Repchitect Back to site
Legal

Privacy Policy

EffectiveAugust 22, 2026
Last updatedSeptember 5, 2026
Applies toTrainers, gyms, clients and site visitors
In plain English

Orientation only. This summary is not part of the policy.

Contents
  1. Who we are and what this covers
  2. Our role, and your trainer's role
  3. What we collect
  4. What we do not do
  5. Partner offers and affiliate links
  6. How we use information
  7. Legal bases
  8. Who else processes it
  9. Information stored on your device
  10. Portal links
  11. Photos, video and retention
  12. Before-and-after images
  13. Diagnostics and error reports
  14. Email
  15. The public trainer directory
  16. Fonts and map data
  17. Security
  18. How long we keep information
  19. Your rights
  20. Children
  21. International transfers
  22. Not a HIPAA service
  23. Changes and contact

01Who we are and what this covers

1.1 This policy explains how Repchitect, LLC (“Repchitect,” “we,” “us”) handles personal information in the Repchitect application, the client portal, the public trainer directory, our marketing site, and related services (together, the “Platform”).

1.2 It covers four groups of people: trainers and gym staff who hold accounts; clients who reach a trainer's coaching through a portal link; visitors who browse the marketing site or the trainer directory; and people who contact us or request access.

1.3 It works alongside our Terms of Service. Where the Terms describe the relationship, this policy describes the data.

02Our role, and your trainer's role

The key distinction Your trainer decides what information to collect about you and why. We provide the software that holds it. In data-protection terms your trainer is the controller and we are the processor, acting on their documented instructions.

2.1 For client information — programs, logged sets, measurements, photos, food entries, habits, check-ins and messages — the trainer or gym is the controller. They choose what to collect, how long to keep it, and who on their team can see it. We process it to run the Platform for them.

2.2 For trainer and gym account information — name, email, login credentials, subscription and billing records, support correspondence — we are the controller.

2.3 For visitors to the marketing site and directory, we are the controller of the limited information described in 3.4.

2.4 Practical effect for clients: if you want your information corrected, exported or deleted, start with your trainer. They control the account it lives in, and we act on their instruction. If you cannot reach them, contact us and we will help — see section 19.

03What we collect

3.1 Trainer and gym accounts

3.2 Client information, entered by a trainer

3.3 Client information, entered by you

Some of this is health-related. Body weight, measurements, food intake, soreness and injury notes say something about your health. We treat that information as sensitive, and where the law requires explicit consent for it, your trainer is responsible for obtaining that consent before asking you for it.

3.4 Technical information

We do not collect device fingerprints, advertising identifiers, precise location, contact lists, or anything from other apps.

04What we do not do

These are commitments, not omissions:

05Partner offers and affiliate links

5.1 What they are. Your trainer can add brand offers to their coach card in your portal. Repchitect may also present offers of its own to trainers or clients in future; those are labelled as coming from us, not from your trainer. Either way an offer is a link, and following it takes you off the Platform.

5.2 Your information is not part of the deal. We do not give the brand your name, email, training data or any other personal information. We place no advertising or conversion pixels on our pages. We put no identifier for you in the link. And the brand does not receive the address of the page you came from, so your portal link is never disclosed by following an offer.

5.3 Offers are not targeted using your data. Which offers you see depends on your trainer, or on the offer being shown to everyone. It does not depend on your weight, measurements, food log, habits, injuries or anything else you record. If we ever want to select an offer using your information, we will ask your permission first and you will be free to decline.

5.4 When you follow a link you leave us. The destination is an independent business. It sees your IP address and browser as any website does, its own privacy policy governs what happens next, and anything you buy is a transaction between you and them.

5.5 Commissions. Your trainer, or Repchitect, may earn a commission when someone buys through one of these links. It costs you nothing extra. It never changes your program, your targets or the advice you receive.

06How we use information

We use personal information only to:

We do not use client content for any purpose of our own beyond running the service and keeping it safe.

07Legal bases

Where the UK or EU GDPR applies, we rely on: contract, to provide the service you or your trainer signed up for; legitimate interests, to secure the Platform, prevent abuse, support users and run our business, balanced against your rights; legal obligation, for tax, accounting and lawful requests; and consent, where you give it, such as for publishing a before-and-after image or for marketing email. You can withdraw consent at any time without affecting what happened before. Where we act as processor for a trainer, the trainer is responsible for establishing the legal basis for collecting client information in the first place.

08Who else processes it

8.1 We use a small number of infrastructure providers. They process information on our instructions under contract, and they are not permitted to use it for their own purposes.

