Privacy Policy for Rep

Last updated: August 23, 2026

Rep ("we," "our," or "us") is committed to protecting your privacy and complying with applicable data protection laws, including the UK General Data Protection Regulation (UK GDPR) and the EU General Data Protection Regulation (EU GDPR). This Privacy Policy explains how your information is collected, used, and safeguarded when you use our mobile application.

1. Information We Collect

  • Location Data: We collect precise and approximate location data (GPS) while you record an interval run to calculate distance, pace, routes, and splits. Location data is only recorded when an active workout is in progress.

  • Workout & Activity Data: Information related to your training sessions, such as intervals, run duration, split times, and target metrics.

  • Authentication & Third-Party Integration Data: When you connect Rep to third-party services (such as Strava), we use backend infrastructure to securely handle OAuth authentication tokens and profile identifiers required to sync your workout activities.

  • On-Device Data: Workout history and user preferences are stored locally on your device database.

2. How We Use Your Information & Legal Bases (GDPR)

Under UK and EU GDPR, we process your personal data only when we have a valid legal basis. We use your information for the following purposes:

  • Performance of a Contract: To track, calculate, and display real-time/historical running metrics, deliver interval cues, and operate core app features.

  • Consent: To interface with third-party services like Strava via our backend and sync your completed workouts at your direct request. You may withdraw consent at any time by disconnecting the integration.

  • Legitimate Interests: To maintain app performance, ensure security, and troubleshoot technical issues.

3. Infrastructure & Third-Party Services

  • Firebase / Google Cloud: We use Firebase (by Google Cloud) solely as backend infrastructure to facilitate secure Strava OAuth authentication and API communication. Firebase processes technical authentication data securely in accordance with strict data protection standards.

  • Strava: When you choose to sync your workouts, data is shared with Strava governed by Strava’s own privacy policy.

  • No Data Selling: We do not sell, rent, or trade your personal data to third parties for advertising or commercial monetization.

4. Permissions Used

  • Location Services: Required to map and calculate running metrics during active workouts.

  • Notifications: Used to deliver interval alerts, countdown cues, and workout summaries.

  • Internet Access: Required to authenticate with third-party integrations (Strava) via our backend.

5. Your Data Protection Rights (UK / EU GDPR)

If you are located in the UK or European Economic Area (EEA), you possess the following rights regarding your personal data:

  • Right of Access: Request copies of any personal data we hold about you.

  • Right to Rectification: Request correction of inaccurate information.

  • Right to Erasure ("Right to be Forgotten"): Request deletion of your local or backend-associated data.

  • Right to Restriction / Objection: Object to or restrict certain processing of your data.

  • Right to Data Portability: Request transfer of your data to another service.

You can delete your local app data at any time by clearing your app storage or uninstalling the application. To exercise any other GDPR rights, contact us using the details below. You also have the right to lodge a complaint with your local data protection supervisory authority (such as the Information Commissioner's Office in the UK).

6. Contact Us

If you have questions, requests, or concerns regarding this Privacy Policy or your data, please contact:

  • Email: ammier.clarke@threadlinelabs.io