Legal
Privacy Policy
1. Overview
This Privacy Policy describes how Walka collects, uses, and shares information when you use the Walka mobile application (the “App”). By using the App, you agree to this Policy.
2. Information We Collect
2.1 You Provide
- Account info — email address, password (hashed; we never see your plaintext password), and display name.
- Payment details — handled directly by Stripe; we never receive or store your card number. We retain a Stripe customer ID and the last four digits of cards on file for display.
- Payout details — for prize payouts, you connect a Stripe Connect account. Walka does not see or store your bank account number.
2.2 Health and Activity Data
- Step counts read from Apple HealthKit (iOS) or Google Fit (Android), only with your explicit OS-level permission.
- We collect a daily step total per challenge day, not your full HealthKit history.
- Step data is used solely to determine challenge progress and winners. We do not sell or share it for advertising.
- Apple HealthKit data is subject to additional protections. Per Apple’s policies, HealthKit data may not be used for advertising, sold to third parties, or shared with anyone other than for the primary purpose of operating the App. Walka complies with these restrictions.
2.3 Automatically Collected
- Device and app info — device model, OS version, app version, language, time zone, network type.
- Usage data — screens viewed, actions taken (e.g., joining a challenge), session duration. Used for product analytics and debugging.
- Crash and error data — captured by Sentry when the App encounters errors. Sentry receives: device model, OS version, app version, and the stack trace of the error.
Walka’s Sentry integration is configured to:
- Not attach your email, user ID, or IP address to error events;
- Strip query strings from network breadcrumbs (in case URLs contain auth tokens);
- Strip Authorization and apikey headers from any captured HTTP request data;
- Drop console-log breadcrumbs (which could otherwise contain arbitrary application state).
Sentry does not receive your HealthKit / Google Fit step data, payment card details, or Stripe-side payout details.
2.4 We Do Not Collect
- Location data. Walka does not request the location permission on either iOS or Android, and does not collect, store, or transmit your GPS or approximate location.
- Photos, contacts, microphone, or camera data.
- Step data from outside your challenges. We only sync steps for the date ranges of challenges you have actively joined; your wider HealthKit / Google Fit history stays on your device.
2.5 Push Notifications
Walka does not currently send push notifications. Transactional notifications (challenge start, end, payouts) are delivered by email only. If we add push notifications in the future, the App will request push permission at that time and this Policy will be updated.
3. How We Use Information
We use your information to:
- Create and manage your account.
- Process challenge buy-ins, refunds, and payouts.
- Determine challenge progress and winners.
- Display leaderboards to participants of the same challenge.
- Send transactional notifications (challenge start, end, payout).
- Improve the App and debug issues.
- Detect and prevent fraud or abuse.
- Comply with legal obligations.
4. How We Share Information
We share information only as described below:
| Recipient | Data Shared | Purpose |
|---|---|---|
| Supabase | Account info, step totals, payment records | Database hosting (our infrastructure provider) |
| Stripe | Email, name, payment details | Process buy-ins and payouts |
| Apple / Google | HealthKit / Google Fit requests | Read your step counts (data stays on device until you grant access) |
| Sentry | Device info, stack traces, error context | Error monitoring and debugging |
| Apple TestFlight / App Store / Google Play | App install + crash analytics | Distribution and platform analytics |
| Law enforcement, courts | As legally required | Comply with subpoenas, court orders, or legal process |
We do not sell your personal information. We do not share your information for cross-context behavioral advertising.
4.1 Leaderboard Visibility
Other participants in a challenge you have joined can see your display name and your daily step totals for the days of that challenge. Specifically:
- During the challenge, your daily progress is visible on the challenge leaderboard.
- After the challenge ends, the final standings (rank, days completed, days missed, total steps) remain visible to the same participants indefinitely as part of the challenge history.
- Private challenges are visible only to the creator and people they invite via the private link. People who are not invited cannot see participants, leaderboards, or results, even if they have the challenge ID.
- Solo challenges have no other participants, so no leaderboard visibility applies.
We do not display your step totals, name, or challenge history on any public web page, marketing material, or to non-participants.
