This Privacy Policy explains what information the Reracked Android app
(“the App”, “we”, “us”) collects, how it is used, and the
choices you have. Reracked is an offline-first strength-training log: your workout data lives
on your device. You can use the App without an account at all — in that case your log
never leaves your phone, and we never receive it. If you create an account, your
workouts and routines are also synced to our backend so they survive a new phone or a reinstall.
Reracked is operated by Brendan Hamilton, a sole proprietor based in Ontario, Canada,
who is also the Privacy Officer accountable for the personal information described
here. Contact details are in section 11.
1. Information we collect
Account information
- Username and email address — used to create and sign in to your account.
- Password — stored only as a salted, one-way hash. We never store or can read your plaintext password.
Workout data you create
- Workouts, exercises, sets (reps, weight, RPE), routines, notes, dates, and session durations that you log in the App.
- We only receive this if you have an account and are signed in. Without an account
it stays on your device. Some things stay on the device either way and are never sent to us: your
weekly training schedule, app settings, and an in-progress workout.
Emails you send us
- If you email support or ask for a beta invite, we keep that message and your address in the support
inbox so we can reply, and we use the address only for that conversation and for beta-access
updates. We do not add you to a marketing list.
Diagnostics & analytics (optional)
- We use Google Firebase Analytics and Crashlytics to understand feature usage and receive
crash reports. This data is pseudonymous, not anonymous: reports may include a
device-generated installation identifier, device model, OS version, app activity breadcrumbs,
and crash stack traces. Crash reports do not carry your username or email address.
They are labelled with a random Diagnostics ID generated on your device, which is not
derived from your account and cannot be traced back to it by us or by anyone else — you can
see it in Settings → About & Support, and it is the reference to quote if you contact us about
a crash. Error messages are stripped of email addresses, tokens, web addresses and quoted file
contents before they are sent. If you delete your account, the app stops using that Diagnostics ID
and starts a new one; reports already sent cannot be individually deleted or
unlabelled — Firebase deletes them, and the identifiers attached to them,
90 days after they are received.
- This collection is opt-out: you can turn it off at any time in
Settings → “Share analytics & crash reports”.
Server logs and abuse prevention
- Our backend writes one log line per API request containing a request id, the endpoint,
the response status, how long it took, and a one-way hash of your account id. It does not
record your username, email address, or the contents of your request.
- Your IP address is used while a request is in flight, to rate-limit sign-in and account
attempts. It is held in memory for that purpose and is not written to our request logs.
- Because an attacker can simply change address, we also keep a short-lived counter in our
database against the username or email address that was typed — including on
a failed sign-in, where that may not be an account we hold. It is stored as a scrambled
reference rather than the address itself, next to a count and a timestamp and nothing else,
and the original address cannot be read back out of it. These counters are deleted
automatically two hours after they are last touched.
- Backend errors are sent to Sentry with the same request id and hashed account id.
2. What we do NOT collect
- We do not collect your precise location, contacts, photos, or health/fitness sensor data.
- We do not collect your bodyweight. You can optionally enter it in Settings so the App can
score pull-ups, dips and push-ups on the weight you actually moved. That figure is stored only
on your device, is never sent to our server, and is not included in backup or sync. You can
clear it at any time from the same screen.
- We do not sell your personal information, and we do not use it for advertising.
3. How your information is used
- To authenticate you and keep your account secure.
- To store and sync your workout history across your devices, if you have an account.
- To diagnose crashes and see which features are used, so we can fix and improve the App (only if
diagnostics are enabled).
- We do not use your workout data to train models, and we do not profile you.
4. Where your data is stored
Your workout data is stored locally on your device. If you have an account, a copy is
also stored on our backend server (hosted on Railway,
backed by PostgreSQL). Backup copies of that database are kept for disaster recovery: our hosting
provider takes its own, and we take a nightly copy stored off-site with Cloudflare R2, which encrypts
objects at rest. Data in transit is protected with HTTPS/TLS. Authentication tokens are stored in
encrypted storage on your device.
Your data leaves Canada. The providers listed in section 5 are United States
companies, and their servers may be in the United States or elsewhere. Data held by them is subject to
the laws of the country it is stored in, which can include lawful access requests by that
country’s courts and authorities. Using the App means accepting that your data is processed
outside Canada. Your own device keeps a full local copy either way.
5. Data sharing
We share data only with the service providers that make the App work:
- Railway — application and database hosting, including the provider’s own
automatic database backups.
- Google Firebase (Analytics & Crashlytics) — usage analytics and crash reporting,
when enabled. Crash reports are labelled with a random device-generated Diagnostics ID, not with
your username or email address.
- Sentry — backend error diagnostics, labelled with a hashed account id rather than
your username or email address.
- Resend — delivery of password-reset and email-verification messages. These messages
contain a short code, not a link.
- Cloudflare — off-site database backup storage (R2, encrypted at rest), and email
forwarding for anything you send to
support@reracked.app.
- GitHub — hosting for this website. It receives no account or workout data.
