Privacy Policy
Reps is a workout tracker that works fully on your device by default — if you never sign in, your training data stays on your phone and nothing is sent to us. Creating an account is optional: it backs up your data to our EU cloud, syncs it across your devices, and unlocks the AI coach. We don't run ads, we don't track you across other apps or websites, and we never sell your data. This policy explains what we collect when you do sign in, who we share it with, and the rights you have.
Who is responsible for your data (Controller)
The data controller under the EU General Data Protection Regulation (GDPR / "RODO") is:
Szymon Łukiewicz
Poland
- General / support: [email protected]
- Privacy matters: [email protected]
- Website: https://repsworkout.com
Reps is operated by a private individual, not a registered company. We have not appointed a Data Protection Officer, and we are not required to under Article 37 GDPR.
We collect this data directly from you. The only data we receive from a third party is the identity confirmation returned by Apple or Google when you choose those sign-in methods.
At a glance
- Reps works without an account. If you don't sign in, all your training data stays on your device. Nothing is sent to our servers — no cloud sync, no cloud backup. The one exception is a font fetch (see Google Fonts below), which shares your IP address with Google.
- Signing in is optional. If you create an account, your data syncs to our EU cloud so it's backed up and available on your other devices, and you unlock the AI coach.
- No ads, no tracking, no data selling — ever. There is no advertising SDK in Reps and nothing follows you across other apps or websites.
- Two optional measurements, both switchable off in the app. Reps can send anonymous usage statistics (which screens are opened — no account, no device identifier, no training content) and error diagnostics when something crashes or fails. Both are explained on first launch and can be turned off at any time in Settings → Data.
- The AI coach shares data with a third party. When you use it, your messages and relevant training data are sent to Anthropic (in the United States) to generate replies.
- Error monitoring stays in the EU. Diagnostics go to Sentry's Frankfurt region — never your training data or chat content.
- You can delete everything. Deleting your account permanently erases all your cloud data.
The two ways you can use Reps
Your privacy depends entirely on which mode you use.
Local-only (no account)
If you use Reps without signing in:
- All of your training data stays on your device in a local database.
- We receive nothing. No workouts, no personal records, no settings — none of it reaches our servers.
- There is no cloud sync and no cloud backup. If you delete the app or lose the device, that data is gone.
- The AI coach and multi-device sync are not available in this mode.
The only data that reaches a third party in local-only mode is the font fetch described under Google Fonts below (your IP address and user-agent when the app loads a font). Nothing else leaves your device.
Signed-in (optional account)
If you create an account, your training data syncs to our EU cloud so it can be backed up, used across your devices, and (optionally) used by the AI coach. What we store in this mode is described in the next sections.
How you sign in (passwordless)
We use passwordless sign-in. You can sign in with:
- Email one-time code — we email you an 8-digit code to enter.
- Sign in with Apple
- Sign in with Google
We store your email address and a user ID. We do not use or store passwords.
Providing your email address is necessary to create an account and to use cloud sync and the AI coach — without it you can't sign in. You can still use Reps fully in local-only mode without giving us anything.
What we collect, why, and our legal basis
When you're signed in, we store the following in our cloud. When you're in local-only mode, none of this is collected by us.
- Account (email, user ID, sign-in method, account-creation date, optional display name) — to create and secure your account and sign you in. Legal basis: Art. 6(1)(b) — performance of our contract with you.
- App settings (units kg/lbs, theme, rest-timer seconds) — to sync your preferences across devices. Legal basis: Art. 6(1)(b) — performance of contract.
- Training data (exercises including custom ones, routines, training plans, workouts — sessions, sets, reps, weights, dates, duration, notes, ratings — and personal records) — to back up your training and make it available across your devices. Legal basis: Art. 6(1)(b) — performance of contract. Where an entry reveals information about your health (see below), that data is additionally covered by Art. 9(2)(a) — your explicit consent.
- AI coach data (your chat threads and messages — your prompts and the assistant's replies — plus a per-day usage counter) — to provide the AI coach and enforce its daily limit. Legal basis: Art. 6(1)(a) — your consent, given by the in-app opt-in before your first message and withdrawable in Settings → Data (the coach is optional and off until you turn it on).
- Server logs and coach usage metrics (request method, path, status, timing, and a hashed user ID; for each AI-coach message or connected-assistant tool call also the conversation ID, the model, token and tool-call counts, the response time and how it ended — never the content) — to keep the service stable, reliable, and secure. Legal basis: Art. 6(1)(f) — our legitimate interest in operating a secure, reliable service.
- Error diagnostics (optional, on by default, switchable off in Settings → Data — see Sentry below; stack traces, technical environment, error codes and the names of the app screens opened before the error — never what you typed. Diagnostics sent from the app carry no user ID at all; user IDs in server-side diagnostics are hashed) — to detect and fix crashes and errors. Legal basis: Art. 6(1)(f) — our legitimate interest in a stable, reliable app.
