← Back to GoodReps
Last updated: July 28, 2026 · Effective: June 4, 2026
The short version
Camera + voice stay on your device. Pose detection happens locally via TensorFlow.js. Voice meal logging transcribes audio in your browser; only the resulting text leaves your device.
Sign-in is optional. Without an account, all your data lives only on your device's localStorage.
When you sign in, your workouts, meals, breath sessions, XP, achievements, and preferences are synced to Supabase so they follow you across devices. You can delete everything at any time from Profile → Delete Account.
We never sell your data. No advertisers. No tracking cookies. No third-party analytics SDKs in the app. Our anonymous usage counters are aggregate-only and roll up after 90 days.
If anything in this policy is unclear, email support@goodrepsapp.com and we'll explain.
Privacy Policy
1. Who we are
GoodReps is an AI-powered fitness app operated by GoodReps App, Inc. ("GoodReps", "we", "us"). The app, the website at goodrepsapp.com, and the API at goodrepsapp.com/api/* are all part of the same service.
For privacy questions, data requests, or to exercise any of your rights below, contact: support@goodrepsapp.com
2. What we collect
On-device only (we never see this)
- Camera feed. Processed entirely on your device by TensorFlow.js MoveNet and MediaPipe Hands. No frames, images, or pose keypoints are ever uploaded.
- Voice audio for meal logging. Transcribed in your browser using the Web Speech API. The raw audio never leaves your device.
- Local-only data (when signed out). If you choose not to sign in, your workouts, meal log, breath sessions, gamification state, calibration, and preferences live exclusively in your browser's
localStorage. They are not transmitted anywhere. Clearing your browser data deletes them permanently.
Data we collect when you sign in or interact with our services
- Account email. Used to send you a magic sign-in link via Supabase Auth, and as your identifier across devices.
- Synced fitness data. When signed in, your workout log, food log, breath sessions, breath-hold tests, gamification state (XP, level, streak, achievements), food profile, and section preferences are stored on Supabase Postgres so they follow you across devices.
- Optional profile fields. Display name and body weight, if you set them. Used for calorie estimates and your own dashboard.
- Voice meal transcript text. When you use voice meal logging, the transcribed text (not audio) is sent to Anthropic's Claude API for parsing into macronutrients. The text is processed transiently and not stored by Anthropic beyond their standard API retention.
- Meal photos (photo logging). When you use "Snap a meal," the photo is resized on your device and sent once to Anthropic's Claude API to identify foods and estimate nutrition. GoodReps never stores the photo on our servers — only the food items you confirm are saved to your log. Photos are processed transiently and are not used to train Anthropic models.
- Coach prompts. When you use GoodReps Coach, your typed message and a small context summary (today's workout count, today's food log totals, current section preferences — never your full history) are sent to Anthropic's Claude API to generate the response.
- Payment information. If you purchase Pro, Stripe processes your card data directly. We never see or store card numbers, expiry, or CVC. We receive only your purchase confirmation, the email you used at checkout, your Stripe customer ID, and an internally-generated license key.
- Accountability buddies (Pro feature). If you invite a buddy by email, that email address is sent to Resend for delivery. If you redeem a buddy code, you and the inviter form a pair record; you can each see the other's name (if set), level, current streak, last-active date. No buddy ever sees the contents of your workouts, meals, or messages.
- Verified social posts (UGC). If you share an achievement card and submit your post URL for verification, the URL and the magic token in your caption are stored so we can confirm the post and award bonus XP. The post itself is already public — we only read what anyone could read.
- Anonymous usage counters. Aggregate counts like "a workout was completed" or "Coach was used" are written to Vercel KV (Upstash Redis) keyed by date + event type only. Each device generates a random install ID that is not tied to your email or any identity. We never log the contents of your workouts, meals, or messages. Counters expire automatically after 90 days. You can disable this entirely in Profile → Privacy → Anonymous usage analytics.
- Transient request metadata. Like every web service, our hosting provider (Vercel) receives your IP address when you make a request. IP is used for routing and basic rate-limiting and is held in Vercel's edge logs subject to their retention. We do not write your IP to any of our own databases.
