Privacy policy
Last updated: 27 August 2026
Rekord is a training log. This explains what it stores, where, why, and how to get rid of it. Every claim here was checked against the database schema and the code that writes to it, not written from memory — if something in the app changes, this changes with it.
Who is responsible
Rekord is operated by Harald Eskeland, Norway. For anything in this document, including a request to see or delete your data, write to privacy@konturdesign.no.
Because we are established in Norway, the EU/EEA General Data Protection Regulation applies. You can complain to the Norwegian Data Protection Authority (Datatilsynet) at datatilsynet.no if you think we have handled your data badly.
The short version
- Rekord needs an account. Your training is stored on your phone and works offline; the account exists so it survives a lost phone and so the social half works.
- Your bodyweight never leaves your phone. Not to us, not to anyone.
- Nothing you train is public until you tap Share. A session is private by default, every time.
- We do not track you, advertise to you, or sell anything about you. There is no advertising identifier and no advertising network. We do collect crash reports and a short list of events about the subscription screen — both are described below.
- You can delete your account and everything in it from inside the app, in Settings → Delete account.
What is stored on your phone only
This never reaches our servers:
- Bodyweight, whether you typed it or it came from Apple Health.
Bodyweight is the one thing that stays on the device and is never synced, never shared and never visible to anybody else. Everything you log is written to your phone first and works with no signal at all; it is synced to your account afterwards, and a sync failure never blocks logging.
What is stored on our servers, once you sign in
Signing in exists so your log survives a lost phone and so the social half works. Then we store:
Your account
- Your email address, or the private relay address Apple gives us if you use Sign in with Apple.
- A username and display name if you choose them, a profile picture if you upload one, and a short bio.
- Whether your account is public or private.
Your training
- Sessions: when they started and ended, what you called them, the exercises, the weights and reps, and notes you wrote.
- Any custom exercises you created, including a photograph if you added one.
- Photographs you attached to a session.
The social parts
- Who follows whom.
- Comments, and which sessions you have nodded at.
- Challenges you entered, gyms you joined, and clubs you joined or created.
- Club profile pictures, cover pictures and messages you chose to add.
- Sessions you planned with other people, including which gym and what you were training.
Two things you were asked about once
- How you heard about Rekord, if you answered.
- Whether you agreed to hear from us by email, and when you agreed.
Special category data
Bodyweight is health data, which the GDPR treats as a special category needing stronger protection. Our answer is not to hold it: it stays on your device.
The training you sync — sets, weights, how long you trained — is fitness rather than medical data, and we hold it because it is the point of the app.
Apple Health
If you connect Apple Health, Rekord writes your finished sessions to it so they count toward your rings, and reads your most recent bodyweight so you do not have to type it.
Health data is never used for advertising or marketing, never shared with third parties, and never used to profile you. Apple requires this and we agree with it. Bodyweight read from Health stays on your device.
You can disconnect at any time in the iOS Health app.
Why we are allowed to store it
Under the GDPR we rely on:
- Performing our contract with you for your account and your training — you asked for a backed-up training log and this is it.
- Your consent for marketing emails and for your profile picture, both of which you can withdraw at any time.
- Our legitimate interest in keeping the service working and secure — rate limiting, abuse prevention, crash reports, and understanding whether the subscription screen works.
Who else sees it
- Supabase hosts our database, authentication and file storage in the EU. They process data on our instructions and cannot use it for anything else.
- Apple handles Sign in with Apple and, if you use it, the App Store.
- Sentry receives crash reports, on servers in the EU. What it is sent is described below.
That is the whole list. There are no advertising networks, no data brokers, and nothing in the app that builds a profile of you or follows you to other apps or websites.
Crash reports and the subscription screen
Two things are measured, and it is worth being exact about both, because neither is the kind of analytics this app argues against.
Crash reports. When the app crashes or freezes, a report goes to Sentry so it can be fixed. It contains the crash itself — which function failed, the app version, the iOS version and the device model — together with your account identifier, so that "this affected four hundred people" and "this affected one person four hundred times" can be told apart. It deliberately does not include your name, your email address, your IP address, screenshots, or anything you have trained or written. Reports are deleted after 90 days.
The subscription screen. Rekord records when the Pro screen was shown, which plan was chosen, and whether a purchase succeeded, was cancelled or failed. These are stored in our own database alongside your account; there is no third-party analytics service involved. They record what happened on that one screen and nothing about your training.
Who else sees your training
Other people see only what you choose to show them:
- A session is private until you tap Share.
- A private account's shared sessions are visible only to followers it has accepted.
- Public and gym leaderboards count only sessions you have already shared, unless you turn on counting your unshared training in Settings.
- Entering a challenge counts your totals for that challenge. Other entrants see the total, never the sessions behind it.
- Joining a club lets that club's private boards count every session you finish, including unshared sessions. Club members see totals, never the sessions behind them, and leaving the club stops the counting.
How long we keep it
- Your account and training: until you delete them.
- Deleting your account removes everything immediately and permanently, including your photographs. It is not a soft delete and there is no restoration.
- Backups are kept for 7 days and then overwritten, so a deleted account can persist in a backup for up to a week.
Your rights
You can ask us to give you a copy of your data, correct it, delete it, restrict what we do with it, or object to it. Two of those are built into the app rather than requiring an email:
- A copy: Settings → Export my data gives you every session and bodyweight as a JSON file.
- Deletion: Settings → Delete account.
For anything else, write to privacy@konturdesign.no. We will answer within 30 days.
Children
Rekord is not intended for anyone under 13, and we do not knowingly hold data about anyone under 13. Write to us if you believe we do and we will remove it.
A new profile starts private rather than public unless the Apple Account confirms the person is an adult — and it stays private when that is unknown, or when a guardian has set communication limits on the account. We are told which side of eighteen somebody falls on and nothing else: no date of birth, no age, no range, and we keep only that one answer.
Changes
If this policy changes in a way that affects you, we will tell you in the app before it takes effect rather than quietly updating this page.