Klaym is a location-based sports gamification app. We collect only the data necessary to run the service — primarily your fitness activity data from Strava — and we never sell it to third parties.
This Privacy Policy explains what personal data Klaym collects, how it is used, and your rights as a user. By using Klaym, you agree to this policy.
When you register, we collect:
When you connect your Strava account, we receive and store the following for each activity you sync:
We do not collect your Strava athlete profile photo, follower list, kudos, or any social data.
GPS polylines from activities are decoded into H3 hexagonal grid cells. These cells represent geographic areas you have physically covered. The raw GPS track is stored server-side; the derived hex grid data is visible to other Klaym users as part of the territory game.
You can log activities manually without Strava. For each manually entered activity we store:
Manually entered activities do not contain GPS polyline data and do not claim map hexagons. They are used only to calculate Effort Points.
The iOS app can import workouts directly from Apple Health. If you grant HealthKit access, we read and store:
We request read-only access to HealthKit — we never write to Apple Health. HealthKit access can be revoked at any time in iOS Settings → Health → Data Access. Workouts are deduplicated using a UUID stored locally on your device.
If you grant notification permission, we store your device's APNs token on our server to send you gameplay notifications (e.g. match day alerts, territory events). You can revoke notification permission at any time in iOS Settings → Klaym → Notifications. Tokens are deleted when you log out.
You may optionally set a "Home Hex" — a single map hexagon representing a location you regularly visit (such as a gym or neighborhood). The following rules apply:
/auth/me endpoint, which is accessible only to you.We implement this privacy-by-design approach in compliance with GDPR Article 25 (Data Protection by Design and by Default).
We collect standard server logs including IP addresses, request timestamps, and API endpoints accessed. This data is used for security, rate limiting, and debugging. It is not linked to your public profile.
We do not use your data for advertising, profiling, or any purpose beyond operating Klaym.
Klaym integrates with Strava via their official API. By connecting your Strava account you authorize Klaym to:
Klaym does not write to your Strava account, post activities, or access payment information.
You can revoke Klaym's access to your Strava account at any time at strava.com/settings/apps. When you do, we stop receiving new activity data. You can also disconnect from within Klaym's profile settings.
Strava's own Privacy Policy applies to data held by Strava: strava.com/legal/privacy.
The following information is visible to other Klaym users:
Your email address, full GPS tracks, activity timestamps, Apple Health data, push notification token, and your Home Hex designation are never visible to other users.
Klaym uses the following third-party services to operate:
We do not sell, rent, or share your personal data with any other third parties.
We retain your data for as long as your account is active. If you delete your account, your personal data (email, name, activities, territories) will be permanently removed within 30 days.
Server logs are retained for up to 30 days for security purposes, then automatically deleted.
As a user, you have the right to:
If you are in the European Economic Area (EEA), you also have rights under the GDPR. Our legal basis for processing your data is contract performance (providing the Klaym service you signed up for) and legitimate interest (security and abuse prevention).
Klaym uses the following security measures to protect your data:
No system is completely secure. If you discover a security issue, please report it to us at the contact address below.
Klaym does not use tracking cookies or advertising cookies. We store the following data in your browser's localStorage:
This data stays on your device and is cleared when you log out.
Klaym is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify you via the app. Continued use of Klaym after changes are posted means you accept the updated policy.
If you have questions about this Privacy Policy or want to exercise your rights, contact us: