Privacy Policy
Last updated 16 August 2026
RecompX is a strength-training app. This page explains what we collect, why, who else sees it, how long we keep it, and how to get rid of it. We have tried to write it in plain language rather than legalese — but it is the binding description of what we do with your data.
This policy covers both the RecompX mobile app and the recompx.app website, including the waitlist, the free guides and the waist-ratio quiz.
Who is responsible for your data
RecompX is operated by Gautam Sharma, an individual based in the United States. Under the GDPR and UK GDPR we are the data controller for the data described here. You can reach us at any time at [email protected].
What we collect
Before you create an account
The setup questions come before you make an account. Your answers and the plan they produce are stored only on your own phone until you sign up — they are not sent to us, and we cannot see them. If you never create an account, deleting the app deletes them and nothing reaches our servers. When you do create an account, those answers are copied to it so your plan follows you to a new phone.
In the app
- Your email address, so you can sign in and so we can send you a sign-in code. If you sign in with Google or Apple, we receive your email address and name from them. If you use Apple’s Hide My Email, we only ever see the relay address.
- What you tell us during setup — your training experience, how many days a week you can train, what equipment you have, your goal, any injuries you flag, and optionally your age range, sex, height, weight and waist measurement. This is what we use to pick your training plan.
- What you log — your workouts, the exercises, sets, reps and weights, your protein entries, and any body measurements you record over time.
- Messages you send to the AI coach, along with the plan and recent-training context sent with them so it can answer usefully.
- Subscription status — whether you have an active subscription, and the purchase and renewal events behind it. Payment card details never reach us; see “Payments” below.
- Basic usage analytics — which screens and features are used, and whether you come back. These events are tied to an account identifier, not to your name or email, and we do not put your body measurements or coach messages into analytics.
- Technical data that any app or server necessarily sees: device type, operating system version, app version, and the IP address your requests arrive from.
On the website
- Waitlist and free-guide forms — your email address, and optionally your name, country, and any feature request you type in.
- Where you came from — campaign tags in the link you clicked (utm_source, utm_medium, utm_campaign, utm_content, utm_term) and the domain that referred you. This tells us which post or ad brought you here. It does not identify you on other sites.
- Email engagement — whether our emails to you were opened and whether links in them were clicked.
The waist-ratio quiz is different. Everything you enter into it — your height, waist, weight and answers — is calculated entirely in your browser. Those numbers are never sent to us or stored anywhere. If you separately choose to enter your email to get a guide, that email is handled as described above; your quiz measurements are still not sent with it.
Health data, and why we treat it carefully
Your body measurements, weight, waist and injury notes are more sensitive than the rest. Under GDPR some of this may qualify as special category data concerning health. We handle it accordingly:
- We process it only on the basis of your explicit consent, given by choosing to enter it. Every body measurement in RecompX is optional.
- It is stored in your own account rows, protected by row-level security so that one account cannot read another’s.
- It is never sent to analytics, never used for advertising, and never sold or shared with data brokers.
- You can withdraw consent by deleting the measurements, or by deleting your account, at any time.
What we do not do
We do not collect your contacts, your precise location, your photos, or data from Apple Health. We do not track you across other apps or websites, and we serve no third-party advertising. We do not sell your personal information, and we do not share it for cross-context behavioural advertising — as those terms are defined under the CCPA/CPRA. We have not done so in the preceding twelve months.
We do not use your data to train AI models, and our AI provider is contractually barred from training on it either.
Why we collect it, and our legal basis
Under the GDPR and UK GDPR we must tell you the lawful basis for each purpose. Ours are:
- To run your account and give you a plan that fits you — performance of our contract with you.
- To store your body measurements and injury notes — your explicit consent, which you can withdraw at any time.
- To answer your coach questions using your real numbers — performance of our contract, plus your consent for any health details involved.
- To understand which parts of the app work — our legitimate interest in improving the product, balanced against your privacy by keeping health data and identifiers out of analytics.
- To send you marketing or waitlist email — your consent, given when you submit the form. Every email has an unsubscribe link.
- To keep the service secure and prevent abuse — our legitimate interest in a working, non-abused service.
Payments
Subscriptions are sold through the Apple App Store and managed for us by RevenueCat. Your payment method, card number and billing address go to Apple, not to us — we never see or store them. We receive only your subscription status and the associated purchase events, linked to your account identifier so your subscription follows you to a new device.
