Your data, explained
Privacy without the fog.
This policy explains what repClimb collects, why it is needed, when it is shared, and the controls available to you.
Effective September 21, 2026 · Version 1.3
The short version
You own your training history.
repClimb stores the information needed to log workouts, build plans, track progress, and answer questions about your training. We do not sell or rent personal data, use it for targeted advertising, or track you across other companies' apps or websites.
This version updates the external MCP connection flow so OAuth scope approval is the external data-sharing approval; no separate browser consent page is required. Version 1.0 is operated by Yuval Sharon, an individual in Israel. Questions and privacy requests can be sent to support@repclimb.app.
Information we collect
- Account information: your email address, authentication identifiers, account status, timezone, preferred weight unit, and week-start preference.
- Training information: goals, plans, workouts, exercises, sets, weights, repetitions, RPE, progress, personal records, and related notes or settings you choose to save.
- Imported history: workout data you choose to import from a supported Strong or Hevy CSV export. Imported records become part of your repClimb account.
- Internal AI content: prompts, relevant training context, responses, tool activity, model and usage metadata, and processing outcomes associated with repClimb AI-assisted features.
- External MCP activity: OAuth connection and scope grants, plus limited operational events for MCP tool calls. Plans or workouts created through MCP become ordinary training data in your account.
- Support information: the content of emails you send us and the information needed to verify and resolve your request.
- Optional analytics and diagnostics: only if you affirmatively enable them in Account → Privacy controls, PostHog receives allowlisted app events, screen names, release/platform details, safe error categories, bounded performance aggregates, and crash or JavaScript exception diagnostics.
We do not ask you to create a medical profile. Please do not include passwords or unnecessary sensitive health information in prompts, workout notes, MCP requests, or support emails.
Essential feature
Internal repClimb AI processing is not external MCP sharing
AI is required for core repClimb features. Before account setup is completed, repClimb asks for separate permission to send your prompts and the relevant training context to OpenAI. If you do not agree, you cannot complete account setup or use the service.
Relevant context may include workout history, goals, plans, exercise information, and results returned by repClimb's internal tools. Only information needed to create the requested answer or plan should be included. This is repClimb's internal AI feature path; agreeing to it does not authorize Muse or another external MCP client to receive your data.
repClimb retains AI prompts, responses, tool requests and results, model metadata, usage, and outcomes in first-party audit records tied to your account. The current code deletes those identifiable records with the account's internal data deletion, subject to limited legal retention and temporary secured backups. repClimb does not currently run a separate program that trains or fine-tunes a model on identifiable user content. We will not treat this statement as advance permission for a materially new use: a new purpose or recipient will require an updated disclosure and renewed affirmative consent where required.
Separate affirmative permission
External MCP connections and data sharing
MCP (Model Context Protocol) lets an external AI client—such as Muse, Claude, ChatGPT, Codex, Cursor, Gemini, or another compatible client—call a repClimb tool for the account authenticated through OAuth. A tool response is sent only after the client has an authenticated token with the required scope and the client actually calls the tool. The OAuth scope approval is the affirmative approval for external data sharing; no separate repClimb browser cookie or consent page is required.
External MCP scope approval is separate from internal OpenAI processing consent. Existing OpenAI consent is not needed for MCP, and MCP scope approval does not grant repClimb internal AI processing permission. If the external sharing purpose or scope materially changes, the OAuth provider will request the relevant scope again before that sharing begins.
The data categories depend on the scope and tool the external client requests:
- Read access (
mcp:read): user-scoped workout summaries and, only when requested, entries and raw sets such as weights, repetitions, RPE, units, and timestamps; the shared and user's custom exercise catalog with names, aliases, IDs, and muscle groups; training configuration including goals, plans, plan items, plan-group rotation, timezone, week-start, and weight unit; and exercise statistics such as personal records, dates, session counts, and bounded trend points. - Write access (
mcp:write): the external client may submit a plan name, goal text, exercise selections, targets, load values, and typed draft-plan edits. It may finalize a reviewed draft or instantiate a finalized plan, including the selected conflict policy for an open workout. Successful writes return the resulting plan or workout data, which is then stored as your repClimb training data. - Not part of the MCP tools: the current MCP surface does not provide your email address, authentication tokens, internal Ask conversation history, or arbitrary account access. Scope is not a promise that an external client will keep data private after receiving it.
Read and write scopes are independent. A read-only token cannot call write tools; a write-only token cannot call read tools; a token with both scopes can use all eight tools. The server enforces ownership and scope for every request. Draft creation and edits persist changes, finalization is the separate commit step for activating a draft, and starting a workout can resume, merge, or close an open workout according to the requested conflict policy. Review the external client's confirmation UI before approving any write.
