Privacy Policy
This Privacy Policy explains how RepRoute ("RepRoute", "we", "us", or "our") collects, uses, discloses, stores, and protects your personal data when you visit our website, create an account, or use our fitness planning web application (together, the "Service"). We are committed to handling your data lawfully, fairly, and transparently, in compliance with the Thailand Personal Data Protection Act B.E. 2562 (the "PDPA") and, where it applies to you, the EU General Data Protection Regulation (the "GDPR").
1. Definitions
- Personal data — any information relating to an identified or identifiable natural person.
- Sensitive / special-category data — data revealing health or other categories given heightened protection under GDPR Article 9 and PDPA section 26.
- Processing — any operation performed on personal data, such as collection, storage, use, disclosure, or erasure.
- Data controller — the party that determines the purposes and means of processing (that is us, for direct users).
- Data processor / sub-processor — a third party that processes personal data on our behalf and on our instructions.
2. Data Controller and Contact
The data controller responsible for your personal data is Jirawut Suwatcharakulthorn, operating as a sole proprietor in Thailand. For any privacy enquiry or to exercise your rights, you may contact our Data Protection Officer through our contact form.
EU representative (GDPR Article 27): RepRoute is established in Thailand. Before we actively offer the Service to data subjects in the EU/EEA, we will appoint a representative in the Union and publish their name and contact address here. This appointment is pending.
3. Data We Collect
We collect the categories of data below. Most of it you provide directly; some (such as security logs) is generated automatically when you use the Service.
3.1 Account data
- Email address
- Password (stored as a salted hash by Supabase Auth; we never see plaintext)
- Account creation date and last sign-in timestamp
- If you sign in with a third-party provider (for example Google), that provider shares your email and basic profile identifier with us so we can create or match your account
3.2 Profile data
- Display name and (optionally) username
- Age, height, weight (used to calibrate exercise intensity and load)
- Equipment availability, training goals, preferences, and schedule
- Display preferences such as language, theme, units, and time zone
- Anything you choose to add to your public profile — a short bio, a free-text location, and an avatar and banner image if you upload them. You control who can see these under Settings → Profile.
3.3 Sensitive health data
Depending on which features you use, we hold the following health-related data about you:
- Injury flags — the body region (e.g. lower back, knee, shoulder), the affected side, and how severely it limits you
- Body-weight history — every weight you log, with its date
- Height, and either your age or your date of birth if you provide one
- Sex, where you choose to set it (used only to calculate energy and protein targets)
- Your estimated daily energy expenditure, which we derive from your weight history and food logs
- Readiness check-ins — how you rated your sleep, stress, soreness, and motivation before a session, the readiness score derived from those ratings, and any body areas you tell us are hurting that day
- Your nutrition diary — individual food entries, daily calorie, protein and water totals, and the targets set for each day
- Medical conditions and physical limitations you select or describe (for example asthma, arthritis, a heart condition, recovery from surgery, pregnancy or postpartum status, or reduced mobility), and any training preference derived from them — such as the back-movement direction that is more comfortable for you
- Any health-relevant note you choose to enter (for example a limitation you describe in your own words)
- Photos you upload for a scan, where you use a photo feature
Some of this health data is sent outside RepRoute to generate your plans. Our text inference providers are Groq and Cerebras, both based in the United States. Our image inference provider is Cloudflare Workers AI, which runs on a global edge network. What we send depends on the feature:
- Generating an adaptive plan (including during onboarding) — your injury flags, any medical conditions or limitations you selected (for example asthma, arthritis, a heart condition, pregnancy or postpartum status, or reduced mobility), your body weight, height, age and sex where you have set them, your goal, experience level, training frequency, session length, equipment (including equipment you described in your own words), any calibration results, and any context you typed. Sent to Groq / Cerebras.
- Life-context adjustment of an existing week — the situation you described, your answers to any follow-up questions, the affected injury regions, your equipment, your goal, and the structure of the plan being adjusted. We do not send your weight, height, age, or sex. Sent to Groq / Cerebras.
- The in-app assistant — only the message you type and up to eight previous messages in that conversation. No profile, injury, or workout data is attached. Sent to Groq / Cerebras.
- Onboarding text helpers — when you describe your injuries, medical conditions or limitations, your equipment, or other context in your own words, that free text is sent to Groq / Cerebras so it can be turned into structured settings.
- Nutrition — when you describe a meal in your own words, that text is sent to Groq / Cerebras. When you scan a food photo, the photo goes to Cloudflare Workers AI and the foods it detects, together with any note you typed, are then sent to Groq / Cerebras for the final estimate.
