REPS ENPL

Privacy Policy

Last updated · 4 July 2026

Reps is a workout tracker that works fully on your device by default — if you never sign in, your training data stays on your phone and nothing is sent to us. Creating an account is optional: it backs up your data to our EU cloud, syncs it across your devices, and unlocks the AI coach. We don't run analytics or ads, and we never sell your data. This policy explains what we collect when you do sign in, who we share it with, and the rights you have.

Who is responsible for your data (Controller)

The data controller under the EU General Data Protection Regulation (GDPR / "RODO") is:

Szymon Łukiewicz
Poland

Reps is operated by a private individual, not a registered company. We have not appointed a Data Protection Officer, and we are not required to under Article 37 GDPR.

We collect this data directly from you. The only data we receive from a third party is the identity confirmation returned by Apple or Google when you choose those sign-in methods.

At a glance

The two ways you can use Reps

Your privacy depends entirely on which mode you use.

Local-only (no account)

If you use Reps without signing in:

The only data that reaches a third party in local-only mode is the font fetch described under Google Fonts below (your IP address and user-agent when the app loads a font). Nothing else leaves your device.

Signed-in (optional account)

If you create an account, your training data syncs to our EU cloud so it can be backed up, used across your devices, and (optionally) used by the AI coach. What we store in this mode is described in the next sections.

How you sign in (passwordless)

We use passwordless sign-in. You can sign in with:

We store your email address and a user ID. We do not use or store passwords.

Providing your email address is necessary to create an account and to use cloud sync and the AI coach — without it you can't sign in. You can still use Reps fully in local-only mode without giving us anything.

What we collect, why, and our legal basis

When you're signed in, we store the following in our cloud. When you're in local-only mode, none of this is collected by us.

Where we rely on legitimate interests (Art. 6(1)(f)), our interest is keeping Reps stable, reliable, and secure. You can object to this processing under Article 21 — and you can opt out of the optional error diagnostics by emailing privacy@repsworkout.com. See Your rights.

Health-related entries

Reps does not ask you for medical or health data, and it has no body-measurement or health-tracking feature. Ordinary workout logs — exercises, sets, reps, weights, and dates — are used only to show you your own training and are not medical data. Some fields are free text (for example, workout notes), so if you choose to type health information there — such as an injury or a medical condition — that is your choice. Please avoid entering sensitive health details you would not want stored. To the extent anything you voluntarily enter qualifies as special-category data under Article 9 GDPR, we rely on the explicit consent you give by choosing to enter it (Art. 9(2)(a)); you can edit or delete it at any time, and you can remove all of it by deleting your account. We do not otherwise seek out or infer health data.

The AI coach

The AI coach is optional and requires you to be signed in. It is off until you choose to open it. The app clearly tells you, in the chat, that you're talking to an AI system and that your messages and relevant training data are sent to a third-party AI provider (Anthropic) to generate replies. By choosing to use the coach, you agree to this. If you never open it, none of your data is sent to Anthropic. You can stop using the coach at any time, and you can remove your chat history by deleting your account.

How it works:

The AI coach is not a decision-maker. It provides suggestions and general information only. It does not make any automated decision that produces legal or similarly significant effects for you (no processing under Article 22 GDPR).

The AI coach is not medical advice. It gives general fitness information only. It is not a substitute for a doctor, physiotherapist, or other professional. We show you this disclosure in the app. Please don't put personal data about other people, or sensitive information you'd rather not share, into the chat.

Who we share data with

We don't sell or rent your data. We share it only with the service providers ("processors") we need to run Reps, and only for the purposes below. Each acts under a data processing agreement with us.

Google Fonts

Separately from sign-in, the app and our website load two fonts (Anton and Inter) from Google Fonts. When a font is fetched, Google receives your device's IP address and user-agent. Google is an independent recipient here — it receives this data for its own purposes, not as a processor acting on our instructions. We rely on our legitimate interest (Art. 6(1)(f)) in displaying the app's typography. This is the only third-party data flow that also happens in local-only mode, and it applies even if you never create an account. For transfers of this data to the United States, Google relies on its certification under the EU–US Data Privacy Framework.

