Reps Weekly Privacy Policy

Version: 2.5
Last Updated:
Effective Date:

Reps Weekly is the product name used by its individual operator, who is based in Victoria, Australia. “Reps Weekly” is not presently a separate company or legal entity. In this Policy, “Reps Weekly”, “we”, “us” and “our” refer to that operator.

Privacy and support contact: repsweekly@gmail.com

1. Scope of this Policy

This Privacy Policy explains how personal information is collected, used, disclosed, stored and otherwise processed when you download or use the Reps Weekly mobile application, contact support, use team or reporting features, view advertising, or otherwise interact with Reps Weekly.

Reps Weekly is intended for worldwide availability. Your rights and our obligations may differ depending on where you live. This Policy does not claim that every privacy law in every jurisdiction applies in the same way.

2. About Reps Weekly

Reps Weekly is a general fitness and wellness application that helps users follow bodyweight workout schedules, log repetitions, monitor progress, maintain streaks and badges, and optionally participate in teams and informal leaderboards.

An account is required to use the main application features. Authentication is currently provided using an email address and password through Firebase Authentication.

3. Information We Collect or Process

3.1 Account and profile information

We process information such as:

Passwords are handled by Firebase Authentication. Reps Weekly does not store your plain-text password in Cloud Firestore.

3.2 Workout and fitness information

We process information such as:

This is fitness information and may be treated as sensitive or health-related information under some laws, even though Reps Weekly does not collect clinical records and is not integrated with Apple Health, Health Connect or another health-record platform.

3.3 Team and social information

If you create or join a team, we may process:

Signed-in users can browse a minimal directory of public teams showing the team identifier, team name, member count, maximum count and public status. Private teams and private codes do not appear in that directory.

Full team details, membership, administrators, private join code and available team statistics are intended to be visible only to current team members and authorised administrative access. A team administrator can remove members.

3.4 Reports, feedback and integrity information

When you submit or trigger relevant features, we may process:

Player reports, bug reports and integrity events are not public. Ordinary users cannot read, update or delete these records after submission.

3.5 Device, app and local information

The app or its service providers may process:

Reps Weekly does not request your contacts, precise GPS location, camera, microphone, photo library or health-platform records for its ordinary workout-tracking features.

3.6 Local notifications

Workout reminders are scheduled locally on your device using your notification preferences, workout state and device timezone. Reps Weekly does not use Firebase Cloud Messaging for remote push notifications. Notification permission may be denied or withdrawn through your device.

4. How We Use Information

We use information to:

Reps Weekly does not intentionally provide workout contents, fitness progress, team data, private join codes, player-report content, bug-report content or integrity-event content to Google AdMob for advertising personalisation.

5. Legal Bases Where Relevant

Where laws such as the GDPR or UK GDPR require a legal basis, processing may rely on:

Accepting this Privacy Policy acknowledges that you have read it. It does not replace a separate consent where applicable law requires one for a particular activity.

6. Advertising and Advertising Privacy Choices

Reps Weekly uses Google AdMob to display banner advertising on Android and iOS. Google and participating advertising technology providers may process information such as IP address, device or app-scoped identifiers, advertising identifiers where available, approximate location inferred from IP, consent signals, device/app information and ad interactions.

Depending on your location, consent, age treatment, device settings and Google’s requirements, ads may be personalised, non-personalised or limited, or no ad may be available.

Reps Weekly uses Google’s User Messaging Platform (UMP) to request updated advertising-consent information, present required messages and determine whether ads may be requested. No banner ad is requested unless UMP reports that an ad request is permitted. If consent handling fails and UMP does not report a valid prior state, the app does not request an ad.

UMP and Google Consent Mode are also used to communicate applicable European analytics-storage choices. Advertising eligibility and Analytics eligibility are evaluated separately: the fact that UMP permits an ad request is not treated as permission to use Analytics.

Where Google reports that a Privacy Options entry is required, an “Advertising privacy choices” entry is available in the app’s Settings. This can be used to review or change available choices. Other controls may also be available through your device or Google’s ad settings.

Reps Weekly does not sell personal information for money. However, certain advertising-related disclosures or transfers by Google or participating ad technology providers may be treated as “sharing,” targeted advertising or a “sale” under some United States privacy laws. Applicable choices are offered through UMP and Privacy Options where available and required.

