Privacy Policy

Last updated 1 September 2026. This policy covers the whyrep.com website and the WhyRep mobile app for iOS and Android, listed on Google Play as WhyRep: Workout Tracker.

The short version

Your training history is created and kept on your own phone, and the free tracker works fully with no account at all. If you never sign in, no copy of your training sits on any server. Signing in changes that: from then on the app keeps an automatic backup of your training, so that losing your phone does not lose your training history. Asking the coach a question also sends the part of your training that question is about, one message at a time.

There are no advertising pixels anywhere, no cookies on the website, no data sold or rented, and nothing that follows you to other websites or other apps. Everything that does leave your phone or your browser is listed below, with what sends it and when.

What this policy covers, in two parts

The website and the app collect different things for different reasons, so they are written up separately. Part one is whyrep.com, which today is a waitlist page. Part two is the WhyRep app. If you only use one of them, only that part applies to you.

WhyRep is published by Arqam Waheed, an individual developer. The contact for anything in this policy, including any request to see or delete your data, is the email address at the bottom of this page.

Part one: the website

What is collected when you join the waitlist:

That is the complete list for the waitlist. No name, no IP address stored by us, no device fingerprint, no location, no health or fitness data. Your email address doubles as the record key, so signing up twice does not create a second record. Error monitoring is separate and is described below; your email address is deliberately kept out of it.

Why the waitlist is collected

To email you once when the beta opens, and to know which channel a signup came from so effort goes where it is actually working. Your email is not sold, rented, or shared for anyone else's marketing, and never will be.

Where the waitlist is stored

In Google Firebase Firestore, in a project controlled by WhyRep. Google acts as the data processor. The site itself is hosted on Cloudflare Pages, which processes requests in order to serve the page and may log them for security and abuse prevention as part of its normal operation. Error reports go to Sentry instead, as described below; the waitlist and the error monitor are kept separate.

How long the waitlist is kept

Until the beta launch email has gone out and you have had a reasonable chance to act on it, or until you ask for it to be deleted, whichever comes first. If WhyRep is discontinued before launch, the waitlist is deleted.

Visitor counting on the website

This site uses Cloudflare Web Analytics to count visits. Cloudflare acts as a data processor. It is switched on at the Cloudflare account rather than written into the page, so it is listed here alongside everything else that leaves your browser.

It is cookieless. It sets nothing on your device, gives you no identifier, and cannot follow you to another website. What it receives on a page view:

What it does not receive: your email address, any identifier that persists between visits, and anything you type into the page. Because there is no persistent identifier, the counts are of visits, not of people, and no profile of you exists to build on. Cloudflare derives the country from your IP address as the request arrives; the address itself is not stored in the analytics.

Error monitoring on the website

This site uses Sentry to find out when a page breaks. Sentry acts as a data processor. It is separate from the visitor counting above: it is not used to measure marketing or to build a profile of you, and it is not shared with anyone.

When an error occurs, or on a small sample of visits for speed measurement, Sentry receives:

Your email address is never sent to Sentry. The address you type into the waitlist form is deliberately stripped out before anything leaves the page.

On shared workout template links only (addresses beginning whyrep.com/t), Sentry also records a replay of the page if it breaks, so the fault can be reproduced. All text and images are masked out of that recording before it is sent, and the shared workout itself is never included. The main site does not record replays at all.

Cookies and browser storage on the website

No cookies are set by this site. These browser storage entries are used, all readable only by this site:

None is used for advertising or for tracking you across other websites. Clearing your browser storage removes them all.

Part two: the app

WhyRep is a workout tracker. You log your sets, and the app reads that log and gives each session a verdict. That analysis runs on your phone. It is ordinary code on the device, not a request to a server, so no set, weight, rep count or RIR value is sent anywhere in order to produce a verdict.

The sections below list everything the app holds, everything it can send, and what makes it send.

What stays on your device

Uninstalling the app removes all of it from your phone. Note that Android's own backup feature, which is a function of your phone and your Google account rather than of WhyRep, may hold a copy of an app's data under Google's policies rather than this one. That is separate from the account sync described further down.

What leaves your device, and what makes it happen

This is the complete list. Each one has its own section below.

Nothing else in the app makes a network request. There is no advertising software in it, no analytics product that follows you between apps, and no data sold or shared for anyone else's marketing.

Signing in

Sign-in is handled by Clerk, acting as a data processor for WhyRep. When you sign in, Clerk holds your email address, your name, and your profile image URL if your sign-in method provides one, and issues WhyRep an account identifier for you.

Signing in is optional. Onboarding shows a "Skip for now" button every time it is shown, and the entire free tracker works with no account. An account is what makes the coach, purchases and account sync possible, and nothing else in the app depends on one.

