Version 2026-09 · Last updated: September 2026
Privacy policy
Draft pending legal review. This text is a first draft written for this product and has not yet been reviewed by a lawyer. Bracketed fields will be completed before launch.
1. Who is responsible
The controller of your data is David Mañas (“RackMates”, “we”). You can write to privacidad@rackmates.app about anything to do with your data.
This policy covers the RackMates app (iOS and Android) and the website rackmates.app. It is deliberately written in plain language: we want you to understand it without a lawyer. If something is unclear, ask us.
2. The idea in one sentence
RackMates needs to know whether you are at your gym, not where you are. Your exact location never leaves your phone. Everything else in this policy follows the same logic: we keep the minimum the app needs and delete it when it is no longer needed.
3. What we process and why
| Data | Purpose | Legal basis | Retention |
|---|---|---|---|
| Account: email, name, handle, photo (optional), language, accepted terms version, sign-up date | Create and keep your account, sign you in, tell you about legal changes | Performance of the contract (art. 6(1)(b) GDPR) | While you have an account |
| Verified email | Prevent fake accounts before creating plans, joining them or messaging someone. We email you a 6-digit code; we store only a hash (HMAC-SHA256) of the code and delete it after 24 hours. We do not ask for your phone number | Legitimate interest in community safety (art. 6(1)(f)) | While you have an account |
| Sign in with Apple or Google | Create the account without a password. We receive an identifier and, if you allow it, your email | Performance of the contract | While you have an account |
| Training profile: level, training types, availability, bio, favourite gyms | Show you to your people and suggest people who match your schedule, type and level | Performance of the contract | While you have an account or until you delete it |
| Presence (“inside” / “outside”) | Count how many RackMates people are at a place and show your circle that you are inside. The distance check runs on your phone; the server only receives “inside” or “outside”, never coordinates. If you enable automatic check-in, the geofence is also evaluated on the phone | Performance of the contract | Detailed entries and exits: 90 days. After that we keep only hourly aggregates that do not identify you |
| Plans, participations and messages (plan, group and direct chats) | So you can meet and talk with your people | Performance of the contract | While you have an account. Plan chats are hidden 24 h after the plan and deleted after 90 days |
| Circle, blocks, reports | Connect you with whom you choose, hide people you block, moderate the community | Performance of the contract; legitimate interest in safety | Blocks: while you keep them. Reports: 12 months after resolution |
| Workouts, routines, records, challenges | Your workout log. Stored on your phone and synced when online | Performance of the contract | While you have an account |
| Health data (optional) | Only if you enable “Save to Apple Health / Health Connect”: we write your finished workouts to that app. We do not read health data or upload it to our servers | Explicit consent (art. 9(2)(a)) | Lives on your device; you control it from Health / Health Connect |
| Push notifications: device token | Notify you about plans, messages and requests | Performance of the contract | Until you sign out or delete the app |
| Purchases: RevenueCat identifier, product, dates | Know whether you are Pro or have Boost credits. We never see your card: you pay Apple or Google | Performance of the contract | While you have an account and as long as tax law requires |
| Technical data: IP address, app and OS version, error logs | Keep the app working, limit abuse (per-IP limits) and fix bugs | Legitimate interest | Server logs: 30 days. Errors in Sentry: 90 days |
| App usage (optional) | Only if you enable “Help improve RackMates” in Me → Privacy: anonymous usage events in PostHog (EU servers). Off by default | Consent (art. 6(1)(a)) | 12 months |
| Website waiting list: email and language | Tell you once when the app launches | Consent | Until the launch notice or until you ask us to delete it |
| Gym claims: contact name, role, email, message | Verify that whoever claims a page represents the gym | Legitimate interest / pre-contractual steps | 12 months after resolution |
We make no automated decisions with legal effects on you. The “affinity” you see with other people is a simple sum of overlaps in schedule, training type and level; it does not build a profile and is not used for anything else.
4. What we do not do
- We do not store your exact location or your movement history.
- We do not sell or share your data with third parties for advertising. There are no ads.
- We do not read your health data.
- We use no cookies and no analytics on the website.
- We never present the “inside now” number as the gym’s occupancy: it only counts people who checked in on RackMates.
5. Who else sees your data
Other RackMates people
- Your name, handle, photo, level, training types, bio, schedule and reliability are visible to people who share a gym with you and to anyone who opens your public profile (
rackmates.app/u/your-handle, which only shows name, handle and photo). - Your presence (“inside”) is seen by your circle and appears in the gym’s “inside now” samples. With invisible mode you still add to the number but appear in no list.
- Open plans are seen by people at the gym; heads-ups to your circle, only by your circle.
- Someone you block stops seeing you, and you them.
Processors
We use these providers, under data-processing agreements and, when outside the EU, under the European Commission’s standard contractual clauses or other Chapter V GDPR safeguards:
| Provider | What it does | Where |
|---|---|---|
| Hetzner Online | API server, database and backups (encrypted in transit) | Germany (European Union) |
| Cloudflare | Website, DNS, contact email forwarding and storage of photos and backups (R2) | European Union for stored data; global network to serve the website (standard contractual clauses) |
| Resend | Sends emails (verification code, password recovery, legal notices) | USA (standard contractual clauses) |
| Expo (EAS) | Delivers push notifications to Apple and Google | USA (standard contractual clauses). Only receives the device token and the notice text |
| RevenueCat | Manages subscriptions and purchases | USA (standard contractual clauses). Receives a user identifier and store receipts |
| Sentry | Error logging for the app and the API | European Union |
| PostHog | App usage analytics, only if you enable it | European Union |
| Apple and Google | Stores, payments, sign-in and notifications | Under their own policies; they act as independent controllers |
There are no other recipients, except where the law requires it (for example, a court order).
6. Where it is stored
Application data is hosted in the European Union. Some providers above are in the USA and receive specific data (an email while it is sent, a notification token). In those cases we apply the standard contractual clauses and, where the provider is certified, the EU-US Data Privacy Framework.
7. Your rights
You can exercise at any time your rights of access, rectification, erasure, restriction, portability and objection, and withdraw any consent you gave without affecting what came before.
Most of them are inside the app, without writing to anyone:
- Download your data: Me → Privacy → Download my data (a JSON with everything we hold about you).
- Delete your account: Me → Privacy → Delete account. Everything is deleted immediately; it disappears from backups within 30 days at most.
- Correct your profile: Me → Edit profile.
- Invisible mode, blocks, optional analytics, Apple Health / Health Connect: Me → Privacy.
For the rest, write to privacidad@rackmates.app. We reply within a month at most. If you are not satisfied, you can complain to the Spanish Data Protection Agency (aepd.es) or your local supervisory authority.
8. Minors
RackMates is for people aged 16 or over. We ask when you sign up and, if we detect an account belonging to someone younger, we delete it. If you think a minor is using RackMates, write to us.
9. Security
Communications are encrypted (TLS). Passwords are stored hashed (Argon2) and verification codes only as a hash. Access to production data is limited to the team members who need it and is logged. If we suffered a breach affecting you, we would tell you and notify the authority within the legal deadlines.
10. Changes
If we change anything relevant in this policy, we will tell you in the app before it takes effect and ask you to accept the new version. The version number (above) lets you know which text you accepted.