Privacy Policy

Last updated: May 28, 2026 · Version 1.0.1

One-sentence summary: Rekomp was built to run entirely on your device. Your health, workout, medication, and body photo data is stored locally and never sent to our servers — because the app has no accounts, no login, and no cloud sync.

1. Who We Are

Rekomp ("app", "we", "us") is a strength training tracker integrated with personal GLP-1 medication logging.

Rekomp is currently operated by Kayo Rodrigues de Lima, an individual, acting as data controller under the Brazilian General Data Protection Law (Lei nº 13.709/2018 — "LGPD") and applicable international privacy frameworks.

Mailing address: Curitiba, Paraná, Brazil.

Data Protection Officer (DPO) / Privacy contact: dpo@rekomp.com.br

If Rekomp is transferred to a legal entity in the future, this Policy will be updated to reflect the new controller, with prior notice to users through the app.

2. The Core Principle: Local Storage

Rekomp was designed with a local-first (offline-first) architecture. In concrete terms:

As a practical consequence: we, the operators of Rekomp, do not have access to your workout logs, medication doses, symptoms, weight, or body photos. They never leave your device through the app.

3. Data Processed Locally on Your Device

The following data is entered by you and stays only on your device:

CategoryExamplesWhere it lives
Basic identificationName or nickname you type, body weight, protein goalLocal SQLite
Health data (sensitive)GLP-1 medication, dose, injection date and time, injection sites, symptoms and severity, notesLocal SQLite
WorkoutRoutines, exercises, sets, reps, loads, RPE, session historyLocal SQLite
NutritionProtein logs, meals, custom foodsLocal SQLite
Body photosProgress photos you optionally addPrivate app folder on device
Body photos: progress photos you add are saved in a private app folder on your device. They are never uploaded to the cloud, never shared, and never accessible by us. Using "Erase all data" or deleting individually permanently removes the image files from the device.

4. Data We Collect for Technical Operation and Improvement

While your health data stays local, the app uses technical tools that process non-health data for stability and product improvement:

4.1 Usage Analytics (PostHog)

We use PostHog to understand how the app is used in aggregate (e.g., which screens are accessed, whether onboarding was completed, how often the app is opened). These events are designed to not contain sensitive health data — we do not log specific medication names, doses in mg, symptoms, or photo content as event properties.

4.2 Crash Reporting (Sentry)

We use Sentry to detect and fix app errors and crashes. When an error occurs, technical information is collected (error type, screen, device model, OS version) for diagnosis. We do not send your health data in these reports.

4.3 Push Notifications

The app schedules local notifications on your device (e.g., rest timer end between sets). For notifications to work, there may be technical processing of a notification identifier by the platform's notification service (Apple APNs or Google FCM).

4.4 App Stores (Apple and Google)

When you download or update Rekomp from the App Store or Google Play, Apple and Google collect data according to their own privacy policies, outside our control (e.g., download metrics and performance data). We recommend reviewing those platforms' policies.

4.5 Payments (future)

The app is currently free. In the future, a paid subscription plan may be offered. When that occurs, payment processing will be handled by Apple (App Store) and/or Google (Google Play) and/or a specialized intermediary (e.g., RevenueCat), subject to those companies' privacy policies. We do not collect or store credit card data. This Policy will be updated with relevant details before any billing is activated.

5. Third-Party Service Providers

The companies below act as processors or service providers, handling only the technical data described in Section 4:

ServicePurposePolicy
PostHogAggregated usage analyticsposthog.com/privacy
SentryCrash reportingsentry.io/privacy
AppleDistribution and (future) paymentsapple.com/legal/privacy
GoogleDistribution and (future) paymentspolicies.google.com/privacy

We do not sell, rent, or commercialize personal data. We do not share health data with insurers, employers, advertisers, or pharmaceutical companies.

6. Legal Basis for Processing

We process data based on the following legal grounds:

7. Your Rights

You have the following rights at any time:

Because we hold no server-side copy of your health data, the most direct way to exercise deletion and portability rights is through the app's own functions.

8. California Residents — CCPA / CPRA Notice

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):

To exercise CCPA rights, contact us at dpo@rekomp.com.br. We will respond within 45 days as required by law.

9. International Users

Rekomp is available internationally. The app is operated from Brazil, and this Policy is primarily governed by Brazilian law (LGPD). Users outside Brazil — including users in the United States and the European Union — are welcome to use the app. Because your health data never leaves your device, there is no international transfer of health data. The limited technical data processed by PostHog and Sentry is subject to those providers' own privacy policies and data transfer mechanisms.

10. Security

We adopt technical and organizational measures appropriate to the local nature of the app:

No system is absolutely secure. Since data lives on your device, the physical and logical security of your device (screen lock, OS updates, not using a compromised device) also matters for protecting your information.

11. Data Retention and Deletion

Your data stays on the device as long as you keep the app installed and do not request deletion. There is no server-side retention because there is no server storing this data. Deletion is controlled by you through the app.

12. Children

Rekomp is not intended for users under 18 years of age. The app addresses prescription medication and strength training, topics that require adult supervision and professional guidance. We do not knowingly collect data from minors. If a minor has used the app, we recommend uninstalling and deleting data by a parent or legal guardian.

13. Educational Content — Not Medical Advice

Important: Rekomp is a personal tracking and organization tool. Estimates presented — including the estimated medication level chart, deload detection, and rest and protein suggestions — are educational approximations based on general literature. They do not represent clinical measurements, do not constitute medical advice, diagnosis, or prescription, and do not replace the guidance of your physician, pharmacist, nutritionist, or fitness professional. Always consult healthcare professionals before starting, adjusting, or stopping medications and training programs.

14. Changes to This Policy

This Policy may be updated to reflect changes to the app, third parties, or applicable law. Relevant changes will be communicated through the app. The date of the last update and version number appear at the top of this document.

15. Contact

Questions, requests, or exercise of rights: dpo@rekomp.com.br