CaloReps
Privacy Policy
We take your privacy seriously. This policy explains how we handle your data.
- Effective Date
- July 16, 2026
- Website
- https://caloreps.com
- Contact
- info@caloreps.com
1. Introduction & Scope
CaloReps ("we", "our", "us") operates the CaloReps mobile fitness application ("App"). This Privacy Policy describes how we collect, use, disclose, store, and protect your personal information when you use the App.
This policy is designed to comply with:
General Data Protection Regulation (GDPR) — European Union
UK General Data Protection Regulation (UK GDPR) and Data Protection Act 2018
California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA)
Personal Information Protection and Electronic Documents Act (PIPEDA) — Canada
Children's Online Privacy Protection Act (COPPA) — United States
Other applicable regional privacy laws
By using the App, you acknowledge you have read and understood this Privacy Policy.
2. Data Controller
CaloReps acts as the Data Controller for personal data processed through the App.
Contact Email: info@caloreps.com
Website: https://caloreps.com
For GDPR or UK GDPR-related requests or to contact our data protection representative, use the email above.
3. Information We Collect
3.1 Information You Provide Directly
During onboarding and ongoing use, you may provide:
Account credentials: email address, hashed password;
Physical data: age, sex assigned at birth, height, weight, body fat percentage, waist, neck, and hip circumference measurements;
Fitness assessment data: exercise 1-repetition maxes (1RMs), pull-up counts, training experience duration;
Health indicators: sleep quality score, stress level, recovery quality, joint health score, injury areas and pain severity;
Program preferences: fitness goal, training days per week, session duration, equipment availability, disliked exercises, priority muscle groups;
Workout logs: exercises performed, sets, reps, weights, session dates;
Optional nutrition data: custom calorie and protein targets;
User-generated content: coach notes, feedback text, specific injury descriptions.
3.2 Information Collected Automatically
Device identifiers: device type, model, operating system version, unique device ID;
App usage data: features accessed, screens visited, session frequency and duration, button interactions;
Crash reports and error logs containing device state at time of crash;
Performance and diagnostic data;
IP address (used for geographic region inference, not stored long-term).
3.3 Information from Third Parties
Subscription and purchase status from RevenueCat and your App Store account;
Authentication tokens if you sign in via Apple Sign-In or Google Sign-In (we do not receive your payment card data);
Aggregate analytics from App Store platforms.
4. Special Category Data (Health Information)
Health and fitness data is classified as "special category" personal data under GDPR and "sensitive personal information" under CCPA. We process this data with heightened protection.
Legal bases for processing health data (GDPR):
Explicit consent: obtained during onboarding and account setup (Article 9(2)(a) GDPR);
Contractual necessity: required to deliver personalized fitness programs (Article 6(1)(b) GDPR);
Legitimate interests: service quality improvement, subject to appropriate safeguards (Article 6(1)(f) GDPR).
You may withdraw consent at any time. Withdrawal will not affect the lawfulness of prior processing but may limit your access to AI-powered features.
5. How We Use Your Information
5.1 Service Delivery
Generating AI-powered personalized workout programs tailored to your fitness level, goals, and health status;
Computing nutritional estimates (BMR, TDEE, protein, fat targets);
Tracking and displaying your fitness progress over time;
Providing exercise recommendations, substitutions, and alternatives;
Sending workout reminders and progress notifications (with your permission).
5.2 AI Processing via Third-Party API
Your fitness and health data is transmitted to Anthropic's Claude API to generate personalized programs. This transmission is:
Governed by a Data Processing Agreement between CaloReps and Anthropic;
Used solely to generate your program and not for training Anthropic's models unless separately agreed;
Subject to Anthropic's Privacy Policy (anthropic.com/legal/privacy).
We minimize the data sent to the API — only the data necessary to generate your program is transmitted.
5.3 Account & Business Operations
Creating, managing, and securing your account;
Processing and managing your subscription via RevenueCat;
Sending transactional communications (account verification, password reset, subscription receipts);
Providing customer support and responding to inquiries.
