OneRep
ExercisesBlogCompareUpdatesTermsPrivacyOpen app
Back to OneRep

In this document

ControllerData we processPurposes and legal basesHealth-related dataCoach and AIProvidersInternational transfersRetentionDevice storageYour rightsAge requirementSecurityChanges and contact

Privacy Policy

Effective 26 August 2026GDPR information notice

This policy explains what OneRep processes, why it is needed, which providers receive it, and the choices available to you.

01Controller

The controller under the General Data Protection Regulation (GDPR) is:

OneRep
Germany
support@onerep.life

This policy applies to onerep.life, the OneRep PWA at app.onerep.life, and the OneRep mobile applications.

02Data we process

Account and authentication

Name, email address, password hash, email-verification status, session identifiers, and security events.

Profile and preferences

Age, units, goals, experience level, dietary preferences, reminders, app settings, and consent choices.

Fitness and nutrition

Workouts, exercises, sets, food and water logs, recipes, supplements, calorie and macro targets, body weight and measurements, progress metrics, check-ins, soreness, sleep quality, mood, and notes you choose to provide.

Coach content

Messages, voice transcription submitted as text, uploaded images, generated responses, saved memories, proposed actions, goals, and action history.

Subscription data

Stripe or Apple customer, subscription, and transaction identifiers depending on where you bought, plus product, entitlement, subscription status, and renewal and expiry information. For App Store purchases we receive the transaction and its status from Apple, nothing more. OneRep never receives full payment-card details from either.

Apple Health and Health Connect

If you switch health sync on, OneRep reads workouts and workout routes, activity (steps, distance, flights, active and basal energy, exercise minutes, VO₂ max, cycling and running metrics), vitals (heart rate, resting and walking heart rate, heart-rate recovery, heart-rate variability, respiratory rate, blood oxygen, blood pressure, blood glucose, body and wrist temperature), sleep, mindful minutes, body measurements, and dietary records from Apple Health on iOS or Health Connect on Android. OneRep also writes workouts you finish in the app, and the nutrition and body measurements you log, back to those stores. Nothing is read or written until you grant permission on the device, and you can revoke it there at any time.

Shared recipes

If you publish a recipe to the community feed, its title, description, ingredients, steps, photographs, country of origin, and the name you chose to publish under become visible to every signed-in OneRep user. Publish anonymously and the name is replaced; everything else is still public. Reports made against a recipe, and the accounts you block, are held so the feed can act on them, and are visible only to us.

Technical data

IP address, browser or device type, operating system, timestamps, application errors, security logs, and information needed for offline synchronization.

Usage analytics

Pages and screens viewed, referring site, approximate country and region derived from your IP address, device and browser type, screen size, and a record of interactions such as clicks, scrolling, and navigation within a session. It also counts anonymous product events — that a workout was logged, that Coach was asked something, that checkout was started — recorded as counts and categories with no account identifier and none of the content involved. This is collected on every visit and is not optional.

Optional product analytics

The same feature usage, but tied to pseudonymous device or account identifiers so it can be followed across sessions, and only after you enable optional analytics in the app.

03Purposes and legal bases

  • Providing the service and account under Article 6(1)(b) GDPR, including synchronization, workout and nutrition records, support, and subscription access.
  • Security, fraud prevention, debugging, and service reliability under Article 6(1)(f) GDPR. Our legitimate interest is operating a secure and dependable service.
  • Billing, tax, accounting, and legal compliance under Article 6(1)(c) GDPR.
  • Usage analytics under Article 6(1)(f) GDPR. Our legitimate interest is understanding how the site and app are used so we can find broken flows, fix them, and decide what to build. This analytics is a necessary part of operating OneRep and cannot be switched off. It is self-hosted on our own infrastructure, sets no advertising or cross-site tracking cookies, is never combined with advertising data, and is not sold or shared. You may object under Article 21(1) GDPR by contacting us.
  • Optional product analytics with consent under Article 6(1)(a) GDPR and, where applicable, Section 25 TDDDG. This is separate from the above, is off unless you turn it on, and you can withdraw consent in Privacy & Sync settings.
  • Optional personalized insights and Coach features to perform the service you request under Article 6(1)(b) GDPR. Where submitted data constitutes health data, processing is based on your explicit consent under Article 9(2)(a) GDPR.

You may withdraw consent at any time with future effect. Withdrawal does not affect processing performed lawfully before withdrawal. Some data is necessary to create an account or provide a requested feature; without it, that feature may not work.

04Fitness and health-related information

Body measurements, soreness, recovery notes, dietary information, and similar records may reveal information about health and can qualify as special-category data. OneRep uses this information only to provide the tracking, progress, and Coach functions you choose to use. It is not used for advertising, sold to data brokers, or disclosed to insurers or employers.

Health sync is optional and off until you turn it on. When you do, OneRep reads from Apple Health on iOS, or Health Connect on Android, exactly the categories listed in Data we process, and writes back the workouts, nutrition, and body measurements you record in the app. Permission is granted on the device, per category, and revoked the same way; turning it off stops the reads and the writes.

Data obtained from Apple Health is used only to show you your own training, recovery, and nutrition inside OneRep, and — where you have enabled Coach — to inform the answers Coach gives you. It is never used for advertising or marketing, never sold or shared with data brokers, insurers, or employers, and never disclosed to any third party for their own purposes. It is not used to build advertising profiles, and no third-party advertising or tracking service receives it. It is stored on our infrastructure alongside the rest of your account data, described in Retention, and it is deleted when you delete the record or your account.

