Privacy Policy
Last updated: 27 June 2026 · App-owned editable content maintained by the SpokeWatch project.
1. Who we are
SpokeWatch is a research and prevention prototype that maps reported bicycle thefts, sightings and related incidents in and around Adelaide, South Australia. The project is run by an independent researcher and community contributor, not by South Australia Police or any government agency. References to legislation in this policy are provided as a transparency standard, not as legal advice.
2. What we collect
Incident reports. When you submit a stolen or spotted bike, we collect the details you provide: bike make, model, colour, frame number (optional), approximate location, date and time, a short description, and any photos you choose to attach.
Account information. If you create an account to manage your reports, we collect the email address you sign up with and a securely hashed password (or, where you use a third-party provider, an account identifier from that provider). We do not see your password. Your email address is stored by Supabase (our authentication and database provider) and is used to send you transactional emails (e.g. sign-in links, recovery claim updates). These emails are delivered via Lovable's email infrastructure. An internal send log records your email address, the template name, and the send status for each message; this log is used for delivery auditing and suppression (bounce/unsubscribe handling) only.
Technical data. Standard server logs (IP address, user-agent, request path, timestamp) are retained briefly for security, abuse prevention and debugging. We do not use third-party advertising or behavioural-tracking cookies.
What we deliberately don't ask for. Please do not submit your home address, full legal name, phone number, registration plate, driver licence details or other sensitive personal information in report descriptions. If you do, we may redact it before publication.
3. How we use information
- Display incidents publicly on the map and analytics dashboards so cyclists can make informed decisions.
- Allow you to manage, edit, claim and resolve reports you create.
- Detect spam, fraud, abuse and other policy violations.
- Produce aggregated, de-identified insights about theft patterns for community awareness and research.
- Communicate operational updates about your reports (e.g. when a bike you claimed is marked spotted).
4. AI-assisted features
SpokeWatch currently includes an optional AI-powered bike-matching feature that suggests possible stolen-bike matches when a community member reports an abandoned or spotted bike. When this feature runs, a subset of report data (bike description, brand, colour, suburb, date and any standout features you entered) is sent to the Lovable AI gateway (ai.gateway.lovable.dev), which routes the request to a third-party large-language model for comparison. No photos, exact coordinates, serial numbers or account identifiers are included in this request.
Training data. We do not knowingly authorise the use of your data for AI model training via this gateway. If Lovable's terms permit such use and you object, you may contact us to opt out of AI matching for your reports.
Feature availability. This AI feature may be removed or replaced in future versions of SpokeWatch. If it is removed, this section will be updated or deleted accordingly. Check the "Last updated" date above for the current status of this policy.
5. Location data
Map coordinates attached to incident reports are intentionally fuzzed to a coarse neighbourhood-level point before being shown publicly. The exact pin you set is retained server-side only to support potential de-identified analysis and any future, consented authority-facing exports. We do not continuously track your device location.
6. Sharing
Public report content (bike description, fuzzed location, photos, status) is visible to anyone who visits the site — that is the point of the community map. Beyond that, we do not sell personal information. We share data with third parties only in these limited cases:
- Supabase — database, authentication and file storage. Stores your email address, account record, bike registry, incident data and the email send log. Supabase is hosted on AWS infrastructure and governed by Supabase's Data Processing Agreement.
- Lovable — application hosting and email delivery infrastructure. Your email address is passed to Lovable's email system to deliver transactional messages. Lovable does not receive your password or payment details.
- The Lovable AI gateway, solely to run the optional bike-matching feature described in section 4 above. This applies only when the feature is active; see section 4 for details and opt-out.
- Law enforcement where we are legally compelled or where you have explicitly asked us to assist with a case relating to your own bike.
- Successors in the event the project is transferred to another operator, with notice posted on this page.
7. Retention
Public incident records are retained indefinitely so the historical map remains useful, unless you ask us to remove a specific report you submitted. Account records are retained for as long as your account is active, and removed within a reasonable period after deletion. Server logs are typically rotated within 30 days.
Email data. Your email address is held in Supabase's authentication system for the lifetime of your account. The internal email send log (which records your address alongside the template name and delivery status for each message sent to you) is retained as part of your account record and removed when your account is deleted. We do not retain email addresses for marketing purposes after account deletion.
Account deletion. To delete your account and associated personal data (including email address, bike registry, and email send log), contact us via the About page. We will process the deletion within a reasonable period and confirm when complete. Note that public incident reports you submitted may be anonymised rather than deleted, as they form part of the community safety record.
8. Security
Data is stored on managed cloud infrastructure with encryption in transit (HTTPS) and at rest. Access controls restrict the underlying database to authenticated, role-based queries. No online service can be guaranteed 100% secure; please use a unique, strong password and notify us promptly if you believe your account has been compromised.
9. Your rights
Consistent with the Australian Privacy Act 1988 and the 13 Australian Privacy Principles, you have the right to:
- Access — request a copy of the personal information we hold about you (email address, account record, bike registry entries, email send log).
- Correction — ask us to correct inaccurate personal information.
- Deletion — ask us to delete your account and associated personal data. See section 7 for details on what is removed and what may be anonymised. Supabase and Lovable retain data as processors; deletion requests we action with them will be reflected in their systems within the timeframes they commit to in their own DPAs.
- Opt-out of AI matching — ask us to exclude your reports from the AI bike-matching feature (see section 4).
Contact us via the About page and we will respond within a reasonable timeframe.
10. Children
SpokeWatch is not directed at children under 13. If you believe a child has provided personal information, contact us and we will remove it.
11. Changes
We may update this policy as the project evolves. Material changes will be reflected in the "Last updated" date at the top of this page.
12. Contact
Privacy questions, access requests or takedown requests can be sent via the contact details on the About page.
