Privacy Policy

Effective and last updated: September 23, 2026

Hamen keeps favorites, complete listening history, plan progress, and onboarding answers on your device. Hamen does not sell personal data, display advertising, access your microphone, record audio, or collect health data. The Android app does not create an account. Superwall on Android and, starting with iOS build 60, on iOS processes limited purchase and app-instance information to provide and restore Premium access. Older iOS releases use Adapty; their purchase records and server integration remain in use during the transition. Apple server notifications are delivered through Prizmaly's Netlify-hosted receiver to Adapty and Superwall for billing and subscription records. On Android, Meta and TikTok measurement are disabled unless you affirmatively enable Anonymous measurement; you can change that choice later in Menu. On iOS, Hamen requests App Tracking Transparency permission. Meta cross-app tracking and purchase attribution require authorization through that system request. In iOS build 60 and later, Prizmaly's server verifies an Apple transaction and records the app-reported tracking choice before forwarding eligible Superwall events to Meta. Older iOS releases use Adapty's attribution integration. Hamen does not directly log completed purchases to Meta. Hamen also uses the TikTok Business SDK for consented advertising measurement. Hamen starts that SDK and sends TikTok events only after you authorize tracking; otherwise no TikTok SDK tracking or events occur. Meta automatic purchase logging is disabled on both platforms. TikTok automatic purchase logging is also disabled. After a successful canonical Google Play purchase, Android may send TikTok one consented initial StartTrial, Subscribe, or Purchase event; restores and renewals do not create client events. iOS sends only verified StoreKit conversions with a stable transaction event ID. The iOS app also uses Mixpanel for limited, first-party product analytics about the onboarding flow, and Superwall for the limited analytics described below. These optional analytics are enabled by default and future client collection can be disabled in Menu after completing onboarding. They are independent of App Tracking Transparency and are not used by Hamen for cross-app advertising. Disabling them does not stop essential store billing and server-notification processing.

Scope and operator

This policy applies to the Hamen mobile application for Android and iOS, including the package and bundle identifier com.prizmaly.hamen. The data controller and app operator is PRIZMALY YAZILIM TICARET LIMITED SIRKETI (“Prizmaly”, “we”, “our”, or “us”). For privacy questions or requests, contact info@prizmaly.com.

Information kept only on your device

Favorites, the complete listening-history list, onboarding answers, listening-plan progress, timer settings, and playback preferences are stored locally on your device. Hamen does not sync these local records to a Prizmaly server or use them to build a health profile. On Android, after you enable Anonymous measurement, opening a player sends Meta a configured content identifier and type as an app-interaction event and sends TikTok only a fixed generic audio-content marker. TikTok does not receive the selected preset, category, title, typed text, or listening history. Neither event uploads the complete local history or any audio recording.

On Android, you can erase this information, including onboarding and playback settings, with Menu → Reset local data. The Android app does not offer account sign-in.

On iOS, Sign in with Apple is optional. If you use it, Apple authenticates you and Hamen may receive an Apple user identifier and, when Apple provides them, your name and email address. Hamen stores the raw Apple identifier, name, and email only on that device; it does not send those raw details to Prizmaly servers, Adapty, Superwall, Meta, TikTok, or Mixpanel, and it does not create a Prizmaly server account. Hamen derives a pseudonymous UUID by hashing the Apple user identifier with a Hamen-specific namespace. In iOS build 60 and later, it supplies that UUID to Superwall for billing identity and, when enabled, optional analytics. Older iOS releases supply it when optional Superwall analytics is enabled. Superwall does not receive the raw Apple identifier, name, or email. Menu → Delete Account removes the locally stored Apple profile, favorites, listening history, listening-plan data, and listening statistics from that device.

Uninstalling Hamen also removes its local app data, subject to your device and operating-system backup settings. Resetting local data, deleting the local iOS profile, or uninstalling does not by itself erase purchase records held by an app store, Superwall, or Adapty.

Purchases and subscription access

When Hamen offers Premium purchases, Google Play or Apple processes the payment under its own privacy policy. Hamen does not receive or store your full payment-card or bank-account details.