3. Who else processes your data (and why)
GoodReps uses a small set of well-known third-party processors. Each one only receives the minimum data needed to do its job. Each has its own privacy policy linked below — if you'd rather not have your data sent to a particular processor, the alternative is to not use the feature that uses it.
| Processor | Used for | What it receives |
Supabase privacy | Magic-link auth, server-side data sync, buddy pairs, user profile | Email, workout/food/breath/gamification/prefs rows, buddy invites + pairings, user profile fields. Encrypted at rest. |
Stripe privacy | Pro purchases (one-time + subscription), customer portal, subscription lifecycle | Card data (direct to Stripe, never touches us), billing email, customer ID, subscription state, license key in customer metadata. |
Anthropic (Claude API) privacy | GoodReps Coach (free + Pro), voice meal parsing, photo meal parsing | Your Coach prompt + small context summary; voice meal transcript text; meal photos (sent once for parsing, never stored by GoodReps). Processed transiently. Subject to Anthropic API DPA — not used to train Anthropic models. |
Resend privacy | Email delivery: Pro receipts, buddy invites, admin pipeline notifications | Recipient email, subject, body for those transactional emails. |
Vercel privacy | App + API hosting + edge functions | IP address (transient), HTTP request metadata, edge logs. |
Vercel KV / Upstash Redis privacy | Aggregate analytics counters, UGC verification records | Counter values keyed by date + event + random install ID. UGC tokens + verified post URLs. 90-day expiry on analytics. |
jsDelivr CDN privacy | Serving TensorFlow.js, MediaPipe, and Supabase JS libraries on first load | IP address (transient), user agent (standard CDN access logs). |
Google Fonts privacy | Loading the Bebas Neue and Space Mono webfonts on the landing page + privacy page | IP address (transient). |
Google Play Services privacy | Install + in-app review prompt on Android (via @capacitor-community/in-app-review) | Whether the review prompt was shown. We do not use the Advertising ID — that's explicitly excluded in our AndroidManifest. |
We do not use: Google Analytics, Facebook Pixel, advertising SDKs, third-party trackers, session-replay tools, or any "fingerprinting" service. There are no ads in GoodReps.
4. How we use your data
- Run the app you signed up for. Sync your data across devices, award XP and achievements, count reps, generate share cards.
- Communicate with you. Magic sign-in links, Pro receipts, buddy invite confirmations, occasional product updates (you can opt out anytime via the unsubscribe link in any email).
- Process payments. Stripe handles the card; we receive only the confirmation needed to grant Pro.
- Improve the app. The anonymous counters in §2 tell us which features get used and where users drop off. Always opt-out-able.
- Comply with the law. Respond to lawful legal requests, prevent abuse, enforce our terms.
We do not sell your data, share it with advertisers, build advertising profiles, or use it for any purpose disconnected from running GoodReps for you.
Our lawful bases (UK / EU / Ireland)
If UK or EU data protection law applies to you, these are the Article 6 bases we rely on:
- Contract. Running the app you signed up for — sync, XP and achievements, rep counting, Pro entitlement, and the transactional emails that go with them.
- Consent. Anonymous usage analytics, marketing emails, camera and microphone access, and Accountability Buddies. Each is opt-in or opt-out-able in Profile, and you can withdraw consent at any time without losing access to the rest of the app.
- Legitimate interests. Keeping the service secure and preventing abuse (rate limiting, UGC verification), and understanding aggregate feature usage where you haven't opted out. We've balanced these against your rights and use the least data that works.
- Legal obligation. Tax and financial records held via Stripe, and responding to lawful legal requests.
We do not use your data for automated decision-making or profiling that produces legal or similarly significant effects.
5. Your rights
Regardless of where you live, you have the following rights over your GoodReps data:
- Access. Request a copy of your data by emailing support@goodrepsapp.com — we'll provide it within 30 days.
- Portability. Export your workout history as CSV any time via the Log panel's Export button.
- Deletion. Profile → Delete Account. Server-side rows in Supabase are removed, all locally-stored data is wiped from your device, your Pro subscription is cancelled if active, and you're signed out. Stripe customer records (for tax / dispute compliance) and edge logs (per Vercel retention) may persist as required by law.
