Security at REPCIR

Your health data, protected.

A coach that knows your injuries, your best lifts, and how you slept last night is holding some of the most personal data you have. We build REPCIR so that knowing you never means exposing you: your training and health stay encrypted, private by default, and yours to see, export, or erase whenever you want.

How we protect your data

Encrypted in transit and at rest

Your data is encrypted on the wire and on disk. Connections run over HTTPS, and storage sits behind providers that encrypt at rest by default.

Private by default

Your training and health are yours alone. No one else's coach can read your data unless you explicitly grant access. There is no default sharing.

Per-member consent in circles

Train with family or partners and each person stays in control. People in your circle only see what you choose to share, and your data isn't pooled without a yes.

See and forget anything

You can view what your coach remembers about you and forget any memory on demand. Knowing you should never mean owning you.

Export or delete everything

Download your data or delete your account anytime from settings. When you delete, we remove your data on the timeline our policy describes.

We never sell your data

We don't sell your personal data and don't share it for cross-context behavioral advertising. Your health signals aren't a product we trade.

How we think about it

Health and training data is sensitive, so we treat it that way. We use encryption in transit and at rest, access-controlled and scoped database access, signed media URLs, rate limiting, and monitoring. We send AI model providers only the context a coaching response needs, never your data to train public models.

We’re also early and honest about it. We won’t claim certifications we haven’t earned. Rather than wave a badge, we’d rather show you the posture: least access, private by default, consent before sharing, and a clear path to see, export, or delete everything. As REPCIR grows, our security program grows with it.

For exactly what we collect, how we use it, and who processes it, read our Privacy Policy.

Report a vulnerability

Found something that doesn’t look right? We want to hear from you. Email security@repcir.com with the details and steps to reproduce, and give us a reasonable window to investigate and fix before any public disclosure.

We read every report, act in good faith, and won’t pursue researchers who disclose responsibly and avoid privacy violations, data destruction, or service disruption. Please don’t access other people’s data or run automated attacks against the service.

Train with a coach that respects your data.

Free to start, no credit card. Private by default, and yours to delete anytime.

Start free