International transfers

Our database, authentication, and AI server are hosted in the EU. Some providers, however, are located in the United States, so using those features transfers data outside the European Economic Area:

Anthropic (AI coach). When you use the AI coach, your messages and relevant workout context are transmitted to Anthropic PBC (United States), which processes them solely to generate the coach's replies on our behalf as our processor under a Data Processing Agreement. This transfer to the United States is protected by the EU Standard Contractual Clauses (Commission Implementing Decision (EU) 2021/914) incorporated into our agreement with Anthropic. As noted above, under Anthropic's commercial terms Anthropic does not use these inputs or outputs to train its models and deletes them within 30 days, except where longer retention is required by law or to enforce its usage policy.

Sentry (optional error monitoring). Where error diagnostics are transferred to Sentry (United States), the transfer is protected by an appropriate safeguard under Chapter V GDPR (Standard Contractual Clauses, or the EU–US Data Privacy Framework where the provider is certified).

Google Fonts. As described above, the font fetch may transfer your IP address and user-agent to Google in the United States; Google relies on its EU–US Data Privacy Framework certification for that transfer.

You can ask us for more information about these transfers and safeguards by emailing privacy@repsworkout.com.

How long we keep your data

Notifications

Reps uses local, on-device notifications only — for example, a reminder about an unfinished workout. These are generated on your device. We don't use a push service, and no device tokens are sent anywhere.

What we don't do

We want to be clear about this:

Your rights

Under the GDPR (RODO), you have the right to:

How to exercise these rights. For most requests — including access and a copy of your data (portability) — email privacy@repsworkout.com. Please note: Reps does not have an in-app data-export or download feature, so we handle access and portability requests by email. For portability requests we provide the eligible data in a structured, commonly used, machine-readable format (for example JSON or CSV). We'll respond within one month, as required by Article 12(3) GDPR.

You can delete your account yourself in the app (see below).

Deleting your account

You can permanently delete your account and all your cloud data:

After the live data is deleted, any residual copies in our providers' encrypted backups are purged on the normal backup-rotation cycle — within about 30 days.

Deletion is permanent and cannot be undone.

Connecting external AI tools (optional — advanced)

Reps can connect to external AI tools using the Model Context Protocol (MCP). If you choose to connect an external client (for example, a desktop AI assistant), that client can read your training data at your direction. Any connection tokens are stored encrypted. This feature is entirely optional; if you don't connect an external client, nothing changes.

How we protect your data

We use reasonable technical measures to protect your data. We won't overpromise, but here's what we do:

No system can be guaranteed perfectly secure, but we take reasonable steps to keep your data safe.

Age requirement

You must be at least 16 to use Reps (this is the age of digital consent under Article 8 GDPR as applied in Poland). If you are under 16, you may only use Reps with the consent of a parent or guardian. This is a stated requirement; the app does not technically verify your age. If we learn that we hold data from someone under 16 without the required consent, we will delete it. A parent or guardian can contact us at privacy@repsworkout.com.

Changes to this policy

We may update this Privacy Policy from time to time — for example, when we add features or when the law changes. When we make material changes, we'll update the "Last updated" date at the top and let you know in the app. Please check back occasionally.

Complaints

If you believe we've handled your data improperly, please contact us first at privacy@repsworkout.com so we can try to put it right. You also have the right to lodge a complaint with the Polish supervisory authority:

Prezes Urzędu Ochrony Danych Osobowych (UODO)
ul. Stawki 2, 00-193 Warszawa, Poland
https://uodo.gov.pl

If you live in another EU/EEA country, you may also complain to your local data protection authority.

Contact

Szymon Łukiewicz
Poland