Privacy Policy
Last updated: August 11, 2026
What data RepQuest collects
- Workout data you log manually, or — with your explicit permission — read from Apple Health / Google Health Connect (type, duration, intensity). RepQuest only reads this data; it does not write anything back beyond what you log in-app.
- Gameplay data: level, XP, Reward Points, unlocked cosmetics.
- An anonymous account identifier created automatically on first launch. If you link Sign in with Apple/Google, we receive only the minimal identifier those services provide — no password is ever created or stored.
How this data is used
Your recent workout history is sent to our AI quest-generation service (built on OpenAI's API, called through our own secured server — your data is never sent directly to OpenAI from your device) so it can write a quest that reacts to your real training pattern.
What we do NOT do
- We do not use Health/Health Connect data for advertising or ad targeting, on any tier.
- We do not sell your data to data brokers, advertisers, or any third party.
- We do not share Health data with any third party beyond the minimum necessary to generate your quest text, and never in a form that identifies you personally.
Your rights, by region
EU/UK (GDPR): access, correction, erasure, portability, and objection. India (DPDP Act): access, correction, erasure, and easy consent withdrawal. Australia/NZ (Privacy Act regimes): access and correction. Japan (APPI): disclosure, correction, and deletion. UAE (PDPL): access, correction, deletion, and objection to direct marketing. Everywhere else: the same practical rights apply as a baseline. Since most accounts are anonymous by design, verifying identity for a request is intentionally lightweight.
Your controls
Revoke Health/Health Connect access anytime from your device Settings — RepQuest falls back to manual logging. Request account deletion anytime by emailing the address below; we delete within 30 days.
Security
The AI provider's API key lives only as an encrypted secret on our server infrastructure — never in the app, never on your device. All traffic between the app and our backend uses HTTPS/TLS. No advertising code has access to Health data, ever — this is enforced architecturally, not just promised.
International data transfers
Our backend providers operate globally, which can mean data is processed outside your country, including the United States. Appropriate safeguards apply where required; this section is finalized ahead of a full public launch.
Advertising
RepQuest shows ads based on general, non-health data only. Any future personalized advertising would require your explicit platform-level permission first (e.g. Apple's App Tracking Transparency).
Children's privacy
RepQuest is not directed at children and does not knowingly collect data from anyone under the applicable minimum age in their jurisdiction.
Data retention
Workout and gameplay data is kept for as long as your account is active, so your character and history stay intact. If you request deletion, everything tied to your account is removed within 30 days. Anonymous, aggregated figures (like the community charity pool total) are not personal data and are retained after individual account deletion.
Third-party service providers
RepQuest runs on a small set of infrastructure providers: Supabase (database and authentication), Cloudflare (backend API), and OpenAI (quest text generation, called only through our own server — never directly from your device). Each processes only the minimum data needed to do its job, under its own security and privacy commitments.
Changes to this policy
If this policy changes in a material way, the "Last updated" date above will change and, where required, we'll let you know in-app before the change takes effect.
Contact
Questions, data requests, or anything else — visit the Contact page or email support@repquestapp.com directly.
This policy accurately describes RepQuest's actual data practices but is not a substitute for jurisdiction-specific legal advice.