Privacy Policy
SweatPotatoes — What we keep, and who sees it. Mostly: your partner. That is the whole app.
Last updated: 22 August 2026 · Effective: 22 August 2026
In short
SweatPotatoes is an app for two people who promise each other they will move, and then tell each other whether they did. Almost everything it stores exists so that one specific person — the partner you chose — can see it.
- We do not sell your data, and we never use it for advertising.
- We do not track your body: no distance, no pace, no calories, no heart rate, no location. The only figure we keep about a session is the number of minutes you said it lasted.
- What your duo partner sees is described in section 3, in full. It is the most important part of this document.
- Your data is stored in the European Union (Ireland).
1. Who we are
SweatPotatoes is published by Thomas Viot, sole trader (micro-enterprise) trading as Serviprog, registered at 19 chemin des Mûriers, 66680 Canohès, France, under registration number 930 679 204. Publication director: Thomas Viot.
We are the data controller for the personal data described here, within the meaning of the General Data Protection Regulation (GDPR). You can reach us at contact@sweatpotatoes.app.
This policy takes effect on 22 August 2026.
2. What we collect, and why
Only what the app needs to work. There is no hidden collection: every category below is something you can see on a screen.
Your account
- Email address — Signing in, getting back into your account, and the rare message we have to send you about the service. Legal basis: performance of the contract.
- Password — Stored hashed, never in clear text, and unreadable by us. Legal basis: performance of the contract.
- Display name — So your partner sees a person rather than an identifier. Legal basis: performance of the contract.
- Profile picture — Optional, from your camera or your photo library. Legal basis: your consent — you choose whether to add one.
If you sign in with Apple, you may use Hide My Email. We then only ever receive a relay address, and that is enough: the app never needs your real one.
Your duo
An invitation code, and the link between two accounts once your partner joins. Nothing about their device and nothing from your address book: the app never reads your contacts. An invitation travels as a code or a link that you send yourself, through whichever app you choose to send it with.
Your pacts
A pact is what the app is for, and it is what we store most of:
- the day, and your own hour, duration, activity and place;
- the routine you picked, if you picked one;
- whether you marked the session as done, when, and how many minutes you logged;
- the note you write when a session did not happen, and the note attached to a request to move a day — both free text, written by you;
- the stake you laid on your partner, and the one they laid on you;
- the photo you send as proof of a session;
- your weekly rhythm, your breaks, and the record of your past pacts.
Legal basis: performance of the contract — this is the service. The photo and the stake are optional and rest on your consent; the app works in full without either.
Two answers from the onboarding — your activity level, and what makes you bail — describe your physical condition. We treat them as health data within the meaning of article 9 of the GDPR, so they rest on your explicit consent. They are used only to pitch the app's tone, they are never shared with your partner, and you can ask us to erase them at any time.
Notifications
If you allow them, we store a push notification token for each of your devices, and the platform it runs on. It is used for one thing: telling you what your partner just did. We never send marketing notifications. Legal basis: your consent, which you can withdraw at any time in your device settings.
Subscription
If you subscribe, the purchase is made by Apple or by Google. We never see your card, your bank details or your billing address. We store only whether you have an active subscription, the date the paid period ends, and the identifier of the product bought — which is what lets one subscription cover both of you. Legal basis: performance of the contract, and our legal accounting obligations.
Technical and product data
- Technical logs kept by our hosting provider — IP address, timestamps, error traces — used to keep the service up and to investigate incidents and abuse. Legal basis: our legitimate interest in a secure, working service.
- Product analytics, where enabled: pseudonymous events describing what kind of thing happened, such as a pact being sealed. No free text is ever sent to analytics — not your name, not a place, not a note, not an excuse. Legal basis: our legitimate interest in improving the app, or your consent where local law requires it.
What we never collect
No location or GPS trace. No health or fitness data from Apple Health, Google Fit, Strava or any wearable. No contacts. No advertising identifier, and no cross-app tracking — we do not ask for App Tracking Transparency permission because we have nothing to track you with.
3. What your partner sees
- your display name and profile picture;
- your side of every pact you share: the activity, the hour, the duration, the place you named, and the routine if you picked one;
- whether you kept it, when you ticked it off, and how long you said it lasted;
- the note you write when a session did not happen, and any note attached to a request to move a day;
- the proof photo you choose to send;
- the stake you laid on them, and the one they laid on you once the pact has played out — a stake set to be hidden is kept hidden by the database itself until then;
- whether your subscription covers the two of you.