You control whether to connect a client, which scopes to approve, and whether to approve individual client actions. repClimb currently has no separate MCP connection manager or in-app revoke toggle. To stop a client from making new requests, disconnect or remove the repClimb server in that client and use any revoke control provided by the client or its OAuth account; contact support@repclimb.app if you need help. Disconnecting cannot delete a copy the external client already received. Account deletion removes the repClimb-side consent and account data, but does not control deletion by the external client.
repClimb does not control, verify, or make claims about how Muse, Meta, or any other external MCP client processes, stores, analyzes, or retains data after a tool response reaches that client. Review the client operator's own privacy notice and terms before connecting it.
How we use information
- Provide, personalize, and maintain workout logging, planning, progress tracking, imports, internal AI features, and MCP tools you choose to use.
- Authenticate accounts, preserve account settings, enforce OAuth scopes, and protect the service from fraud, abuse, and security threats.
- Respond to support, access, export, correction, and deletion requests.
- Investigate defects and reported incorrect or unsafe AI or MCP behavior, and improve reliability and product quality.
- Comply with legal obligations and establish, exercise, or defend legal claims when necessary.
Depending on the processing, we rely on providing the service you requested, your consent, our legitimate interests in operating and protecting repClimb, or compliance with law. Where processing is based on consent, you may withdraw it for future processing, subject to the current controls described above.
Optional analytics and crash diagnostics
Product analytics and crash diagnostics are off by default. If you choose to enable them in Account → Privacy controls, PostHog Cloud EU (Frankfurt) processes screen names, allowlisted product outcomes, app or server release, platform, bounded latency or usage aggregates, safe error categories, and crash or JavaScript exception diagnostics using an internal repClimb identifier.
We do not send raw prompts, crisis text, crisis route labels, AI answers, tool contents, workout details, imported files, email addresses, authentication tokens, or request bodies to PostHog, regardless of analytics consent. Session replay and broad touch recording are disabled. Current PostHog project retention is up to 12 months. You can withdraw analytics consent at any time in Account → Privacy controls; this stops future optional mobile capture and user-linked backend product events. Withdrawal does not automatically erase earlier records, but you can request their deletion by email.
Essential security logs and anonymous operational server measurements are separate and may remain active to keep the service reliable and secure.
Retention, backups, and deletion
- Account, training, and identifiable internal AI audit records are retained for the lifetime of your account in the current product and removed from repClimb's active account data when you delete the account, unless limited retention is required by law.
- MCP connection and operational events are represented by the OAuth provider's token and scope grants plus repClimb operational events. MCP event telemetry contains the tool name, duration, success status, and error code when applicable; it does not store the tool arguments or results in the event payload. Training records created by MCP remain ordinary account training data.
- Support correspondence is retained only while reasonably needed to resolve the request, protect the service, document a privacy request, or meet a legal obligation.
- Optional analytics and diagnostics are processed by PostHog Cloud EU (Frankfurt) for up to 12 months under the current project configuration. They are no longer collected after you withdraw consent; request deletion of earlier telemetry from support.
- External client copies are not retained or deleted by repClimb. The external client operator controls its own retention and deletion practices.
Deleted information may remain temporarily in secured backups until those backups expire through their normal cycle. Backup copies are not used as active product data. We may retain statistics that are aggregated or irreversibly de-identified so they can no longer reasonably be linked to you.
You can delete your account in the app from Account → Delete account. This permanently deletes the account and its training data from the repClimb account system and cannot be undone. It does not reach into an external MCP client's systems.
Your choices and privacy rights
Depending on where you live, you may have the right to access, correct, export, delete, restrict, or object to processing of your personal data, withdraw consent, or complain to a data-protection authority.
For version 1.0, send a request from your account email to support@repclimb.app. We may ask for information needed to verify that you control the account. Where portability applies, we will provide applicable user-supplied data in a commonly used machine-readable format. We respond within the period required by applicable law.
Withdrawing consent does not affect processing that was lawful before withdrawal. Some processing is essential to provide repClimb; if it cannot continue, account deletion may be the available choice. A request to stop external sharing cannot erase data that an external client already received.
Security, limited access, and age limit
We use reasonable technical and organizational safeguards designed to protect personal data. No service can guarantee absolute security.
The operator may access an individual user's workout or AI records only when reasonably needed to respond to that user's support request, investigate a defect or security incident, enforce service protections, or review a reported incorrect or unsafe AI response. Access is limited to the information and time needed for that purpose.
repClimb is intended only for people aged 16 or older. If you believe someone under 16 has created an account, contact us so we can investigate and take appropriate action.
Changes and contact
We may update this policy as repClimb changes. This policy shows its effective date and version so you can identify the disclosure in force. For material changes, we will notify account holders by email and through an in-app notice before the change takes effect where those channels are available. If a new use, provider, or external sharing category requires renewed consent, we will present the updated disclosure and ask for fresh affirmative consent rather than relying only on continued use or the existing internal OpenAI consent.
Privacy questions, security reports, MCP connection help, and data requests can be sent to support@repclimb.app.