- Correction. Update your name, email, weight, or preferences in Profile at any time.
- Opt out of analytics. Profile → Privacy → Anonymous usage analytics. Counter-writes stop immediately.
- Opt out of buddies. Profile → Accountability Buddies → Unpair. Your buddy stops seeing your stats and vice versa.
- Opt out of marketing emails. Unsubscribe link in any email. Transactional emails (Pro receipts, magic links) still go through — they're required to operate the app.
- Lodge a complaint. If you're in the EU/UK, you can complain to your local data protection authority. We'd rather hear from you first so we can fix the problem — email us.
6. Data retention
- Account + synced fitness data: kept while your account is active. Deleted within 30 days of Delete Account.
- Anonymous analytics counters: 90-day rolling expiry. No per-event rows are kept.
- Stripe customer records: retained per Stripe's policy and as required for tax / financial law (typically 7+ years). Card data is held by Stripe, not us.
- Email delivery logs (Resend): 30-90 days per Resend's policy.
- Verified UGC submissions: kept while the achievement loop is active so we don't re-verify the same post twice. Can be deleted on request.
- Server / edge access logs (Vercel): retained per Vercel's standard policy.
7. Security
All connections to goodrepsapp.com and to our processors run over HTTPS. Supabase encrypts your data at rest and enforces row-level security policies so a signed-in user can only access their own rows. We use Stripe-managed checkout pages so card data never touches our servers. Admin endpoints require a server-side password and fail closed if it's unset. We rotate API keys when staff turns over.
No system is 100% secure. If we ever experience a breach affecting your data, we'll notify affected users within 72 hours and disclose what we know.
8. International data transfers
GoodReps is operated from the United States. Our Supabase project is hosted in the US; Stripe, Anthropic, Vercel, Resend, and Upstash are also US-based. If you're outside the US (including the EU/UK), your data will be transferred to and processed in the US. We rely on Standard Contractual Clauses (where applicable) for these transfers via our processors' DPAs.
9. Children's privacy
GoodReps is not directed at children under 13 (or under 16 in the EU/UK) and we do not knowingly collect data from them. If you believe a child has provided us data, contact support@goodrepsapp.com and we'll delete it promptly.
10. Cookies and local storage
GoodReps uses your browser's localStorage to keep your workouts, meal log, and preferences on-device by default. When you sign in, we set a Supabase auth cookie (httpOnly, secure) to keep you signed in. We do not set any third-party tracking cookies. The third-party CDN (jsDelivr) and Google Fonts may log your IP address when you load their resources.
11. Regional addendum — UK, Ireland/EU, Australia, Canada, New Zealand
GoodReps is available in these markets and the sections above apply to everyone. This addendum adds the country-specific detail each regime requires. Nothing here reduces the rights in §5 — it only tells you which regulator to go to and which extra rules we're following.
United Kingdom (UK GDPR + Data Protection Act 2018)
- Controller. GoodReps is the data controller for the data described in §2. Contact support@goodrepsapp.com for any data protection question.
- Lawful bases. Listed in §4.
- Your additional rights. Beyond §5 you may object to processing based on legitimate interests, ask us to restrict processing while a dispute is resolved, and withdraw consent at any time (withdrawal doesn't affect processing already carried out).
- Complaints. You can complain to the Information Commissioner's Office (ICO) at ico.org.uk. Please email us first — we'd rather fix it.
- Transfers. Your data is processed in the US (§8). We rely on the UK International Data Transfer Addendum to the EU Standard Contractual Clauses through our processors' data processing agreements.
- No UK representative. We're a small US operation and have not appointed an Article 27 UK representative; write to us directly at the address above.
Ireland and the EU (GDPR)
Everything in the UK section applies, reading "EU GDPR" for "UK GDPR". Complaints go to your national supervisory authority — in Ireland, the Data Protection Commission (dataprotection.ie). Transfers to the US rely on the EU Standard Contractual Clauses via our processors' DPAs.
Australia (Privacy Act 1988 + Australian Privacy Principles)
- Access and correction (APP 12/13). Use the routes in §5, or email us — we'll respond within 30 days and won't charge you for it.
