In short — the plain-language version
- We collect your Google account email, profile and workout data — because that's what the product is.
- We never sell your personal data. No exceptions.
- Only a trainer you've actively linked with can see your training data — and their access ends the moment the link does.
- Your workouts are never visible to anyone you haven't linked with. Reviews are always anonymous.
- You can access, correct or delete your account and data at any time.
1.Scope of this policy
This Privacy Policy explains how Korep ("we", "us") processes personal data when you use our mobile app and website (the "Service"). It is designed to meet our obligations under Indian law, including the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Information Technology Act, 2000 and its rules. By using the Service you consent to the processing described here.
2.What we collect
| Category | Examples | Source |
|---|---|---|
| Identity | Email address and basic profile (name, profile picture) from your Google account, used to sign you in; plus name, date of birth, gender and profile photo you set. An optional phone number if you choose to add one. | You / Google Sign-In |
| Fitness profile | Training goal, experience level, chosen gym | You |
| Workout data | Sessions, exercises, sets, reps, weights, durations, notes, plans, streaks | You, or a trainer you've linked with logging on your behalf |
| Trainer profile (trainers only) | Bio, years of experience, specialisations, certification documents, pricing and availability | You |
| Connections & reviews | Trainer requests, link status, waitlist positions, reviews and flags you submit | You |
| Subscription & billing | Your subscription status and the amounts and dates of subscription payments you make for paid plans. We never see or store your UPI PIN, bank details or card numbers. | You / payment provider |
| Device & usage | Device model, OS version, app version, crash logs, notification preferences and tokens | Your device |
We practise data minimisation: no phone number required, no contact-list access, no background location tracking — your gym is a choice you make, not a place we follow you to. Signing in with Google means we never handle a password.
3.How we use your data
- To run the product: sign you in via Google, show your dashboard, compute streaks, weekly volume, estimated 1RM and progression suggestions, deliver plans and notifications.
- To run the marketplace: show trainer profiles (with rating and specialisations) to clients at the same gym, manage requests, waitlists and links.
- To keep records straight: maintain the audit history of reviews and your subscription and billing records.
- To keep the platform honest: enforce review eligibility, detect fake sessions and review fraud, and compute trainer verification.
- To improve the Service: analyse aggregated, anonymised usage (never your identity) and fix crashes.
- To meet legal obligations and respond to lawful requests from authorities.
4.Who can see your data
Other users
- Your linked trainer(s): while a link is active or paused, they can view your sessions, plans and progress dashboard, and log sessions for you. They never see your activity with other coaches.
- Clients browsing the directory (about trainers): trainers' public profile — name, photo, bio, specialisations, pricing, rating, review count and badges. A trainer's phone number is shown only if that trainer chooses to display it. A client's email is never shown to anyone.
- Nobody else sees your training. Your workout data is visible only to a trainer you're actively linked with — never to other trainers, other clients, or the public.
- Reviews are anonymous: your name and identity are never displayed alongside a review, and trainers are not told who wrote one.
Service providers (processors)
- Supabase — our backend infrastructure (database, authentication, file storage), processing data on our instructions.
- Google — to authenticate you through Google Sign-In (we receive your Google account email and basic profile; Google handles the sign-in under its own privacy policy).
- Razorpay — to process your subscription payments for paid plans; they handle your payment instrument under their own privacy policy.
- Google AdMob — to serve banner advertising in free tiers (see Section 11).
Legal
We may disclose data where required by law, court order or governmental authority, or to protect the rights, safety and integrity of the Service and its users.
5.What we never do
- We never sell your personal data.
- We never reveal a reviewer's identity to a trainer.
- We never show your workout data to anyone you haven't actively linked with.
- We never share a client's workout data with a trainer whose link has ended.
- We never see or store UPI PINs, bank account numbers or card details.