- Anonymous usage statistics (optional, on by default, switchable off in Settings → Data — see Usage statistics below) — to see where people get stuck and which features are worth keeping. Legal basis: Art. 6(1)(f) — our legitimate interest in understanding and improving how Reps is used. This is collected whether or not you have an account, because it contains nothing that identifies you.
Where we rely on legitimate interests (Art. 6(1)(f)), our interest is keeping Reps stable, reliable, and secure. You can object to this processing under Article 21 — and you can switch off both error diagnostics and usage statistics yourself, at any time, in Settings → Data. Switching them off takes effect immediately: nothing further is sent, and anything still waiting to be sent is discarded. See Your rights.
Health-related entries
Reps does not ask you for medical or health data, and it has no body-measurement or health-tracking feature. Ordinary workout logs — exercises, sets, reps, weights, and dates — are used only to show you your own training and are not medical data. Some fields are free text (for example, workout notes), so if you choose to type health information there — such as an injury or a medical condition — that is your choice. Please avoid entering sensitive health details you would not want stored. To the extent anything you voluntarily enter qualifies as special-category data under Article 9 GDPR, we rely on the explicit consent you give by choosing to enter it (Art. 9(2)(a)); you can edit or delete it at any time, and you can remove all of it by deleting your account. We do not otherwise seek out or infer health data.
The AI coach
The AI coach is optional and requires you to be signed in. It is off until you turn it on. The first time you open it, the app asks you to agree before anything is sent: it names what leaves your device (your messages and relevant training data) and who receives it (Anthropic), and it offers a plain “Not now”. Until you agree there is no way to send a message — the chat has no text field. You can withdraw at any time in Settings → Data, which switches the coach off again and brings the question back the next time you open it. Replies come from an AI system, not a person. If you never turn the coach on, none of your data is sent to Anthropic; you can also remove your chat history by deleting your account.
How it works:
- The coach runs through our own server (hosted on Railway, EU region — Amsterdam), which calls Anthropic PBC (United States) using a Claude model to generate replies.
- What is sent to Anthropic: your chat messages and relevant training data used as context to answer you — for example your recent workout history, personal records, your active plan, exercise names, and sets, reps, weights, and dates. In other words, it is not only the text you type: relevant training data is shared with Anthropic during a chat.
- Under Anthropic's commercial (API) terms, Anthropic does not use these inputs or outputs to train its models, and it deletes them within 30 days, except where longer retention is required by law or to enforce its usage policy.
- Your chat history is stored in our EU database for the life of your account (and deleted when you delete your account). The copy Anthropic receives is separate and transient, deleted on Anthropic's cycle described above.
- There is a daily usage limit, based on how much work the coach does for you rather than on a fixed number of messages.
The AI coach is not a decision-maker. It provides suggestions and general information only. It does not make any automated decision that produces legal or similarly significant effects for you (no processing under Article 22 GDPR).
The AI coach is not medical advice. It gives general fitness information only. It is not a substitute for a doctor, physiotherapist, or other professional. We show you this disclosure in the app. Please don't put personal data about other people, or sensitive information you'd rather not share, into the chat.
Who we share data with
We don't sell or rent your data. We share it only with the service providers ("processors") we need to run Reps, and only for the purposes below. Each acts under a data processing agreement with us.
- Supabase — our database and authentication provider (EU region). Stores your account, training, and chat data.
- Railway — hosting for our server (EU region — Amsterdam). Server logs contain request method/path/status/timing and a hashed user ID — no chat content and no training data.
- Anthropic PBC (United States) — generates AI-coach replies. Receives your chat messages and relevant training context, as described above. This involves an international transfer (see below).
- Apple — only if you use Sign in with Apple, to verify your identity.
- Google — only if you use Sign in with Google, to verify your identity.
- Sentry (EU region — Frankfurt, Germany) — optional error monitoring, for both our server and the app. Receives error diagnostics (stack traces, technical environment, error codes, screen names). It does not receive your training data, chat content, or request bodies; diagnostics sent from the app carry no user ID, and any user IDs in server-side logs are hashed. No international transfer is involved.
Not on this list, on purpose: AI assistants you connect yourself, such as Claude or ChatGPT. The data they read goes to their provider at your direction and under your agreement with that provider — they are not our processors. See Connecting Claude, ChatGPT or another AI assistant below.
Usage statistics
To see where people get stuck — and to know whether a feature is used at all before we spend months on it — Reps can send a small number of anonymous usage events to our own server in the EU. This is on by default, is explained on first launch before anything is sent, and can be switched off at any time in Settings → Data.