5.4 Safety & Legal Compliance
Detecting and preventing fraud, abuse, unauthorized access, and security threats;
Complying with applicable laws, regulations, and legal process;
Enforcing our Terms of Service and other policies.
5.5 Service Improvement (Aggregated/Anonymized)
Improving AI program quality and accuracy through anonymized aggregate analysis;
Conducting internal research and product development;
Generating anonymized usage statistics.
6. Legal Bases for Processing (GDPR/UK GDPR)
Contractual Necessity (Art. 6(1)(b)): Delivering the App services you have signed up for.
Explicit Consent (Art. 6(1)(a), Art. 9(2)(a)): Processing health/fitness data and sending marketing communications.
Legitimate Interests (Art. 6(1)(f)): Fraud prevention, security, and aggregate service improvement — balanced against your rights.
Legal Obligation (Art. 6(1)(c)): Compliance with applicable laws, tax obligations, and regulatory requirements.
7. Data Sharing & Disclosure
We do not sell, rent, or trade your personal data. We share data only as follows:
7.1 Service Providers (Data Processors)
All third-party processors are bound by Data Processing Agreements and are prohibited from using your data for their own purposes:
Anthropic — AI program generation — anthropic.com/legal/privacy
Supabase — Database, authentication, real-time, storage — supabase.com/privacy
RevenueCat — Subscription lifecycle management — revenuecat.com/privacy
Apple Inc. / Google LLC — App distribution, in-app purchase processing
7.2 Legal Requirements
We may disclose your data when required by: a court order or subpoena; applicable law or regulation; government or regulatory authority; or to protect the rights, property, safety, or security of CaloReps, our users, or the public.
7.3 Business Transfers
In the event of a merger, acquisition, restructuring, or sale of assets, your personal data may be transferred to the successor entity. We will provide at least 30 days' notice before your data becomes subject to a materially different privacy policy.
7.4 Aggregated/Anonymized Data
We may share aggregated, de-identified statistical data that cannot reasonably be used to identify you with research partners, analytics providers, or publicly.
8. Data Retention
We retain personal data for no longer than necessary for the purposes outlined in this policy:
Account and profile data: retained while your account is active and deleted when your account is deleted;
Workout logs, health data, nutrition logs, weight logs, personal records, program history, friend requests, and subscription records tied to your account are deleted from active systems when your account is deleted;
Usage logs and analytics: retained for up to 12 months;
Crash reports: retained for up to 6 months;
Anonymized/aggregated data: may be retained indefinitely as it cannot identify individuals.
9. Data Security
We implement industry-standard technical and organizational security measures to protect your data, including:
Encryption in transit: TLS 1.2 or higher for all data transmissions;
Encryption at rest: AES-256 encryption for stored data;
Authentication security: industry-standard password hashing (bcrypt); multi-factor authentication support;
Database security: row-level security policies on all tables; principle of least privilege access;
Access controls: data access limited to authorized personnel on a strict need-to-know basis;
Security monitoring: regular security audits, vulnerability assessments, and penetration testing;
Incident response: documented breach response procedures, including regulatory notification within 72 hours (GDPR) where required.
No method of data transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.
10. Your Privacy Rights
10.1 Rights Under GDPR / UK GDPR (EEA & UK Users)
Right of Access (Art. 15): obtain confirmation of and a copy of your personal data;
Right to Rectification (Art. 16): correct inaccurate or incomplete data;
Right to Erasure (Art. 17): request deletion of your data ("right to be forgotten") subject to legal exceptions;
Right to Restriction of Processing (Art. 18): limit how we use your data in certain circumstances;
Right to Data Portability (Art. 20): receive your data in a structured, machine-readable format;
Right to Object (Art. 21): object to processing based on legitimate interests or for direct marketing;
Right to Withdraw Consent: withdraw consent at any time without affecting lawfulness of prior processing;
Right to Lodge a Complaint: file a complaint with your national supervisory authority (e.g., ICO in the UK, relevant DPA in your EU country).