On Android, we use Superwall as a service provider to present Hamen's own Premium paywall, complete and restore Google Play purchases, determine Premium entitlement, prevent purchase fraud, provide customer support, and understand subscription performance. Starting with iOS build 60, Superwall also handles App Store purchases, restoration and Premium access within Hamen; Adapty is no longer an SDK in those new builds. Superwall processes:

Hamen does not send Superwall your name, email address, phone number, raw Apple user identifier, onboarding answers, microphone audio, or health information. iOS billing identity and optional analytics use the pseudonymous identifiers described above. On Android, Hamen supplies Meta's app-scoped anonymous identifier to Superwall as a custom attribution attribute only after you enable Anonymous measurement. If you decline, the identifier is not set; if you revoke consent, Hamen removes it and stops future direct advertising events. Collection of Google's Advertising ID is disabled and the Android advertising-ID permission is removed. Superwall acts on our instructions as a service provider; its processing is also described in the Superwall Privacy Policy.

In older iOS releases that use Adapty, Adapty may process an app-instance or device identifier to maintain an anonymous profile and associate store purchases with Premium access. If you authorize Apple's App Tracking Transparency request, Adapty may also receive the advertising identifier made available by iOS, and Hamen sends Meta's app-scoped anonymous identifier to Adapty as facebook_anonymous_id. Hamen does not identify the Adapty profile with the optional Sign in with Apple user ID. Adapty acts on our instructions as a service provider; its processing is also described in the Adapty End-Users Privacy Policy.

On iOS, Apple also sends signed purchase and subscription notifications to a Prizmaly-operated receiver hosted by Netlify. The receiver checks Apple's signature and the Hamen app identity, then forwards the notification to Adapty and Superwall. Depending on the notification, its signed data can include transaction and original-transaction identifiers, an app-account token, product identifiers, purchase and expiry dates, subscription or refund status, production or sandbox environment, and price and currency. These identifiers and records support purchase reconciliation, subscription lifecycle reporting, restoration and support. This server billing path operates separately from the optional client-analytics setting. This Apple-notification forwarding function does not intentionally log or persist the full signed notification payload. Netlify processes the request as our hosting provider and may process technical connection and service-operation information. The separate consent and Meta-delivery functions described below handle attribution for newer iOS builds; the existing Adapty integration remains for older releases.

In iOS build 60 and later, Hamen also sends a verified, signed Apple transaction to a Prizmaly server hosted by Netlify to associate the app-reported tracking choice with that purchase or subscription chain. The server verifies Apple's signature, the Hamen app, store environment and product; a family-shared entitlement does not authorize this advertising registration. The raw signed transaction and raw transaction-chain identifier are not persisted by this consent service. Records use a keyed hash of the transaction chain and contain the tracking status, whether export is allowed, and the update time.

Only an authorized record includes Meta's app-scoped anonymous identifier and limited app/device context: bundle and app version, operating-system version, device model, locale, timezone, screen dimensions/density and processor count. Unknown carrier and storage fields are left empty. These details support the Meta app-event format; Hamen does not add listening content, onboarding answers, health data, name, email or phone number. A denied, restricted, unresolved or revoked permission produces a record without the Meta identifier or device details, and the server skips advertising delivery for that latest state. Earlier records and already delivered events are subject to the retention and deletion terms below. Consent updates operate even when optional product analytics is off; they do not prevent purchases if the network is unavailable. A revocation made while offline is applied to server processing once its update is received.

Hamen Android does not currently enable a Superwall-to-Meta or Superwall-to-TikTok server connector. Consequently, neither advertising provider receives Android renewal or cancellation events from Superwall. For tracking-authorized users of older iOS releases, Adapty's Meta integration may send subscription lifecycle and revenue events to Meta. In iOS build 60 and later, a separate Prizmaly server receives Superwall subscription events and forwards eligible events to Meta using the recorded tracking choice described above. This new feed uses distinct event names during the transition. Older and newer attribution records may coexist during that period. Depending on the purchase, events can cover trial start, trial conversion, initial purchase, renewal, cancellation and non-renewing purchase, with product, price, currency, store and permitted anonymous attribution information. Hamen never collects Google's Advertising ID. We use these consented events to measure and optimize Hamen advertising campaigns. Hamen disables automatic client-side purchase logging in both advertising SDKs. After a direct Superwall purchase success for a canonical Hamen product, the Android client may send exactly one initial TikTok conversion: a lifetime product becomes Purchase; a subscription whose returned active access level confirms a free trial becomes StartTrial; any other initial subscription becomes Subscribe. The app SHA-256 hashes Google Play's purchase token before using it as a persistent deduplication/event ID; if the bridge omits that optional token, it hashes the canonical product and Superwall entitlement-activation timestamp. The raw token or order ID is not stored in the TikTok queue or sent to TikTok. Launch, restore, entitlement refresh, and renewal paths never generate these client conversions. On iOS, Hamen does not directly log completed purchases to Meta, while the TikTok adapter sends a direct StartTrial, Subscribe, or Purchase event only from a verified StoreKit transaction and deduplicates retries with that transaction's stable identifier.

