Privacy Policy

Last updated: August 2026

1. What we collect

Workout data: If you use Rep550 without an account, your progress (completed exercises, elapsed time, round count) is stored locally on your device only and is never transmitted to our servers.

Cloud sync (Rep550 Pro subscribers): If you create an account and subscribe, your current round and your round history are stored in our database so you can continue on any device and review past rounds. You can delete this data at any time by deleting your account.

Friends & sharing (Rep550 Pro): If you use the Friends feature, we store your optional display name, the email addresses of people you invite (kept while the invite is open — up to 30 days, after which it expires — so it can be linked if they join), your connections, and a log of connection changes (invited, accepted, disconnected). While you and a friend are both members, your current and past rounds are visible to each other; you can hide your results per friend, hide individual completed rounds (which also removes them from the friends leaderboard), or disconnect at any time, and lapsed memberships pause sharing automatically. Restarted rounds are never shared, and you can delete them from your history.

Public links (only ones you create): Nothing you do is public unless you press a button that makes it so. Two things can be published, both off by default and both reversible:

A finished round. Sharing a round from the completion screen copies that round — the exercises you completed, the time it took and the date — to a page at an unguessable web address, shown with your display name (or the part of your email before the @ if you haven't set one). Your email address itself is never shown. The page is a snapshot: changing your history later doesn't change it, and “Stop sharing” deletes it outright, after which the link stops working for everyone who has it. These pages ask search engines not to index them.

A live round. Creating a watch link from your account page makes a web address that shows the round you are doing right now — the grid as you complete it, how long you have been going, and your display name. It shows nothing when you aren't mid-round, and nothing about your history, your account or your membership. Turning the link off permanently breaks that address. Above it, “Share my live training” governs both audiences at once: with it off, neither your friends nor anyone holding a link can see the round in progress, and your finished rounds are unaffected either way.

Timing within a round: When you mark an exercise done, we record when. This stays with your own round data and is used to show your progress and pace; it is not part of what a friend or a public link shows.

Sessions: Signing in sets one cookie that identifies your account. Changing your password, resetting it, or using “sign out on all other devices” invalidates every session except the one you're using — so if you ever think someone else has access, changing your password removes it. That sign-in cookie is the only one Rep550 itself sets; the analytics providers above set their own, which the Cookie Policy lists. No analytics is loaded at all on pages whose address contains a link token or an email address.

Confirming your email: We record when you confirm your email address — by clicking a sign-in link, a confirmation link, or completing a password reset. Until an address is confirmed we treat it as unproven, so it can't be used to send or receive friend invites. This is what stops someone signing up with your address and receiving invites meant for you.

If someone invites you: Every invite email carries an unsubscribe link. Using it records your address on a do-not-invite list so no Rep550 member can invite you again — that list stores nothing but the address itself, and you don't need an account to use it. Declining an invite also blocks that person from re-sending it, and if you disconnect from a friend they cannot invite you again — only you can restart that connection.

Analytics events: We collect anonymised usage data (page views, session counts) via Google Analytics 4 and Facebook Pixel to understand how the app is used and improve it. This data does not identify you personally.

Product analytics (HeyCatch): We also use HeyCatch to understand how the app is used. It records page views, clicks and navigation between pages automatically. While you are signed in we additionally send your account identifier, your email address, your display name if you have set one, the state of your membership, and the date you signed up — so we can tell whether a change to the app helped real members rather than anonymous sessions. Signing out clears that association. Our server separately reports subscription events (started, changed, cancelled) against your account identifier; payment details are never part of it. Rounds, times and what you complete in the workout are not sent to HeyCatch.

Account & billing data: When you create an account we store your email address and a securely hashed password (we never store your password itself). If you subscribe, Stripe processes your payment details; we store only your email, Stripe customer reference, and subscription status.

2. How we use it

Analytics data is used solely to improve the product experience. Account data is used to verify your access and send sign-in links. We do not sell your data to third parties.

3. Third-party services

  • HeyCatch — product analytics. heycatch.ai
  • Google Analytics 4 — aggregated usage analytics. Google Privacy Policy
  • Facebook Pixel — advertising measurement. Meta Privacy Policy
  • Stripe (paid plan) — secure payment processing.
  • Resend (paid plan) — magic-link email delivery.

4. Data retention

Local workout data stays on your device until you clear your browser storage. Cloud-synced rounds, history, and friend connections (including the connection-change log) are retained while your account is active and deleted when you delete your account. Analytics data is retained per Google's and Meta's standard policies. Account and billing data is retained while your account is active.

5. Your rights

Depending on your location (e.g. EU/EEA under GDPR, California under CCPA), you may have the right to access, correct, or delete your personal data. To exercise these rights, please contact us. To opt out of analytics tracking, see our Cookie Policy.

6. Contact

For privacy-related requests, email us at hello@rep550.com.

← Back to Rep550