Privacy policy
Last updated 27 September 2026
SpotKat helps lost cats get home: people photograph cats they see outside, and owners of missing cats get the photos that look like theirs. That only works with some personal data, such as photos and places. This page says what we collect, why, who sees it and how you get rid of it.
Who we are
SpotKat (the app and spotkat.nl) is run by Spartak Kagramanyan, a private person in the Netherlands. We are the controller of your personal data under the GDPR (AVG).
Questions, requests or complaints: [email protected].
What we collect and why
Your account. When you sign in with Apple or Google we receive your email address (with Apple this can be a private relay address), your name and an account ID from that provider. We store the name you choose and your language. We need this to run your account (performance of a contract).
Your cats. Name, photos, description (colours, markings, collar and so on), sex, neutered, age, indoor or outdoor, breed and, if you add one, a microchip number. Only you see the microchip number.
A missing cat report. The place and time your cat was last seen, the area name, how your cat behaves, and your note to spotters. If you want, a phone number and a short note so people can reach you, and whether it may be printed on your poster. We need this to run the search you ask for.
Photos you send of a cat. The photos, the exact place and time you took them, and your note. Your phone removes the hidden photo data (EXIF) before sending.
Your places. If you set up alerts, the places you save (a name and a point on the map) and which alerts you want.
Your location. Only while you use the app, and only after you allow it. We use it to show lost cats near you and to place the photos you send. Your position for the nearby list is not stored; it is stored when you send photos, report a cat or save a place.
Your phone. An install ID and a push token so we can send you notifications, and when the app last checked in.
Points and counts: your points, and how many photos you sent and cats you helped home.
Usage numbers. To see whether SpotKat works, we count on which days an account uses the app, how often lost-cat pages are opened (from a poster QR code, a shared link or the website) and how often posters are made. For page views we store no IP address and no browser details, only a code that changes every day, so nobody can be followed from day to day. When you delete your account, your days of use are no longer linked to you.
Purchases. When you buy a SpotKat Go pass, Apple or Google handles the payment. We and RevenueCat receive your SpotKat account ID and the purchase, never your card details.
Crash reports. When the app or our server fails, Sentry receives the error, device and app details and your account ID, but not your name, email or location.
Safety and abuse. Photos and texts are checked automatically for content that does not belong here. If we ban an account, we keep the sign-in account ID and a one-way hash of the email address to keep it from coming back.
We don't sell your data, don't show ads and don't track you across apps. Our server logs don't store IP addresses.
Who sees what
- Everyone, on the public page of a missing cat and on its poster: the photos, the name, the description, the area and time it was last seen, and the owner's note. Never the exact place, the owner's name or the microchip number.
- Signed-in users who ask: the owner's phone number and note, if the owner added them. Everyone can ask at most five times a day, and we record who asked.
- The owner of a lost cat that your photo may show: your photos, the exact place and time, your note and your first name.
- People near a place they saved: that a cat went missing nearby, with the public details above.
- Nobody else sees your places, your location or your email address.
Automatic checks with AI
When you send photos, Google's Gemini model checks whether there is a cat on them and describes its colours and markings, so we can compare it with lost cats nearby. When you add your own cat, OpenAI's model can draft the description from your photos; you always check it. OpenAI's moderation model checks photos and texts for abuse.
These services only get the photos and texts they need, not your name or email, under API terms that do not let them train their models on it. The matches are suggestions: only the owner decides whether a photo shows their cat.
Services we use
These companies process data for us, each only for their task and under a data processing agreement:
- Hetzner (Germany): our server and database.
- Cloudflare R2 (EU): photo storage.
- Apple and Google: sign-in, push notifications and in-app payments.
- Expo: delivering push notifications.
- Google Gemini and OpenAI: the automatic checks above.
- RevenueCat: tracking your SpotKat Go pass.
- Sentry: crash reports.
- Plausible (EU): visitor counts on spotkat.nl, without cookies and without personal data.
- Apple Maps (iPhone) or Google Maps (Android): the maps in the app.
Some of these companies are based in the United States. Transfers there rely on the EU-US Data Privacy Framework or the European Commission's standard contractual clauses.
How long we keep it
- Photos you send: 30 days, then we delete them with their place and note. A photo an owner marks as the one that brought their cat home stays with that search.
- A search for a missing cat: it runs 30 days or until you mark your cat as home. Your cat and past searches stay in your account until you delete the cat or your account.
- Notifications in your inbox: 7 days.
- Sign-in on a phone: ends after a year without use, or when you sign out.
- Your account: until you delete it. See below.
- A banned account's hashed email and sign-in ID: as long as the ban lasts.
Deleting your account
In the app: Me, then Delete account. Your account, cats, searches and photos disappear from SpotKat at once. For 14 days you can change your mind by signing in again. After that we permanently delete your account and everything in it, photos included. More on the Delete account page: spotkat.nl/en/delete-account
Your rights
You may see, correct, delete or take along your data, and object to or restrict how we use it. Most of it you can do in the app. For the rest, email [email protected]; we answer within a month.
Do you think we handle your data wrongly? Tell us first. You can also complain to the Dutch Data Protection Authority (Autoriteit Persoonsgegevens): autoriteitpersoonsgegevens.nl
Age
SpotKat is for people aged 16 and over. If you are younger, ask a parent to use it with you on their account.
Security
All traffic is encrypted. We store sign-in tokens only as a hash, photos in a private storage bucket and microchip numbers visible only to the owner. Only we have access to the server and the admin tools.
Changes
When we change this policy, the date at the top changes. For big changes we let you know in the app first.