Coach chat

Coach chat is a WhyRep Plus feature. When, and only when, you send a message, the app sends to our own server:

That request goes to a Cloudflare Worker run by WhyRep, which checks your sign-in, applies a daily limit, and passes the question to Anthropic, whose model writes the answer. Cloudflare and Anthropic both act as processors for WhyRep. The answer comes back to your phone and the conversation is stored on your phone.

If you never send a coach message, no fitness data leaves your device through this route at all.

Account sync

If you are signed in, your training history is backed up automatically. There is no switch to turn on and no button to press. The app uploads a copy when you finish a workout and when it goes to the background, and only when something has actually changed since the last upload. Its purpose is backup and restore: so that losing your phone does not lose your training history.

If you never sign in, none of this happens, and there is no copy of your training on any server.

The uploaded copy contains your sessions, exercises and sets, templates, splits, custom exercises, the fixes you have accepted or declined, any volume adjustments you have made yourself, and the profile details you entered at setup. It is stored in Cloudflare R2, in storage controlled by WhyRep, under a location the server works out from your account. Your phone does not get to name that location, which is what makes it impossible for one person's app to ask for another person's history.

Your coach chat history is deliberately not synced. It is the most personal thing the app holds and the least useful to keep, so it stays on the phone and goes when the app goes.

The uploaded copy is not analyzed. It is stored so it can be given back to you. Verdicts, plateau findings and every other piece of analysis are computed on your phone, and that is an architectural rule in WhyRep rather than a promise about intentions.

Signing out clears the training from your phone. The app uploads your backup first, so that signing in again on that phone or a new one brings your training back. The phone is cleared whether or not that upload succeeded, so sign out on a working internet connection.

The uploaded copy is kept until you delete it or delete your account, both of which are described under "Deleting your data" below.

Purchases

WhyRep Plus is sold through Google Play and the App Store, and subscription state is managed by RevenueCat acting as a processor for WhyRep. RevenueCat receives an app user identifier, the purchase and subscription state for your account, and basic device information. It is used to answer one question: whether Plus is active for you.

Payment card details are handled by Google or Apple and are never seen by WhyRep.

RevenueCat also receives one label saying which version of the upgrade screen your app shows, which is either the word "control" or the word "product_first". WhyRep shows two slightly different arrangements of that screen, and this label is the only way to tell which of them people found clearer. The choice is made by your phone from a random number generated when you installed the app. That random number stays on your phone and is never sent anywhere.

What is deliberately not sent is anything the analyzer worked out about you. The upgrade screen does change depending on what the app found in your own training, and that decision is made entirely on your phone: which version of the screen you see is transmitted, but the reason you were shown it never is. That is a design choice with a real cost to us, because it means we cannot tell whether one arrangement works better for people who have just hit a plateau. We would rather not know that than send it.

Crash reporting in the app

The app uses Sentry, acting as a processor, to find out when something breaks. On a crash or an error, Sentry receives the error and its technical stack trace, your device model and operating system version, an installation identifier, and your IP address, which every internet request carries.

Training data is deliberately kept out of crash reports. The app scrubs its reports before sending so that workouts, weights and notes do not ride along inside a diagnostic. Crash reporting is not analytics: it is not used to profile you or to measure marketing.

Deleting your data

Different things live in different places, so there are three separate answers, and you can use any of them independently.

After an account deletion request, records that have to be kept for legal or accounting reasons are kept and nothing else is. Purchase and subscription records held by Google Play or the App Store are held under their policies and are not ours to delete. The deletion page sets out the detail.

Where your data is processed

WhyRep uses service providers based in the United States, listed by name in the sections above. If you are in the UK or the EU, this means data described on this page may be processed outside your country. Each provider is used as a processor acting on WhyRep's instructions, and none of them is given your data for their own marketing.

Your rights

You can ask for a copy of what is held about you, ask for it to be corrected, or ask for it to be deleted, at any time and without giving a reason. Email the address below, or use the deletion page linked above, and it will be handled. If you are in the UK, EU, or a jurisdiction with comparable law, these rights are yours by statute rather than by our permission.

Children

WhyRep is not directed at children under 13. The waitlist is not intended for them, and accounts are not knowingly created for them. If you believe a child has given us their information, email the address below and it will be deleted.

Changes

If this policy changes materially, the date at the top changes with it, and the change is described in the release notes of the version it applies to. Anyone on the waitlist will be told in the launch email rather than left to notice.

Contact

Questions, or a deletion request: support@whyrep.com. To delete a WhyRep account and the data held for it, use the account deletion page.