What an event contains. The name of the event from a fixed list (for example "a workout was finished"), the app version, your platform, the major version of your operating system, your language, and whether you are signed in. Sizes are grouped into ranges rather than reported exactly — a finished workout is recorded as "6–10 sets", never "8 sets".
What an event never contains. No account ID, no email, no device identifier, no advertising identifier, and no stored IP address. No exercise names, weights, repetitions, notes, ratings, personal records or chat content — nothing about what you trained, only that something happened. There is no free-text field an event could carry such a thing in.
How events are grouped. Events from a single run of the app share a random identifier that is created in memory when the app opens and is never written to your device. When you close the app it is gone, so events from two different sessions cannot be connected to each other or to you. Times are recorded as a calendar day and a running order within the session — never a clock reading.
How long we keep them. Individual events are deleted automatically after 14 months. Aggregate counts derived from them (for example "how many workouts were finished in August") contain no event-level data and are kept indefinitely.
Because these events contain nothing that identifies you, they are not personal data — but we describe them here anyway, because you should be able to decide about them regardless of how they are classified.
Google Fonts
Separately from sign-in, the app and our website load two fonts (Anton and Inter) from Google Fonts. When a font is fetched, Google receives your device's IP address and user-agent. Google is an independent recipient here — it receives this data for its own purposes, not as a processor acting on our instructions. We rely on our legitimate interest (Art. 6(1)(f)) in displaying the app's typography. This is the only third-party data flow that also happens in local-only mode, and it applies even if you never create an account. For transfers of this data to the United States, Google relies on its certification under the EU–US Data Privacy Framework.
Website statistics
Our website (repsworkout.com — not the app) counts visits with Cloudflare Web Analytics, a service of Cloudflare, which also hosts the site. It sets no cookies, stores nothing on your device and doesn't follow you across other websites. For each page view Cloudflare processes the page address, the site that linked to it, your browser and device type and your country (derived from your IP address, which is not kept in the statistics), and shows us only aggregated counts. Cloudflare acts as our processor. We rely on our legitimate interest (Art. 6(1)(f)) in knowing how people find the site. For transfers to the United States, Cloudflare relies on the EU–US Data Privacy Framework and Standard Contractual Clauses.
International transfers
Our database, authentication, and AI server are hosted in the EU. Some providers, however, are located in the United States, so using those features transfers data outside the European Economic Area:
Anthropic (AI coach). When you use the AI coach, your messages and relevant workout context are transmitted to Anthropic PBC (United States), which processes them solely to generate the coach's replies on our behalf as our processor under a Data Processing Agreement. This transfer to the United States is protected by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) incorporated into our agreement with Anthropic. As noted above, under Anthropic's commercial terms Anthropic does not use these inputs or outputs to train its models and deletes them within 30 days, except where longer retention is required by law or to enforce its usage policy.
Sentry (error monitoring). Error diagnostics are sent to Sentry's EU region (Frankfurt, Germany) and are not transferred outside the EEA.
Usage statistics. Anonymous usage events go to our own server (Railway, EU — Amsterdam) and are stored in our own EU database. No third party receives them, and they are not transferred outside the EEA.
Google Fonts. As described above, the font fetch may transfer your IP address and user-agent to Google in the United States; Google relies on its EU–US Data Privacy Framework certification for that transfer.
AI assistants you connect. If you connect Claude, ChatGPT or another assistant, what it reads goes to its provider — which may be in the United States — at your request and under your agreement with that provider, not to a processor of ours. See Connecting Claude, ChatGPT or another AI assistant below.
You can ask us for more information about these transfers and safeguards by emailing [email protected].
How long we keep your data
- Account, settings, training, and chat data: kept for as long as your account exists. When you delete your account, this data is deleted (see Deleting your account).
- Server logs, coach usage metrics and error diagnostics: kept for up to 90 days and then automatically deleted.
- AI assistant connections: kept while the connection is active. A revoked or lapsed connection can no longer be used, and all of them are deleted when you delete your account.
- Local-only data: lives solely on your device until you delete the app or clear its data. We never receive it, so we can't delete it for you.
Notifications
Reps uses local, on-device notifications only — for example, a reminder about an unfinished workout. These are generated on your device. We don't use a push service, and no device tokens are sent anywhere.
What we don't do
We want to be clear about this:
- No third-party analytics SDKs — no Firebase, Crashlytics, Mixpanel, Amplitude, PostHog, or Google Analytics. Our usage statistics are first-party: they go to our own server and no one else.
- No profiling and no automated decision-making. We never build a profile of you, and nothing about your account is decided automatically.
- No advertising — no ad SDKs, no ads.
- We do not sell or rent your personal data.
- No cross-app or cross-site tracking.
- No location or GPS collection.
Your rights
Under the GDPR (RODO), you have the right to:
- Access the personal data we hold about you.
- Rectify data that's inaccurate or incomplete.
