← Back to Tail Wind Labs
RepBase Privacy Policy
Effective Date: February 7, 2026 · Last Updated: February 7, 2026
Tail Wind Labs LLC ("we," "us," or "our") operates the RepBase mobile application and associated services (collectively, the "Service"). RepBase is a fitness tracking and social workout platform within the Tail Wind Labs ecosystem.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Service. Please read this policy carefully. By using RepBase, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Account Information (via Breeze)
RepBase uses Breeze, our centralized authentication platform, for account management. When you create an account, the following information is shared from Breeze:
- Email address, username, and display name
- Avatar/profile photo URL
- Account role and verification status
For details on how your account data is handled, please also review the Breeze Privacy Policy.
1.2 Profile Information You Provide
- Personal Details: Bio, date of birth, sex (Male, Female, Other, or Prefer Not to Say), and location (city, state, country).
- Privacy Preferences: You control the visibility of your age, sex, location, and whether followers require approval.
- Coach Profile: If you opt into coaching features, we collect coach bio, specialties, and social media links (Instagram, YouTube, personal website).
- Social Links: Optional Instagram handle, YouTube channel, and personal website URLs.
1.3 Fitness and Health Data
Important: RepBase collects sensitive health and fitness data to provide its core workout tracking functionality:
- Workout Data: Completed workouts with start time, end time, and duration. Exercise sets including repetitions, weight, rest-pause indicators, warm-up sets, and failure sets.
- Cardio Metrics: Distance, duration, speed, incline, resistance level, heart rate, and calories burned.
- Strength Metrics: One-rep max (1RM) history and calculations, exercise goals with target 1RM and timelines.
- Body Measurements: Body weight, body fat percentage, and custom body measurements recorded with progress photos.
- Training Programs: Custom workout programs, cycles, and training schedules you create or save.
1.4 Photos and Media
- Progress Photos: Photos you upload with associated metadata including body weight, body fat percentage, body measurements, date taken, and visibility settings (Public, Followers Only, or Private).
- Post Photos: Images you share in social posts.
- Profile Photos: Your profile avatar image.
Photos are stored securely and respect the visibility settings you choose. We do not scan photo content or extract biometric data from images.
1.5 Social and Community Data
- Posts and Comments: Content you create, including text posts, workout shares, and comments on others' posts.
- Social Connections: Your follower/following relationships, follow requests, and blocked users.
- Engagement: Likes on posts and programs, program reviews and ratings, discussion forum participation.
- Reports: Content and photo reports you submit about other users' content.
1.6 In-App Economy Data
- Currency Balance: Your Iron (RepBase currency) balance.
- Purchases: Shop item purchases including social themes, profile badges, and app themes.
- Challenge Participation: Daily challenge completions and associated rewards.
1.7 Automatically Collected Information
- Device Information: Device type, operating system and version, app version, and unique device identifiers.
- Usage Data: Feature usage, screen views, session duration, and interaction patterns.
- Analytics: We use Firebase Analytics to collect aggregated usage statistics.
- Crash Reports: We use Firebase Crashlytics to collect crash logs and diagnostic data.
- Network Information: Connection type and quality for app performance optimization.
1.8 Notification Data
- Push Notification Tokens: We use Firebase Cloud Messaging to send push notifications to your device.
- Notification Preferences: Your settings for rest timer alerts, workout reminders, and daily challenge notifications.
2. How We Use Your Information
We use the information we collect to:
- Provide core workout tracking: Record and display your workouts, track strength progress, calculate 1RM estimates, and manage training programs.
- Enable social features: Facilitate post sharing, profile viewing, following, and community interactions.
- Power the in-app economy: Process Iron transactions, manage shop purchases, and track challenge completions.
- Personalize your experience: Display relevant content, respect your privacy preferences, and apply your chosen themes and badges.
- Improve the Service: Analyze usage patterns, identify bugs through crash reports, and develop new features.
