Privacy notice
Repdelta is a private workout journal. This notice explains how the Repdelta website and cloud service use your information. Independently self-hosted instances are controlled by their own operators.
Who is responsible
Jovan Rakic, operating Repdelta in Switzerland, is responsible for the personal data processed by the official cloud service. Send support, privacy, or data-rights requests to the contact below.
Jovan Rakic, operating Repdelta
Switzerland
jovan@rakic.ch
Information we use
- Account information: identity-provider account identifiers, name, email address, and profile preferences.
- Your journal: workouts, dates and times, exercises, sets, repetitions, weights, notes, body-weight entries, and photos you choose to upload.
- Subscription information: payment-provider customer and subscription identifiers, subscription status, billing interval, and payment events needed to manage access. Payment card details are entered with Stripe, not stored in Repdelta’s journal database.
- Technical information: session identifiers and the request information necessary to deliver the service, prevent abuse, and investigate failures, which can include IP addresses and browser information.
- Correspondence: information you send when asking for support or exercising your rights.
Photos and notes can reveal sensitive information. Only upload material you are comfortable storing in your private account. Body-progress photos are re-encoded by the app to remove camera and location metadata.
Why we use it
We process information to create and authenticate your account, save and display your journal, manage trial and subscription access, answer support requests, protect the service, and meet applicable legal obligations. Where applicable data-protection law requires a legal basis, these activities rely on providing the service you request, legitimate interests in security and support, and legal obligations. Optional photos and notes are supplied at your choice; delete them when you no longer want them kept.
Service providers and international processing
The marketing website is served by Cloudflare. The cloud app and journal database are hosted on a European VPS. Logto provides hosted sign-in; if you choose Google sign-in, Google also processes information for that sign-in. Stripe provides subscription checkout and billing. Our email provider processes correspondence sent to our support address.
These providers receive information needed for their role. Sign-in providers receive account and authentication information; Stripe receives information needed for checkout, payment, and subscription management; infrastructure providers process requests and hosted data. Your workout journal and photos are not sent to Stripe for payment processing.
Provider processing can take place outside your country, including outside Switzerland and the European Economic Area. The providers’ privacy notices describe their own processing: Cloudflare, Logto, Stripe, and, if used, Google. Contact us for information about the hosting location and applicable transfer safeguards.
Cookies and browser storage
The marketing website does not add analytics, advertising trackers, or account cookies. The app uses necessary session cookies for sign-in, and browser storage to recover workout edits if a save fails. The current app does not support offline sync. Sign-in and payment services have their own necessary storage and privacy notices. Remove recovered drafts from shared browser profiles if needed.
Privacy and security
Your journal is associated with your account and is not a public feed. Account checks restrict access to private journal data and photos. We use HTTPS for the public service. Authorized operational access may be needed to maintain the service or handle your request. No internet service can guarantee absolute security.
Retention and deletion
We retain your journal while your account exists, including if your subscription lapses, so cancellation does not erase your training history. You may delete individual journal items in the app. To request account deletion, email us from your account email address; we may verify the request before acting.
We aim to delete account and journal data from the live service within 30 days of a verified deletion request. Residual backup copies expire within 90 days and are not used for ordinary service access. A restoration must preserve verified deletion requests. Records required for accounting, legal obligations, or the resolution of disputes may be retained for the period those purposes require. Stripe and sign-in providers may separately retain information under their own policies.
Your choices and rights
Depending on the law that applies, you may request access to your information, correction, deletion, a copy or portability, restriction of processing, or object to certain processing. Email us to make a request. You can also contact your local data-protection authority; in Switzerland this is the Federal Data Protection and Information Commissioner. Requests for a data copy are handled through support; the app does not currently include a self-service export.
Changes
We update this notice when our processing changes. The date above identifies the current version. We will provide notice of material changes where appropriate.