Privacy Policy
Last updated 1 September 2026. This policy covers the whyrep.com website and the WhyRep mobile app for iOS and Android, listed on Google Play as WhyRep: Workout Tracker.
The short version
Your training history is created and kept on your own phone, and the free tracker works fully with no account at all. If you never sign in, no copy of your training sits on any server. Signing in changes that: from then on the app keeps an automatic backup of your training, so that losing your phone does not lose your training history. Asking the coach a question also sends the part of your training that question is about, one message at a time.
There are no advertising pixels anywhere, no cookies on the website, no data sold or rented, and nothing that follows you to other websites or other apps. Everything that does leave your phone or your browser is listed below, with what sends it and when.
What this policy covers, in two parts
The website and the app collect different things for different reasons, so they are written up separately. Part one is whyrep.com, which today is a waitlist page. Part two is the WhyRep app. If you only use one of them, only that part applies to you.
WhyRep is published by Arqam Waheed, an individual developer. The contact for anything in this policy, including any request to see or delete your data, is the email address at the bottom of this page.
Part one: the website
What is collected when you join the waitlist:
- Your email address, exactly as you typed it.
- A short source tag such as
tt-mainorlanding, taken from the?src=parameter on the link you arrived through. It records which channel a signup came from. It is not tied to you as a person and is not used to build a profile. - A timestamp of when you signed up.
That is the complete list for the waitlist. No name, no IP address stored by us, no device fingerprint, no location, no health or fitness data. Your email address doubles as the record key, so signing up twice does not create a second record. Error monitoring is separate and is described below; your email address is deliberately kept out of it.
Why the waitlist is collected
To email you once when the beta opens, and to know which channel a signup came from so effort goes where it is actually working. Your email is not sold, rented, or shared for anyone else's marketing, and never will be.
Where the waitlist is stored
In Google Firebase Firestore, in a project controlled by WhyRep. Google acts as the data processor. The site itself is hosted on Cloudflare Pages, which processes requests in order to serve the page and may log them for security and abuse prevention as part of its normal operation. Error reports go to Sentry instead, as described below; the waitlist and the error monitor are kept separate.
How long the waitlist is kept
Until the beta launch email has gone out and you have had a reasonable chance to act on it, or until you ask for it to be deleted, whichever comes first. If WhyRep is discontinued before launch, the waitlist is deleted.
Visitor counting on the website
This site uses Cloudflare Web Analytics to count visits. Cloudflare acts as a data processor. It is switched on at the Cloudflare account rather than written into the page, so it is listed here alongside everything else that leaves your browser.
It is cookieless. It sets nothing on your device, gives you no identifier, and cannot follow you to another website. What it receives on a page view:
- The page address you landed on, and the referring address if you arrived from a link elsewhere.
- Browser, operating system, device type, and the country your request came from.
- Page load and performance timings.
What it does not receive: your email address, any identifier that persists between visits, and anything you type into the page. Because there is no persistent identifier, the counts are of visits, not of people, and no profile of you exists to build on. Cloudflare derives the country from your IP address as the request arrives; the address itself is not stored in the analytics.
Error monitoring on the website
This site uses Sentry to find out when a page breaks. Sentry acts as a data processor. It is separate from the visitor counting above: it is not used to measure marketing or to build a profile of you, and it is not shared with anyone.
When an error occurs, or on a small sample of visits for speed measurement, Sentry receives:
- The error message and the technical stack trace that produced it.
- The page address, with the part after
#and any?parameters removed before sending. This matters on shared-template links, where that part of the address contains the workout itself. - Browser, operating system, and page performance timings.
- Your IP address, which Sentry receives because every internet request carries one.
Your email address is never sent to Sentry. The address you type into the waitlist form is deliberately stripped out before anything leaves the page.
On shared workout template links only (addresses beginning whyrep.com/t), Sentry also records a replay of the page if it breaks, so the fault can be reproduced. All text and images are masked out of that recording before it is sent, and the shared workout itself is never included. The main site does not record replays at all.