Your partner does not see your email address, your password, your device identifiers, your payment details, or the price you paid.
The place is a free text field. Write a neighbourhood or the name of a gym rather than your home address if you would rather not share one — nothing in the app needs it to be precise.
Leaving a duo ends this sharing for everything that comes after it. Pacts you already shared stay in the record of the duo you shared them in, because they were shared by both of you and that record is theirs too.
4. Camera and photos
The app asks for the camera or your photo library only when you choose to send a proof photo or set a profile picture. Refuse, and everything else carries on working.
Proof photos are held in private storage: only the two people in that pact can read them, and the rule is enforced on the server rather than on your phone. Profile pictures are held in public storage so they can be displayed without a signed request — the file name cannot be guessed, but treat a profile picture as something that could be seen outside the app, and choose it accordingly.
Before a photo is sent, your phone resizes and re-encodes it. Whatever metadata the file carried is dropped at that moment and never leaves the device, including the GPS coordinates a camera writes into a picture and the date and model of the phone that took it. What reaches us is the image itself, and nothing that was hidden inside it.
Please do not send photographs of other people without their agreement.
5. Who we share it with
We do not sell data and we share none of it for advertising. We use the following processors, each bound by contract to act only on our instructions:
- Supabase — Hosting, database, sign-in and file storage. European Union (Ireland).
- Expo — Delivering push notifications to your device. United States.
- Apple — App distribution, Sign in with Apple, payments, and push delivery on iOS. United States and European Union.
- Google — Sign in with Google, and app distribution and payments on Android. United States and European Union.
- RevenueCat — Subscription state — whether you are subscribed, and until when. United States.
- PostHog — Product analytics, where enabled. European Union.
Transfers outside the European Union are covered by the European Commission's Standard Contractual Clauses and, for the United States, by our processors' certification under the EU–US Data Privacy Framework where it applies.
We may also disclose data where the law requires it — a court order, or a lawful request from an authority — or where it is necessary to establish, exercise or defend legal claims.
6. How long we keep it
- Your account, and the pacts, notes, stakes and history attached to it: for as long as your account exists, because the record of what the two of you did is the service itself.
- Proof photos: for as long as the pact they belong to, or until you delete them.
- Push tokens: until you sign out on that device, turn notifications off, or the platform rejects the token.
- Technical logs: up to 12 months.
- Accounting records relating to a purchase: 10 years, as French commercial law requires.
You can delete your account yourself, from Settings. It happens straight away rather than within 30 days: the account itself, your name, your profile picture, every photo you sent, your notes, your excuses, your stakes and your push tokens all go at that moment, except for anything we are legally obliged to keep. Pacts that were shared with a partner stay in that partner's own record, with your name taken off them. What is left of you at that point is an identifier attached to nothing, which exists only so those pacts still have two sides. It goes too, along with the pacts themselves, the day your partner closes their account in turn.
7. Your rights
Under the GDPR, at any time you may:
- ask what we hold about you, and get a copy of it;
- have anything inaccurate corrected — your name and picture you can change yourself, in Settings;
- ask for your data to be deleted, or delete your account yourself from Settings;
- ask us to restrict processing, or object to what we do on the basis of a legitimate interest;
- receive your data in a portable format;
- withdraw a consent you gave, with no effect on what was done before you withdrew it.
Write to contact@sweatpotatoes.app from the address on your account, and we will answer within one month.
If you think we have handled your data badly, you can complain to the CNIL (3 place de Fontenoy, 75007 Paris, www.cnil.fr), or to the supervisory authority of the country you live in.
8. Security
Data travels encrypted. On the server, every single read is checked by the database itself against one rule: that the person asking is you, or the partner you chose. Proof photos sit in private storage under the same rule. Passwords are stored hashed, and nobody on our side can read one.
No system is perfect. If a breach ever affects your data and puts you at risk, we will notify the CNIL within 72 hours and tell you where the law requires it.
9. Children
SweatPotatoes is not meant for children. You must be at least 16 to have an account. If we learn that an account belongs to someone younger, we delete it.
10. Changes, and contact
We may update this policy. If a change matters, we will say so in the app or by email before it takes effect, and the date at the top always says when the version you are reading was written.
Thomas Viot, 19 chemin des Mûriers, 66680 Canohès, France — contact@sweatpotatoes.app.