On Android, Google Play Billing automatically sends Google limited technical context and billing-operation diagnostics. This can include the Hamen package and version, Billing Library version, Android version, device brand or model and build information, a random billing-client session value, billing API outcomes, service-connection issues, error or response codes, and operation timing or latency. Google uses this information to operate, improve, and troubleshoot Google Play Billing.

Analytics, diagnostics, and advertising

The Hamen Android app includes Meta App Events SDK 18.3.0 and TikTok Business Android SDK 1.7.0 for optional app analytics, install attribution, and advertising campaign measurement. Both SDKs remain uninitialized and Hamen sends no events to either provider until you affirmatively enable Anonymous measurement. After you agree, Meta may receive app activation and explicit onboarding, paywall, content-player, and checkout events. TikTok may automatically receive install and launch events and receives only the standard Registration, CompleteTutorial, ViewContent, AddToCart, and Checkout events that Hamen explicitly sends. A successful direct purchase can additionally send one initial StartTrial, Subscribe, or Purchase event under the strict rules above. TikTok content events use closed, generic identifiers such as hamen_audio and allowlisted Premium-plan identifiers; no listening preset, wellness category, onboarding answer, typed text, or other free-form value is sent to TikTok.

Those requests can include an app-scoped anonymous SDK identifier, install-referrer information, app package and version, device model, operating-system version, locale, screen characteristics, session and network context, installer package, user agent, and IP or connection information. Event-specific commerce values can include an allowlisted product marker, price, and currency. Hamen does not request Android location permission or send a location field. Network providers and the SDK endpoints necessarily receive connection information such as an IP address when a request is made.

Meta and TikTok automatic purchase and subscription logging are disabled. TikTok enhanced data postback—which could otherwise inspect interface metadata or button text—is disabled, as are TikTok automatic retention events and SDK monitoring. Collection of Google's Advertising ID is disabled in Meta and TikTok; the Android AD_ID permission and related Privacy Sandbox advertising permissions are removed, and Anonymous measurement does not enable those identifiers. TikTok may still use Google Play Install Referrer and its own app-scoped anonymous identifier for consented attribution.

You can decline measurement or revoke it later with Menu → Anonymous measurement. Revocation stops future direct events, clears unsent TikTok event payloads, and removes the Meta attribution attribute from the Superwall user, but does not erase data already processed by a provider. Hamen does not display third-party ads, but consented Meta and TikTok event and eligible purchase data may be used to attribute, measure, report on, and optimize ads for Hamen. Meta's processing is described in the Meta Privacy Policy, and TikTok's processing is described in the TikTok Privacy Policy.

The Hamen iOS app also includes Meta App Events. Automatic purchase and subscription logging is disabled. In iOS build 60 and later, only after the App Tracking Transparency request is authorized may Hamen initialize Meta and send manual app-activation, onboarding-completion, paywall-view, and checkout-initiation events. Checkout parameters can include the App Store product identifier, price, currency, and whether the product is a subscription or lifetime purchase. Hamen does not include listening choices, listening history, goals, sessions, Apple profile details, or health information in these events.

On iOS, access to Apple's advertising identifier and Hamen's delivery of Meta's anonymous identifier require authorization through the App Tracking Transparency prompt. In build 60 and later, Hamen supplies that identifier to Superwall and the Prizmaly consent service only while authorized, and clears it from the current consent data when permission is no longer authorized. The server does not infer consent merely from a purchase or Superwall user ID. Older releases using Adapty apply their existing Adapty attribution permissions. You can change tracking permission later in iOS Settings. Denying the request does not restrict any Hamen feature.

