SupMup — Privacy Policy

SupMup is a paddleboarding app: wind conditions, recorded sessions, and a feed shared between paddlers.

Last updated: 30 July 2026

This policy describes what the app actually does. Where something is not private, it says so plainly rather than implying otherwise.

What we collect

DataWhyWhen
Name, email address and profile picture from the account you sign in with — Google, or Apple. Sign in with Apple can give a private relay address instead of your real one, and that is all we ever see To create your account and show who posted a paddle When you sign in
Precise location (GPS) To show conditions where you are, and to record a route, distance and speed while a session is running While you use the app, and in the background while a session is recording
Recorded sessions — route, distance, duration, speed, calories, weather at the time Your paddling log, and the feed if you share it When you save a session
Photos you attach, and your profile picture if you upload one To show on your session or profile When you choose them
Captions, comments, reports and blocks The social features When you write them
Usage analytics tied to your account id To understand which features are used Only while analytics is switched on — see below

SupMup itself never asks for your date of birth, address or payment details, and there is nothing in the app that collects them. It does not ask for your phone number either — but see the note below about what the Google sign-in library reports separately.

What the Google sign-in library may collect

Signing in uses Google's own Sign-In and Firebase Authentication libraries. Those are Google's code running inside the app, and Google publishes what they are capable of collecting independently of what SupMup asks for. According to Google's own declarations, that can include:

SupMup does not request any of these, is not shown them, and does not store them. They are listed here because they form part of the app's published App Store privacy information, and it would be misleading to describe the app's own collection without saying what the sign-in library reports. What SupMup actually receives and keeps from a Google sign-in is the three items in the table above: your name, your email address and your profile picture.

Background location

While a session is recording, SupMup keeps tracking your position with the screen off, so a paddle is not lost when your phone goes in a dry bag. On Android this runs as a foreground service with a permanent notification; on iOS the system location indicator stays visible. Recording only ever starts when you start it, and stops when you stop it.

Who your data is shared with

SupMup uses these third-party services. Each receives only what is listed.

Google Firebase (Google LLC)

Sign-in, database, file storage, server functions and analytics. All account data, sessions, photos and comments are stored here. Data is held in Google Cloud's nam5 multi-region (United States).

Google Cloud Vision — SafeSearch

Every photo you upload — session photos and profile pictures — is sent to Google Cloud Vision to be checked for adult or violent imagery before it is published. See Photo screening below.

Open-Meteo

Weather forecasts. Your coordinates are sent to api.open-meteo.com to get conditions for that spot. If you search for a place by name, the text you type is sent to geocoding-api.open-meteo.com. No account identifier is sent with either request.

BigDataCloud

Turning coordinates into a place name — the "Málaga, Spain" label under the conditions. Your coordinates, rounded to four decimal places, are sent to api.bigdatacloud.net. No account identifier is sent with the request, and nothing is sent back to us.

CARTO and OpenStreetMap

Map tiles behind your route. Loading a map tells CARTO's servers roughly which part of the world is being viewed. Map data is © OpenStreetMap contributors.

YouTube (Google LLC)

The tutorials section plays videos through youtube-nocookie.com, YouTube's reduced-tracking embed. YouTube still receives your IP address and which video was played when you play one.

We do not sell your data, and we do not share it with advertisers. There is no advertising in SupMup and no cross-app tracking, so the app does not ask for tracking permission.

What other people can see

An honest limitation about photos. Marking a session private keeps it out of the feed, and that part is enforced by the server. But the photo attached to it is served from a long-lived link. Anyone who is given that link can open the image, even without a SupMup account, and that remains true after the session is made private. Treat a photo you attach as something that could be forwarded. We intend to replace these with short-lived links; until this policy says otherwise, it has not happened.

Routes have a further wrinkle worth knowing: when you share a session card, the start and end of the route are trimmed by default so the image does not publish where you launched from. The stored route itself is not trimmed.

Photo screening and moderation

Photos are checked before anyone can see them. An uploaded image goes to a private location that nobody — including you — can read from, is sent to Google Cloud Vision SafeSearch, and is only published if it passes. Refused images are deleted; we keep a record of the account, the time and the category, and no copy of the picture.

What this screening is not. SafeSearch detects adult and violent imagery. It is not CSAM detection, which is a different technology with different legal obligations, and SupMup does not claim to perform it.

Reports are counted, not read. There is no review queue and nobody reads individual reports. When enough separate people report the same thing it is hidden automatically. If you need a person, email the address at the bottom of this page — that is the only route to one.

Analytics

Analytics is off unless you turn it on. Nothing is measured, and no analytics identifier is stored on your device, until you switch it on in Profile → Edit profile → Analytics.

If you do switch it on, it records which screens and features are used, tied to your account id. It never records what you type: search terms, captions and comments are never sent as analytics data. Switching it back off takes effect immediately and detaches your account id.

The setting is per device, so turning it on for one phone does not change another.

Keeping and deleting your data

Your data is kept while your account exists. Delete your account in Profile → Edit profile → Delete account, or see the account deletion page.

Deleting your account removes, permanently and without a recovery period:

Abandoned photo uploads that were never published are removed automatically within about a day. Anonymous, aggregated analytics that cannot be traced to you may remain.

Your rights

You can see everything on your profile in the app, correct your name, bio and picture at any time, switch analytics off, and delete everything. Depending on where you live you may have further rights over your data, including a copy of it. Email us and we will help.

Children

SupMup is not directed at children and we do not knowingly collect data from anyone under 13. If you believe a child has created an account, email us and we will remove it.

Security

Traffic is encrypted in transit. Access to your data is enforced by server-side rules rather than by the app, so a modified client cannot read what it should not — with the photo-link exception described above, which is stated there precisely because it is the one place this is not true.

Changes

If this policy changes materially we will update the date at the top. Continuing to use SupMup after a change means you accept the updated policy.

Contact

astrobeastco@gmail.com