8.2 We may also disclose information: to professional advisers under confidentiality; to authorities where legally required, after review; to protect the rights, safety or property of any person; and to an acquirer in a merger or sale of assets, subject to this policy.

8.3 Client payments to trainers do not pass through us. When you follow a trainer's payment link you leave the Platform and deal with that trainer's own payment provider under their privacy policy. We receive no payment details and no confirmation of what you paid.

09Information stored on your device

9.1 The app sets no cookies. It does use your browser's local storage, which stays on your device and is not transmitted to us as a tracking signal.

9.2 On a client's device the portal saves: your portal token, so the app reopens without the link; a snapshot of your current program and recent activity, so workouts open and log without a signal; a queue of sets logged offline, held until they can be sent; your workout position; and your theme choice.

9.3 This matters on a shared device. The snapshot contains your program and training information in readable form, and the saved token grants access to your portal. On a shared or public computer, use a private window, or clear site data when you are done.

9.4 On a trainer's device the app stores a login session and a small cache of account settings.

9.5 For directory visitors the map keeps a cache of city coordinates so it does not repeat lookups. It holds place names, never your location.

9.6 Clearing your browser's site data removes all of it. Anything not yet synced is lost, so connect first if you have logged sets offline.

9.7 Notifications are optional and per device. If you turn them on, your browser creates a push subscription for that device and we store it, with the device's time zone and browser type, so that we can send the notifications you chose. Each one is a title and a single line, such as "New message from your coach": never the message itself, and never anything that identifies you to the push service. Every kind of notification can be switched off, and turning notifications off, or clearing site data, deletes the subscription. A subscription that stops working is deleted. On iPhone, notifications work only for the app added to the Home Screen. We send nothing of our own through them: no announcements, no offers.

10Portal links

10.1 Clients do not create passwords. Access runs on a private link containing a token, which the app presents on every request. Anyone holding that link can see that client's information.

10.2 Keep it private. Do not post it, forward it, or leave it open on a shared device. Because the token travels in the link, it can also be recorded in browser history and in the history of any device where the link was opened.

10.3 If a link is exposed, ask your trainer to issue a new one, which retires the old one.

10.4 We never place a portal token in an image address, in an email we send on a trainer's behalf to a third party, or in any log we retain for analysis.

11Photos, video and retention

11.1 Progress photographs are held in private storage. They are not publicly addressable. When your trainer or you view them, the app requests a temporary signed link that expires after about an hour. The file address itself is scoped to the client it belongs to, so one client's images cannot be reached from another's session.

11.2 Form-check videos are uploaded to our media provider and delete automatically after approximately 30 days. If a video matters to you or to your trainer's records, download a copy. The Platform is not an archive.

11.3 Trainer demonstration videos that a trainer records for reuse are kept until the trainer deletes them.

11.4 Exercise demonstration clips in the built-in library are generic stock material. They contain no user content.

12Before-and-after images

The only images that become public Everything else in this app stays in private storage. A published before-and-after pair is world-readable by design, so it is handled differently at every step.

12.1 A trainer may publish before-and-after image pairs on their public page. Publication requires recorded consent. The system will not publish a pair unless a consent timestamp is stored against it.

12.2 Publishing copies the image into public storage. It does not simply expose the private original. This is deliberate: it means withdrawing consent can actually remove the public file.

12.3 Withdrawing consent deletes the public copy, and the address stops resolving. Ask your trainer, or contact us and we will act on it.

12.4 The public file address contains no client identifier, so it does not reveal whose body it is. The link between an image and a client stays in the database, behind access controls.

12.5 What we cannot undo: once an image has been public, someone may have copied, screenshotted, cached or indexed it. Removal stops future access from us; it cannot retrieve copies already taken. Consider that before agreeing to publication.

13Diagnostics and error reports

13.1 When the app hits an error it sends us a report so we can fix it. A report contains the error message, the file and line it came from, the app version, and a short trail of the last few actions taken.

13.2 That trail records which element was used, never what it said. A button is recorded by its identity, not by its label, because a label can carry a person's name. Credentials and tokens are stripped before storage.

13.3 Reports are deduplicated, so a repeated fault is stored once rather than thousands of times, and they are readable only by us.

13.4 Reports are not used to build profiles, measure engagement, or track anyone across sessions.

14Email

14.1 We send service email: invitations, password resets, account and billing notices, and security alerts. These are part of the service and cannot be turned off while an account is active.

14.2 Marketing email, if we send it, is sent only to trainers and requires opt-in where the law requires it. Every marketing message carries an unsubscribe link.

