REP

Privacy Policy

Last updated: September 27, 2026

1. Who we are

REP (getrep.app and the REP mobile app) is a coaching platform where coaches and athletes create workout plans, track training, and communicate. It is operated by Moonbase Digital OÜ, a private limited company registered in Estonia (registry code 17165709), Kuldnoka tn 15-17, 10619 Tallinn, Estonia ("Moonbase Digital", "we", "us").

Moonbase Digital OÜ is the data controller for the personal data described in this policy. For any privacy question or request, contact us at privacy@getrep.app.

This policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the rights you have under the EU General Data Protection Regulation (GDPR).

2. Data we collect

Account and profile data:

  • Name, email address, date of birth, and gender, provided when you create an account. If you sign in with Apple or Google, we receive the name and email associated with that account.
  • An optional profile photo.
  • For athletes: height and a history of body-weight entries.
  • For coaches: your public coach profile, including your name, description, certifications, services, and locations.

Health and wellbeing data (special-category data under Article 9 GDPR):

  • Your answers to the athlete onboarding questionnaire: training experience and habits, injuries or physical limitations, sleep, stress and how you cope with it, fitness self-assessments, and training goals.
  • Pre-workout check-ins: self-reported mood, sleep, energy, eating, and motivation.
  • Post-workout feedback: muscle and joint pain ratings and free-text comments.

Training data: workout plans, sessions, exercises, sets, weights, reps, effort ratings, completion times and timezone, and notes and comments written by you or your coach.

Messages and media: chat messages and attachments you exchange with your coach or athletes, and images or videos you upload.

Billing data (for paying coaches): the legal name, contact name, billing email, phone number and address of the billing account, its registration number and VAT number where applicable, invoice and payment history, and card metadata (brand, last four digits, expiry). Your full card number never reaches our servers — it is collected and stored directly by Stripe.

Device and notification data: push notification tokens, device platform and app version, and a log of notifications we have sent you, which can include chat message previews.

Usage data: error and performance reports, and technical logs including IP addresses.

Email data: a log of the emails we have sent you (address, subject, delivery result) and your email preference choices.

AI usage data: for each AI-assisted request we record which feature ran, for which coach, and how much text was processed. We do not store the request or the answer.

3. Why we process your data, and on what legal basis

  • To provide the service — storing your training data, syncing it between you and your coach, delivering messages and notifications, and processing payments. Legal basis: performance of a contract (Article 6(1)(b) GDPR).
  • To process health and wellbeing data, including using it in AI-assisted insights for your coach — legal basis: your explicit consent (Articles 6(1)(a) and 9(2)(a) GDPR), which you give in the onboarding questionnaire and can withdraw at any time.
  • To sort the comments you write while logging a workout into questions, problems and too-easy workouts for your coach's dashboard, using an AI provider. Legal basis: performance of a contract (Article 6(1)(b) GDPR). Pain and injury are only looked for with your explicit consent, as above.
  • To keep the service secure and reliable — monitoring for errors, abuse, and outages. Legal basis: our legitimate interest in operating a secure service (Article 6(1)(f) GDPR).
  • To understand how visitors find and use our website and app, using the analytics tools described in section 10. Legal basis: your consent (Article 6(1)(a) GDPR), which you give in the cookie banner and can withdraw at any time.
  • To send you emails about your account, invitations, trial and billing. Legal basis: performance of a contract, and our legitimate interest in keeping you informed about the service you use.
  • To meet legal obligations — in particular keeping accounting records such as invoices, as required by the Estonian Accounting Act. Legal basis: legal obligation (Article 6(1)(c) GDPR).

We do not sell your personal data, and we do not use your data for third-party advertising.

4. AI-assisted features

REP includes AI-assisted features for coaches: short dashboard insights, automatic flagging of athlete workout comments that mention pain or ask a question, and "worth knowing" notes that point a coach to something in an athlete's recent training or plan. These features are powered by OpenAI, acting as our data processor.