- Cross-border disclosure (APP 8). Your data is stored and processed in the United States by the processors listed in §3. By using GoodReps you acknowledge that once your data is overseas we can't control it under Australian law in the same way, though our processor agreements require equivalent protections.
- Notifiable Data Breaches scheme. If a breach is likely to result in serious harm, we'll notify you and the Office of the Australian Information Commissioner (OAIC) as the scheme requires — the 72-hour commitment in §7 is our own floor, not the statutory deadline.
- Complaints. Email us first; if you're not satisfied you can complain to the OAIC at oaic.gov.au.
- Government identifiers. We don't collect or use any government-issued identifier, and we don't require one to use GoodReps.
Canada (PIPEDA)
- Consent. We collect only what §2 describes and use it only for the purposes in §4. You can withdraw consent for analytics, marketing, camera/microphone, and buddies at any time in Profile.
- Storage outside Canada. Your data is stored in the United States and is subject to US law, including lawful access requests by US authorities.
- Complaints. Email us first, then the Office of the Privacy Commissioner of Canada at priv.gc.ca.
New Zealand (Privacy Act 2020)
- Information privacy principles. Access and correction work through the routes in §5.
- Disclosure outside New Zealand (IPP 12). Your data is processed in the US by the processors in §3, under contractual protections comparable to the Privacy Act.
- Privacy breaches. We'll notify you and the Office of the Privacy Commissioner where a breach is likely to cause serious harm, as Part 6 requires.
- Complaints. privacy.org.nz.
12. Changes to this policy
We'll update the "Last updated" date when this policy changes. For material changes (new processors, new data categories, changes that materially affect your rights), we'll surface a notice in the app the next time you open it. Continued use after a change means you accept the updated policy. The full revision history is in our public git repository.
Terms of Service
Use of the app
GoodReps is provided "as is" without warranty of any kind. The app uses AI-based pose estimation to count exercise repetitions and provide form feedback. This technology is not perfect and should not be relied upon as a substitute for professional fitness instruction.
Always consult with a healthcare provider before starting any new exercise program. GoodReps is not a medical device and does not provide medical advice. Voice meal parsing and Coach responses are generated by an AI model and may be incorrect — verify nutritional and training information with qualified sources.
Calorie estimates
Calorie burn estimates provided by GoodReps are approximations based on standard MET (Metabolic Equivalent of Task) values and user-provided body weight. Macros parsed from voice or text input are AI-generated estimates from public food databases. Actual values vary. These figures should not be used for medical or dietary decisions.
GoodReps Pro
GoodReps Pro is offered as a $7/month subscription, a $49/year subscription, or a $99 one-time lifetime purchase (launch pricing through the first year of public availability; the lifetime tier may rise to $149 thereafter). There is no free trial; the free tier of the app lets you evaluate GoodReps before purchasing. "Lifetime" refers to the lifetime of the product; if GoodReps is discontinued, Pro features will continue to work in the last released version. Subscriptions auto-renew until cancelled via Profile → Manage Subscription. Refunds are handled per the policy of the platform through which the purchase was made (Google Play, App Store, or web via Stripe) and as required by applicable consumer protection law.
Accountability Buddies
Buddy invites grant the recipient 30 days of GoodReps Pro at no cost as a gift from the inviter. Both users agree that their name (if set), level, current streak, and last-active date are visible to their paired buddy for as long as the pairing is active. Either side can unpair at any time. Misuse of the buddy system (spam invites, fake accounts) may result in restriction or removal.
User-generated content (share cards + post verification)
When you share a GoodReps achievement card to a social platform and verify the post for bonus XP, you confirm the post is public and contains the GoodReps magic token in the caption. We may fetch and display your verified post in admin tools for curation, and may repost selected verified content on official GoodReps social channels with a +500 XP feature code. You retain all rights to your underlying content; verifying a post grants GoodReps a non-exclusive license to display the URL on our brand channels. We will remove any verified post on request.
Limitation of liability
To the maximum extent permitted by law, GoodReps and its creators shall not be liable for any injury, damage, or loss arising from use of the app, including but not limited to injuries sustained during exercise. You use GoodReps at your own risk.