Privacy Policy

Last updated October 8, 2026

myreplog is a workout log. To do its job it necessarily holds detailed records about your training and your body. This page describes exactly what we store, who processes it, where it goes and how to get it back or delete it. It reflects how the service actually works today, not a template.

Who we are

myreplog is owned and operated by Alvseike, a sole proprietorship registered in Norway, organisation number 921 279 485 MVA. Alvseike is the data controller for the personal data described on this page.

For any privacy question, or to exercise any of the rights below, contact [email protected].

What we collect

We only collect data you give us or that is produced by your use of the app. We do not buy data, and we do not track you across other websites.

CategoryFieldsWhy
AccountEmail address, first name, Google account identifierTo create and secure your account. Sign-in is Google only — we never receive or store a password.
ProfileHeight, body weight, display name, unit preference (kg/lb)Body weight sets your protein target and is charted over time if you log it. Height is stored if you enter it; no feature uses it yet. Display name appears on records you choose to share, and the coach addresses you by it.
TrainingPrograms, exercises, sessions, every logged set (weight, reps, targets, personal records), session notesThis is the product. It is the log itself.
Onboarding answersExperience level, goal, available equipment, days per week, session length, injuries or limitations you describeTo generate a program that fits you, and to let the AI coach account for limitations.
NutritionThe free text you type to describe a meal, plus the protein and calories parsed from itTo show your daily protein against your target.
Body weight historyWeight entries with timestampsTo chart body weight over time.
Billing statePlan, plan status, subscription identifier, trial end dateTo know what you are entitled to. We never see or store card numbers.
Strava (optional)Access and refresh tokens, and the activities we sync — type, distance, duration, elevation, heart rate, caloriesOnly if you connect Strava. Disconnecting deletes the tokens.

Who processes your data

We use the following sub-processors. Each one only receives what it needs.

ProcessorPurposeData it receivesLocation
ClerkAuthenticationEmail, name, Google identifierUnited States
PolarMerchant of record — subscriptions, payment, VAT and invoicingEmail, billing address and card details, which go directly to Polar and its payment processor — they never reach our serversUnited States
CloudflareHosting, the D1 database where your log is stored, and cookieless visit statistics (Cloudflare Web Analytics)All application data, request metadata such as IP address, and the page-view details listed under Cookies and local storageGlobal edge network
DeepSeekThe AI coaching, program generation and nutrition parsing featuresTraining data, onboarding answers and the meal text relevant to each requestChina
StravaActivity sync, only if you connect itOAuth tokens and the activities returnedUnited States
Google FontsWeb fonts on public pagesYour IP address, as with any request to a CDNGlobal

AI processing and international transfers

Read this section carefully if you are in the EU, the EEA or the UK. The AI features are powered by DeepSeek, which is operated from China. When you generate a program, run a session analysis, answer an in-workout prompt or log a meal, the data needed for that request — which can include your training history, the notes you write on a set or a session, your stated goal, your equipment and any limitation or injury you described — is sent to DeepSeek for processing.

China has not received an adequacy decision from the European Commission. This is an international transfer to a country without an adequacy finding, and you should treat it as a meaningful factor when deciding whether to use the AI features.

The rest of the app — logging sets, viewing history, tracking personal records, charting progress — never contacts DeepSeek. You can use myreplog as a pure workout log without any AI request being made.

We do not send your email address, your surname, your body weight or your payment details to DeepSeek. If you have set a display name, the session analysis includes it so the coach can address you by it.

What is public

Most of your data is private to your account. Three features deliberately publish something, and all of them are opt-in:

  • Record pages — when you choose to share a personal record, we create a page at /records/… showing your first name only, the exercise, the weight and the reps. We never publish your surname or your email. These pages are indexable by search engines.
  • Shared session links — sharing a session creates an unguessable link. Those pages are marked noindex, so they are not listed by search engines, but anyone holding the link can open them.
  • Shared programs — publishing a program to the community section makes the program itself public. It does not publish your logged sets.

Cookies and local storage

We do not use advertising cookies, and nothing on this site follows you to other sites or builds a profile of you.

We count visits with Cloudflare Web Analytics, a script Cloudflare adds to our pages, including the pages inside the app. It sets no cookies and stores nothing in your browser. For each page view it records the page address, the page that referred you, your browser, operating system and device type, your country, and how quickly the page loaded. It does not record your name, your email or anything you log, and we see the results only as totals.

There is no consent banner because nothing is stored on your device beyond what is strictly necessary.

Clerk sets essential cookies to keep you signed in. Without them, authentication cannot work.

The app also stores a small amount of data in your browser's local storage: your kg/lb preference, the id of a session currently in progress, which progress sections you have expanded, and a timestamp used to recover from a stale deployment. None of it leaves your device, and clearing your browser data removes it.

How long we keep it

  • Your account data and training log are kept until you delete them or close your account.
  • Deleting your account deletes your user record, and the database removes your programs, sessions, logged sets, nutrition entries and body weight history along with it.
  • Public record pages you created are removed when the account is deleted. Copies already cached by search engines or shared by others are outside our control.
  • Transaction records are retained where accounting and tax law requires it, which in Norway is five years.

Security

  • All traffic is served over HTTPS.
  • Authentication is handled by Clerk using Google OAuth. We never handle or store passwords.
  • Every API request that touches your data verifies your session token on the server before returning anything.
  • Card details are handled by Polar and its payment processor, and never reach our servers or our database. We store only whether a subscription is active and when the paid period ends.
  • No system is perfectly secure. If a breach affects your personal data and is likely to result in a risk to your rights, we will notify the Norwegian Data Protection Authority within 72 hours and tell you directly where the law requires it.

Your rights

If you are in the EU, EEA or UK, the GDPR gives you the rights below. We apply them to everyone, wherever you are.

  • Access — get a copy of the data we hold about you.
  • Rectification — correct anything inaccurate. Most profile fields are editable in the app.
  • Erasure — have your account and data deleted.
  • Portability — receive your data in a machine-readable format.
  • Objection and restriction — object to processing based on legitimate interests, or ask us to restrict it.
  • Withdraw consent — disconnect Strava, unpublish a record, or stop using the AI features at any time. Withdrawal does not affect processing already carried out.

Email [email protected] to exercise any of these. We will respond within one month.

You also have the right to complain to a supervisory authority. In Norway that is Datatilsynet (datatilsynet.no). If you are elsewhere in the EU or EEA, you may complain to your local authority.

Children

myreplog is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, contact us and we will delete it.

Changes to this policy

If we change how we handle your data, we will update this page and change the date at the top. Where a change materially affects your rights — a new sub-processor receiving your training data, for example — we will tell you in the app before it takes effect.