors added: Apple (turning catch coordinates into a place name) and Planespotters.net (loading stock aircraft photos).
1. What Tailspot collects — and what it does not
What the app collects
| What | Why | Where it goes |
|---|---|---|
| Anonymous device ID | Ties your catches and leaderboard score to your device without an account or email. Minted by our server on first launch; stored in your device's Keychain so it survives reinstalls. Never tied to your name. | Our backend (api.tailspot.app, hosted on Fly.io in the US). Also used as your anonymous analytics ID. |
| Public handle (optional) | If you claim one, it appears next to your score on the leaderboard. Entirely optional. | Our backend. |
| Catch records | Each catch stores: the aircraft's ICAO 24-bit address (a public radio identifier), callsign, timestamp, your GPS coordinates at the moment of the catch, and — if you played the bonus round — the answer you picked. | Our backend, for catch validation, the leaderboard, and so we can restore your collection if you reinstall (see §5). |
| Your approximate area, while the app is open | The app asks our server "what aircraft are near this bounding box?" every ~10 seconds so the sky view stays live. The box is derived from your location. It is used to answer the query, not to build a movement history. | Our backend. |
| Usage analytics + session replay | Anonymous product events (e.g. "app opened", "catch uploaded" — with the aircraft's identity and a coarse place name, never your coordinates) and recordings of the app's screens as you use them, so we can find and fix problems. Your catch photos and the live camera view are masked out of these recordings. See §3. | PostHog (our analytics processor), keyed to the anonymous device ID. |
| Crash and performance data | Crash counts, hang rate, peak memory (Apple's on-device MetricKit, summarized). | PostHog. |
What the app does NOT collect
- No account, email address, or real name — ever.
- Your camera's live view is never uploaded. Identification is geometric (GPS + compass + public flight data), not image recognition in the cloud. The photo snapped when you catch a plane stays on your device, and both the live camera view and your catch photos are masked out of session-replay recordings (see §3).
- No background location. The app uses location only while it's open ("While Using the App" permission) and does not build a location history.
- No advertising identifiers (IDFA), no ad networks, no data brokers.
2. How we use your data
| Data | Used for | NOT used for |
|---|---|---|
| Device ID + catches | Your collection, catch validation (were you really under that plane?), leaderboard score, reinstall restore. | Advertising, profiling, sale to anyone. |
| GPS catch coordinates | Catch validation only — compared against public flight tracks. | Public display, sharing with third parties, location history. |
| Approximate area while open | Fetching the aircraft near you. | Anything else. |
| Public handle | The leaderboard. | Anything else. |
| Analytics + replay | Understanding usage, fixing bugs. | Advertising or tracking across apps. |
3. Analytics, session replay, and diagnostics
The app embeds the PostHog SDK (posthog.com), our analytics processor. It collects, keyed to the anonymous device ID:
- Product events — things like "app opened," "catch uploaded," "trophy unlocked." Catch events include the aircraft's identity (a public fact) and a coarse place name like "Berkeley, US" — never your GPS coordinates.
- Session replay — periodic screenshots of the app's interface while you use it, replayed as a recording. This shows what any user of the app sees: aircraft labels, your collection, your handle. The live camera view is excluded from recordings, and your catch photos are masked — screens that display one of your photos show a blank box in its place. We use replays to find broken flows; they are visible only to the developer and PostHog as processor.
- Diagnostics — crash counts, hang rate, and memory summaries from Apple's on-device MetricKit.
Separately, Apple's own opt-in crash reporting (part of iOS, governed by Apple's privacy policy) may reach us via App Store Connect if you've opted in on your device.
4. Data sharing
We do not sell your data. Full stop.
Data is shared only with processors, solely to operate the app:
- Fly.io — backend hosting (US).
- PostHog — analytics and session replay (see §3).
- Apple — (a) opt-in crash reporting; (b) when you catch a plane, the catch coordinates are sent to Apple's geocoding service to turn them into a place name ("Oakland, US") for your collection card.
- Planespotters.net — when your collection shows a stock photo of an aircraft, the image loads directly from Planespotters' servers, which necessarily see your IP address (like any image on any website). The request identifies the aircraft, not you.
5. Data retention, restore, and deletion
On your device: your catch collection and all catch photos live in the app's local database. Photos exist only on your phone — they are never uploaded, and deleting the app deletes them permanently; we cannot recover them.
On our server: your device ID, optional handle, and catch records are retained while your device is active. Because catch records are on the server, reinstalling the app on the same device can restore your collection (cards and scores — not photos).
Deletion: email privacy@tailspot.app with subject "Data deletion request." We will delete your device ID, handle, and all associated catch records within 30 days and confirm by reply. There is currently no in-app deletion flow for backend data; we plan to add one. Analytics deletion requests are forwarded to PostHog for the same device ID.
6. GDPR / EEA residents
You have the rights of access, erasure, portability (your catch records in machine-readable form), and objection (your catches then stay on-device only). Email privacy@tailspot.app; we respond within 30 days. Legal basis: legitimate interest (operating a game whose core mechanic records catches; understanding and fixing the app) and, for the handle, contract performance.
7. CCPA (California residents)
We do not sell personal information. California residents may request access or deletion via privacy@tailspot.app.
8. Children
Tailspot is rated 4+ and suitable for all ages. No account or email is required, so no age verification is performed. If you believe a child under 13 submitted data (e.g., a handle), contact us and we will delete it promptly.
9. Security
All transmission is HTTPS. The backend holds anonymous device IDs and catch records — no passwords, payment data, or government identifiers, because we never collect any. No system is perfectly secure; we take reasonable precautions.
10. Changes
Material changes get a new effective date and a note at the top of this document; significant ones get an in-app or App Store notice.
11. Contact
Noah Landesberg
privacy@tailspot.app