On iOS, Reps Weekly does not currently request App Tracking Transparency permission. The current Google Mobile Ads Flutter integration does not send IDFA without ATT permission. Google may still use other permitted identifiers, such as an app- or publisher-scoped first-party identifier, device information or IP-derived information.

Google’s advertising practices are described at Google Advertising Policies and Technologies .

7. Analytics, Crash Diagnostics and Operational Configuration

7.1 Google Analytics for Firebase

Reps Weekly uses Google Analytics for Firebase to understand how the app is used and to improve features, reliability and the user experience. The app records limited events for signup, login, onboarding completion or skipping, workout completion, team creation or joining, and interval-timer start or completion. The only intentional event parameter is the standard signup-method value email_password.

Reps Weekly does not set a Firebase Authentication UID as an Analytics User-ID, does not create custom Analytics user properties, and does not intentionally include email addresses, usernames, team identifiers or codes, exercise names, workout contents, repetition counts, targets, difficulty, interval duration, report or integrity-event content, free text or other user-generated fitness content in Analytics events.

The Analytics SDK may automatically process technical and usage information needed to provide Analytics, including app-instance or installation identifiers, app version, device and operating-system information, language, session and interaction information, and coarse geographic information derived from network information. Advertising identifiers may be processed where available, permitted and configured by Google and the device platform. Reps Weekly does not request precise GPS location for Analytics.

Analytics collection starts disabled. For users to whom the applicable European consent requirement does not apply, UMP may report that consent is not required and Analytics is then enabled automatically. Where consent is required, Analytics remains disabled until UMP and Consent Mode report that analytics_storage is granted; denial or later revocation keeps or makes it disabled. There is no general in-app Analytics opt-out outside those applicable consent choices. Advertising consent and Analytics consent are separate, and canRequestAds() is not used as Analytics permission.

Learn more in Google’s Privacy Policy and Firebase privacy and security information.

7.2 Firebase Crashlytics

Reps Weekly uses Firebase Crashlytics in release builds to identify crashes, Flutter fatal errors and uncaught asynchronous errors and to improve app stability. Crashlytics may automatically process crash stack traces, exception information, crash time and application state, app identifier and version, operating-system and device information, Crashlytics installation UUIDs, Firebase installation IDs, session identifiers and related technical diagnostics.

Reps Weekly does not intentionally assign a Firebase Authentication UID, email address or username as the Crashlytics user ID, and does not intentionally attach workout contents, team information, reports, integrity-event content or other user-generated content through custom Crashlytics keys or logs. An exception message or platform crash report may nevertheless contain technical values produced by the app or operating system, so diagnostic collection cannot be described as completely anonymous.

Google currently states that Crashlytics keeps crash stack traces and associated installation identifiers for 90 days before beginning removal from live and backup systems. Google controls that service-level process.

7.3 Remote Config

Firebase Remote Config is used to fetch operational configuration such as maintenance status, maintenance messaging and minimum supported app build. Remote Config uses Firebase installation identifiers to return configuration values. Reps Weekly uses local notifications and does not use Firebase Cloud Messaging as a remote-push communication channel.

8. Service Providers and Disclosures

Information may be processed by:

We may also disclose information where reasonably necessary to comply with law, valid legal process, protect users, investigate abuse or security incidents, enforce applicable terms, or establish, exercise or defend legal claims.

If operation of Reps Weekly is transferred, relevant information may be transferred as part of that transaction subject to applicable law and appropriate notice.

9. International Processing

Ordinary authorised production access by the operator is from Australia. Service providers operate internationally.

Current infrastructure includes Cloud Firestore configured in Australia’s australia-southeast1 region and Realtime Database configured in the United States’ us-central1 region. Firebase Authentication is operated by Google from the United States. Remote Config, App Check, Crashlytics, Analytics, AdMob, UMP, Gmail and other provider data may be processed in countries where Google, Apple or their service providers operate.

Where required, international transfers are handled through provider contractual and legal transfer mechanisms. Location selection for one database does not mean that all service metadata or all other services remain in that location.

10. Visibility of Information

11. Retention

We retain information for as long as reasonably necessary for the purpose for which it was collected, to operate the service, maintain records, investigate reports, protect users, resolve disputes, prevent abuse, comply with legal obligations and enforce applicable terms.