14.3 We do not use tracking pixels to record whether you opened a message.

14.4 Email sent between a trainer and a client outside the Platform is between them. We are not a party to it.

15The public trainer directory

15.1 Trainers choose whether to publish a public page. Nothing appears in the directory until a trainer publishes it.

15.2 Published means public. A published page can be read by anyone, indexed by search engines, cached and copied. Trainers should publish only what they are content for the world to see, including photographs, prices and location.

15.3 Contact details appear on a public page only if the trainer switches that on. When it is off, those details are not merely hidden from view — they are not present in the published record at all.

15.4 Unpublishing removes a page from the directory going forward. Search engine caches are outside our control.

15.5 Browsing the directory requires no account, and we do not build a profile of what a visitor looked at.

16Fonts and map data

16.1 Fonts. Typefaces are served from our own servers. Loading a page of ours sends no request to a font provider and discloses nothing to one.

16.2 Maps. The directory's map view is optional and loads only when you open it. When you do, map images are fetched from OpenStreetMap, which receives your IP address as part of that request. Turning city names into map positions uses the same provider's lookup service. We do not request, collect or transmit your device location. The map centres on the trainers shown, not on you.

16.3 Video playback loads from our media provider, which receives the technical information any video service needs to stream a file.

17Security

17.1 Measures we maintain include: encryption in transit; row-level access rules in the database so a trainer reaches only their own clients and a client reaches only their own record; private storage with short-lived signed links for photographs; a strict content security policy limiting what code and content a page may load; privileged keys held only in server-side secrets and never in the browser; rate limiting on sensitive endpoints; and separation of the client portal from the trainer application.

17.2 Your part: trainers should use a strong, unique password and keep their device secure; clients should treat a portal link as a password.

17.3 No system is perfectly secure and we cannot guarantee absolute security. If a breach affecting your personal information occurs, we will notify affected users and, where required, regulators, within the time the law allows. Where we act as processor for a trainer, we will notify the trainer without undue delay so they can meet their own obligations.

17.4 Report a suspected vulnerability or compromise to security@repchitect.com.

18How long we keep information

We also keep what we must to resolve disputes, enforce agreements and comply with law.

19Your rights

19.1 Depending on where you live, you may have the right to access a copy of your information, correct it, delete it, restrict or object to processing, receive it in a portable format, withdraw consent, and not be discriminated against for exercising these rights. We do not make decisions about you by automated means that produce legal or similarly significant effects.

19.2 Clients: start with your trainer, who controls your record. If you cannot reach them, or they do not respond, contact us at privacy@repchitect.com and we will help you reach a resolution.

19.3 Trainers and gyms: contact us directly at privacy@repchitect.com. You are also responsible for responding to your own clients' requests, and we will support you in doing so.

19.4 We respond within 30 days, or sooner where the law requires. We may need to verify identity first, and we will not use verification information for anything else. An authorised agent may act for you with proof of authority.

19.5 California residents: we do not sell or share personal information as those terms are defined under the CCPA/CPRA, and we have not done so in the preceding twelve months. We do not use or disclose sensitive personal information beyond the purposes permitted for providing the service.

19.6 EU and UK residents: you may lodge a complaint with your supervisory authority. We would appreciate the chance to address it first.

19.7 Deletion has consequences. Deleting a client record removes training history, photographs and progress data permanently. Ask your trainer to export anything you want to keep before you ask for deletion.

20Children

20.1 The Platform is not directed to children under 13, and we do not knowingly collect their information.

20.2 A trainer who coaches a minor is responsible for obtaining verifiable consent from a parent or guardian before entering that minor's information, and for complying with the laws that apply where they operate.

20.3 If you believe a child's information has been provided without proper consent, contact privacy@repchitect.com and we will delete it.

21International transfers

21.1 We operate from the United States and our providers operate globally, so information may be processed in countries whose data-protection laws differ from your own, including the United States.

21.2 Where we transfer information out of the UK, EEA or another region requiring it, we rely on approved safeguards such as Standard Contractual Clauses, together with the technical measures in section 17. Contact us for details of the safeguards for a specific transfer.

22Not a HIPAA service

22.1 Repchitect is a general fitness tool. It is not designed or offered as a HIPAA-compliant service or an electronic medical record, and we do not enter business associate agreements unless separately agreed in writing.

22.2 Trainers must not use the Platform to hold protected health information in a regulated capacity, and should not record clinical diagnoses, treatment records or medical documentation in it.

23Changes and contact

23.1 We may update this policy. The effective date at the top always reflects the current version, and we keep prior versions available. For material changes we give notice in the app or by email before they take effect.

23.2 Questions, requests and complaints: Repchitect, LLC, 1325 Ave of the Americas #27, New York, NY 10019, privacy@repchitect.com.