Cookies and browser storage on the website
No cookies are set by this site. These browser storage entries are used, all readable only by this site:
whyrep-themeinlocalStorage, remembering whether you chose light or dark mode.whyrep-srcinsessionStorage, holding the source tag described above until you close the tab.sentryReplaySessioninsessionStorage, on shared-template links only, identifying one visit to the error monitor described above. It is discarded when you close the tab.
None is used for advertising or for tracking you across other websites. Clearing your browser storage removes them all.
Part two: the app
WhyRep is a workout tracker. You log your sets, and the app reads that log and gives each session a verdict. That analysis runs on your phone. It is ordinary code on the device, not a request to a server, so no set, weight, rep count or RIR value is sent anywhere in order to produce a verdict.
The sections below list everything the app holds, everything it can send, and what makes it send.
What stays on your device
- Your training history in full: sessions, exercises, sets, weights, reps, RIR values, and any notes you write.
- Your templates, splits and any custom exercises you add.
- The profile details you enter at setup: sex, bodyweight and training experience. These feed the analyzer's experience thresholds and are used for nothing else.
- Your coach chat history, which is stored on the phone.
- Your profile photo, if you set one. It is copied into the app's own private storage and is never uploaded.
- Your settings, including theme and weight unit.
- A random number generated when you installed the app, used only to decide which of two arrangements of the upgrade screen you see, so that it stays the same every time you open it. It is not tied to your phone, your Google or Apple account, or anything outside this app, and it never leaves your device. See "Purchases" below.
Uninstalling the app removes all of it from your phone. Note that Android's own backup feature, which is a function of your phone and your Google account rather than of WhyRep, may hold a copy of an app's data under Google's policies rather than this one. That is separate from the account sync described further down.
What leaves your device, and what makes it happen
This is the complete list. Each one has its own section below.
- Signing in sends your email address and name to Clerk, our sign-in provider. Optional: the sign-in screen has a "Skip for now" button and the free tracker works without an account.
- Sending the coach a message sends your question, the recent training that question is about, and the recent messages in that conversation. It happens only when you press send, and only on WhyRep Plus.
- Being signed in uploads a copy of your training history, automatically, so you can restore it on a new phone. It happens when you finish a workout and when the app goes to the background. There is no setting to switch on: it is part of having an account.
- Buying or restoring Plus sends purchase and subscription state to RevenueCat, and to Google Play or the App Store.
- A crash or an error sends a crash report to Sentry.
Nothing else in the app makes a network request. There is no advertising software in it, no analytics product that follows you between apps, and no data sold or shared for anyone else's marketing.
Signing in
Sign-in is handled by Clerk, acting as a data processor for WhyRep. When you sign in, Clerk holds your email address, your name, and your profile image URL if your sign-in method provides one, and issues WhyRep an account identifier for you.
Signing in is optional. Onboarding shows a "Skip for now" button every time it is shown, and the entire free tracker works with no account. An account is what makes the coach, purchases and account sync possible, and nothing else in the app depends on one.
Coach chat
Coach chat is a WhyRep Plus feature. When, and only when, you send a message, the app sends to our own server:
- Your question, as you typed it.
- Workout context: the recent training the question is about. This is fitness data about you and is described as such in the app's Google Play data safety disclosure.
- The recent messages in that conversation, so the answer follows on from what you already asked.
That request goes to a Cloudflare Worker run by WhyRep, which checks your sign-in, applies a daily limit, and passes the question to Anthropic, whose model writes the answer. Cloudflare and Anthropic both act as processors for WhyRep. The answer comes back to your phone and the conversation is stored on your phone.
If you never send a coach message, no fitness data leaves your device through this route at all.
Account sync
If you are signed in, your training history is backed up automatically. There is no switch to turn on and no button to press. The app uploads a copy when you finish a workout and when it goes to the background, and only when something has actually changed since the last upload. Its purpose is backup and restore: so that losing your phone does not lose your training history.
If you never sign in, none of this happens, and there is no copy of your training on any server.
The uploaded copy contains your sessions, exercises and sets, templates, splits, custom exercises, the fixes you have accepted or declined, any volume adjustments you have made yourself, and the profile details you entered at setup. It is stored in Cloudflare R2, in storage controlled by WhyRep, under a location the server works out from your account. Your phone does not get to name that location, which is what makes it impossible for one person's app to ask for another person's history.