The Hamen iOS app also includes the TikTok Business SDK for app attribution, advertising analytics, campaign measurement, and campaign optimization. Hamen does not initialize or activate the TikTok Business SDK and sends no TikTok events until Apple's App Tracking Transparency status is Authorized. If permission is denied, restricted, not yet determined, or later no longer authorized, Hamen does not start TikTok SDK tracking or send TikTok events. This choice does not restrict any Hamen feature.

After authorization, automatic TikTok event reporting is limited to Install and Launch; automatic retention events are disabled. Hamen manually logs Registration, CompleteTutorial, ViewContent, AddToCart, InitiateCheckout, and verified StartTrial, Subscribe, and Purchase events. A verified App Store transaction identifier is used to deduplicate transaction events. Event data is limited to technical app, device, operating-system, locale, timezone, and network context; an app-scoped identifier or advertising identifier permitted by iOS; and, where relevant, the App Store product identifier, price, currency, and limited trial, subscription, or purchase context. We use this information to measure, analyze, and optimize advertising for Hamen.

Hamen does not send TikTok listening choices or history, binaural category or frequency, onboarding answers, Apple profile details, health data, free text, email address, phone number, or name. TikTok's automatic advanced matching or enhanced-data collection is disabled. The TikTok SDK's SKAdNetwork configuration is also disabled because Hamen's existing Meta attribution configuration manages the conversion schema, avoiding competing schema writers. TikTok acts as an advertising-measurement provider; its processing is described in the TikTok Privacy Policy.

Starting with iOS build 60, Superwall is the purchase, restore and Premium-access provider and starts for essential billing even when Share anonymous analytics is off. With that optional setting enabled, it also receives limited app, device, locale, store, paywall and subscription analytics with the pseudonymous identifiers described above. Hamen does not send it listening history, selected listening content, onboarding answers, raw Apple profile details or free-form personal text. The setting is enabled by default and can be turned off with Menu → Share anonymous analytics. Turning it off stops future optional Superwall client events; it does not disable billing, delete existing records, stop Apple server notifications or prevent privacy-choice updates to Prizmaly's server. ATT separately controls the advertising flow described above. Older iOS releases use Superwall as an optional observer alongside Adapty and may include the Adapty profile identifier and purchase-provider name in their analytics. They may avoid starting that observer when optional analytics is off. Hamen does not add a Superwall-to-TikTok server sender on iOS.

The Hamen iOS app uses Mixpanel as a product-analytics service to understand where users progress through or leave the onboarding flow, how long each onboarding screen is actively visible, and whether the native paywall and checkout flow works reliably. When Share anonymous analytics is enabled, Mixpanel may process a random, persistent installation identifier and random onboarding-attempt, session, and event identifiers; limited app version and build, Mixpanel SDK version, app language/locale identifier, device model and manufacturer, screen dimensions, operating-system name and version, and network connection properties such as Wi-Fi status, cellular radio type, and carrier; onboarding screen identifiers, order, and phase; generic interaction occurrences; active and elapsed timing; completion, abandonment, interruption, and resumption events; and whether the optional rating step was continued or skipped. Native purchase-funnel events can also include paywall views, product identifiers and availability, checkout session or attempt identifiers, purchase outcomes and verification status. Hamen does not send purchase price or App Store transaction identifiers to Mixpanel. Hamen does not send Mixpanel the actual onboarding answers, selected goals, age, gender, listening choices or history, Apple profile details, health data, advertising identifier, or precise or approximate location. IP-based geolocation is disabled.

Mixpanel analytics is enabled by default during onboarding. After completing onboarding, you can turn off future collection with Menu → Share anonymous analytics. Turning it off stops future Mixpanel events from that installation. Mixpanel is configured to process Hamen analytics through its European endpoint. Before an analytics identifier is rotated when collection is turned off, Hamen keeps the current and all previously rotated random Analytics Support IDs on your device solely so you can identify records in an access or deletion request. Menu → Delete Account clears the previously retained IDs and rotates the current ID. This product analytics is not combined with third-party data for targeted advertising or advertising measurement, so it does not depend on your App Tracking Transparency choice. Mixpanel's processing is also described in the Mixpanel Privacy Statement.