5. Data Retention
- Account data is retained while your account is active.
- Challenge results (rankings, payouts) are retained indefinitely for tax and audit purposes.
- Daily step data is retained for the duration of the relevant challenge plus 90 days for dispute resolution and chargeback windows. After that, daily step rows are deleted; only the aggregate totals stored in challenge results remain.
- Payment records are retained per legal and tax requirements (typically 7 years).
- Crash and error events captured by Sentry are retained per Sentry’s default policy (currently 90 days).
5.1 What Happens on Account Deletion
When you delete your account (Section 7), Walka takes the following specific actions:
- Your email and display name are replaced with anonymized placeholder values (e.g.,
deleted-user-<uuid>). - Your Supabase auth user record is deleted.
- Daily step rows for your past challenges are deleted.
- Challenge result rows are retained but with the user fields pointing only to the anonymized placeholder — this preserves the integrity of historical leaderboards for other participants but removes your identifying information.
- Stripe customer and Connect records are retained by Stripe for their own legal/tax retention; we unlink them from your Walka identity. To request Stripe-side deletion, you must also contact Stripe directly.
- Sentry events that may reference your user ID are not automatically purged; you may request deletion via susanadelokiki@gmail.com and we will purge events tied to your user identifier within 30 days.
“Anonymized” in this Policy means that we replace identifiers in our database with values that we cannot reverse-engineer back to you without external data. It is not the same as full deletion of every record; some records (e.g., payment ledgers) must be retained by law.
6. Security
We use industry-standard measures to protect your data, including:
- TLS encryption in transit.
- Encrypted storage at rest (Supabase managed Postgres).
- Authentication tokens stored in iOS Keychain / Android Keystore via Expo SecureStore.
- Stripe handles all payment-card data in a PCI-compliant environment.
No system is perfectly secure. We will notify you of any data breach affecting your information as required by applicable law.
7. Your Rights
Depending on where you live, you may have the following rights:
- Access: request a copy of the personal information we hold.
- Correction: correct inaccurate information.
- Deletion: request deletion of your account and personal data, subject to legal retention requirements.
- Portability: receive your data in a machine-readable format.
- Opt-out: opt out of any future sale or sharing of personal data (we do not sell or share, but you may still register the preference).
To exercise these rights, email susanadelokiki@gmail.com or use the in-app account deletion control under Settings.
California (CCPA/CPRA)
California residents have the rights described above and the right to non-discrimination for exercising those rights. We do not sell or share personal information as defined under CCPA/CPRA.
EEA, UK, and Other GDPR Jurisdictions
Our legal bases for processing are: performance of contract (to operate challenges you’ve joined), legitimate interests (fraud prevention, product improvement), consent (HealthKit permission), and legal obligation (tax/regulatory retention).
You have the right to lodge a complaint with your local data protection authority.
[CONFIRM A DATA TRANSFER MECHANISM IF YOU EXPECT EEA/UK USERS — SCCs OR EQUIVALENT.]
8. Children
The App is not intended for users under 18. We do not knowingly collect data from children. If you believe a child has provided us data, contact susanadelokiki@gmail.com and we will delete it.
9. Third-Party Services
When you connect a Stripe payout account, Stripe’s privacy policy also applies to your use of their service. Walka has no control over how Stripe, Apple, or Google handle your data within their own systems.
10. International Users
Walka is currently available only to residents of the United States. Paid challenges are not offered outside the US. We have not implemented data transfer mechanisms (such as Standard Contractual Clauses) for users in the EEA, UK, or Switzerland, and do not knowingly process personal information from those regions.
If you are located outside the United States, please do not create an account or use the App. If you do, you acknowledge that your information will be transferred to and processed in the United States, where data protection laws may differ from those in your country.
If Walka expands to additional countries in the future, this Policy will be updated and appropriate transfer mechanisms will be put in place.
11. Changes to This Policy
We may update this Policy. Material changes will be notified in-app or by email. Continued use after the effective date constitutes acceptance.
12. Contact
Walka, Inc.535 Mission St
San Francisco, CA, 94105
susanadelokiki@gmail.com