Privacy Policy
Effective 2 September 2026
The short version
REPS X is a workout tracker. Your workout data belongs to you. We collect the minimum needed to run the app: an optional sign-in identity and your training progress. We show no ads, we run no third-party ad or tracking SDKs, and we never sell your data.
What we collect and why
- Account (optional). If you sign in (Google, or Apple on iOS), we receive your name, email address and profile photo from that provider via Firebase Authentication. Signing in is needed for cross-device sync and food photo scans. Basic workouts and manual food logging for subscribers work without an account, storing data on your device.
- Workout data. Completed days, streaks, rep levels, test results, ratings, settings and cycle history. Stored on your device; if you sign in, also in Google Firebase (Realtime Database) under your account so your devices stay in sync.
- Purchases. Subscriptions are processed by Apple (App Store), Google (Play) or Stripe (web) — we never see your payment details. RevenueCat, our subscription manager, receives purchase receipts and an app user ID to unlock Premium across your devices.
- Microphone (optional). Voice rep counting listens for counting words using speech recognition on your device. Audio is used live for recognition and is not recorded, stored or uploaded by us. The microphone is only active while voice mode is on during a workout.
- Health data (Apple Watch, optional). The watch app can run workout sessions through Apple HealthKit (heart rate, calories, workout time). That data stays in Apple Health under your control — it is never transmitted to our servers, never used for advertising, and never shared with third parties.
- Body profile and food log (optional). The Calories tab can store the weight, height, birth year and sex you enter (to estimate resting and workout energy) and the meals and activities you log. This is stored on your device and, when signed in, in your account’s own database node so your devices stay in sync. It is never used for marketing. You can clear your food log in You; deleting your account removes the cloud profile and food log as well.
- Food photos (optional). If you use the photo scan in Calories, the photo you take is sent over an encrypted connection to our server and on to our AI provider, OpenAI, to estimate what the food is and its calories. Food photos you scan are kept in your account so you can review them; delete any photo from the gallery, and deleting your account removes them all. Photos are stored with our hosting provider, Netlify, and are readable only by your signed-in account. The provider processes the image to return the estimate, does not use it to train its models under the API terms we use, and may hold it for up to 30 days for abuse monitoring. We also keep a per-account count of scans per day to apply the daily limit. Scanning is optional and needs you to be signed in.
What we don’t do
- No advertising and no ad SDKs.
- No selling or renting of personal data — to anyone, ever.
- No use of health or fitness data for marketing.
- No data collection from children — REPS X is not directed at children under 13.
Where your data lives
Cloud data is stored in Google Firebase (project servers in the EU/US) and subscription state in RevenueCat. Both act as processors for us. On your device, data is kept in the app’s local storage and never leaves it unless you sign in. Food photos you choose to scan are processed by OpenAI (United States) as a processor for us and stored for you in Netlify Blobs (United States) until you delete them or your account.
Your controls
- Export: Settings → Data Backup exports everything to a file you own.
- Delete: You → Account → Delete account removes your sign-in identity and all cloud data immediately, including your food photos (you confirm by signing in once more). You → Start the 30 days again wipes progress on one device only. If you cannot open the app, email us from the signed-in address and we’ll remove your account and cloud data within 30 days. Step-by-step instructions are on the Support page.
- Sign out: stops all cloud sync immediately; your local data stays on the device.
- Subscriptions: manage or cancel in your App Store / Google Play account settings; on web, through the billing portal link in the app.
- Photo scans: never automatic. A photo is sent only when you take or choose one with the Photo button, and only that photo.
Legal bases (UK/EU)
We process account and workout data to perform our contract with you (running the app and sync you asked for), and purchase data to fulfil your subscription. Where consent applies (microphone, HealthKit), the operating system asks you first and you can revoke it in system settings at any time.
Changes & contact
If this policy changes materially we’ll update the date above and note it in the app’s What’s New. Questions or data requests: syedahmadfahmybinsyedsalim@gmail.com. Need help with the app? See Support.