- Photo scans — photos you submit for a gym, equipment, food, or program scan are sent to Cloudflare Workers AI. We do not store the photo itself; only the text the scan produces is saved.
- Importing a program — the program text you paste goes to Groq / Cerebras; a program photo goes to Cloudflare Workers AI first.
These transfers happen only when you use one of these features, and we stop making them as soon as you withdraw your consent for health-data processing (see section 4). We do not send your name, email address, or account identifier with any of these requests.
3.4 Activity and usage data
- Workout completions, sets, reps, and weights you log
- Plans generated for you and adjustments you make
- The profile snapshot sent to generate an adaptive plan, and the notes returned with it, saved alongside the plan itself
- Optional content you submit, such as support messages, food entries, and photos you upload for a scan
- Social activity, where you use those features — friends, follows, blocks, and anything you post to the community library such as published programs, comments, and votes
- If you report another member, or are reported, the report itself — who reported whom, the reason chosen, and any detail typed
- Service logs (rate-limit counters, error reports, feature usage). An error report may record which page failed, your browser user agent, and your account id, so we can find and fix the fault
3.5 Security audit data
For security, fraud prevention, and abuse investigation we record an audit trail of sign-in events, access to other users' data, rate-limited requests, and messages sent through the contact form. Each entry may include:
- IP address
- Browser user agent
- Event type and timestamp
These security audit logs are retained for a maximum of 2 years and then permanently deleted (see Retention Periods below).
3.6 Data we do not collect
We do not collect payment card numbers (these are handled directly by our payment processor), we do not buy personal data from data brokers, and we do not run advertising, analytics, or third-party tracking scripts. See our Cookie Disclosure for the complete list of cookies and storage we use.
4. Sensitive Health Data — Explicit Consent
5. How and Why We Use Your Data
We use personal data for the following purposes:
- To provide the Service — create your account, generate and adapt workout plans, store your logs and progress.
- To personalise plans — calibrate intensity, route around injuries, and respect your equipment and schedule.
- To keep the Service safe — authenticate you, enforce rate limits, detect abuse, and investigate security incidents.
- To communicate with you — send essential transactional emails (email confirmation, password reset, security and account notices) and, only if you opt in, product updates and weekly training summaries.
- To handle support requests — respond to messages you send through the contact form.
- To meet legal obligations — retain consent records and respond to lawful requests.
- To improve the Service — understand which features are used, using aggregated or de-identified data where possible.
6. Legal Basis for Processing
- Contract performance (GDPR Art. 6(1)(b) / PDPA s.24(3)): to deliver the workout planning service you signed up for.
- Explicit consent (GDPR Art. 6(1)(a) + Art. 9(2)(a) / PDPA s.26): for sensitive health data, adaptive plan generation, and marketing emails.
- Legitimate interest (GDPR Art. 6(1)(f)): for security, fraud prevention, rate-limit enforcement, and basic service improvement, balanced against your rights and freedoms.
- Legal obligation (GDPR Art. 6(1)(c)): for retaining consent records and complying with lawful requests.
7. Marketing Communications
We send marketing or product-update emails only if you opt in. You control this at any time under Settings → Notifications, which is the setting that governs whether we send them; the optional box at sign-up records your preference, and you should check Settings if you want to be sure it is set the way you intend. Every marketing email includes an unsubscribe link, and unsubscribing from one stops all of them. Essential transactional messages — such as email verification, password resets, and important security or account notices — are not marketing and are sent regardless of your marketing preference because they are necessary to operate your account.
8. Automated Plan Generation and Profiling
Some plans are produced with the help of automated reasoning systems that process the goals, equipment, and limitations you provide. This is a core part of the Service and is carried out with your consent and to perform our contract with you. These automated suggestions do not produce legal effects concerning you or similarly significant effects within the meaning of GDPR Article 22: they are recommendations you remain free to accept, modify, or ignore, and you can always reach a human by contacting us. We do not use your data for automated decisions about credit, employment, insurance, or any comparable consequential outcome.
