Skip to content

Privacy policy

What we collect, and what we use it for.

Michael Pettersson Solutions AB, Sweden. Last updated 27 September 2026.

The short version: we use your personal information to sign you in and, when subscriptions exist, to manage them. Statistics are built from pseudonymised data. We may email you about HelloReps, and you can say no. Social features use personal information only with your consent. We never sell your data, and we never let other parties use it for marketing.

Who is responsible

The controller of the personal data described here is Michael Pettersson Solutions AB (org. nr 559049-0248), Lidingö, Sweden — the company that makes HelloReps. For anything in this policy, including a request to see or delete your data, write to [email protected].

Your account

When you create an account we store an email address (which you can withhold with Sign in with Apple) and an identifier from the sign-in provider — Apple, Google, or a password that we store only as a hash. We never ask for your name. We use this to sign you in and to keep your sessions secure. With Sign in with Apple we also keep, encrypted, the token Apple gives us, so that deleting your account can revoke the sign-in at Apple too.

When subscriptions become available, we will also use your account to manage them: what you have subscribed to, when it renews, and receipts. Payment details are handled by Apple and never reach us.

You can delete the account from inside the app or from your account page. Deleting the account revokes the sign-in with Apple or Google, ends every session, and removes the account and what is attached to it.

Your training data

Today, everything you log in HelloReps — workouts, sets, programs, bodyweight, notes — is stored on your iPhone. Exporting it makes a CSV or JSON file on the device that goes wherever you send it.

A later version will let you sync your training results to your HelloReps account so you can see them on this website and keep them across devices. When that ships, this policy will be updated to say exactly what is synced, where it is stored, and how to delete it. It will not happen without you turning it on.

Statistics

A later version will let you compare your lifts with other people's, including people of similar sex, bodyweight and age. The figures will be built from pseudonymised data — which is still personal data under GDPR Article 4(5) — so contributing will be opt-in and off by default, described in the setting itself, and you will be able to stop at any time. Before it is available, this policy will say exactly what is used and how it is kept apart from your account. Nothing is collected for statistics today. Everything the app shows you about your own training is computed on your phone and never depends on contributing.

Social features

When profiles, friends, followers and the feed become available, using them means telling us things like a handle, a home city or gym, who you follow, and summaries of the workouts you choose to share. We collect this only after you have consented, by switching those features on. A new profile is private, and nothing is shared until you change that. Body data — bodyweight, height, sex, birth date — stays on your phone and is never part of a profile.

Email from us

We send the email your account needs — confirming your address, resetting a password — whenever you ask for it. We may also use your email address to contact you about HelloReps: news, and offers about our product. Every such email has a way to opt out, and opting out does not affect your account.

If you ask to be notified at launch, we store the address and send one email asking you to confirm it. If you do not confirm it, nothing more is sent and the address is deleted 30 days later. Once confirmed, we use it for the launch email and for the same kind of contact unless you opt out, and it is deleted when you do.

What we do not do

Apple Health and speech recognition

If you allow it, HelloReps writes each finished session to Apple Health and reads your bodyweight back; it reads and writes nothing else, and Health data never leaves your device through HelloReps. Voice control of the timer on timed exercises uses on-device speech recognition; the microphone is open only while a timed exercise is on screen, a badge shows when it is, and nothing is recorded or sent anywhere.

Cookies

We use cookies only where the site cannot work without them, so there is nothing to accept or decline:

None of them follows you between sites, and none is used for measurement or advertising. Cloudflare (below) may set a short-lived cookie of its own if it needs to tell a person from automated traffic.

Our legal grounds

What we doGround under the GDPR
Create and run your account, sign you in, send the email the account needsPerformance of a contract (Art. 6(1)(b))
Rate limiting, security checks and the operational logLegitimate interest (Art. 6(1)(f)) — keeping the service available and unabused
News and offers about HelloReps to account holdersLegitimate interest (Art. 6(1)(f)), and you can opt out at any time
The launch emailConsent (Art. 6(1)(a)), given when you confirm the address
Social features and, when available, statisticsConsent (Art. 6(1)(a)), given in the app, and withdrawn in the same place

Who else handles your data

We keep the list as short as we can:

WhoWhat they handle
DigitalOcean, LLCHosting. The site, the accounts service and its database run on a server in a European datacentre.
Cloudflare, Inc.Sits in front of the site, filtering malicious traffic. Every request to the site and to the app's accounts service passes through it, and because it terminates the encrypted connection it can see what is sent; it forwards the request to our server and keeps short-lived operational logs of its own.
AppleSign in with Apple, and when subscriptions exist, payment. Apple tells us who signed in; payment details stay with Apple.
GoogleServes the site's fonts, and receives your IP address as part of serving them. If you sign in with Google, Google tells us who signed in.
An email delivery service in the EUDelivers the email we send you, and so handles your address and the message.

Your data is stored in the European Union. DigitalOcean, Cloudflare and Google are US companies: a request may be handled at the Cloudflare location nearest you, which can be outside the EU, and support access at our hosting provider may come from outside it. Those transfers are covered by the EU standard contractual clauses in their data processing agreements, or by the EU–US Data Privacy Framework. We make no other transfers outside the EU.

Where and how long

DataHow long we keep it
Your accountUntil you delete it
Sessions in the appA session lasts 75 days from its last use, and its record is deleted 75 days after that, so that a stolen, reused one is still recognised
Links in email (confirmation, password reset)Deleted a day after they are used or expire
Launch sign-up, unconfirmed30 days
Launch sign-up, confirmedUntil you opt out
The service's operational logOne month. It records errors and what the service did, not the pages you visit or your IP address

Your rights and how to reach us

Under the GDPR you can ask us to:

You can withdraw a consent at any time, in the same place you gave it; that does not undo what was done before. Write to [email protected] and we will answer within 30 days. If you are not happy with how we handled it, you can complain to the Swedish Authority for Privacy Protection, Integritetsskyddsmyndigheten (IMY), or to the supervisory authority in your own country.

Changes to this policy

When something that matters changes — a new service that handles your data, a new use of it, a different retention — we update this page and move the date at the top before the change takes effect.

An unhandled error has occurred. Reload 🗙