Privacy policy
RACK is a strength and running training app. This policy explains what we collect, why we collect it, who we share it with, and the rights you have over your information.
Who we are
RACK is operated by Skye Digital Ltd, registered in England and Wales (company number 17207998), with its registered office at Flat 68 Hudson House, Station Approach, Epsom, KT19 8DL. In this policy, "we", "us" and "our" refer to that entity. We are the data controller for personal data processed through the RACK app and this website.
You can contact us at privacy@joinrack.app about anything in this policy.
What we collect
Beta and Android waitlist
The beta link on this site sends you to Apple's beta install flow, which Apple handles under its own terms and privacy notices.
If you join the Android waitlist, we collect the email address you submit and the time you submitted it. We use it only to send you a notification when RACK is ready for Android, plus any essential follow-up about that notice — not a general marketing newsletter. Supabase stores the waitlist for us in its hosted Postgres service. To limit automated abuse, we also keep a salted, one-way hash of the request's network address for roughly 24 hours. An hourly cleanup deletes hashes once they are more than 24 hours old; we do not store the raw address in the waitlist.
RACK Journal newsletter
If you ask to join the RACK Journal, we collect the email address you submit, the time of the request and confirmation, and the current consent wording version. We send a confirmation link first and do not add the address to the Journal audience until that link is used. Confirmation links expire after 24 hours. As with the Android waitlist, a salted, one-way hash of the request's network address is retained for roughly 24 hours to limit automated abuse; the raw address is not stored.
Resend delivers the confirmation and new Journal pieces for us. Every Journal email identifies RACK and includes a one-click unsubscribe link. Resend keeps the suppression needed to prevent further marketing email after an unsubscribe. You can also withdraw consent by emailing privacy@joinrack.app.
Account information
When you create an account we collect the email address (and, where you provide one, name) you sign up with. If you use Sign in with Apple, we receive the identifier and email relay address that Apple supplies — we do not see your underlying Apple ID.
Training data
Sessions you log — exercises, sets, reps, weights, RPE, notes, body-weight entries, programme progress — are stored against your account so you can retrieve them on any device you sign in on.
Social features
If you use RACK's social features, we also process:
- Your connections — the friend requests you send and accept, and the people you block.
- Content you share — posts you publish to your feed, their captions, any photo you choose to attach to a cardio post, and the workouts or cardio sessions you share. Your profile — display name, avatar, and training stats — is visible to people you connect with and others who view it in the app.
- Interactions — likes and similar reactions to other people's posts, and any report you submit about another user.
- Notifications — if you allow them, we register a device push token so we can notify you about friend requests and activity on your posts. You can turn notifications off at any time in iOS Settings.
- Planning a session nearby — when you choose to plan a workout together, RACK uses your local network (and, if you scan a pairing code, your camera) to connect directly with a nearby friend. Your name, profile, and the exercises you plan are shared with the friend you pair with. RACK does not collect GPS location, and the camera is used only to read the pairing code — nothing is recorded or stored.
Purchase information
Subscriptions and one-off purchases are processed by Apple through the App Store. We receive a transaction identifier and entitlement state so we can unlock features — we do not see your card details, billing address, or full Apple ID.
Usage information
We collect information about how the app and this website are used — pages and screens viewed, taps, approximate region inferred from IP, device type, app version. In the app this may include masked session replays: anything you type and any images are obscured before a recording leaves your device. App usage is linked to a random account identifier rather than your name or email, and is analysed in aggregate to understand where people get stuck.
Support correspondence
If you email us, we keep your message and our reply so we can follow up and improve the product.
Apple Health (opt-in)
RACK's use of Apple Health is opt-in and limited to workouts — we do not read your broader Health history.
- Writing strength workouts. If you enable Apple Health recording, RACK writes completed strength workout summaries to Apple Health. You do not need a separate Apple Workout session — when recording is enabled, RACK's own session is written for you.
- Importing cardio workouts. If you enable cardio import, RACK reads outdoor cardio workouts you logged in Apple's Workout app (or a connected device) — duration, distance, pace, and, where recorded, the GPS route. This data is stored in RACK so it can sync across your devices, appear in your training history, and, if you choose to share that session, be shown to people you share it with (including the route on a map).
- No heart-rate/calorie copy in RACK. Apple Watch heart-rate and active calorie samples are not stored in RACK or Supabase.
Why we use it
- To provide the service — your account, your training history, your subscription entitlements.
