Overview

Klaym is a location-based sports gamification app. We collect only the data necessary to run the service — primarily your fitness activity data from Strava — and we never sell it to third parties.

This Privacy Policy explains what personal data Klaym collects, how it is used, and your rights as a user. By using Klaym, you agree to this policy.

Data We Collect

Account Data

When you register, we collect:

Strava Activity Data

When you connect your Strava account, we receive and store the following for each activity you sync:

We do not collect your Strava athlete profile photo, follower list, kudos, or any social data.

Location & Territory Data

GPS polylines from activities are decoded into H3 hexagonal grid cells. These cells represent geographic areas you have physically covered. The raw GPS track is stored server-side; the derived hex grid data is visible to other Klaym users as part of the territory game.

Manual Activity Entry

You can log activities manually without Strava. For each manually entered activity we store:

Manually entered activities do not contain GPS polyline data and do not claim map hexagons. They are used only to calculate Effort Points.

Apple Health (iOS only)

The iOS app can import workouts directly from Apple Health. If you grant HealthKit access, we read and store:

We request read-only access to HealthKit — we never write to Apple Health. HealthKit access can be revoked at any time in iOS Settings → Health → Data Access. Workouts are deduplicated using a UUID stored locally on your device.

Push Notifications (iOS only)

If you grant notification permission, we store your device's APNs token on our server to send you gameplay notifications (e.g. match day alerts, territory events). You can revoke notification permission at any time in iOS Settings → Klaym → Notifications. Tokens are deleted when you log out.

Home Hex (Private Location Feature)

You may optionally set a "Home Hex" — a single map hexagon representing a location you regularly visit (such as a gym or neighborhood). The following rules apply:

We implement this privacy-by-design approach in compliance with GDPR Article 25 (Data Protection by Design and by Default).

Usage Data

We collect standard server logs including IP addresses, request timestamps, and API endpoints accessed. This data is used for security, rate limiting, and debugging. It is not linked to your public profile.

How We Use Your Data

We do not use your data for advertising, profiling, or any purpose beyond operating Klaym.

Strava Integration

Klaym integrates with Strava via their official API. By connecting your Strava account you authorize Klaym to:

Klaym does not write to your Strava account, post activities, or access payment information.

You can revoke Klaym's access to your Strava account at any time at strava.com/settings/apps. When you do, we stop receiving new activity data. You can also disconnect from within Klaym's profile settings.

Strava's own Privacy Policy applies to data held by Strava: strava.com/legal/privacy.

Data Sharing & Third Parties

What other users can see

The following information is visible to other Klaym users:

Your email address, full GPS tracks, activity timestamps, Apple Health data, push notification token, and your Home Hex designation are never visible to other users.

Infrastructure providers

Klaym uses the following third-party services to operate:

We do not sell, rent, or share your personal data with any other third parties.

Data Retention

We retain your data for as long as your account is active. If you delete your account, your personal data (email, name, activities, territories) will be permanently removed within 30 days.

Server logs are retained for up to 30 days for security purposes, then automatically deleted.

Your Rights

As a user, you have the right to:

If you are in the European Economic Area (EEA), you also have rights under the GDPR. Our legal basis for processing your data is contract performance (providing the Klaym service you signed up for) and legitimate interest (security and abuse prevention).

Security

Klaym uses the following security measures to protect your data:

No system is completely secure. If you discover a security issue, please report it to us at the contact address below.

Cookies & Local Storage

Klaym does not use tracking cookies or advertising cookies. We store the following data in your browser's localStorage:

This data stays on your device and is cleared when you log out.

Children's Privacy

Klaym is not directed at children under the age of 16. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, please contact us and we will delete it promptly.

Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For significant changes, we will notify you via the app. Continued use of Klaym after changes are posted means you accept the updated policy.

Contact

If you have questions about this Privacy Policy or want to exercise your rights, contact us:

Klaym

Vienna, Austria

Email: privacy@klaym.app

App: klaym.app