9. Data Processors and Sub-processors
We engage the following processors. Each is bound by a data-processing agreement and processes your data only on our documented instructions. We share only the minimum data each processor needs for its function.
| Processor | Purpose | Location |
|---|---|---|
| Supabase | Database + Auth | Tokyo, Japan (ap-northeast-1) |
| Cloudflare Workers | App hosting + edge runtime | Global edge |
| Cloudflare R2 | Static media storage | Global edge |
| Cloudflare Turnstile | Bot protection | Global edge |
| Resend | Transactional email | US / EU |
| Groq | Text AI inference (primary) | US |
| Cerebras | Text AI inference (fallback) | US |
| Cloudflare Workers AI | Image AI inference — gym, food & program photo scans | Global edge |
| Upstash Redis | Rate limiting and usage quotas — stores your IP address and account id as short-lived counter keys, and no other data | Global |
| Fontshare (Indian Type Foundry) | Serves the Satoshi display font used across the site — receives your IP address and browser user agent on every page load | India / global CDN |
| YouTube (Google) | Exercise demonstration videos, embedded in privacy-enhanced mode — receives your IP address and which video you played, but only when a video actually loads | US / global |
| Have I Been Pwned | Checks a new password against known breached passwords. Receives only the first five characters of a hash of the password, never the password, your email, or your account id | Global edge |
| Stripe | Payments and subscription billing — receives your email address, your RepRoute account id, and the billing address you enter at checkout | US / global |
| Google sign-in (optional) — if you choose it, Google confirms your identity and shares your email address and basic profile identifier with us | US / global |
Two of these act as independent controllers for their own purposes as well as processing data for us. Stripe handles payments and is separately responsible for the card data you enter on its checkout page, for fraud prevention, and for its own financial record-keeping. Nothing reaches Stripe until you start a checkout — at that point we create a Stripe customer holding your email address and your RepRoute account id, which is why an abandoned checkout still leaves a record with them. Google is involved in two separate ways. If you choose "Continue with Google" to sign in, the sign-in itself is governed by Google's own privacy policy; if you never use it, no sign-in data reaches Google. Independently of that, exercise demonstration videos are hosted on YouTube, which Google owns — so whenever a video loads, Google receives your IP address and which video you played, whether or not you use Google sign-in. We embed these in YouTube's privacy-enhanced mode, and no video loads until you open one.
Two further providers receive data on ordinary use without you choosing them. The Satoshi display font is served by Fontshare, so it receives the IP address and browser user agent of everyone who loads any page, including this one. And when you set or change a password, we check it against known breached passwords using Have I Been Pwned, which receives only the first five characters of a hash of that password — never the password itself, your email address, or your account id.
We also use public third-party food databases (Open Food Facts and the USDA FoodData Central database) to look up nutrition information. When you search for a food, the search term is sent to these services; we do not send them any account identifier or health data.
10. When We Disclose Data
We do not sell your personal data and we do not share it for cross-context behavioural advertising. We disclose personal data only:
- to the processors listed above, to operate the Service;
- where you direct us to (for example, making part of a profile public through a feature you choose to enable);
- to comply with a valid legal obligation, court order, or lawful request from a competent authority;
- to protect the rights, safety, and property of RepRoute, our users, or the public; and
- in connection with a merger, acquisition, or sale of assets, in which case we will notify you and any new owner will remain bound by this policy or a materially equivalent one.
11. International Data Transfers
Our primary database is hosted in Tokyo, Japan (Supabase ap-northeast-1). Some processors — in particular our text AI inference providers (Groq and Cerebras), our image AI provider for photo features (Cloudflare Workers AI), Resend, and, if you subscribe or use Google sign-in, Stripe and Google — are based in the United States or operate global edge networks. Where data leaves Thailand or the EEA we rely on Standard Contractual Clauses (SCCs) approved by the European Commission and on the supplementary safeguards described in those agreements, as well as the transfer mechanisms required under the PDPA.
12. Retention Periods
- Account and profile data: kept until you delete your account, then irreversibly purged after a 30-day grace period during which deletion can be cancelled.
- Smart-feature usage log: a metering record only — which feature you used, which provider handled it, how many tokens it consumed and what that cost. It contains no prompt text and no generated content. Kept for 90 days, then automatically deleted.
- Inputs and notes stored with a generated plan: when a plan is generated we save the profile snapshot that produced it — your goal, training frequency, session length, experience level, equipment, injury flags, any medical conditions or limitations you selected, any calibration results, any context you typed for that week, and, where you have set them, your body weight, height, age, and sex — together with the plan notes and which provider produced them, attached to the program record itself. This is not deleted after 90 days: it is kept for as long as you keep that program, so the plan remains explainable and reproducible, and it is removed when you delete the program or your account. It is included in your data export.
- Consent events: 7 years, as required for proof of consent under PDPA and GDPR. The IP address attached to a consent record is removed after 2 years.