To generate these, we send OpenAI the context each feature needs: the athlete's first name, training figures such as completed sessions, sets, weights and effort ratings, the exercises planned for the next sessions, and the comments the athlete wrote while logging a workout, which are sorted into questions, problems with the plan, and workouts that felt too easy. Legal basis: performance of a contract. We do not send full names, contact details, or chat messages.

Only if the athlete has given explicit consent in the onboarding questionnaire do we also ask the AI to flag comments that mention pain or injury, and send weekly averages of their pre-workout check-ins (sleep, energy and motivation) and their own note about limiting injuries. Without that consent, comments are still classified, but pain and injury are not looked for.

AI outputs are suggestions for the coach. They never change a training plan by themselves. Under our agreement with OpenAI, data sent through its API is not used to train OpenAI models.

Athletes can use REP without consenting to AI processing of their health data, and can withdraw that consent at any time in the app or by contacting us.

5. Who can see your data inside REP

REP is a coaching platform, so sharing between connected users is core to the service: your coach can see your profile, training data, wellbeing check-ins, workout feedback, and messages you send them; your athletes can see the plans, notes, and messages you share with them.

Coach profiles (name, description, certifications, services, locations) are visible to users browsing for a coach.

A small number of Moonbase Digital administrators can access data where necessary to operate the service and provide support.

6. Service providers (data processors)

We use a small number of service providers to run REP. They process personal data only on our instructions and under data processing agreements:

  • Hetzner Online GmbH (Germany) — application hosting and databases, located in Helsinki, Finland (EU).
  • Cloudflare, Inc. (US) — content delivery, DNS, web hosting, and media storage; uploaded media is stored in Western Europe.
  • Stream.io, Inc. (US) — in-app chat infrastructure; chat messages and attachments are stored by Stream.
  • Stripe Payments Europe, Ltd. (Ireland) — payment processing, card storage, invoice emails and card-expiry reminders. Stripe receives the billing details of the paying coach (legal name, contact name, billing email, phone, address, registration and VAT numbers).
  • Merit Aktiva (Merit Software OÜ, Estonia) — invoicing and accounting. Merit receives the same billing details and a copy of each invoice.
  • OpenAI (US/Ireland) — AI-assisted features, as described in section 4.
  • Resend (US) — transactional email, such as invites and billing notices.
  • Functional Software, Inc. (Sentry, US) — error and performance monitoring, using EU-based data ingestion.
  • Google Ireland Limited (Ireland) and Google LLC (US) — Google Analytics for website and app usage statistics (only with your consent, see section 10), Firebase Cloud Messaging for Android push notifications, and Google Fonts.
  • PostHog, Inc. (US), with data hosted in the EU (Frankfurt) — product analytics and session recordings across the website and the app, only with your consent (see section 10).
  • Apple Inc. (US) — iOS push notifications.
  • Slack Technologies, LLC (US) — internal team notifications; when you create an account or become a coach, our team channel receives your name and email address (and your coach profile name).
  • Giphy (US) — GIF search in chat, used only when you search for a GIF.

7. International transfers

Your data is primarily stored in the EU (Finland and Western Europe). Some of the providers listed above are based in the United States or process data there. Where personal data is transferred outside the European Economic Area, we rely on the European Commission’s Standard Contractual Clauses and, where the provider is certified, the EU–US Data Privacy Framework.

8. How long we keep your data

We keep your personal data while your account is active.

When you delete your account (available in the app) or ask us to delete it, we delete your sign-in identity, name, email address, and profile photo, and disconnect your identity from the account. Training records connected to your former coach or athletes are retained in de-identified form, and messages you sent may remain visible to the people you exchanged them with, as is usual for messaging services.

When the last administrator of a coaching account deletes their account, we also delete the saved card and the customer record at Stripe and remove the contact name and phone number from the billing account. The legal name, address, registration number, and invoices of the billing account stay for the accounting period below.

Invoices and related billing records, including the billing email address on them, are kept for seven years after the end of the financial year, as required by the Estonian Accounting Act. We keep the record of who accepted the billing terms, and the log of administrative actions on a billing account, for the same period as evidence of the contract.