- To run RACK's social features — showing your posts and profile to the people you share them with, delivering friend requests and notifications, and keeping the community safe through reporting and blocking.
- To support you — answering questions, investigating bugs, recovering data on request.
- To notify Android waitlist members — sending the Android availability notice they requested.
- To send the RACK Journal — after double opt-in, sending newly published Journal pieces and recording delivery so an issue is not repeated.
- To improve the product — understanding which features get used, where people get stuck, what to build next.
- To prevent abuse — detecting fraud, automated sign-ups, and breaches of our terms.
- To meet our legal obligations — tax, accounting, and responding to lawful requests.
Legal bases
Under UK GDPR we rely on the following legal bases:
- Contract — to deliver the service you signed up for.
- Legitimate interests — to keep the service secure, prevent abuse, and improve it. We balance these against your interests and rights.
- Consent — for the Android launch notification, the RACK Journal and non-essential analytics cookies on this website. You can leave the Android waitlist by emailing us, unsubscribe from the Journal through any issue, and withdraw analytics consent by clearing site data or declining the banner.
- Legal obligation — where the law requires us to retain or disclose information.
Who we share it with
We do not sell your personal information. Some information is visible to other people by design when you use RACK's social features; beyond that, we share your information only with the processors and counterparties we need to run the service:
- Other users — content you choose to share (feed posts, captions and photos, your profile, and shared workouts) is visible to the people you share it with. When you plan a session nearby, your name, profile, and planned exercises are exchanged directly with the friend you pair with over the local network.
- Supabase Inc. — hosted Postgres database and authentication for the app, including storage of Android waitlist and Journal opt-in records and the delivery log.
- Resend, Inc. — confirmation-email and RACK Journal delivery, audience management and unsubscribe suppression.
- Apple Inc. — App Store distribution, Sign in with Apple, in-app purchase processing.
- Google LLC — anonymised website analytics (only loaded after you accept the consent banner).
- PostHog, Inc. — in-app usage analytics and masked session replay, hosted in the EU.
- Professional advisers — accountants, auditors, and lawyers, where reasonably required.
- Authorities — where compelled by law or to protect our rights or those of others.
International transfers
Some of our processors are based outside the UK. Where personal data is transferred outside the UK or EEA, we rely on the UK Government's adequacy regulations, the UK International Data Transfer Agreement, or Standard Contractual Clauses with the UK Addendum, as appropriate.
How long we keep it
We keep account and training data for as long as you have an active account. If you delete your account we delete or anonymise associated personal data within 30 days, except where we are required to retain it for legal, accounting, or fraud-prevention reasons. Anonymous, aggregated statistics may be retained indefinitely.
We keep an Android waitlist email until we send the Android availability notice, you ask us to remove it, or 24 months pass without an Android launch — whichever happens first. We delete it within 30 days after that point. Email privacy@joinrack.app from the address you submitted to leave the waitlist. We have not selected a separate launch-email delivery provider; if we appoint one before sending the notice, we will update this policy to name that processor first.
Unconfirmed Journal requests expire after 24 hours. We keep a confirmed Journal subscription while you remain subscribed. If you unsubscribe, we stop marketing email and retain the minimum suppression record needed to honour that choice. You can request deletion of the underlying opt-in record by emailing privacy@joinrack.app.
Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- correct inaccurate personal data;
- request that we delete your personal data;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent where we rely on it; and
- complain to the UK Information Commissioner's Office at ico.org.uk.
To exercise any of these rights, email support@joinrack.app. We aim to respond within one month.
Cookies and similar technologies
This website uses a small number of cookies and similar storage:
- Essential — to remember your consent preference. These do not require consent.
- Analytics — set only after you accept the consent banner. Used to understand aggregate site usage.
You can decline analytics cookies at any time by clearing site data in your browser, which will surface the consent banner again.
Children
RACK is not directed at children under 13, and we do not knowingly collect personal data from anyone under that age. If you believe a child has provided us with personal data, please contact us and we will delete it.
Security
We use industry-standard measures — encryption in transit, hashed credentials, access controls, and audit logging — to protect your information. No system is perfectly secure; if we ever become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.
Changes to this policy
We may update this policy from time to time. When we make material changes we will update the "last updated" date at the top of this page and, where appropriate, notify you in the app or by email.
Contact
Questions, requests, or complaints? Email privacy@joinrack.app or write to us at Flat 68 Hudson House, Station Approach, Epsom, KT19 8DL.