- Erase your data ("right to be forgotten").
- Restrict processing in certain cases.
- Object to processing based on our legitimate interests.
- Data portability — receive a copy of your data in a portable format.
- Withdraw consent at any time (for the AI coach or any health-related data), without affecting the lawfulness of processing before you withdrew it.
- Lodge a complaint with a supervisory authority (see below).
How to exercise these rights. For most requests — including access and a copy of your data (portability) — email [email protected]. You can also export your training data yourself at any time from Settings → Data & privacy in the app; for anything that export doesn't cover, email us. For portability requests we provide the eligible data in a structured, commonly used, machine-readable format (for example JSON or CSV). We'll respond within one month, as required by Article 12(3) GDPR.
You can delete your account yourself in the app (see below).
Deleting your account
You can permanently delete your account and all your cloud data:
- In the app: open Settings → Account → Delete account. This starts an immediate, permanent hard delete of your account and all associated cloud data across every table — including your training data and your AI-coach chat history. It is not a soft delete or a grace period. Your local data on that device is also wiped.
- By web: you can also request deletion at https://repsworkout.com/delete-account.html.
After the live data is deleted, any residual copies in our providers' encrypted backups are purged on the normal backup-rotation cycle — within about 30 days.
Deletion is permanent and cannot be undone.
Connecting Claude, ChatGPT or another AI assistant
You can connect an AI assistant you already use — for example Claude (Anthropic) or ChatGPT (OpenAI) — to your Reps account through the Model Context Protocol (MCP). It is optional, and nothing happens until you set it up in the assistant yourself; the guide is at repsworkout.com/connect.
- What the assistant can do. While you chat with it, the assistant can read your training data (workout history, records, exercise progress, routines, plans and your exercise library) and, when you ask and confirm, create or change routines, plans and custom exercises in your account. It cannot log a workout for you, and it cannot delete your account or your workout history.
- Signing in. You connect on our sign-in page at api.repsworkout.com, with the email address of your Reps account (or Apple or Google, where offered). If you don't have a Reps account yet, you can create one on that page: it is the same free account you would create in the app, and you accept the Terms and this Privacy Policy and confirm you are 16 or older exactly as on the app's sign-in screen.
- What we store. For each connection: hashes of the tokens the assistant holds, your sign-in session in encrypted form (AES-256-GCM), which assistant it is, when it was last used, and whether it was revoked — on our server (Railway, EU region) and in our database (Supabase, EU).
- Who receives your data, and why. What the assistant reads is sent to the company behind that assistant (for example Anthropic or OpenAI) because you asked for it. That company handles it under its own terms and privacy policy and your account with it — including any retention or model-training settings you have there. It is not our processor, and we don't control what it does with that data. This is different from the AI coach inside Reps, which runs under our agreement with Anthropic. Our legal basis for sending the data is Art. 6(1)(b) — providing the service you asked for.
- Transfers. These companies may be in the United States. The transfer happens at your request, to a service you chose.
- How long, and how to stop. Access tokens expire after 30 days and are renewed while you keep using the connection; a connection left unused lapses after 180 days. Remove the connector in the assistant's settings and it stops using Reps. Email [email protected] and we'll revoke all your connections straight away. Deleting your Reps account deletes every connection immediately.
How we protect your data
We use reasonable technical measures to protect your data. We won't overpromise, but here's what we do:
- Encryption in transit — data travels between the app, our server, and our providers over HTTPS.
- Row-level security (RLS) — every row in our database is protected so that only your own authenticated session can read your rows.
- Encrypted backups — our providers keep backups in encrypted form.
- Hashed identifiers in logs — user IDs in server logs, coach usage metrics and error diagnostics are hashed, and none of them contain chat content or training data.
No system can be guaranteed perfectly secure, but we take reasonable steps to keep your data safe.
Age requirement
You must be at least 16 to use Reps (this is the age of digital consent under Article 8 GDPR as applied in Poland). If you are under 16, you may only use Reps with the consent of a parent or guardian. This is a stated requirement; the app does not technically verify your age. If we learn that we hold data from someone under 16 without the required consent, we will delete it. A parent or guardian can contact us at [email protected].
Changes to this policy
We may update this Privacy Policy from time to time — for example, when we add features or when the law changes. When we make material changes, we'll update the "Last updated" date at the top and let you know in the app. Please check back occasionally.
Complaints
If you believe we've handled your data improperly, please contact us first at [email protected] so we can try to put it right. You also have the right to lodge a complaint with the Polish supervisory authority:
Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
https://uodo.gov.pl
If you live in another EU/EEA country, you may also complain to your local data protection authority.
Contact
- Privacy questions and requests: [email protected]
- General support: [email protected]
- Website: https://repsworkout.com
Szymon Łukiewicz
Poland