- Security audit logs (sign-in events, data-access records, and rate-limit violations, including any IP address and user agent): permanently deleted after 2 years.
- Support messages: kept for up to 2 years for follow-up and record-keeping, then deleted. If you delete your account, the email address and name attached to your support messages are redacted when your account is purged.
- Email delivery records: when we send you an email (verification, password reset, a weekly summary, or an announcement) we keep a delivery record containing the subject line, the send status, and a one-way hash of the recipient address — not the address itself. These records let us prove an email was sent, retry a failed send, and avoid sending you the same announcement twice. They are deleted after 2 years.
- Programs you publish to the community library: these stay visible to other users for as long as your account exists. When your account is purged, the programs you published are deleted along with it and disappear from the library — we do not keep them as anonymous content. There is currently no self-service way to withdraw a published program on its own, so if you want one removed while keeping your account, ask us via the contact form.
- Workout history: your logged workouts are stored for the lifetime of your account, and you may export or delete them at any time. How far back you can view progress charts in the app depends on your plan (Free: the past week; Pro: up to 1 year; Elite: your full history) — this affects display only, not what we retain.
13. Your Rights
You have the following rights with respect to your personal data:
- Access — request a copy of the data we hold about you
- Rectification — correct inaccurate or incomplete data
- Erasure — ask us to delete your data ("right to be forgotten")
- Portability — receive your data in a structured, machine-readable format
- Objection — object to processing based on legitimate interest
- Restriction — ask us to limit how we process your data
- Withdraw consent — at any time, without affecting prior processing
- Lodge a complaint — with a competent supervisory authority
14. How to Exercise Your Rights
Most rights can be exercised in-app under Settings → Privacy, including data export and account deletion. For requests that cannot be self-served, use our contact form. We respond within 30 days as required by PDPA and GDPR; where a request is complex we may extend this and will tell you why. We do not charge for exercising your rights unless a request is manifestly unfounded or excessive. We may ask you to verify your identity before acting on a request.
15. Children
RepRoute is intended only for users aged 16 or older. You confirm at sign-up that you meet this minimum age. We set the threshold at 16 so that a single gate satisfies the highest digital-consent age applied across EU member states, as well as Thai PDPA expectations. We do not knowingly collect data from anyone below this age. If we learn that we have collected data from a person below this age without verifiable parental consent, we will delete it.
16. Security
We protect your data with row-level security on every database table, encrypted transport (TLS), encryption at rest by Supabase, JWT-based authentication, server-side rate limiting, and Cloudflare Turnstile bot protection. Service-role keys are held only in server runtime secrets and are never exposed to client code. Uploaded images are validated by file signature. When one member views another member's profile, and when a member of staff opens a user's account record, that access is recorded in an audit log. No method of transmission or storage is perfectly secure, but we work to protect your data using measures appropriate to its sensitivity.
Breach notification. If a personal-data breach is likely to affect your rights, we will notify the relevant supervisory authority — and, where the breach poses a high risk to you, affected users — without undue delay and, where feasible, within 72 hours of becoming aware of it, as required by GDPR Articles 33–34 and PDPA section 37.
17. Cookies and Similar Technologies
Every cookie and storage entry we set is strictly necessary, and we run no advertising or analytics trackers, so we do not display a cookie consent banner. The one exception is not ours: playing an embedded YouTube demonstration video lets Google set storage on its own domain, and that only happens if you choose to open a video. A full, itemised list — including the offline cache and the on-device workout queue — is in our Cookie Disclosure. If we ever introduce a non-essential cookie of our own, we will ask for your consent first.
18. Third-party Links
The Service may link to third-party websites or embed third-party content (for example exercise demonstration videos). We are not responsible for the privacy practices of those third parties, and this policy does not apply to them. Please review their own privacy policies.
19. Complaints and Supervisory Authorities
We would like the chance to address your concern first, so please consider contacting us before lodging a complaint. If you are in Thailand, you may lodge a complaint with the Personal Data Protection Committee (PDPC). If you are in the European Economic Area, you may complain to the data-protection authority of your country of residence, place of work, or place of the alleged infringement.
20. Changes to This Policy
We may update this policy from time to time. When we make a material change we will bump the effective date and ask you to review and accept the updated policy the next time you open RepRoute, before you can continue using it; where required by law we will also notify you by email and re-request your consent. Your continued use of the Service after an update takes effect means you accept the revised policy (except where renewed consent is required). The current version is 2026-08-18.