Hackysack Privacy Policy
Last updated: October 1, 2026
Hackysack is a small, open source app for checking in at places and sharing them with friends. This page explains what it collects and what happens to it. The code is public at https://github.com/samgro/hackysack, so you can check any of it.
The short version
- Your data is yours. You can export all of it, or delete your account, from the app at any time.
- We don't sell data or show ads, and nothing in the app tracks you for advertising.
- Only the people you choose see your checkins: your friends, or just you.
- We don't look at your checkins or location unless you ask us to, for example to help debug a problem, or someone reports something you posted.
What we store
- Account: your Apple account ID, plus the name and email Apple shares when you sign in (this can be a private relay address). We also keep an encrypted token from Apple, used only to disconnect Hackysack from your Apple ID when you delete your account.
- Profile: name, bio, hometown and profile photo.
- Checkins: the place, the time, your message, photos, the friends you tagged, and whether it's for friends or just you. We save the place's location, not your phone's GPS reading.
- Friends and activity: friends, friend requests, likes, comments and notifications.
- Places you add: name, address, location, and an optional website and phone number.
- Reports and blocks: who you've blocked, and what you report: which checkin, comment or person, why, your note, and a copy of what was reported as it was then.
- Sign-in: a scrambled copy of your sign-in token and the app and iOS version your phone reports, so you stay signed in. We don't store your IP address.
- Swarm import (only if you connect it): your Swarm checkins and photos, including what Swarm sends about each one, which can name friends you were with there. Checkins you kept private in Swarm are left out unless you turn on Include private Swarm checkins, and then only you can see them; the rest are shared with your friends. We also keep an encrypted Swarm access token, and delete it when you disconnect.
What stays on your phone
If you allow Always location, iOS tells Hackysack when you arrive somewhere and when you leave. The app keeps these visits on your phone for 90 days and uses them to suggest checkins and to recognize places like home and work. It also remembers the places you've told it to stop suggesting, so they stay dismissed.
To suggest a place, the app sends the visit's location to our server. The server replies with nearby places and doesn't save the location. Nothing becomes a checkin, and no friend sees anything, until you accept a suggestion. Deleting the app or your account erases this history, and signing out offers to.
Who can see what
- Your friends: checkins you share with friends, with their photos, tags, likes and comments.
- Just you: checkins you mark private.
- Anyone signed in to Hackysack: your name, bio, hometown, profile photo, when you joined, and how many friends and shared checkins you have. That's how friends find you.
- If a friend tags you, the people who can see their checkin see your name and photo.
- Nobody you've blocked, or who has blocked you: someone you block can't find you or see your profile, and neither of you sees the other's checkins, comments or tags. You can still find them, to unblock them.
- Photos on checkins are only sent to people who can see that checkin. (Photos imported from Swarm that we couldn't copy are still linked from Foursquare's servers.)
Services we use
- Railway runs our server, Neon hosts our database, and Cloudflare R2 stores photos. They hold data for us and don't use it for anything else.
- Apple: Sign in with Apple. Apple Maps draws maps, searches the city names you type, and turns your current location into a city name when you set your hometown. TestFlight sends us crash reports and any feedback you submit.
- Sentry receives crash and error reports from the app and our server: what went wrong, what the app was doing just before (which screens were open and which requests it made, without their contents), the app version, your device model, iOS version and language, and a random account ID. It also counts app sessions (when the app was opened, for how long, and whether it crashed, under a random ID for your install) so we can tell how often each version crashes. It never receives your name, email, location, messages, photos or IP address. Reports are deleted after 30 days. When you report a checkin, comment or person, Sentry tells us a report arrived, never what it says.
- Foursquare, only if you import from Swarm.
- Place data comes from Overture Maps, an open dataset we keep a copy of. Your searches never go to a third party. When you search somewhere new, our server downloads public place data for that area, and nothing about you is sent.
Logs
Our server logs record which requests happened and whether they failed, with a random account ID. They never include your name, email, location or messages.
Who looks at your data
Hackysack is run by one person. We can technically read the database, but we won't look at your checkins or location history unless you ask us to, to debug a problem, or someone reports them. Otherwise we only look at totals, like how many checkins were made each day.
When someone reports a checkin, comment or person, we read what was reported and the note that came with it, within 24 hours, and remove anything that breaks the community guidelines.
Your controls
- Export: Settings → Export My Data gives you a zip with everything above, plus your photos and the visit history stored on your phone. Crash reports aren't included: they're diagnostics, not your data.
- Edit or delete any checkin at any time.
- Report a checkin, comment or person that breaks the community guidelines. It disappears for you straight away, and nobody is told who reported it.
- Block anyone from their profile or from one of their checkins. Settings → Blocked Users lists them and lets you unblock.
- Delete your account: Settings → Delete Account. This immediately removes your profile, checkins, photos, comments, likes, friendships, blocks, reports, sign-ins and Swarm connection. Private places you added are deleted too, unless a friend has checked in there. Public places you added stay, without your name. It also disconnects Hackysack from your Apple ID, so it no longer appears under Sign in with Apple in your iPhone's settings. Database backups roll off within 15 days, and crash reports linked to your account ID expire within 30 days.
- Or email us and we'll do any of this for you.
How long we keep things
Everything stays until you delete it or delete your account, except that sign-in records are deleted 30 days after they expire or you sign out, and crash and error reports expire after 30 days.
Kids
Hackysack isn't for children under 13.
Changes
Every change to this page is in the repository's history. We'll tell you in the app or in TestFlight's notes before anything important changes.