Privacy Policy
QRep is a strength-training tracker that runs on your device. This policy explains what QRep does and does not do with your data. The short version: QRep has no accounts and no cloud sync — your training data stays on your iPhone and Apple Watch, with one exception you start yourself, program sharing, described below.
What we collect
QRep has no user accounts, no login, and no analytics or advertising SDKs. We do not receive your workouts, your health data, or any record of how you use the app, and we have no technical ability to see them.
Your programs, workouts, personal records, timers, machine setup memory and settings are stored locally on your device.
There is exactly one exception, and you trigger it deliberately: publishing a program as a share link uploads that program's structure to a server we operate. Nothing else is ever uploaded.
Program sharing
QRep can turn one of your programs into a link and QR code that another lifter can import. Doing so is always something you start, one program at a time.
What is uploaded: the program's structure — its name, its phases and sessions, the exercises in each session, and their prescribed sets, reps, weights and rest times, plus any custom exercises the program references.
What is never uploaded: your workout history, your logged sets, your personal records, your machine setup memory, your timers, and your Apple Health data. The share document is built to exclude them — they are not filtered out at the server, they never leave your phone.
No identity is attached. A share carries no account, no name, no device identifier and no advertising ID. Shares you create are not linked to you or to each other. Alongside the program the server stores only the share's short code, when it was created, its size in bytes, how many times it has been downloaded, and a one-way hash of the revoke credential described below.
Share links are public. Anyone holding the link or QR code can view the program on qrep.app and import it. Treat a shared program's name as public text.
Opening a link contacts the server. When you or a friend imports a share, the app fetches that program and the server adds one to that share's download count. Nothing about who fetched it is stored.
You can revoke a share at any time from the app's shared-links screen. QRep gives you a one-time revoke credential when you publish; the server keeps only a one-way hash of it, so nobody who obtained a copy of the database could revoke or re-publish your shares. Revoking takes the link offline immediately, and the stored program is deleted within 30 days. A share you never revoke stays available indefinitely.
Access to stored programs is restricted to QRep's own server code. The database grants no public read access.
Apple Health (HealthKit)
If you grant permission, QRep writes finished workouts to Apple Health. Workouts finished in an Apple Watch session are saved with their duration, active energy, and heart rate. Workouts saved from the iPhone carry their duration only — no energy and no heart rate — plus one QRep metadata field, QRepTotalVolumeKg (the session's total lifted volume), stored with the workout in Apple Health. This lets your workouts show up alongside the rest of your Health data.
- The only Health data QRep reads is on your Apple Watch, and only during an active workout session: the watch app reads your live heart rate on-device (shown on the wrist as you train) and your active energy, and saves both with the workout. These readings are never transmitted off-device. The iPhone app reads no Apple Health data at all.
- Health data written to Apple Health is managed by Apple Health, under your control, and is governed by Apple's privacy terms. You can revoke QRep's Health access at any time in Settings → Health.
- Health permission is requested only when you finish your first workout, not at launch. If you decline, QRep works normally and simply does not save to Health.
Apple Health data is never included in a shared program and never reaches our server.
Subscriptions
QRep Premium is sold through Apple's App Store using StoreKit — either as an auto-renewing subscription or as a one-time lifetime purchase. There is no third-party billing or payment processor. Apple handles the transaction and your payment details; QRep never sees your payment information. On your device, QRep stores only a local flag indicating whether a purchase unlocks premium features.
Export and import
QRep lets you export your data to a file, as JSON or CSV. This is always something you start, and you choose where the file goes through the iOS share sheet (for example, Files, Messages, or another app). QRep does not upload your exports anywhere — an export goes where you send it, and never to us. Importing a file is likewise initiated by you.
Apple Watch
The QRep watch app communicates with your iPhone over Apple's WatchConnectivity, directly between your paired devices. This data does not pass through us.
The QRep website
qrep.app hosts the shared-program preview pages, this policy, and the link to the App Store. Like any website it runs on hosting infrastructure that records standard request logs — IP address, browser user-agent, the page requested and a timestamp — which we use to keep the service running and to count how many people follow a share link to the App Store. The site sets no cookies and carries no tracking or advertising.
Service providers
We use third-party hosting providers to run qrep.app and to store shared programs. They process that data on our behalf and for no other purpose.
Children
QRep is not directed at children. QRep asks no one for personal information at any point, so we do not knowingly hold personal information from anyone, of any age.
Changes to this policy
If this policy changes, we will update the "Last updated" date above and post the new version at the same URL.
Contact
Questions about this policy: support@qrep.app