Skip to main content

Privacy notice and analytics settings

This notice explains how Repit handles personal information across the coach web app, client apps, organisation workspaces, public pages and related services.

Effective 7 August 2026 · Version 2026-08-07

Who is responsible

EF PRODUCT LABS LTD, operating as Repit, is responsible for account, billing, security, support and direct service-operation information. A coach, gym, school, team or other organisation may be the controller for client information it chooses to manage through Repit; in that situation, Repit processes the information on its instructions.

EF PRODUCT LABS LTD is registered in England and Wales under company number 17285911. Its registered office is 71–75 Shelton Street, Covent Garden, London, United Kingdom, WC2H 9JQ.

Privacy questions and requests can be sent to support@repit.coach. If your request concerns information managed by a coach or organisation, we may direct it to that controller.

Information we use and why

We collect information you provide, information supplied by an authorised coach or workspace, and technical information generated when the service is used.

Categories of information, examples, purposes and legal bases
CategoryExamplesPurposeLegal basis
Account and identityName, email, avatar, role, organisation membership and sign-in records.Create and secure accounts, manage access, and provide support.Contract; legitimate interests in security and service operation.
Coaching and client recordsProgrammes, workouts, check-ins, notes, goals, adherence and coach-client links.Provide coaching workflows selected by the coach, organisation or athlete.Contract; processor instructions where a coach or organisation is the controller.
Health and fitness informationReadiness, injuries, body measurements, nutrition, cycle and training information.Provide user-selected fitness, readiness and coaching features.Article 6 contract or legitimate interests, plus explicit consent or another applicable Article 9 condition selected by the responsible controller.
Billing and commercePlan, customer and transaction references, invoices, purchases and session credits.Take payment, administer subscriptions, prevent fraud and keep accounting records.Contract; legal obligation; legitimate interests in fraud prevention.
Communications and supportInvitations, service messages, support requests, feedback and bug diagnostics.Deliver communications, resolve problems and improve reliability.Contract; legitimate interests; consent for optional marketing.
AI interactionsPrompts, conversation history, proposals, tool actions and relevant coaching context.Provide requested AI assistance, review safety and diagnose failures.Contract; legitimate interests in safe service operation.
Device, security and usageIP address, browser, device, timestamps, audit records and optional analytics events.Secure and operate Repit, prevent abuse and understand product use.Legitimate interests for essential security; consent for optional analytics.

Health and special-category information

Some Repit features can contain health-related or other special-category information. Those features should only be used where the responsible controller has an appropriate UK GDPR Article 6 basis and Article 9 condition. Where Repit asks an individual for consent, it must be freely given, specific, informed and capable of withdrawal.

Coaches and organisations must not require unnecessary sensitive information or use Repit as an emergency or medical record system.

How information is shared

Information may be shared with:

  • the coaches, clients and workspace members authorised by the relevant relationship and permissions;
  • Supabase for database, authentication, storage and server services;
  • Vercel for web hosting and delivery;
  • Stripe and connected payment providers for web payments and billing;
  • Apple, Google and RevenueCat where app distribution or in-app subscriptions apply;
  • Resend and similar delivery providers for transactional email;
  • OpenAI for requested AI features, subject to configured data controls;
  • PostHog only for optional analytics after consent; and
  • professional advisers, regulators, courts or authorities where legally required.

Repit does not sell personal information or share it with third parties for their independent direct marketing.

AI and automated features

AI features can analyse the context supplied to a conversation and propose coaching actions. Coaches are expected to review proposals before applying them. Repit does not intend AI outputs to make solely automated decisions that produce legal or similarly significant effects about an individual.

Do not place information in an AI conversation unless it is necessary for the requested task and you are authorised to use it.

International transfers

Some providers may process information outside the United Kingdom. Where required, Repit relies on safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, and contractual and technical protections. You can ask us for more information about safeguards relevant to your data.

Current provider terms include the PostHog DPA and the Supabase DPA.

Retention

We keep account and service information while it is needed to provide Repit. Retention then depends on the record's purpose: security and support records are kept for a proportionate investigation period; optional attribution records follow the periods below; and financial, tax, contract and transaction records may be retained for the legally required period.

Deletion removes or de-identifies information according to the account lifecycle described on our account-deletion page. Backups and provider systems may take additional time to age out, and legal holds may temporarily override normal deletion.

Your rights

Depending on the circumstances, UK data-protection law gives you rights to be informed, access your information, correct it, erase it, restrict processing, receive portable data, object, withdraw consent, and challenge certain automated decisions.

Send a request to support@repit.coach. We may verify your identity and normally respond within one month. You can complain to the UK Information Commissioner's Office at ico.org.uk, although we would appreciate the opportunity to resolve the concern first.

Security and incidents

Repit uses access controls, scoped permissions, encryption in transit, logging and provider security controls designed to protect information. No system is completely secure. If we become aware of an incident, we investigate, contain it and notify affected people or regulators where required.

Children and young athletes

Coach accounts are for adults. Where an organisation uses Repit with a young athlete, the organisation is responsible for appropriate authority, notices, safeguarding and age-appropriate use. Contact us if you believe a child's information has been provided without proper authority.

Marketing

Product marketing is optional. You can unsubscribe using the link in an email or contact us. Service, security, billing and account messages are not marketing and may still be sent when necessary.

Coach GEO experiment

During coach setup, Repit may ask for country, coaching context and a categorical source describing how you heard about Repit. Choosing AI assistant or Other allows an optional detail of up to 120 characters. You can choose Prefer not to say, and these questions do not affect access.

Repit keeps self-reported answers separate from observed attribution. A browser-readable consent cookie is not treated as server proof. Until purpose-specific server-verifiable consent is available, the experiment currently uses the self-report-only path.

The information is used for experiment qualification and bounded acquisition comparisons. Raw source detail is deleted after 90 days, and the minimised user-level record is deleted or irreversibly aggregated after day 150. Account deletion removes the user-level experiment record and pending enrolment job.

Cookies and optional analytics

Essential storage supports sign-in, security and preferences. PostHog and campaign attribution start only after optional analytics is accepted.

On production these settings use the .repit.coach scope so the choice applies across Repit subdomains.

NamePurposeRetention
repit_consentRecords whether you accepted or rejected optional analytics.Up to 180 days
repit_attr_prod / repit_attr_stagingKeeps first-touch attribution after analytics is accepted.Up to 30 days
repit_conversion_attemptLinks an accepted analytics journey to a server conversion record.30-day cookie; server record up to 90 days

No analytics choice saved yet

Changes to this notice

We review this notice when our processing, providers or legal obligations change. We will publish the new effective date and bring material changes to users' attention where appropriate.