Coach requests send a bounded selection of account context, which may include health-sync figures, to the AI providers named in Coach and artificial intelligence solely to produce the response you asked for. Those providers act on our instructions as processors, under contracts that limit them to serving the request. Coach is optional; without it, no health data leaves our infrastructure.

You control which optional records you add and can remove records or delete your account. Do not submit medical records or information about another person.

05Coach and artificial intelligence

When you choose Coach or another AI feature, OneRep sends your prompt, a bounded selection of relevant account context, and any image you submit to OpenRouter. OpenRouter routes the request to the selected model provider, currently OpenAI. Both OpenRouter and that provider may process the request. OneRep minimizes the transmitted context, and AI remains optional.

OneRep disables AI on its own servers if the required processor approval or disclosure is unavailable, or if the OpenRouter connection is not in place.

Coach may generate recommendations and proposed changes, but it does not make decisions that produce legal or similarly significant effects under Article 22 GDPR. Changes to your data are presented for review where confirmation is required. You can use OneRep Core without subscribing to Coach.

06Service providers and recipients

Convex

App hosting, database, file storage, and synchronization across your devices. The configured deployment region is Frankfurt, Germany.

Cloudflare

Website and PWA delivery, network security, and associated request logs.

OpenRouter and OpenAI

OpenRouter is the AI gateway and routes optional Coach, meal interpretation, image, and related requests to the selected model provider, currently OpenAI. Both providers may process the request.

Umami

Usage analytics — page and event counts, no session recording — self-hosted by OneRep on our own infrastructure in Germany. Data does not leave that server and is not sent to a third-party analytics company. This runs on every visit.

PostHog

Optional product analytics hosted in the Frankfurt region. Disabled unless you enable it.

Resend

Account verification, password-reset, and essential service emails.

Stripe

Checkout, subscription management, billing, and fraud prevention for subscriptions bought on the OneRep website.

Apple

App Store distribution and, for in-app purchases, payment, billing, renewal, and refunds. Apple is the seller of record for those purchases and acts as an independent controller of the payment data it collects.

USDA FoodData Central

Food search, barcode lookup, product information, and nutrition data, served from our own infrastructure. USDA data is in the public domain.

Device platform providers

Apple, Google, or browser services may process speech recognition, notifications, camera access, and other device features when you choose to use them.

Providers process data under their own privacy terms where they act as independent controllers, such as app stores and payment providers, and under data-processing terms where they act on our behalf.

07International transfers

Core OneRep data is hosted in the configured Convex Frankfurt region. Some providers may process data in the United States or other countries outside the EEA. Where the destination is not covered by an EU adequacy decision, transfers are protected through appropriate safeguards such as the European Commission's Standard Contractual Clauses and supplementary measures where required. You may request information about applicable safeguards by contacting us.

08Storage and retention

  • Account, profile, workout, nutrition, progress, and Coach records are generally retained while your account remains active.
  • Coach image uploads expire after 24 hours.
  • Authentication and security records are retained as needed to protect accounts and investigate abuse.
  • Subscription, invoice, and transaction records are retained for applicable statutory accounting and tax periods, which may be up to ten years in Germany.
  • Provider logs and backups are retained for limited operational periods under the relevant provider's retention schedule.

You can permanently delete your OneRep account from Data & Account settings. We delete or anonymize associated application data without undue delay, except information that must be retained by law, is needed to establish or defend legal claims, or remains temporarily in protected backups.

09Cookies and device storage

OneRep uses on-device storage, offline caches, and similar technologies that are necessary for authentication, security, preferences, offline use, and synchronization. Usage analytics runs on every visit and may keep a short-lived session identifier on your device so that a visit can be counted once rather than many times; it is not used to identify you across other sites. Optional product analytics storage is used only after you enable it, and you can withdraw that consent in the app's Privacy & Sync settings. Clearing browser or app storage may sign you out and remove changes that have not yet been saved to your account.

10Your rights

Subject to the GDPR's conditions and exceptions, you may request access, rectification, deletion, restriction, portability, or objection to processing based on legitimate interests. You may withdraw consent at any time and lodge a complaint with a competent data-protection supervisory authority in the EU or EEA, particularly in the country where you live or work or where an alleged infringement occurred.

Send requests to support@onerep.life. We may need to verify your identity. You also have direct controls in the app to edit records, change privacy preferences, and delete your account.

11Users aged 16 and over

OneRep is not intended for children under 16, and we do not knowingly create accounts for them. If you believe a child under 16 has provided personal data, contact us so that we can investigate and delete it where appropriate.

12Security

We use measures designed to protect personal data, including authenticated access, per-user authorization, transport encryption, bounded AI context, expiring uploads, validated data-changing operations, and account-deletion controls. No online service can guarantee absolute security.

13Changes and contact

We may update this policy when the service, providers, or legal requirements change. Material changes will be communicated in the app or by another appropriate method before they take effect where required.

Questions and privacy requests can be sent to support@onerep.life.

OneRep

Questions? support@onerep.life

ExercisesBlogCompareUpdatesTermsPrivacyapp.onerep.life