Privacy Policy

    How Reppit handles your data: what we collect, why we are allowed to, who else sees it, and what you can make us do with it.

    Version 2.0 · Effective 21 September 2026 · Last updated

    Who we are

    Reppit is made by Steinslett Solutions ENK, a sole proprietorship registered in Norway (D-U-N-S 347783385). We are the data controller for everything described here. Reach us at hello@reppit.fit.

    What we collect

    • Your account: email, username, display name, date of birth, country, and a password (hashed — we never see it). If you sign in with Apple or Google we get your name and email from them, nothing more.
    • Your training: workouts, sets, reps, weights, rest times, notes, programs, goals, experience level and available equipment.
    • Your body stats: weight, height and measurements you enter, and body photos if you add them.
    • What you post: feed posts, comments, reactions, stories, clips, group and challenge activity, and the gym you tag a session at if you choose to.
    • Your Coach conversations: what you ask Coach, what it answers, and the training data it reads to answer.
    • Device and usage data: device type, OS and app version, timezone, which screens you use, crashes and errors, your IP address, and a push token if you turn notifications on.

    Training and body data can count as health data under GDPR Article 9. We process it because you explicitly chose to give it to us by using the app for what it is.

    What is public, and what is not

    Anything you post to the feed, a group or a challenge is visible to other Reppit users, and a shared program or profile link can be opened by anyone who has it, including search engines. If you delete a post we remove it, but we cannot recall a screenshot someone already took.

    Body photos are not part of this. They never appear in the feed, on your profile or anywhere another user can reach — they are served only to you, over an authenticated request, and location data is stripped out of the file before it ever leaves your phone. They are encrypted on our servers. If you set up a photo passphrase, they are also encrypted on your device first, with a key only you hold, and then we cannot open them at all.

    Your workouts, Coach conversations and body stats are private unless you post them.

    Why we are allowed to use it

    What we doLegal basis
    Run your account, your training and CoachContract — Art. 6(1)(b)
    Process health data (training, body stats, photos)Explicit consent — Art. 9(2)(a)
    Take subscription paymentsContract — Art. 6(1)(b)
    Keep the service secure, stop abuse, moderate what is postedLegitimate interest — Art. 6(1)(f)
    Fix bugs and improve the app, including CoachLegitimate interest — Art. 6(1)(f)
    Send you marketing emailConsent — Art. 6(1)(a), opt in, withdraw anytime
    Keep payment recordsLegal obligation — Art. 6(1)(c)

    Where we rely on consent you can withdraw it at any time, and where we rely on legitimate interest you can object — email us and we will act on it. Neither undoes processing we already did.

    Who can read your data

    Reppit is a small team. To support you, debug a problem, moderate a report or check that Coach is giving sane advice, we may read your workouts, your posts, your Coach conversations and the messages you send us. We look when there is a reason to, not routinely. We do not go looking at body photos, and if you have set a photo passphrase we could not read them even if we tried.

    Your Coach conversations and training data also help us improve how Coach works. We do not sell them, we do not use them for advertising, and we do not hand them to anyone to train a general-purpose AI model. If you would rather we did not use yours this way, email us and we will exclude you.

    Who we share it with

    We do not sell your data. We use these providers to run Reppit:

    • Hetzner (Germany and Finland) — the servers and the database Reppit runs on
    • Amazon Web Services (EU regions) — file storage, the CDN, and the email we send you
    • Apple and Google — sign-in, the app stores, subscriptions and push notifications
    • RevenueCat (United States) — keeping track of who has an active subscription
    • OpenAI (United States) — generating Coach's replies, under terms that forbid keeping your data to train on

    Your account, training and photos live on servers in the EU. Where a provider is in the US, the transfer is covered by the EU–US Data Privacy Framework or the European Commission's standard contractual clauses. Beyond that we hand data over only when the law requires it, or to protect someone's safety.

    How long we keep it

    WhatHow long
    Your account, training, photos and Coach historyUntil you delete them, or delete your account
    Posts you madeUntil you delete them
    Payment records5 years — Norwegian bookkeeping law
    Support email3 years
    Crash and security logs90 days for crashes, 12 months for security
    A deleted accountErased within 30 days, apart from what the law makes us keep

    Your rights

    Under GDPR you can ask us for a copy of your data, correct it, delete it, restrict or object to how we use it, or get it in a portable format.

    You can delete your account yourself, from Settings in the app. That erases your data on the schedule above. For anything else — a copy of your data, a correction, an objection — email hello@reppit.fit and we will answer within 30 days.

    If you think we have got it wrong, you can complain to Datatilsynet, the Norwegian Data Protection Authority, or to the equivalent authority where you live.

    Age

    You need to be 13 or older to use Reppit. If you are under 16, your parent or guardian needs to agree to you using it. If we find an account belonging to someone under 13 we delete it. Parents can email us to see or delete their child's data.

    Keeping it safe

    Everything travels over TLS, the database and file storage are encrypted at rest, body photos get a second layer of encryption of their own, and passwords are hashed. Access to production is limited to the people who need it. No system is perfect: if there is a breach affecting you, we tell Datatilsynet within 72 hours and you as soon as we know it matters to you.

    Cookies

    The website uses only the cookies it needs to work. No analytics, advertising or tracking cookies, on the site or across other apps. If that ever changes we will ask you first.

    Changes

    If we change how we handle your data in a way that matters, we will tell you in the app or by email before it takes effect. Questions, complaints or requests: hello@reppit.fit.

    See also our Terms of Service, or read who makes Reppit.