Privacy Policy
Last updated: 14 July 2026
This Privacy Policy explains how Hamkke ("Hamkke", "we", "us") collects, uses, shares, and protects your personal information when you use the Hamkke mobile app, the website at hamkke.fit, and related services (together, the "Service"). Hamkke is operated by [LEGAL ENTITY / OPERATOR NAME], a company registered in Ireland (registered office: [BUSINESS ADDRESS]), which is the data controller responsible for your personal information.
1. Who this applies to
This policy applies to everyone who visits our website or uses the Hamkke app. Hamkke is intended only for adults aged 18 and over (see Section 10).
2. Information we collect
a. Account and identity information
- Account details you provide at sign-up: your name, email address, password (stored only as a salted hash — we never store your plaintext password), and date of birth (we use this to confirm you are 18+ and to show your age).
- Email verification: we email you a temporary 6-digit code to confirm you own your email address. We store only a hashed form of the code, with an expiry.
b. Identity verification information (optional)
Identity verification is optional. It is not required to browse the member directory ("Discover") or to use the app — any signed-in member can browse Discover. If you choose to verify, you provide your legal name, date of birth, the type of government ID you hold, and your consent; in return your profile receives a "verified" trust badge. The badge is the only thing verification unlocks.
c. Profile and fitness data
- Your training profile: tagline, gym name and building, goals, years training, experience tier, and your key lifts (e.g. squat, bench, deadlift).
- Optional body metrics: bodyweight and height, and your preferred units (kg/lb, cm/in).
- Your matching preferences (the roles and range you are open to).
d. Workout and activity logs
The exercises, sets (weights and reps), dates, and session durations you log. Logging works offline: entries are kept on your device and synced to our servers when you are online.
e. Social and matching data
Training sessions you book with other lifters (the other person's name, the time, location, and any note you add) and connection/booking requests you send.
f. Information from services you choose to connect
- Google Sign-In: if you sign in with Google, Google sends us a signed token from which we receive your Google account email, name, and account identifier (and, if available, your profile picture). We use this only to create or access your Hamkke account. Your use of Google Sign-In is also subject to Google's privacy policy.
- Apple Health / Google Health Connect (optional): if you choose to connect a health app, the app may read body metrics you authorise (such as bodyweight and height) to pre-fill your profile. This data is read with your permission and is not shared with third parties.
- Spotify (optional): if you choose to link Spotify, the app controls and displays your playback (current track, play/pause) during a workout. We do not store your listening history.
These integrations are off until you turn them on, and you can disconnect them at any time in your device or app settings.
g. Device and technical information
When you use the app or our servers respond to your requests, we automatically process limited technical data needed to run and secure the Service — for example your device's locale, app version, and standard server request logs (such as IP address, timestamp, and the endpoint called) used for security, rate-limiting, and debugging. We do not use third-party analytics, advertising, or tracking SDKs in the app.
h. The website (hamkke.fit)
Our marketing website does not run analytics or advertising cookies and does not collect your information on a server. The "early access" form simply opens your own email app with a pre-filled message to us — your email address is only shared with us if you choose to send that message. Fonts and other assets are served from our own domain rather than third-party content delivery networks, so simply viewing the website does not share your IP address with outside font, analytics, or advertising providers.
3. How we use your information
- To create and operate your account and provide the app's features (matching, profiles, workout logging, sessions).
- To verify your email and confirm eligibility (18+).
- To keep the Service secure — preventing abuse, fraud, and unauthorised access (e.g. rate-limiting and access control).
- To communicate with you about the Service, including service messages and, where you have asked to hear from us, product updates. You can opt out of non-essential messages at any time.
- To comply with legal obligations and enforce our terms.
4. Legal bases (for EEA/UK users)
Where the EU/UK GDPR applies, we rely on: performance of a contract (to provide the Service you signed up for); your consent (e.g. connecting a health app or Spotify, and marketing emails); legitimate interests (keeping the Service secure and improving it); and legal obligation (where we must keep or disclose data by law). Some details you choose to give us — such as your bodyweight, height, and information about your training — may be treated as health-related (special category) data; where that is the case we process it only with your explicit consent, which you can withdraw at any time without affecting your ability to use the rest of the Service.
5. How we share your information
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We share information only:
- With other members, as you direct — Hamkke has a member directory ("Discover"). What another member can see about you depends on your relationship to them and on your profile's visibility setting:
- Members who are not your accepted connections see only a limited ("coarse") card: your display name, your experience tier, the tagline you write, your gym's name, and your "verified" badge if you have one.
- Your sensitive training details — your lifts (strength numbers), your training goals, and your precise building/location — are shared only with members you have accepted as mutual connections.
- Your bodyweight, height, email address, and date of birth are never shown to other members at all.
- Discovery is public by default, but you control it: if you set your profile to private, non-connections see only a minimal locked card.
- With service providers (sub-processors) who run parts of the Service on our behalf, under contract and only as needed:
| Provider | Purpose |
|---|---|
| Railway | Application hosting and the PostgreSQL database |
| Google (Sign-In / Identity) | Optional "Sign in with Google" authentication |
| Resend / SMTP email provider | Sending verification and account emails |
| Apple App Store & Google Play | App distribution (and any future in-app purchases) |
| Expo / EAS | Building and delivering the app |
- For legal reasons — to comply with the law, respond to lawful requests, or protect the rights, safety, and property of Hamkke, our members, or the public.