Who else processes your data
We keep this list short on purpose. Each of these is a processor acting on our instructions under a data processing agreement.
- Supabase — hosts our database, files and sign-in. Your account data lives here.
- Anthropic — when you message the AI coach, your message and relevant training context are sent to Anthropic’s API so it can answer. Anthropic does not use it to train their models.
- RevenueCat — subscription management, as described above.
- PostHog — product analytics, excluding health data and identifiers as described above.
- Plunk — sends our waitlist, guide and product emails, and stores the contact details you submit through the website forms.
- Cloudflare — hosts this website and stores the guide PDFs we email you.
- Apple and Google — only if you choose to sign in with them, and Apple for all payments.
We may also disclose data if the law genuinely requires it, or to establish or defend legal claims. If RecompX is ever sold or transferred, your data may move with it — you will be told before that happens, and this policy will continue to apply until you are given notice of a new one.
Where your data goes
We are based in the United States, and so are our providers. Your data is stored and processed there.
If you use RecompX from the EEA or the UK, this means your data is transferred outside it. Those transfers rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), together with the safeguards in each provider’s data processing agreement. You can ask us for details of the safeguards that apply.
How long we keep it
- Account and training data — for as long as your account exists. Delete the account and it goes.
- After you delete your account — removed from our live systems immediately. Copies may persist briefly in our hosting provider’s encrypted, automated backups until those expire on their normal rotation, typically within 30 days. We do not restore deleted accounts from backups.
- Marketing contacts — until you unsubscribe or ask us to delete you, after which we keep only the minimum needed to remember not to email you again.
- Analytics events, which are not tied to your name or email, may persist in aggregate.
- Purchase records — kept as long as tax and accounting law requires, typically six to seven years.
How we protect it
Data is encrypted in transit (TLS) and at rest by our hosting provider. Access to your rows is enforced at the database level by row-level security, so an account can only ever read its own data. Administrative access is limited to the operator and protected by multi-factor authentication. No system is perfectly secure. If a breach ever affects your personal data we will act without undue delay: notifying the relevant supervisory authority within 72 hours where the GDPR or UK GDPR applies, notifying affected residents as US state law requires, and telling you directly where there is a real risk to you.
Deleting your data
You can delete your account from inside the app: open your profile and choose Delete my account. This permanently removes your account and everything attached to it — your plan, your logged workouts, your personal records, your coach conversations and your measurements. It cannot be undone, and we do not keep a copy.
If you would rather we did it for you, email [email protected]. Deleting your account does not automatically cancel an App Store subscription — manage that in your Apple ID settings.
Your rights
Wherever you live, you can ask us to do any of the following, and we will not treat you differently for asking:
- Access — get a copy of the data we hold about you.
- Correct — fix anything inaccurate.
- Delete — erase your data, as described above.
- Export — receive your data in a portable, machine-readable format.
- Object or restrict — tell us to stop or limit a particular use, including anything based on legitimate interest.
- Withdraw consent — at any time, without affecting what we did lawfully beforehand.
- Opt out of marketing — unsubscribe from any email, or just ask us.
Email [email protected] and we will respond within 30 days. We may need to confirm you control the account’s email address before acting, so that nobody else can make these requests about you.
If you are in the EEA or UK: you also have the right to complain to your local data protection authority. In the UK that is the Information Commissioner’s Office (ico.org.uk). We would rather you came to us first so we can put it right.
If you are in California: you have the rights to know, delete, correct, and to opt out of sale or sharing. As stated above we do not sell or share your personal information, so there is nothing to opt out of — but the request channel is the same email address, and you may use an authorised agent.
Cookies and similar technologies
This website sets no advertising or tracking cookies and runs no third-party ad scripts. The app stores your sign-in session on your own device so you stay logged in. Campaign tags travel in the link you click rather than in a cookie that follows you around.
Children
RecompX is not intended for anyone under 16, we do not knowingly collect data from children, and we do not knowingly sell or share the personal information of anyone under 16. If you believe a child has given us data, email us and we will delete it.
Changes
If this policy changes we will update the date at the top of this page. If a change materially affects your rights or how we use your data, we will tell you in the app or by email before it takes effect.
Contact
Questions, requests, or complaints about any of this: [email protected].