Last updated
Privacy policy
Who we are
One Rep Closer is run by Graham Bond, a sole trader in the United Kingdom, trading as One Rep Closer. For UK GDPR, we are the controller of the personal data described on this page. The publisher named on both app stores is Graham Bond, trading as One Rep Closer.
Write to privacy@onerepcloser.fit. Email is how we work; we do not publish a postal address.
The short version
We collect the little the app needs to do its job and nothing beyond it. We do not sell your data, we do not share it so that somebody else can market to you, we do not show ads, and we do not build a profile of you. This website sets no cookies at all, which is why you were not asked about any.
This website
No cookies. The site stores nothing in your browser. The fonts are served from our own domain, so loading a page sends no request to Google Fonts or any other font service.
Page counts. We use Cloudflare Web Analytics to see how many people read each page. It is cookieless, it does not fingerprint your browser, and it cannot follow you to other sites. We get counts, not people.
Server logs. The site is hosted by Cloudflare. Like any web server, Cloudflare records the requests it serves — the IP address the request came from, the time, the page, the browser’s user-agent — to deliver the site and keep it from being abused. We do not use those records to work out who you are.
The waitlist. If you give us your email address, it goes to Buttondown, who run the list for us. The IP address the form was submitted from goes with it: Buttondown uses it to filter out bot sign-ups. Buttondown then emails you to confirm you meant it, and you are only added if you click that link. We use the list for one thing, telling you the app is out. Every email has an unsubscribe link, and you can ask us to remove you at any time.
The app
When you are signed out
Everything you log is written to a database on the phone itself. Your templates, your sessions, your sets, your records, your settings — all of it is on the device, and none of it is sent to us. The app works with the phone in aeroplane mode, and it works if we disappear.
Two things still use the network, and neither carries your training with it:
- Checking whether Premium has been bought on this device. That check goes to RevenueCat, who run subscriptions for us, under an anonymous identifier they generate for the install. It carries your purchase history and basic device information, set out under Subscriptions below.
- Opening a template somebody shared with you. The code you type goes to our server, which sends back the template it stands for. No account and nothing about your training goes with it.
The app asks for no device permissions. It does not use the camera, your photos, your location, your contacts or your microphone, and it does not connect to Apple Health or Google Fit. It has no fields for medical information — notes are free text, so please keep anything medical out of them.
When you sign in
You sign in with Apple or with Google. There is no password to create and none for us to lose. From the provider we receive your email address and, if your account has one to give, your name. Apple sends a name on the first sign-in only, so that is the moment we keep it. If you use Apple’s Hide My Email, the relay address is the only address we ever see. The sign-in token that keeps you signed in is held in the phone’s own keychain.
Signing in makes the workouts already on the phone part of your account, and they are included in the backup from then on.
The backup
Backup is why an account exists, and it is free. Once you are signed in, the app copies to our server: your templates, the sessions you have logged and the sets inside them, your personal records, the exercises you created yourself, your app settings, and your account row — which holds your email address, your display name, your unit preferences (kilograms today) and whether Premium is active. It runs on its own when you finish a workout and when you leave the app. There is no button to press and nothing to remember.
The database is hosted by Supabase and is configured so that only your own account can read your own rows. Like any server, it also records the requests the app makes to it, including the IP address they come from. The first time you sign in on a new phone, the restore runs by itself.
Sharing a template
If you send somebody a template, the app publishes that template under an eight-character code: its name, its notes, its blocks and targets, and any exercises you created that it uses. The name on your account at that moment is published with it, so the person opening it can see who sent it. Your email address is never published.
Anyone holding the code can open it, including people with no account at all. Treat a shared template as public, and keep anything private out of one. There is not yet a way to withdraw a code from inside the app — email us and we will remove it.
Subscriptions
Premium is sold by Apple and Google, not by us. RevenueCat sits between the stores and the app and tells it whether Premium is active, which plan it is, and when the period ends. When you are signed in, your account id is what RevenueCat knows you by, so Premium follows you to a new phone. When you are signed out, they know the install by an anonymous identifier instead.