- In a business transfer — if Hamkke is involved in a merger, acquisition, or sale of assets, information may be transferred as part of that transaction (you will be notified).
6. Data retention
We keep your account information for as long as your account is active. If you deactivate your account it becomes dormant and your data is preserved until you sign back in. If you delete your account, we permanently remove your account and the data we hold for it (profile, workouts, sessions, requests, and verification records). Backups and legally required records may persist for a limited period before being overwritten.
Cloud workout history and your plan
Your cloud workout history is retained according to your subscription plan's retention window:
- Free — the most recent 3 months of history.
- Plus — the most recent 1 year of history.
- Pro — unlimited history.
If a paid subscription ends, is cancelled, or its payment is not renewed, your account reverts to the Free plan and its 3-month retention window. Any cloud workout history older than your current plan's window is first hidden from the app, and then — after a short grace period — permanently deleted, with the oldest entries removed first (a "first-in, first-out" basis). In practice this means that if a subscription remains unpaid so that only the Free window applies, training entries older than 3 months are progressively and permanently erased, oldest first. You can stop and reverse this at any time before deletion by upgrading again, which immediately restores access to the still-hidden history; entries already permanently deleted cannot be recovered. This retention rule applies only to cloud history — data stored locally on your own device is governed by your device and the app's local settings.
7. Your rights and choices
Depending on where you live (including under the EU/UK GDPR and the California CCPA/CPRA), you may have the right to access, correct, delete, port, or restrict the processing of your personal information, to object to certain processing, and to withdraw consent. You can exercise the core of these directly in the app:
- Access & correct: view and edit your profile and data in the app.
- Delete: permanently delete your account and its data from the app's settings.
- Deactivate: make your account dormant without deleting it.
- Marketing: opt out of non-essential emails at any time.
For any request, or to ask for a copy of your data, contact us at the address below. We will not discriminate against you for exercising your rights. If you are in the EEA, you also have the right to lodge a complaint with a supervisory authority — in Ireland, the Data Protection Commission (dataprotection.ie). If you are in the United Kingdom, you may lodge a complaint with the Information Commissioner's Office (ico.org.uk). Members in South Korea should also see Section 11.
8. Security
We protect your information with measures including encrypted connections (TLS), hashed passwords, token-based authentication, per-user access controls so members can only reach their own data, and rate-limiting. No system is perfectly secure, but we work to safeguard your information and to limit what we collect in the first place.
9. International data transfers
We are based in Ireland, and we and our service providers may store and process your information in the European Union for our application hosting and database (Railway). Some of our other service providers — such as Google Sign-In, our email provider, the app stores, and Expo/EAS — may store or process limited information in the United States or other countries whose data-protection laws may differ from yours. Where personal information is transferred outside the EEA, we use appropriate safeguards — such as the European Commission's Standard Contractual Clauses — for these transfers. For members in the United Kingdom, where personal information is transferred outside the UK we rely on the UK's equivalent safeguards, such as the UK International Data Transfer Agreement (IDTA) or the UK Addendum to the Standard Contractual Clauses. If you are in South Korea, see Section 11 for the specific details of how your data is transferred overseas.
10. Age and children
Hamkke is for adults 18 and over. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a minor has provided us information, contact us and we will delete it.
11. Information for users in South Korea
If you are in the Republic of Korea, the Personal Information Protection Act ("PIPA") gives you additional rights and requires us to tell you certain things. This section supplements the rest of this policy.
Consent
We ask for your consent separately for each purpose at sign-up — including, where applicable, the collection of sensitive information (such as health-related body and training data), the provision of information to third parties, the transfer of your information overseas, and marketing messages. You may decline optional consents and still use the core of the Service, and you may withdraw any consent at any time.
Cross-border transfer of personal information
To provide the Service, we transfer your personal information outside Korea:
- Items transferred: the account, profile, fitness/training, and usage data described in Section 2.
- Recipient & country: Railway (application hosting and database) in the European Union, together with the other service providers listed in Section 5 (some of which — such as Google, our email provider, the app stores, and Expo/EAS — are in the United States).
- Purpose & retention: to operate, secure, and provide the Service, retained for the periods described in Section 6.
Where PIPA requires it, we obtain your consent to this overseas transfer.
Your PIPA rights
You may request access to, correction or deletion of, or suspension of the processing of your personal information, and withdraw consent, using the in-app tools or the contacts below.
Privacy officer and Korean representative
Privacy Officer (개인정보 보호책임자): [NAME / TITLE], privacy@hamkke.fit. Where required, our domestic representative in Korea is [KOREAN DOMESTIC REPRESENTATIVE — NAME, ADDRESS, CONTACT]. You may also report concerns to the Personal Information Protection Commission (PIPC) or the Korea Internet & Security Agency (KISA) Privacy Call Center (118).
12. Changes to this policy
We may update this policy as the Service evolves. We will change the "Last updated" date above and, for material changes, provide a more prominent notice. Your continued use of the Service after an update means you accept the revised policy.
13. Contact us
Questions or privacy requests: privacy@hamkke.fit. Postal: [BUSINESS ADDRESS].
See also our Terms and Copyright & IP Policy.