Hamen does not include Firebase Analytics or Firebase Crashlytics. It does not request microphone permission, capture or upload microphone recordings, or display advertising. Hamen does not request GPS or device-location permission or collect precise device location. Superwall and other service endpoints receive IP and connection information; Superwall may derive approximate city, region, country or timezone from an IP address. The Mixpanel geolocation setting described above remains disabled. Hamen does not collect contacts, browsing history, messages, photos, videos, personal audio files, or health and fitness data on either platform.

Why we process purchase, app-event, and product-analytics information

We process purchase information to perform the Premium service you request, restore purchases, maintain service security, respond to support and deletion requests, comply with store and legal obligations, and evaluate subscription performance. We process the limited Meta and TikTok app-event and attribution information described above—after affirmative consent on Android and subject to Apple's tracking control on iOS—to understand the acquisition funnel, measure advertising, prevent duplicate reporting, and improve campaign performance. We process the limited Mixpanel and optional Superwall product-analytics information to identify onboarding and paywall reliability issues, understand completion and drop-off, and improve the first-run and subscription experience. Where applicable, the legal bases are performance of a contract, our legitimate interests in operating, securing, analyzing, and promoting Hamen, consent where required, and compliance with legal obligations.

Sharing and international processing

We do not sell personal data. Purchase information may be processed by Google Play and Superwall on Android, and Apple, Adapty and Superwall on iOS, for store payment, access-level management, support, fraud prevention, reconciliation and subscription analytics. Netlify hosts Prizmaly's iOS Apple-notification receiver, which forwards verified notifications to Adapty and Superwall during the transition, and the receipt-consent and Meta-delivery services for newer iOS builds. New iOS builds use Superwall for billing; older releases and historical records may still involve Adapty. Optional iOS Superwall client analytics includes the pseudonymous identifiers described above. On Android, for users who enable Anonymous measurement, Meta and TikTok receive the app events and identifiers described above directly from their SDKs, while Hamen Android currently has no active Superwall-to-Meta or Superwall-to-TikTok server connector. Its TikTok revenue sharing is limited to the direct, deduplicated initial conversion described above and excludes renewals. On iOS, Meta may receive the limited direct App Events described above. The newer Prizmaly relay shares eligible Superwall subscription events with Meta only under the latest received consent record associated with a verified Apple transaction; older Adapty integrations may share their lifecycle events when their tracking authorization permits attribution. On iOS, TikTok receives the limited Business SDK events and identifiers described above only after tracking authorization; TikTok processes them for Hamen advertising attribution, measurement, analytics, reporting, and optimization. On iOS, Mixpanel processes the limited onboarding product-analytics information described above on our behalf through its European service endpoint. Mixpanel is not used by Hamen for advertising, cross-app tracking, data brokerage, or enrichment with third-party data. Netlify's hosting processing is described in the Netlify Privacy Statement. These providers may process information in countries other than yours and apply their own legal safeguards for international transfers. We may also disclose information when required by law or to protect users, Hamen, or our legal rights.

Retention and deletion

On-device Hamen data remains until you reset it or remove the app. On iOS, the locally stored Apple profile remains until you use Menu → Delete Account or remove the app. Purchase and access-level records are retained only as long as needed for access restoration, support, fraud prevention, accounting, store, and legal obligations. Store transaction records controlled by Google or Apple are subject to those companies’ retention rules.

Prizmaly's consent service retains records under hashed transaction-chain keys to enforce the latest received tracking choice. Authorized records include the permitted Meta anonymous identifier and device context; denied records omit them. Earlier consent records are not automatically erased by a later denial. A separate delivery ledger retains hashed event keys and limited attempt/result information for retries and duplicate prevention, without the raw event body or signed receipt. These server records currently have no automatic expiry. We retain them for consent enforcement, delivery reliability and support until deleted following a valid request or a retention review. You can use the contact process below to request access or deletion.

