Cookie Disclosure
This page explains the cookies and the persistent browser-storage entries that RepRoute uses. We treat browser localStorage, sessionStorage, IndexedDB, and the offline cache the same as cookies for transparency.
Because RepRoute works offline, some of what we store on your device is your own training data, not just a preference — for example a workout you logged while offline, waiting to be uploaded. All of it stays on your device; none of it is used for tracking or advertising, and none of it is shared with anyone. We also keep a number of small functional entries (for example which onboarding steps and one-time notices you have already seen), which are not listed individually below.
When you sign out, RepRoute actively clears the offline page cache, the saved onboarding draft, and the offline workout queue from your device, so your data does not linger on a shared or lost device.
Why You Will Not See a Cookie Banner
Everything we set is strictly necessary, and we run no advertising, analytics, or third-party tracking scripts that would require an opt-in. Under the ePrivacy Directive and PDPA guidance, strictly necessary technologies do not require consent, so we have chosen not to display a banner that offers no meaningful choice.
There is one thing we do not set ourselves: playing an embedded YouTube demonstration video allows Google to store data on its own domain. That happens only if you deliberately open a video player, never on page load, so we treat it as your choice rather than something to gate the whole site behind a banner. See Third-party Cookies below.
Cookies and Storage We Set
| Name | Purpose | Duration | Type |
|---|---|---|---|
sb-<project-ref>-auth-token | Supabase authentication session. Required to keep you signed in between page loads. | 400 days (rotating refresh) | Essential cookie |
sb-<project-ref>-auth-token-code-verifier | One-time PKCE verifier used during the OAuth sign-in handshake. | ~5 minutes | Essential cookie |
app-design (localStorage) | A superseded visual-design preference. We no longer write this entry and we remove it when you next change a theme setting; it is listed because it may still exist on your device. | Until removed or you clear it | Essential (legacy) |
app-theme (localStorage) | Stores your dark / light mode choice so the correct theme is applied on first paint. | Until you clear it | Essential |
NEXT_LOCALE | Remembers the display language you pick in Settings so the app renders in your chosen language on every request. | 1 year | Essential cookie |
rr_twa | Records that RepRoute is running inside our Google Play Android app rather than in a normal browser tab. We set it because Google Play rules do not allow us to sell subscriptions inside the app, so purchase and billing screens must be hidden there; the cookie is also what lets our server refuse a checkout request that comes from the app. It is set only when the app launches RepRoute, holds no identifier, and is never used for tracking or advertising. | 1 year | Essential cookie |
rr_ctx_twa (localStorage) | The on-device twin of rr_twa, so the app still recognises itself if the cookie is cleared. | Until you clear it | Essential |
reproute (IndexedDB) | The offline workout queue. If you log sets with no connection, the session — exercises, weights, and reps — is held here on your device until it can be uploaded. | Until uploaded; cleared when you sign out | Essential |
rr:today-cache, rr:offline-finish, rr:offline-deadletter (localStorage) | Your current training day and any logged workout that could not be uploaded, kept so nothing you logged is lost. | Until uploaded; cleared when you sign out | Essential |
reproute:onboarding (sessionStorage) | Your in-progress onboarding answers — including goal, body stats, and any injuries you entered — so closing a tab mid-setup does not lose them. | Until the tab closes or you sign out | Essential |
reproute-pages, reproute-assets (Cache Storage) | The offline app cache. So RepRoute opens without a connection, the service worker stores app code and a copy of pages you have visited — which for signed-in pages such as your dashboard includes your own training data. Payment, billing, admin, settings, and sign-in pages are never cached. | Until the app updates; cleared when you sign out | Essential |
Third-party Cookies
We embed Cloudflare Turnstile on our sign-up and sign-in pages to block automated abuse. When Turnstile decides a bot challenge is necessary, Cloudflare may set a short-lived cookie on their own domain to record the challenge result. We do not control these cookies. You can review Cloudflare's practices in the Cloudflare Privacy Policy.
Exercise demonstration videos are hosted on YouTube. We embed them in YouTube's privacy-enhanced mode (youtube-nocookie.com) and no video is loaded until you open one — but once a video plays, Google receives your IP address and can set storage on its own domain. If you would rather Google received nothing, do not open the video players.
The Satoshi font used across the site is served by the Fontshare CDN, which therefore receives your IP address and browser user agent on every page load. It sets no cookie.
We do not embed Google Analytics, Meta Pixel, TikTok Pixel, advertising tags, session-recording tools, or any other third-party analytics or tracking script.
How to Disable Cookies
You can block or delete cookies and local-storage entries through your browser settings. Note that disabling the Supabase session cookie will make it impossible to remain signed in, and disabling app-design or app-theme will cause a brief flash of the default theme on each page load. Browser-specific instructions:
Changes to This Disclosure
If we ever introduce non-essential cookies (for example analytics or marketing), we will update this disclosure, present a consent banner before any such cookie is set, and require your opt-in.