- Google Play — distribution and updates of the Android app, under Google’s
own terms. We receive only the aggregate install and crash statistics the Play Console shows us.
We do not share your personal information with any other third parties except where required by law.
6. Data retention
Two separate things hold your data, and they expire on different schedules.
- The live service. We keep your account and workout data for as long as your
account exists. Deleting your account removes it from the live service straight away (section 7).
- Disaster-recovery backups. We take a copy of the whole database so we can rebuild
the service after a failure. Our hosting provider keeps its own automatic copies for up to three
months, and our nightly off-site copy is deleted 90 days after it is taken. So a backup can still
contain your data for up to 90 days after you delete your account, until that copy expires on its
own schedule.
- Password-reset and verification emails. When you ask for one, the message waits
in our database until the email provider accepts it, so that a temporary fault at their end does
not cost you the only way back into a locked-out account. That queued record holds your email
address and the sign-in code, with the code encrypted; the code is erased as soon as the message
is sent or expires, and the record itself is deleted after seven days.
Backups are never read during normal operation. They are only used if we have to restore the
database — see section 7 for what that would mean for a deleted account.
We also keep a record of account deletions, stored separately from the database so
it survives a restore. It holds no personal details — only a scrambled reference, the date, and
an internal account number — and we keep it for 180 days, longer than any backup that could
still contain the account it refers to. Its only purpose is to let us re-apply a deletion to a
restored database (section 7).
7. Deleting your account and data
If you never created an account, we hold nothing to delete — uninstalling the App or clearing
its storage removes your log from the phone, and that is all there is.
If you do have an account, you can delete it directly in the App:
Settings → Account & Security → Delete account. You confirm with your current password.
Export first if you want to keep a copy — Settings → Export workouts saves your
workout history and your routines to the phone (choose JSON, the complete format), and
Settings → Export full account adds your account details to that. Do it before you
delete — section 8 has the detail.
- On the live service this removes your account, sessions and sign-in tokens, and
every workout, routine, exercise and set, in one step. It cannot be undone.
- On the device you delete from, the App clears its local copy once the server
confirms the deletion.
- On any other device that still holds your log, nothing is erased remotely. We
have no way to reach that device. Clear it there by uninstalling the App or clearing its storage.
- In disaster-recovery backups, a copy taken before your deletion still exists
until it expires (section 6 — up to 90 days). Deleting your account does not reach into
backups that have already been taken.
- If we ever restored the database from one of those backups, an account deleted
after that backup was taken would be in the restored copy. We keep a record of every deletion
outside the database, so re-applying it is a required step of our restore procedure: the account
is deleted again before the service is put back into use. That record contains no personal
details — not your email, username or password — only a scrambled reference that lets
us match it against an account, and it is kept for 180 days, longer than any backup that could
still contain you. This does not erase you from the backup files themselves; those expire on the
schedule in section 6.
- Diagnostic records already held by Firebase, Sentry and our email provider follow
those providers’ own retention policies. Crash reports never carry your username; they are
labelled with a random Diagnostics ID, and deleting your account starts a new one, so later
reports cannot be grouped with earlier ones. Reports already sent cannot be individually
deleted or unlabelled — Firebase deletes crash reports and their identifiers
90 days after they are received.
If you cannot access the App, you may also request deletion by emailing us (see Contact).
Full instructions: Delete Your Account.
8. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal
information. You can view and edit everything you have logged in the App at any time, and you can
export your data yourself: Settings → Export workouts writes it to a file on your phone.
It runs on the device, so it works with no connection. The JSON file is the complete
one — your workouts, exercises, sets, notes and your routines — and the App can
read it back in. The CSV file is your workout history alone, one row per logged set,
for spreadsheets. Neither includes your account details.
For a copy that also includes your account details — your username, email and
sign-up date, alongside your full workout history and routines, in a machine-readable format —
use Settings → Export full account. That one asks our servers for everything we hold
about your account, so it needs an account and a connection; the two files above do not. If you would
rather we sent it to you, email us (see Contact) and we will. You can remove your data from the live
service using account deletion — section 7 sets out exactly what that reaches and what it does
not. For any other request, contact us below.
9. Children’s privacy
The App is not directed to children under 13, and we do not knowingly collect personal information from them.
10. Changes to this policy
We may update this policy from time to time. Changes are posted here with a new “Last
updated” date. If a change materially widens what we collect, how we use it, or who we share it
with, we will give it an effective date at least 30 days later, so you can read it and
delete your account first if you would rather not continue. We have no way to notify you inside the App
or by email today, so this page is where changes are announced.
11. Contact & complaints
Questions about this policy or your data? Email
support@reracked.app. It reaches Brendan Hamilton, the
operator and Privacy Officer. Please say what you are asking for — access, correction, export or
deletion — and we will confirm what we can do and by when.
If you are not satisfied with how we handled a privacy concern, you can complain to the
Office of the Privacy Commissioner of Canada. If you live
elsewhere, your local data-protection authority may also be able to help.