10.2 Rights Under CCPA / CPRA (California Residents)
Right to Know: know what personal information we collect, use, disclose, and sell (we do not sell);
Right to Delete: request deletion of your personal information (subject to legal exceptions);
Right to Correct: correct inaccurate personal information;
Right to Opt-Out of Sale: we do not sell personal information;
Right to Limit Use of Sensitive Personal Information: limit our use of sensitive data to necessary purposes;
Right to Non-Discrimination: we will not discriminate against you for exercising your privacy rights.
10.3 Rights Under PIPEDA (Canadian Users)
Right to access personal information we hold about you;
Right to correct inaccurate information;
Right to withdraw consent (subject to legal and contractual restrictions);
Right to file a complaint with the Office of the Privacy Commissioner of Canada.
10.4 How to Exercise Your Rights
Submit your request by emailing info@caloreps.com with the subject line "Privacy Rights Request". Include your registered email address and specify your request. We will verify your identity before processing.
Response timelines: 30 days (GDPR/UK GDPR) | 45 days (CCPA, extendable to 90 days with notice) | 30 days (PIPEDA).
11. International Data Transfers
CaloReps serves users globally. Your data may be transferred to and processed in countries other than your country of residence, including the United States, where data protection laws may differ from your jurisdiction.
For transfers of EEA/UK personal data to third countries, we rely on:
Standard Contractual Clauses (SCCs) approved by the European Commission or UK Information Commissioner's Office;
Data Processing Agreements with all sub-processors incorporating appropriate transfer mechanisms;
Adequacy decisions where applicable (e.g., EU-US Data Privacy Framework).
12. Children's Privacy
CaloReps is not directed at children under 16 years of age. We do not knowingly collect personal data from users under 16. If you are a parent or guardian and believe your child under 16 has provided us with personal data without appropriate consent, please contact us immediately at info@caloreps.com. We will promptly investigate and, where verified, delete such data.
For users between 16 and 18, use of the App requires verifiable parental or guardian consent as described in our Terms of Service.
13. Cookies & Tracking Technologies
The CaloReps mobile app does not use browser cookies. We may use:
Anonymous device identifiers for crash reporting and analytics (using industry-standard SDKs);
Attribution data to understand how users discover the App;
Local device storage for caching app state and offline functionality.
You can opt out of analytics data collection in the App's Privacy Settings at any time. Opting out does not affect core App functionality.
14. Push Notifications
With your consent, we may send push notifications for: workout reminders, program updates, progress milestones, and important account notifications. You can manage or revoke notification permissions at any time in your device settings or within the App.
15. In-App Analytics
We use anonymized, aggregated analytics to understand how users interact with the App and to improve features. No individual-level behavioral data is shared with third-party advertisers. CaloReps products are ad-free.
16. Changes to This Privacy Policy
We may update this Privacy Policy periodically to reflect changes in our practices, technology, legal requirements, or for other legitimate reasons. We will notify you of material changes by:
Displaying a prominent notice within the App;
Sending an email to your registered address (for significant changes);
Updating the "Effective Date" at the top of this policy.
Where required by applicable law, we will obtain fresh consent for material changes to how we process your health data. Your continued use of the App after the effective date of changes constitutes acceptance of the updated policy, except where consent is required.
17. Data Protection Authority Contacts
If you believe your privacy rights have not been respected, you have the right to lodge a complaint with your relevant supervisory authority:
EU residents: your national Data Protection Authority (find yours at edpb.europa.eu);
UK residents: Information Commissioner's Office (ICO) — ico.org.uk;
Canadian residents: Office of the Privacy Commissioner — priv.gc.ca;
California residents: California Privacy Protection Agency — cppa.ca.gov.
18. Contact & Requests
Email: info@caloreps.com
Website: https://caloreps.com
For all privacy-related questions, data subject requests, or concerns, contact us at the email address above. We are committed to resolving all legitimate privacy inquiries promptly and transparently.