Your coach chat history is deliberately not synced. It is the most personal thing the app holds and the least useful to keep, so it stays on the phone and goes when the app goes.
The uploaded copy is not analyzed. It is stored so it can be given back to you. Verdicts, plateau findings and every other piece of analysis are computed on your phone, and that is an architectural rule in WhyRep rather than a promise about intentions.
Signing out clears the training from your phone. The app uploads your backup first, so that signing in again on that phone or a new one brings your training back. The phone is cleared whether or not that upload succeeded, so sign out on a working internet connection.
The uploaded copy is kept until you delete it or delete your account, both of which are described under "Deleting your data" below.
Purchases
WhyRep Plus is sold through Google Play and the App Store, and subscription state is managed by RevenueCat acting as a processor for WhyRep. RevenueCat receives an app user identifier, the purchase and subscription state for your account, and basic device information. It is used to answer one question: whether Plus is active for you.
Payment card details are handled by Google or Apple and are never seen by WhyRep.
RevenueCat also receives one label saying which version of the upgrade screen your app shows, which is either the word "control" or the word "product_first". WhyRep shows two slightly different arrangements of that screen, and this label is the only way to tell which of them people found clearer. The choice is made by your phone from a random number generated when you installed the app. That random number stays on your phone and is never sent anywhere.
What is deliberately not sent is anything the analyzer worked out about you. The upgrade screen does change depending on what the app found in your own training, and that decision is made entirely on your phone: which version of the screen you see is transmitted, but the reason you were shown it never is. That is a design choice with a real cost to us, because it means we cannot tell whether one arrangement works better for people who have just hit a plateau. We would rather not know that than send it.
Crash reporting in the app
The app uses Sentry, acting as a processor, to find out when something breaks. On a crash or an error, Sentry receives the error and its technical stack trace, your device model and operating system version, an installation identifier, and your IP address, which every internet request carries.
Training data is deliberately kept out of crash reports. The app scrubs its reports before sending so that workouts, weights and notes do not ride along inside a diagnostic. Crash reporting is not analytics: it is not used to profile you or to measure marketing.
Deleting your data
Different things live in different places, so there are three separate answers, and you can use any of them independently.
- Training data on your phone. Uninstall the app. Everything the app stored locally goes with it. Nothing needs to be requested from us, because we never had a copy.
- Your account and everything held for it off the device, including the backed-up copy of your training history, if you have ever signed in. There are two ways, and they do the same thing. In the app: Profile, then Delete my account. On the web, including if you have already uninstalled: the account deletion page at whyrep.com/delete-account, which explains exactly what is deleted, what is kept and for how long. Neither one touches the training stored on your own phone; uninstalling is what removes that.
- Your waitlist email address on this website. Email the address at the bottom of this page and it is removed.
After an account deletion request, records that have to be kept for legal or accounting reasons are kept and nothing else is. Purchase and subscription records held by Google Play or the App Store are held under their policies and are not ours to delete. The deletion page sets out the detail.
Where your data is processed
WhyRep uses service providers based in the United States, listed by name in the sections above. If you are in the UK or the EU, this means data described on this page may be processed outside your country. Each provider is used as a processor acting on WhyRep's instructions, and none of them is given your data for their own marketing.
Your rights
You can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted, at any time and without giving a reason. Email the address below, or use the deletion page linked above, and it will be handled. If you are in the UK, EU, or a jurisdiction with comparable law, these rights are yours by statute rather than by our permission.
Children
WhyRep is not directed at children under 13. The waitlist is not intended for them, and accounts are not knowingly created for them. If you believe a child has given us their information, email the address below and it will be deleted.
Changes
If this policy changes materially, the date at the top changes with it, and the change is described in the release notes of the version it applies to. Anyone on the waitlist will be told in the launch email rather than left to notice.
Contact
Questions, or a deletion request: support@whyrep.com. To delete a WhyRep account and the data held for it, use the account deletion page.