Privacy Policy
Last updated: 2026-04-26
This Privacy Policy explains how personal data is processed when you use the Hang mobile application and related services ("Service").
1. Data Controller
r6lab Radoslaw Jozefowicz
ul. Akacjowa 3
55-003 Krzykow
Poland
EU NIP: PL9730929262
Contact: radek@jozefowicz.dev
2. Personal Data We Process
- Account and purchase data (for premium feature access and subscription status).
- App usage data and device-level technical data (for stability, security, and analytics).
- Session and wellness tracking data that you enter in the app.
- Optional health platform data (for example Apple Health), only if you grant permission.
- Support communications sent by you (for example by email).
3. Purposes and Legal Bases (GDPR Art. 6)
- Service performance (Art. 6(1)(b)): providing core app functionality.
- Legal obligations (Art. 6(1)(c)): accounting, tax, and legal compliance.
- Legitimate interests (Art. 6(1)(f)): security, fraud prevention, diagnostics, and improvements.
- Consent (Art. 6(1)(a)): optional tracking permissions or health data integrations that require consent. You can withdraw consent at any time in app/device settings.
4. Sensitive Data
If health-related data is processed, it is handled only to provide requested features and based on your explicit actions and permissions. Please avoid entering unnecessary sensitive data in free-text fields.
5. Data Recipients
We may share data with trusted processors (for example hosting, analytics, crash reporting, payments, and app distribution providers) only as needed to operate the Service and under appropriate contractual safeguards.
6. International Transfers
Where data is transferred outside the EEA, we apply GDPR-compliant safeguards, such as the European Commission's Standard Contractual Clauses, where required.
7. Data Retention
We retain personal data only as long as necessary for the purposes above, legal obligations, dispute resolution, and enforcement of agreements. Retention periods vary by data category and legal requirement.
8. Your GDPR Rights
- Right of access, rectification, erasure, and restriction.
- Right to data portability.
- Right to object to processing based on legitimate interests.
- Right to withdraw consent at any time (where processing is based on consent).
- Right to lodge a complaint with a competent supervisory authority.
To exercise your rights, contact: radek@jozefowicz.dev
9. Security
We use reasonable technical and organizational measures to protect personal data. No system is fully secure, but we continuously work to protect data against unauthorized access, loss, or misuse.
10. Children
The Service is not intended for children under the age required by applicable law in your country, and we do not knowingly collect personal data from children unlawfully.
11. Cookies and Similar Technologies
If the website or app uses analytics or similar technologies, they are used to operate and improve the Service. Where consent is legally required, such technologies are used only after consent.
12. Changes to This Policy
We may update this Privacy Policy from time to time. The latest version will be available on this page with an updated "Last updated" date.