Your training record stays under your control.
This policy covers the RepChat iOS app and web service. It explains what personal data RepChat collects, why it is used, when it is disclosed, how long it is retained, and the controls available to you. RepChat is operated by the developer identified in its App Store listing and is the controller of the account data described here.
Information RepChat collects
- Account and profile: name, email address, a securely hashed password when one is set, account ID, linked Google or Apple provider and provider-specific account identifier, the provider's verified email address, and an optional name supplied during account creation; unit and appearance preferences; timezone; and optional date of birth, sex, height, weight, primary goal, activity level, and training experience.
- Training and fitness: Exercises, sets, repetitions, weight, distance, duration, elevation, effort, saved Workouts, Calendar entries and recurrences, completion History, Goals, Progress, Recovery, and related estimates.
- Apple Health, when you choose to connect it: RepChat may receive heart-rate data for the time of a completed Workout and reduce it on your device to 30-second summaries before upload. RepChat stores average and peak heart rate, recovery measurements, measurement coverage and gaps, coarse source and Workout-match classifications, optional heart-rate zones and time in zone, and the derived curve used for your private Workout insight. RepChat does not upload or store the raw heart-rate samples, HealthKit object identifiers, device names, product identifiers, serial-like identifiers, or source-app bundle identifiers.
- Content and sharing: Workout and Goal names, chat messages, AI prompts and voice transcripts, clarification replies, reports, AI action records, goal-friend relationships, the progress you choose to share with a RepChat friend, and sanitized Saved Workout snapshots you explicitly send to a reciprocal friend.
- Device, security, and operations: a random app-specific iOS device identifier, device name and platform, app version, native and web session records, encrypted ActivityKit push tokens, Live Activity preferences, IP address, approximate country derived from that address, user agent, essential session-cookie data, encrypted MFA authentication factors, keyed hashes and use status for MFA recovery codes, short-lived TOTP replay-prevention counters, synchronization and mutation records, audit records, and technical error and performance events. Plaintext recovery codes are shown once and are not stored by RepChat.
This information comes from you, from your use of RepChat and your device, from Google or Apple when you choose that sign-in method, from Apple Health only when you choose to connect it, and from a RepChat friend when you choose to follow their shared Goals. Optional profile fields can be left blank. RepChat does not currently collect payment information, contacts, precise location, advertising identifiers, photos, or videos.
How RepChat uses information
- To create and secure your account, synchronize devices, preserve offline changes, maintain History, and provide Calendar, Workout, Goal, Progress, Recovery, export, and sharing features.
- To calculate fitness estimates and personalize insights, suggested durations, default information cards, and AI assistance using your selected goal and optional profile and training context.
- When you connect Apple Health, to match a completed RepChat Workout to its time window, provide a private cardiovascular-demand story and private Goal metrics, and, if you separately enable export, prepare that completed Workout to be saved to Apple Health and contribute to Activity progress.
- To deliver notifications and Live Activities, prevent fraud and token reuse, investigate synchronization problems, recover the database, measure reliability, and protect RepChat and its users.
- To comply with law, enforce RepChat's terms, and respond to support requests.
Where applicable law requires a legal basis, core processing is necessary to provide the service you request; AI Trainer and microphone processing rely on your consent; security and privacy-filtered reliability monitoring serve RepChat's legitimate interests; and some processing may be required by law. You may withdraw AI consent at any time without disabling the rest of RepChat.
AI Trainer, text, and voice
After you explicitly allow AI Trainer, RepChat sends your prompt or voice transcript and the relevant Workout, Calendar, Goal, Progress, and optional Profile context to OpenAI so it can interpret the request, answer it, or prepare an action. In Realtime voice mode, microphone audio is streamed to OpenAI while the session is active. RepChat does not store the raw microphone audio, but it stores the resulting request or transcript, action, result, and usage totals under the retention schedule below. RepChat does not send your password, authentication tokens, Calendar-feed token, or ActivityKit push token to OpenAI. RepChat also excludes Apple Health-derived data from AI Trainer prompts and context.
OpenAI processes this information under its API terms and published data controls. Those controls state that API data is not used to train OpenAI models by default unless the API customer opts in, and that default abuse-monitoring or application-state retention can be up to 30 days, with longer retention possible when legally required. Avoid including information you do not want processed in a chat or voice request.
Apple Health controls and isolation
Connecting Apple Health is optional and separate for each RepChat account. RepChat stores your RepChat consent and feature choices, but Apple intentionally does not tell apps whether you denied permission to read a type. RepChat therefore does not label an absence of measurements as a permission denial. You manage HealthKit permission in Apple's system settings.