RevenueCat’s own privacy notice sets out what it receives from an app like ours, and it is more than the answer it gives back. It gets your purchase history in the form the store provides it — an Apple receipt file or a Google purchase token — the last time the app was used, and technical information about the device, which their notice describes as device type and operating system. Their guidance for the App Store privacy label adds your locale and currency code, and says they do not collect health or fitness data, precise location, or device diagnostics.
We never see your card, your bank or your store account.
Feedback
Send feedback in the Profile tab opens a form hosted by Tally. It carries your platform and the app’s version number with it, so we know which build you are on. The message is what you type. The email address on that form is optional, and we only use it to reply. Because the form opens in a web browser, Tally also receives the ordinary details of that request, including the IP address it comes from.
Who processes data for us
| Service | What it receives | Why |
|---|---|---|
| Buttondown | Your waitlist email address, and the IP address the sign-up came from | Runs the waitlist and its confirmation and unsubscribe emails |
| Supabase | Your account and everything in your backup; a shared template and the sender name on it; and the technical details of the requests the app makes, including your IP address | Hosts the database behind accounts, backup and sharing |
| RevenueCat | Your account id, or an anonymous identifier when you are signed out; your purchase history as an Apple receipt or Google purchase token; the last time the app was used; and basic device information — device type, operating system, locale and currency | Tells the app whether Premium is active |
| Apple | Your sign-in, and everything to do with paying on iOS | Sign in with Apple, and App Store billing |
| Your sign-in, and everything to do with paying on Android | Sign in with Google, and Google Play billing | |
| Tally | What you write in the feedback form, your platform and app version, an email address if you give one, and the details of the browser request that opens the form, including your IP address | Hosts the in-app feedback form |
| Cloudflare | The requests this website serves, cookieless page counts, and the email you send to our addresses | Hosts and protects the website, and forwards our email to us |
Some of these providers are outside the United Kingdom and process data abroad. Where your personal data leaves the UK, we rely on the safeguards each of them publishes for international transfers; their privacy notices, linked above, set out what those safeguards are.
Our legal bases
- Performing a contract with you — your account, your backup, sharing a template you chose to share, and your subscription.
- Your consent — the waitlist. You give it by confirming the email Buttondown sends, and you withdraw it by unsubscribing or by asking us.
- Our legitimate interests — keeping the service working and secure, counting page views without cookies, and answering the messages you send us.
How long we keep things
- Your account and your backup: until you delete your account. Deleting it removes them.
- A shared template: until you ask us to remove the code. We have no automatic expiry yet.
- The waitlist: until you unsubscribe, or until we have finished announcing the launch.
- Feedback, and email you send us: while we still need it to deal with what you wrote, and to keep a record of any request you made about your own data.
- Website logs and page counts: held by Cloudflare under their own retention periods. We keep no copy.
Nothing here is kept “just in case”. If a rule above does not cover something, the answer is that we hold it until you ask us to delete it.
Your rights
Under UK GDPR you can ask us for a copy of the personal data we hold about you, ask us to correct it, ask us to delete it, ask us to restrict or stop a particular use of it, ask for it in a portable form, and withdraw consent you have given. Email privacy@onerepcloser.fit and we will answer within one month.
You do not have to ask us to delete your account: Profile → Delete account in the app does it directly. It erases your account and everything we hold on our server, and it leaves every workout on the phone, where the app carries on working signed out.
If you think we have handled your data badly, please tell us first so we can put it right. You also have the right to complain to the Information Commissioner’s Office, the UK’s data protection regulator, at ico.org.uk.
Children
One Rep Closer is not aimed at children. It is a training log for adults, and we do not knowingly collect personal data from anyone under 13. If you believe a child has given us data, email privacy@onerepcloser.fit and we will delete it.
Changes to this policy
When something changes, we update this page and the date at the top of it. If a change matters to you, we will say so here rather than leave you to spot it.