Category General approach
Active profile and workout data Retained while the account is active and until deleted by the user or through a verified deletion request, subject to deferred processing and the retained records below.
Active team membership Removed when the user leaves, is kicked or completes account deletion. An empty technical membership-pointer document may remain.
Historical team statistics May be retained indefinitely to preserve leaderboard and historical integrity. Current records may retain the Firebase UID and the username recorded when statistics were published. They are not used by Reps Weekly for advertising personalisation.
Logically deleted team documents May remain for historical integrity, dispute handling, security, technical cleanup and record consistency. They may retain team metadata and internal creator or mutation UIDs even after the active roster and join mechanisms are removed.
Player reports Retained while reasonably necessary for moderation, investigation, repeat-offender detection, appeals, disputes, safety and abuse prevention.
Bug reports and recommendations Retained while reasonably necessary to review the submission, diagnose recurring issues, improve the app, maintain a development record or resolve disputes.
Integrity and security events Retained while reasonably necessary to detect abuse, preserve app integrity, investigate suspicious activity, resolve disputes and prevent recurrence.
Deletion-request records Retained while deletion is pending and afterwards as reasonably necessary to document processing, resolve failures, demonstrate the request or meet security and legal needs.
Policy acceptance The current acceptance record is stored with the active profile. Separate advertising-consent state may be controlled by Google UMP and device/provider storage.
Support emails Stored in Gmail and retained while reasonably necessary to resolve the request, maintain an operational record, manage disputes or meet legal obligations. There is no automatic deletion schedule.
Analytics, Crashlytics and provider metadata Google controls service-level processing and retention. Google Analytics permits a 2- or 14-month user/event retention setting, but that setting does not remove data from standard aggregated reports. Crashlytics currently keeps crash reports and associated installation identifiers for 90 days before beginning removal. Account deletion in Reps Weekly does not automatically identify or erase every provider record that is not linked to the Firebase Authentication UID.
Local caches and preferences Retained until cleared, overwritten, logged out, deleted where implemented, removed with the app, or cleaned by the operating system. Some device-level preferences may remain after account deletion.

Information may be retained longer where reasonably necessary for fraud, abuse, safety, security incidents, disputes, legal claims, regulatory obligations, enforcement of terms or preventing repeat misconduct.

12. Account and Data Deletion

You can request account deletion in the app through Settings > Delete Account. The in-app process requires reauthentication. If you are the final team administrator while other members remain, you must first promote another member.

If you cannot access the app, have uninstalled it or do not want to reinstall it, use the public deletion page: https://rarpss.github.io/reps-weekly-legal/delete_request.html .

You may also email repsweekly@gmail.com with the subject “Delete My Account.”

Account deletion is designed to remove sign-in access, the active profile and active team membership. Workout progress, reports and integrity records may require trusted deferred review, deletion or anonymisation. We aim to acknowledge requests within seven days and complete valid requests within 30 days where reasonably practicable. If additional time is allowed or reasonably necessary, we will explain the delay. Deferred technical cleanup should ordinarily be completed within 90 days unless information is legitimately retained under this Policy.

Historical team statistics are intentionally retained for leaderboard and record integrity and may currently include the internal UID and the username recorded at publication. Some team-operation and deletion-request records may also retain internal identifiers. You may request exceptional removal or pseudonymisation by email. We will assess whether it is legally, technically and operationally possible without unreasonably damaging legitimate historical records or the rights of others.

Analytics and Crashlytics records use app, installation, session and other technical identifiers rather than an intentionally assigned account UID. Deleting a Reps Weekly account therefore does not automatically locate or erase every record already held in those provider systems. Those records remain subject to applicable consent choices, Google’s controls, retention settings and deletion processes.

Deleting the app or an account may not immediately remove information from external device backups controlled by Apple, Google, the device platform or the user’s backup provider.

13. Privacy Rights and Requests

Subject to applicable law and reasonable verification, you may request:

Reps Weekly does not currently provide a one-click complete data-export tool. A verified request may require a manual export, redaction of information concerning other people, and compilation from relevant Firebase records.

Send requests to repsweekly@gmail.com. We aim to acknowledge requests within seven days and respond to valid requests within 30 days where reasonably practicable, subject to any different legal period or permitted extension.

