1. Who operates Reps
Reps is operated by Paolo Manca (“Reps,” “we,” “us,” or “our”). For privacy questions or requests, email paolofmanca@gmail.com.
2. Information that stays on your device
Your saved workout routines, exercises, loads, notes, workout history, progress, preferences, and reminder settings are stored locally on your device using Apple’s storage frameworks. Reps does not provide an account or operate a cloud database containing this training history.
The share extension may temporarily place a supported link and routine text in a private app-group container so the Reps app can open it. The app removes queued share data after it is consumed. Screenshot images selected for text recognition are processed on-device and are not uploaded by Reps.
3. Workout import and AI processing
When you ask Reps to turn a social post into a workout, the following information is processed to perform that request:
- the supported TikTok, Instagram, or YouTube URL;
- for TikTok, public caption and author metadata returned by TikTok’s public embed service; and
- for Instagram, routine text included in the share, pasted by you, or recognized from a screenshot on your device;
- for a public YouTube video or Short, the public audiovisual content that Google Cloud accesses from the submitted URL; and
- for a YouTube fallback, routine text included in the share, pasted by you, or recognized from a screenshot on your device.
The request passes through our service hosted by Cloudflare. TikTok captions and routine text you intentionally supply are sent to the Anthropic API to create a structured, editable workout. Reps does not send social URLs to Anthropic.
For automatic YouTube extraction, the public YouTube URL is sent to Google Cloud and processed with Vertex AI, which analyzes the public video’s audio and sampled frames to create the structured workout. Reps does not download or retain the YouTube video. If automatic processing is unavailable or cannot verify the routine, Reps asks you for text or an optional on-device screenshot instead.
Our application logs contain only operational fields such as a random request ID, status, duration, source platform, cache result, and bounded error code. We do not place URLs, routine text, captions, creator names, or raw IP addresses in those application logs. A salted one-way digest derived from network information is used for abuse prevention and rate limiting.
Successful structured results may be cached by Reps for up to 24 hours so repeated requests are faster. Raw routine text, captions, YouTube media, and model evidence are not stored in that result cache; routine text is represented only inside a salted one-way cache key. Anthropic and Google Cloud handle provider inputs and outputs under their respective API and cloud data-governance terms.
4. Product analytics
If “Help improve Reps” is enabled, Reps sends limited product-use events to Amplitude using a random app analytics identifier. These events describe interactions such as screens viewed, feature entry points, import outcome categories, workout completion, and purchase-flow outcomes.
Analytics does not include workout titles, social links, exercise names, creator handles, notes, loads, rep values, screenshot content, or raw error messages. IP-address, location, carrier, and Apple IDFV collection are disabled in the Reps analytics configuration. Reps uses Amplitude’s European Union data region.
You can disable analytics at any time in Reps → Settings → Help improve Reps. Disabling analytics stops future event delivery and clears queued analytics events and identifiers from the device.
5. Purchases and subscriptions
Purchases are processed by Apple under Apple’s Privacy Policy. Reps does not receive your payment-card details. RevenueCat processes a pseudonymous app user identifier, product and entitlement status, purchase dates, and related transaction information so Reps can offer, unlock, restore, and manage Reps Pro. When analytics is enabled, Reps provides RevenueCat with the pseudonymous Amplitude device identifier to measure subscription events; that link is removed when analytics is disabled.
6. Support communications
If you email support, we receive your email address and the information you include. We use it only to answer your request, troubleshoot Reps, prevent abuse, and maintain reasonable support records. Please do not send sensitive health information, private social content, passwords, or payment-card details.
7. How information is used and our legal bases
We process information only to provide the features you request, maintain subscriptions, secure and operate the service, respond to support, comply with law, and—with your choice enabled—understand product use and improve Reps. Where European data-protection law applies, these activities rely as appropriate on performance of our contract with you, your consent for optional analytics, our legitimate interests in security and support, and compliance with legal obligations.
8. Sharing, sale, tracking, and international transfers
We share information only with the processors described above as needed to provide their services, or when required by law, to protect rights and safety, or as part of a business transfer subject to appropriate safeguards. Reps does not sell or rent personal information, use it for targeted advertising, or track you across apps and websites owned by other companies.
Cloudflare, Anthropic, Google Cloud, RevenueCat, Amplitude, and Apple may process information in countries outside your own. Their contractual and legal transfer safeguards apply to that processing. Amplitude analytics for Reps is configured for EU data residency.
9. Retention and deletion
- On-device data: remains until you delete it in Reps or delete the app, subject to any device backups you control.
- Extraction cache: successful structured results expire within 24 hours.
- AI processing: Anthropic and Google Cloud retain or process provider inputs and outputs according to their applicable API, cloud, security, and legal terms.
- Analytics and purchase records: are retained under the applicable provider settings and legal requirements. You can disable future analytics collection in Reps.
- Support email: is retained only as reasonably needed to resolve and document your request or meet legal obligations.
To request access, correction, deletion, restriction, portability, or objection where applicable, email paolofmanca@gmail.com. We may need limited information to verify and fulfill a request. You may also complain to your local data-protection authority.
10. Children
Reps is not directed to children under 13. If local law requires parental consent at an older age, a child may use Reps only with that consent. If you believe a child provided personal information through an import or support request without appropriate consent, contact us so we can address it.
11. Security, third-party links, and changes
We use reasonable technical and organizational safeguards, including encrypted network transport, strict URL validation, bounded requests, privacy-limited logs, and short-lived result caching. No security method is perfect, and we cannot guarantee absolute security.
Reps links to social platforms and service-provider policies that we do not control. Their practices are governed by their own terms. We may update this policy as Reps changes or legal requirements evolve. The current version and effective date will always appear on this page.