Apple Health-derived summaries and private Health Goal metrics are visible only to the account that connected Apple Health. They are excluded from friends and followers, shared Goals, shared-Workout snapshots and notifications, administrator user and AI review screens, AI Trainer context, Calendar feeds, logs, error reporting, observability metrics, and native diagnostics. RepChat does not use Health data for advertising, marketing, tracking, sale, or data-broker services.
Disconnecting stops future RepChat processing and can delete historical Apple Health-derived summaries stored by RepChat. It does not claim to revoke device permission and does not automatically delete Workouts already written to Apple Health; those require a separate explicit action. Signing out alone does not delete Apple Health data or your RepChat summaries. Deleting a completed RepChat Workout removes its linked summary and export-control record from RepChat, and deleting the account removes all RepChat Apple Health settings and summaries.
Service providers and other disclosures
RepChat discloses only the data needed for the following purposes:
- When you choose Google or Apple sign-in, that provider authenticates you and sends RepChat a verified email address, stable provider-specific identifier, and an optional display name. Apple supplies a name only on the first authorization and may provide a private-relay email address instead of your underlying address. RepChat treats that relay address as your provider-verified address. RepChat does not retain provider access tokens, refresh tokens, authorization codes, or identity tokens after the sign-in transaction.
- Hosting, PostgreSQL database, and encrypted backup providers process account and training data to operate and recover the service.
- OpenAI processes consented AI Trainer text, context, audio, and responses.
- Apple receives device and ActivityKit tokens and the compact notification or Live Activity content needed to deliver it. Workout details can be hidden in Profile → Notifications & Live Activities.
- Sentry receives web and server error and performance events. Session replay is disabled, and RepChat removes user identity, cookies, headers, request bodies, and query strings before export; technical exception text, stack traces, and route paths may remain. Better Stack receives sanitized availability and backup-health events.
- ExerciseDB receives a normalized exercise search term or exercise identifier when RepChat retrieves an exercise demonstration. It does not receive your RepChat account ID from RepChat.
- On successful sign-in, ipwho.is may receive your IP address to return an approximate country for login-security history.
- RepChat may disclose information when you direct it, to protect rights and safety, or when required by a valid legal process.
Providers may process data in the United States or other countries where they operate. RepChat uses appropriate contractual, technical, and organizational safeguards when required for an international transfer.
Google and Apple sign-in controls
RepChat identifies a linked Google or Apple account by the provider's stable account identifier, not by email alone. A matching email does not automatically merge accounts. You can review, add, or remove sign-in methods from Profile → Sign-in & Security after fresh identity verification. A sign-in method cannot be removed if it would leave the account with no usable way to sign in.
You can also revoke RepChat's access in your Google Account's third-party connections or in Apple Account Sign-In & Security under Sign in with Apple. Provider-side revocation stops or resets future provider authorization, but it does not delete your RepChat account or training record. You must use RepChat's account deletion control to delete that data. If you later authorize the same linked provider account, RepChat uses its stable identifier to return you to the existing RepChat account even if the provider email has changed.
No advertising, sale, or tracking
RepChat does not show third-party advertising, sell personal data, share personal data for cross-context behavioral advertising, or combine RepChat data with data from other companies to track you across apps or websites. RepChat does not use Apple's advertising identifier. Service-provider processing and user-directed Goal sharing are not advertising tracking.
On-device storage, cookies, and diagnostics
The iOS app keeps an account-scoped SQLite cache and pending offline changes on your device and protects session credentials and its random device identifier in Keychain. The web app uses a secure, HTTP-only session cookie and local storage for settings such as theme, chart view, selected insight cards, and synchronization position. These are functional technologies, not advertising trackers.
The iOS app uses Apple MetricKit and a closed set of content-free counters for crashes, hangs, launch, synchronization, voice failures, and database recovery. RepChat does not upload MetricKit payloads, stack traces, Workout content, profile fields, record IDs, prompts, tokens, or response bodies from the native diagnostic store. Apple may process system diagnostics under your device analytics settings.
Friend sharing, Calendar feeds, and Lock Screen privacy
A person who enters your Goal sharing word can see your display name and Goals you have not marked hidden, including their current progress. You can hide individual Goals, stop sharing with a friend, or regenerate the sharing word. You may also send a reciprocal friend a sanitized snapshot of a Saved Workout. The snapshot excludes your notes, completion History, scheduled Workouts, and account identifiers. If the friend adds it to their library, their copy is independent: later edits, friendship changes, or deletion of your original do not alter or remove their copy. A Calendar subscription URL is a bearer secret: anyone who has it can read the Calendar items in that feed. Disable and re-enable the feed to invalidate an old URL.