To prevent unauthorised access or deletion, we may ask you to email from the address associated with your account, confirm relevant account information, or provide additional evidence only where reasonably necessary. We will not request excessive identity documentation.

An authorised agent may make a request where required by law, subject to reasonable verification of the agent’s authority and the user’s identity.

If you are dissatisfied with our response, you may appeal or complain at the same email address and may have the right to contact your local privacy or data-protection authority. In Australia, information about privacy complaints is available from the Office of the Australian Information Commissioner .

14. Children and Minimum Age

Reps Weekly is intended only for people aged 18 and older. It is not directed or marketed to children or minors. A person under 18 should not create or use a Reps Weekly account.

Reps Weekly does not currently collect a date of birth or use age-verification technology and therefore cannot conclusively verify every user’s age. This technical limitation does not change the requirement that users must be at least 18 years old.

A parent or guardian who reasonably believes that a person under 18 has created an account or provided personal information may contact repsweekly@gmail.com. We will investigate and take reasonable deletion or protective action where the request can be appropriately verified.

15. Moderation and App Integrity

Automated profanity filtering may be used for usernames and team names. Player reports, reported conduct and integrity events are ultimately reviewed manually by the operator.

Where reasonably necessary, Reps Weekly may warn a user, require content to be changed, remove content, remove a user from a team, suspend or remove an account or team, or preserve relevant records. Reported users may not always be notified immediately where notice could compromise an investigation, facilitate retaliation or enable further abuse.

Moderation appeals may be sent to repsweekly@gmail.com.

Client-side report limits and integrity checks help discourage abuse but are not guarantees that all misuse will be detected or prevented.

16. Temporary Achievement-Share Images

Achievement-share images are generated locally on your device and may include your username, achievement and selected statistics. Reps Weekly does not upload these images to its own servers. Sharing occurs only when you choose a receiving app or service.

The app attempts to delete its temporary image file after sharing. Cleanup is best effort and may fail because of operating-system or file conditions. Once shared, the receiving application or service controls its copy under its own privacy practices.

17. Device Backups

SharedPreferences, cached account information, Firebase-managed local data or other app data may be included in Android, iCloud or other device backups depending on operating-system settings and the backup provider. Those backups are controlled by the platform and user’s provider. Reps Weekly does not directly control deletion from external device backups.

18. Security and Security Incidents

Reps Weekly uses safeguards such as Firebase Authentication, Firestore Security Rules, restricted administrative access, encrypted provider transport, Firebase App Check integration and limited data fields. Access to production administration is intended to be limited to the operator.

No system can be guaranteed completely secure. If a suspected security or privacy incident occurs, we will take reasonable steps to investigate, contain and remediate it, assess affected information and users, preserve necessary incident records, and notify users or regulators where legally required or reasonably appropriate. The Australian Notifiable Data Breaches scheme will be applied where it legally applies.

Suspected incidents can be reported to repsweekly@gmail.com.

19. Fitness and Medical Disclaimer

Reps Weekly is a general fitness and wellness tool. It does not provide medical advice, is not a medical device, and is not operated by a doctor, physiotherapist, personal trainer or healthcare provider. It is not intended to diagnose, treat, cure or prevent any condition and is not intended for emergency use.

Exercise involves inherent risks. You are responsible for deciding whether an exercise or workout is suitable for you. Seek advice from an appropriately qualified professional where needed. You use the app and undertake exercise at your own risk to the maximum extent permitted by law.

Nothing in this Policy or the app excludes, restricts or modifies rights or guarantees that cannot lawfully be excluded, including applicable rights under the Australian Consumer Law.

20. Third-Party Services and Links

Reps Weekly may link to app stores, legal pages, email, merchandise or other external services. We are not responsible for the privacy practices of third-party sites or receiving applications. Review their policies before providing information.

21. Changes to this Policy

We may update this Policy as the app, providers, legal requirements or data practices change. The version and dates at the top identify the current Policy. Material changes may be presented through the app’s policy-update screen or another appropriate notice, and renewed acknowledgement or consent will be requested where required.

22. Contact and Complaints

Operator: Reps Weekly’s individual operator
Product: Reps Weekly
Location: Victoria, Australia
Email: repsweekly@gmail.com

The latest version of this Privacy Policy is available at https://rarpss.github.io/reps-weekly-legal/privacy-policy.html . Related pages: User Agreement and Account and Data Deletion.