The log of emails we have sent you is kept for 180 days. Your email preference choices are kept for as long as needed to honour them.

Encrypted database backups are kept for up to 30 days, after which deleted data also disappears from backups.

Google Analytics data is kept for 14 months and then deleted automatically. PostHog event data is kept for 12 months and session recordings for 30 days, after which they are deleted automatically. PostHog data linked to your account is deleted when you delete your account.

9. Your rights

Under the GDPR you have the right to:

  • Access the personal data we hold about you and receive a copy of it.
  • Correct inaccurate or incomplete data.
  • Have your data deleted ("right to be forgotten").
  • Restrict or object to processing based on our legitimate interests.
  • Receive the data you provided in a portable, machine-readable format.
  • Withdraw consent at any time, without affecting the lawfulness of processing before the withdrawal.

To exercise any of these rights, email privacy@getrep.app. We respond within one month.

If you believe we have mishandled your data, you can lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon, aki.ee) or with the supervisory authority in your own EU member state.

10. Cookies and similar technologies

We use first-party cookies and browser storage that are strictly necessary for the service: authentication session cookies set by our sign-in service (auth.getrep.app), a cookie that remembers that you are signed in, and cookies and local storage that remember interface preferences.

With your consent, we use two analytics tools to understand how visitors find and use REP. Google Analytics 4 tells us which pages are visited, where visitors arrive from, the device and browser used, and approximate location at country or city level; it sets cookies (_ga and _ga_*) that identify your browser for up to two years.

PostHog covers both the public website and the signed-in app. It records automatically which pages you open, what you click, when you submit a form (the fact of the submission, never what you typed into it), and errors the app runs into, so we can see where people get stuck. It sets cookies (ph_*) that identify your browser, and once you sign in it links your activity to your account for as long as you have one. Both tools also record whether you use REP as a coach, athlete or administrator and the billing state of your coaching account (for example trial or active), so we can compare how these groups use REP.

PostHog also makes a session recording: a masked playback of your clicks, scrolling and screen layout. It is not a video of your screen and not a copy of your data. Names, profile photos, chat messages, your answers to the health questionnaire, and payment and billing details are hidden before the recording leaves your browser, as is everything you type into any field. What stays visible is the structure of the page and the training detail we need to see a plan the way you saw it: exercise names, and planned and completed sets, reps and weights.

Neither tool receives your name or email address. We strip invite links, email-preference links and sign-in parameters from the page addresses we report, Google Analytics does not log or store IP addresses, and PostHog data is stored in the EU. Google processes its data in Ireland and the United States under the EU–US Data Privacy Framework. We do not use Google Signals or any advertising features.

Analytics cookies are set only after you click Accept in the cookie banner; if you decline or do not answer, nothing is sent to Google or PostHog. We remember your choice in a first-party consent cookie for six months, and ask again if what we use analytics for changes. You can change it at any time through the Cookie settings link in the page footer; withdrawing consent stops collection and removes the analytics cookies.

Stripe sets cookies needed for secure payment processing when you use billing features. We do not use advertising cookies.

You can remove cookies at any time through your browser settings.

11. Security

All data is encrypted in transit using TLS. Access to production systems is restricted to authorized personnel over a private network, databases are not exposed to the public internet, and backups are stored in the EU. No online service can guarantee absolute security, but we work to protect your data with appropriate technical and organizational measures.

12. Children

REP is not directed at children under 16, and we do not knowingly collect personal data from them. If you believe a child under 16 has created an account, contact us and we will delete it.

13. Changes to this policy

We may update this policy as REP evolves. If we make material changes, we will notify you in the app or by email before they take effect. The date at the top shows when this policy was last revised.

14. Contact

Moonbase Digital OÜ, registry code 17165709, Kuldnoka tn 15-17, 10619 Tallinn, Estonia.

Privacy questions and requests: privacy@getrep.app. General support: support@getrep.app.