Mixpanel onboarding analytics is retained for up to two years unless we configure a shorter period or delete it sooner. You can stop future collection with Menu → Share anonymous analytics. To request access to or deletion of Mixpanel analytics associated with a Hamen installation, use Menu → Contact Us before deleting local account data or uninstalling Hamen. The support-email draft includes the current and all previously rotated random Analytics Support IDs needed to locate the anonymous records, including after you turn future collection off. You can also email info@prizmaly.com and include those Support IDs. We will verify and process valid requests within 30 days unless retention is required by law.

On Android, to request deletion of the Superwall user record or Meta- or TikTok-linked app-event information associated with this Hamen installation, open Menu → Request Data Deletion. Hamen prepares an email containing the automatically generated anonymous Superwall User ID needed to locate the record; this is the Hamen Support ID. You can also email info@prizmaly.com and include that Support ID. The request may also need the approximate installation or event date and app version so we can identify a provider record. We will verify and process valid requests within 30 days unless retention is required by law. Meta, TikTok, and Superwall may retain limited records where required for security, fraud prevention, accounting, or legal compliance. TikTok may apply its own retention periods to events already delivered before consent was revoked.

On iOS, Menu → Delete Account deletes the local Apple profile and local listening data described above; it does not remotely delete Adapty, Superwall, Meta, TikTok, Mixpanel, Apple, App Store or hosting-provider or Prizmaly consent/delivery records. In build 60 and later, it clears local Superwall profile metadata and resets that billing identity once the SDK is available. Older observer-based releases may defer the reset until optional analytics is enabled. Deleting the local profile does not cancel Premium or erase ownership of an App Store purchase. Signing in again with the same Apple account can derive the same pseudonymous identifier; a local reset is not erasure of provider records. To request access to or deletion of an Adapty, Superwall, Meta-linked, TikTok, Mixpanel, notification-hosting or Prizmaly consent/delivery record, use Menu → Contact Us or email info@prizmaly.com. We may ask for the Hamen Superwall Support ID shown in the contact flow, an Adapty profile or Analytics Support ID if available, the app version, approximate installation or purchase date, device details, or an App Store transaction reference strictly as needed to verify the request and locate the relevant record. Do not send payment-card or bank-account details. Contact us before deleting local data or uninstalling if you need help locating a provider record. Adapty, Superwall, Meta, TikTok, Mixpanel and our hosting provider may retain limited records where required for fraud prevention, accounting, or legal compliance.

Deleting customer data does not cancel an active subscription. Manage or cancel subscriptions separately in Google Play or the App Store.

Your rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or object to processing, to obtain a portable copy of covered data, or to complain to a data-protection authority. Contact us to exercise a right. The Android app does not create an account, and the optional iOS Apple profile is stored locally rather than in a Prizmaly account system. Superwall identifies an Android installation with an anonymous User ID. On iOS build 60 and later, Superwall uses an app-instance identifier or the derived pseudonymous signed-in identifier described above. Older iOS releases may also have an Adapty Profile ID. Prizmaly's consent/delivery records use the hashed keys described above. We may need the relevant Hamen Support ID or other limited transaction information to find a provider record.

Security

Hamen minimizes collection and uses encrypted HTTPS connections for purchase-related communication. No system can guarantee absolute security, but we limit access and use reasonable administrative and technical safeguards appropriate to the information processed.

Other Prizmaly services

Prizmaly's website and apps other than Hamen are also designed to minimize collection. Depending on the service and the notice shown in that app, they may process anonymous crash reports or feature-usage counts, information you voluntarily provide such as an email address, and purchase history supplied by Apple App Store or Google Play. They may use Apple or Google for payments and Firebase Crashlytics for anonymous crash reporting. Most app data remains on the device; where a service needs server-side storage, Prizmaly uses encrypted connections and reasonable access controls.

Prizmaly does not sell personal data or use it for unrelated advertising or profiling. A product-specific in-app notice or store disclosure controls if it describes a narrower or different data flow. You may contact info@prizmaly.com to ask about, access, correct, or delete covered information associated with another Prizmaly service.

Children

Hamen is not directed to children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided covered information, contact us so we can investigate and delete it where required.

Changes

We may update this policy when Hamen, our providers, or legal requirements change. We will post the revised effective date here and provide additional notice when required.

Contact

PRIZMALY YAZILIM TICARET LIMITED SIRKETI
Privacy Support
info@prizmaly.com