6.Data ownership & trainer access
All workout data belongs to the client it describes — including sessions logged by a trainer. When a trainer–client link ends (by either side), the trainer's access is revoked immediately and automatically at the database layer, not just hidden in the interface. The client retains every session, plan and record permanently. A trainer who created an offline client record transfers that record — history included — to the person it describes when they sign in with the same Google email.
7.Storage & security
- Data is stored in a managed cloud database with row-level security: access rules are enforced inside the database for every single query, scoped to the signed-in user — the strictest place they can live.
- All data moves over encrypted connections (TLS). Authentication is handled by Google Sign-In — Korep never creates or stores a password, so there is none to leak.
- Sensitive business rules (reviews, links, payments) can only be changed through controlled server-side procedures — not by direct client writes.
- Certification documents are stored in private storage accessible only to their owner and our review process. Profile photos you upload are public to other users of the app by design.
- No system is perfectly secure. If we learn of a breach affecting your data, we will notify you and the authorities as required by law.
8.Retention
- Account data: kept while your account is active.
- Workout history: kept indefinitely while your account exists — that permanence is the product — and deleted when your account is deleted.
- Payment and subscription records: retained as required by Indian tax and financial-record laws, even after account deletion, then deleted.
- Security & fraud-prevention logs: retained briefly, then deleted.
9.Your rights
Under the DPDP Act and this policy you can:
- Access the personal data we hold about you — most of it is visible directly in the app; write to us for a full copy.
- Correct inaccurate profile data — editable in the app at any time.
- Delete your account and data — see Delete your account.
- Withdraw consent for optional processing (e.g., specific notification types, via in-app preferences). Withdrawing consent essential to the Service (like storing workout data) means deleting your account.
- Nominate a person to exercise these rights on your behalf as provided by the DPDP Act.
- Complain — first to our grievance officer (Section 13), and if unresolved, to the Data Protection Board of India.
10.Account & data deletion
You can delete your Korep account and the personal data associated with it at any time. There is no retention lock-in — deletion is your call.
How to delete
- In the app (self-serve): open Profile → Delete account, type DELETE to confirm, then re-sign-in with Google so we know it's really you. Deletion is immediate and irreversible. Full steps are on Delete your account.
- Can't sign in? Email our grievance officer at privacy@korep.in and we'll help you verify your identity and erase your data.
What is deleted
Your name, profile photo and any optional phone number; your Google account is no longer linked to Korep. Your full workout history (sessions, exercises, sets, notes, streaks and progress analytics), plans, trainer–client links, requests, waitlist entries, notifications, preferences and device sign-ins. For trainers: bio, certifications, specialisations, pricing and availability. Reviews you wrote are already anonymous and are disconnected from you entirely on deletion.
What is retained (and why)
Only records we are legally required to keep: payment records retained for the period required by Indian tax and financial-record law, and brief fraud-prevention and security logs — each deleted once no longer required, and no longer linked to a usable identity. Workouts a trainer logged for a client belong to that client and stay with them. Aggregated, anonymised statistics that cannot identify you are unaffected.
Timeline
Deletion takes effect immediately when you confirm in the app; we then permanently remove it from live systems within 30 days and purge it from encrypted backups within 90 days.
For full details, see Delete your account.
11.Advertising
Free tiers of the app may show banner advertisements served by Google AdMob. AdMob may process device identifiers to serve and measure ads under Google's privacy policy. We do not pass your workout data, phone number or profile to advertisers. Paid tiers remove advertising where stated in-app.
12.Children
The Service is intended for users aged 18 and above. We do not knowingly process children's data. If you believe a minor has created an account, contact us and we will delete it.
13.Changes to this policy
We will announce material changes in the app before they take effect and update the "Last updated" date above. Your continued use after the effective date constitutes acceptance.
14.Grievance officer & contact
In accordance with the Information Technology Act, 2000, the DPDP Act, 2023 and rules made thereunder, our Grievance Officer can be reached at:
- Email: privacy@korep.in
We acknowledge grievances within 48 hours and aim to resolve them within 15 days. For anything else: support@korep.fit or our contact page.