Live Activities can display a Workout name, exercise, and set details on a Lock Screen, Dynamic Island, StandBy display, iPad, or paired Apple Watch. Use Profile → Notifications & Live Activities to disable them or hide Workout details, and use device notification settings to control their system access.
Retention schedule
- Expired review drafts are removed by the next daily cleanup.
- Abandoned Workout Builder sessions are removed after 1 day.
- Unanswered AI clarifications expire after 14 days. Completed or failed AI runs and detailed steps are removed after 30 days, and command records after 45 days.
- Compact AI quality reviews—including the request, action flow, diagnosis, and administrator decision—are removed after 90 days.
- Chat messages are removed after 90 days.
- Login-security and system-event history are removed after 90 days. Server performance measurements are removed after 30 days.
- Detailed audit snapshots are reduced to changed-field names after 30 days; compact audit records are removed after 365 days.
- Used or invalidated MFA recovery-code records are removed after 365 days. Active unused recovery codes remain until they are used, regenerated, MFA is disabled, the administrator role changes, or the account is deleted.
- TOTP replay-prevention counters are removed after 2 days.
- Idempotency responses used to prevent duplicate mutations expire after 48 hours. Native refresh sessions normally expire after 30 days, and short-lived authorization codes are removed after use or expiry. Synchronization changes normally remain available for incremental clients for 45 days before compaction.
- Device and Live Activity registrations are revoked when replaced, signed out, rejected by Apple, or disconnected from an active native session. Associated operational rows otherwise remain until account deletion.
- A linked Google or Apple provider and its stable account identifier remain while that sign-in method is linked. They are removed when you unlink the provider or delete the RepChat account. Transient provider tokens and authorization codes are not retained.
- Your Profile, Exercises, saved Workouts, Calendar, History, Goals, body-weight history, and active preferences remain until you remove them or delete your account.
- Apple Health consent settings and derived summaries remain until you disconnect and choose to delete historical summaries, delete the linked completed Workout, or delete your account. Export-control records remain only while the linked completed Workout remains in RepChat.
Daily encrypted database backups are isolated from routine use. Production-server copies roll off after 14 days, an operator-held encrypted recovery copy after 30 days, and independently stored encrypted versions after no more than 90 days. A deleted account can therefore remain only in isolated disaster-recovery backups until those copies age out. Backups are used for service recovery, not routine account access. Legal, fraud-prevention, or security obligations may require limited information to be retained longer.
Your controls and privacy rights
- Correct optional account and Profile information from Profile.
- Download a portable JSON copy of account, profile, training, Calendar, Goal, AI, audit, usage, login-history, and any retained Apple Health consent settings and derived summaries from Profile → Privacy. The export excludes raw samples, source identifiers, installation hashes, internal claim leases, and telemetry.
- Withdraw AI Trainer permission, clear rebuildable downloaded iOS data, manage signed-in devices, and control Goal, Calendar-feed, notification, and Live Activity sharing.
- Permanently delete the account from Profile → Privacy after fresh identity verification: password and MFA when applicable, or an already linked provider for an account without a password. This removes active account data and provider links, invalidates sessions and Calendar access, and starts the backup-expiry period described above.
Depending on where you live, you may also have rights to access, correct, delete, restrict, object to, or receive a copy of personal data, withdraw consent, and complain to a privacy regulator. RepChat will not discriminate against you for exercising an applicable privacy right. Use the controls above or the support contact below. RepChat may need to verify that the request concerns your account.
Security and your responsibilities
RepChat uses HTTPS, password hashing, restricted administrative access, secure native token storage, optional member MFA, mandatory administrator MFA, token encryption where appropriate, redacted operational telemetry, and encrypted backups. No system can guarantee absolute security. Use a unique password when you set one, enable MFA where available, protect signed-in devices and sharing links, and report suspected unauthorized access. Exported files and Calendar feeds are under your control once downloaded or shared.
Children
RepChat is a general fitness service and is not directed to children under 13. A person under 13 must not create an account or submit personal data. Contact RepChat if you believe a child's information was provided to the service.
Contact and policy changes
For privacy questions or rights requests, use the public support contact identified in RepChat's App Store listing or visit the RepChat Support page. Do not include passwords, authentication tokens, or unnecessary health details in a support message. Material changes will be published here with a new effective date and, when required, presented in the app.
Fitness estimates
Calorie, recovery, BMR, TDEE, BMI, MET, and performance figures are estimates, not medical advice. RepChat is not a healthcare provider, and the service is not intended to diagnose, treat, cure, or prevent a condition.
Effective September 27, 2026.