SupMup — Privacy Policy
SupMup is a paddleboarding app: wind conditions, recorded sessions, and a feed shared between paddlers.
Last updated: 30 July 2026
This policy describes what the app actually does. Where something is not private, it says so plainly rather than implying otherwise.
What we collect
| Data | Why | When |
|---|---|---|
| Name, email address and profile picture from the account you sign in with — Google, or Apple. Sign in with Apple can give a private relay address instead of your real one, and that is all we ever see | To create your account and show who posted a paddle | When you sign in |
| Precise location (GPS) | To show conditions where you are, and to record a route, distance and speed while a session is running | While you use the app, and in the background while a session is recording |
| Recorded sessions — route, distance, duration, speed, calories, weather at the time | Your paddling log, and the feed if you share it | When you save a session |
| Photos you attach, and your profile picture if you upload one | To show on your session or profile | When you choose them |
| Captions, comments, reports and blocks | The social features | When you write them |
| Usage analytics tied to your account id | To understand which features are used | Only while analytics is switched on — see below |
SupMup itself never asks for your date of birth, address or payment details, and there is nothing in the app that collects them. It does not ask for your phone number either — but see the note below about what the Google sign-in library reports separately.
What the Google sign-in library may collect
Signing in uses Google's own Sign-In and Firebase Authentication libraries. Those are Google's code running inside the app, and Google publishes what they are capable of collecting independently of what SupMup asks for. According to Google's own declarations, that can include:
- your name and email address;
- a phone number, where a Google account uses one as part of signing in;
- an approximate location, derived from the network rather than from GPS;
- a device identifier, and diagnostic and usage data about how the sign-in itself performed.
SupMup does not request any of these, is not shown them, and does not store them. They are listed here because they form part of the app's published App Store privacy information, and it would be misleading to describe the app's own collection without saying what the sign-in library reports. What SupMup actually receives and keeps from a Google sign-in is the three items in the table above: your name, your email address and your profile picture.
Background location
While a session is recording, SupMup keeps tracking your position with the screen off, so a paddle is not lost when your phone goes in a dry bag. On Android this runs as a foreground service with a permanent notification; on iOS the system location indicator stays visible. Recording only ever starts when you start it, and stops when you stop it.
Who your data is shared with
SupMup uses these third-party services. Each receives only what is listed.
Google Firebase (Google LLC)
Sign-in, database, file storage, server functions and analytics. All account
data, sessions, photos and comments are stored here. Data is held in Google
Cloud's nam5 multi-region (United States).
Google Cloud Vision — SafeSearch
Every photo you upload — session photos and profile pictures — is sent to Google Cloud Vision to be checked for adult or violent imagery before it is published. See Photo screening below.
Open-Meteo
Weather forecasts. Your coordinates are sent to
api.open-meteo.com to get conditions for that spot. If you search
for a place by name, the text you type is sent to
geocoding-api.open-meteo.com. No account identifier is sent with
either request.
BigDataCloud
Turning coordinates into a place name — the "Málaga, Spain" label under the
conditions. Your coordinates, rounded to four decimal places, are sent to
api.bigdatacloud.net. No account identifier is sent with the
request, and nothing is sent back to us.
CARTO and OpenStreetMap
Map tiles behind your route. Loading a map tells CARTO's servers roughly which part of the world is being viewed. Map data is © OpenStreetMap contributors.
YouTube (Google LLC)
The tutorials section plays videos through
youtube-nocookie.com, YouTube's reduced-tracking embed. YouTube
still receives your IP address and which video was played when you play one.
We do not sell your data, and we do not share it with advertisers. There is no advertising in SupMup and no cross-app tracking, so the app does not ask for tracking permission.
What other people can see
- Public sessions — anyone signed into SupMup sees these in the feed: your name, profile picture, route, stats, caption and photo.
- Private sessions — kept out of the feed and off your public profile. Only you can read the session and its data.
- Your profile — name, picture, bio and lifetime totals are visible to other signed-in users.
- Comments — visible to anyone who can see the session they are on.
An honest limitation about photos. Marking a session private keeps it out of the feed, and that part is enforced by the server. But the photo attached to it is served from a long-lived link. Anyone who is given that link can open the image, even without a SupMup account, and that remains true after the session is made private. Treat a photo you attach as something that could be forwarded. We intend to replace these with short-lived links; until this policy says otherwise, it has not happened.
Routes have a further wrinkle worth knowing: when you share a session card, the start and end of the route are trimmed by default so the image does not publish where you launched from. The stored route itself is not trimmed.
Photo screening and moderation
Photos are checked before anyone can see them. An uploaded image goes to a private location that nobody — including you — can read from, is sent to Google Cloud Vision SafeSearch, and is only published if it passes. Refused images are deleted; we keep a record of the account, the time and the category, and no copy of the picture.
What this screening is not. SafeSearch detects adult and violent imagery. It is not CSAM detection, which is a different technology with different legal obligations, and SupMup does not claim to perform it.
Reports are counted, not read. There is no review queue and nobody reads individual reports. When enough separate people report the same thing it is hidden automatically. If you need a person, email the address at the bottom of this page — that is the only route to one.
Analytics
Analytics is off unless you turn it on. Nothing is measured, and no analytics identifier is stored on your device, until you switch it on in Profile → Edit profile → Analytics.
If you do switch it on, it records which screens and features are used, tied to your account id. It never records what you type: search terms, captions and comments are never sent as analytics data. Switching it back off takes effect immediately and detaches your account id.
The setting is per device, so turning it on for one phone does not change another.
Keeping and deleting your data
Your data is kept while your account exists. Delete your account in Profile → Edit profile → Delete account, or see the account deletion page.
Deleting your account removes, permanently and without a recovery period:
- Your profile, name, picture and bio
- Every session you recorded, and its photos
- Every comment and like you made, anywhere in the app
- Every comment and like other people made on your sessions
- Your sign-in credential
Abandoned photo uploads that were never published are removed automatically within about a day. Anonymous, aggregated analytics that cannot be traced to you may remain.
Your rights
You can see everything on your profile in the app, correct your name, bio and picture at any time, switch analytics off, and delete everything. Depending on where you live you may have further rights over your data, including a copy of it. Email us and we will help.
Children
SupMup is not directed at children and we do not knowingly collect data from anyone under 13. If you believe a child has created an account, email us and we will remove it.
Security
Traffic is encrypted in transit. Access to your data is enforced by server-side rules rather than by the app, so a modified client cannot read what it should not — with the photo-link exception described above, which is stated there precisely because it is the one place this is not true.
Changes
If this policy changes materially we will update the date at the top. Continuing to use SupMup after a change means you accept the updated policy.