Legal
Privacy Policy
Last updated July 26, 2026
Overview
Hark is operated by Ryan Vogel. This policy explains the information Hark processes to deliver webhook notifications through the website and iOS app. Hark does not sell personal information or use it for targeted advertising.
Information we process
- Your Google or Apple account identifier, name, email address, and profile image when provided by the sign-in service. Apple may provide a private relay email address.
- Encrypted Apple refresh tokens used only to revoke Sign in with Apple authorization when you delete your account.
- Service settings you create, including titles, image URLs, destination URLs, secret webhook-token hashes, and encrypted webhook tokens.
- Webhook content such as notification titles, bodies, images, destinations, idempotency keys, timestamps, and delivery results.
- Device information needed for delivery, including Expo and APNs push tokens, device name, platform, and last registration time.
- Agent access-token names, scopes, identifying prefixes, hashes, expiry and usage times. Plaintext agent tokens are shown once and are not stored by Hark.
- Approval and reply prompts, choices, expiry, response text or decision, requesting token identity, responding device, and response timestamps.
- Live Activity task titles, status text, optional detail and progress, expiry and update history, requesting token identity, and encrypted ActivityKit delivery tokens. Private mode replaces task content with generic text on the Lock Screen but does not remove the task content from Hark's encrypted network and account-scoped processing.
- Subscription status and billing identifiers when you choose a paid plan. Payment-card details are collected and handled by Stripe, not stored by Hark.
- Limited technical logs used to secure, operate, and troubleshoot the service.
- Aggregate usage counts for product analytics, such as event names, coarse outcome buckets, counters, and the related account, service, or device identifiers — never notification content, prompts, replies, tokens, or addresses.
How we use information
We use this information to authenticate your account, create and secure webhook endpoints, deliver notifications, show delivery activity, prevent duplicate or abusive requests, deliver requested interactions and return your response to the authorized agent, start and update Live Activities you authorize, provide support, and maintain the reliability and security of Hark.
Service providers
Hark relies on Google and Apple for authentication, Expo and Apple for push delivery and app distribution, Autumn and Stripe for optional web billing, and hosting infrastructure for the website, API, and database. These providers process information only as needed to provide their services and under their own privacy terms.
Retention and deletion
We retain account and service data while your account is active and retain recent webhook activity for product operation and troubleshooting. You can permanently delete your account inside the Hark app. Deletion removes your services, devices, and activity from the active database. For accounts using Apple, Hark first asks Apple to revoke stored authorization grants; deletion stops and reports an error if that revocation cannot be confirmed. Limited backup copies may remain temporarily until rotated.
Security and your choices
Webhook URLs contain secret tokens and should be treated like passwords. You can rotate a webhook token or revoke a scoped agent token from the dashboard if it is exposed. Device responses require the signed-in account and a registered device identity. Hark uses access controls and encrypted network connections, but no online service can guarantee absolute security.
Children
Hark is not directed to children under 13, and we do not knowingly collect personal information from children under 13.
Contact
Questions or privacy requests can be sent to ryan@mandarin3d.com.