- Ensure safety: Moderate content, process user reports, and enforce community guidelines.
- Communicate with you: Send notifications, respond to support requests, and provide service updates.
- Deliver advertising: We may in the future display advertisements within the app. Any advertising data collection will be disclosed in updates to this policy.
3. Health and Fitness Data — Special Protections
We recognize that health and fitness data is particularly sensitive. We apply additional protections:
- Fitness data is used solely to provide workout tracking functionality and is never sold to third parties.
- We do not share your health data with advertisers or data brokers.
- Body measurements and health metrics are only visible according to your privacy settings.
- Heart rate and calorie data is used exclusively for workout tracking and personal fitness insights.
- You can export or delete your fitness data at any time by contacting us.
As required by Apple's App Store guidelines and Google Play's Health Connect policies, we handle health data with heightened care and do not use it for advertising purposes.
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
- Public Profile Content: Information you set as public (posts, profile details with visibility settings) is visible to other RepBase users.
- Within the Tail Wind Labs Ecosystem: Your user identity syncs with Breeze for authentication. Your Iron currency balance is reflected in your Breeze wallet.
- Service Providers: We share information with vendors who provide hosting (Railway), analytics (Firebase), crash reporting (Crashlytics), push notifications (FCM), and email delivery (SendGrid).
- Content Moderation: Reported content and associated user data may be reviewed by our moderation team.
- Legal Requirements: We may disclose information if required by law, regulation, or valid legal process.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred as a business asset.
- With Your Consent: We may share your information when you give explicit consent.
5. Your Privacy Controls
RepBase provides granular privacy controls:
| Setting | What It Controls |
| Profile Visibility | Whether your profile is public or private |
| Show Age | Whether your age (from date of birth) is visible on your profile |
| Show Sex | Whether your sex is displayed on your profile |
| Show Location | Whether your city/state/country appears on your profile |
| Require Follower Approval | Whether follow requests must be approved by you |
| Photo Visibility | Per-photo control: Public, Followers Only, or Private |
| Blocked Users | Users blocked from viewing your content and interacting with you |
6. Data Retention
We retain your data as follows:
- Account and profile data: Retained until you delete your account.
- Workout and fitness data: Retained for the lifetime of your account to provide progressive tracking.
- Photos: Retained until manually deleted by you or until account deletion.
- Social content (posts, comments): Retained until deleted by you or until account deletion.
- Challenge and shop data: Retained for the lifetime of your account.
- Analytics data: Retained per Firebase's default policies (up to 14 months).
When you delete your account, we will delete or anonymize your personal data within 30 days, except where retention is required by law. Cached data on your device may remain until you uninstall the app.
7. Data Security
We implement technical and organizational measures to protect your data:
- All data is transmitted over HTTPS/TLS encryption.
- Authentication is handled by Breeze using JWT tokens with short-lived access tokens.
- Rate limiting on API endpoints to prevent abuse.
- Biometric authentication option (Face ID, fingerprint) for app access.
- Role-based access controls for data access.
- Photos are stored with access controls matching your visibility settings.
While we strive to protect your data, no method of electronic transmission or storage is 100% secure.
8. Your Rights
8.1 All Users
- Access: View your data through the app at any time.
- Update: Edit your profile, privacy settings, and content.
- Delete: Delete individual posts, photos, and workouts. Request full account deletion by contacting support@tailwindstud.io.
- Export: Request a copy of your workout data by contacting support.
- Opt-Out: Disable push notifications, adjust privacy settings, and manage feature preferences.
8.2 European Economic Area (EEA) Residents — GDPR Rights
If you are located in the EEA, you have rights under the General Data Protection Regulation (GDPR):
- Right of Access: Request a copy of all personal data we hold about you.
- Right to Rectification: Request correction of inaccurate or incomplete data.
- Right to Erasure: Request deletion of your personal data ("right to be forgotten").
- Right to Restrict Processing: Request limitation of how we process your data.
- Right to Data Portability: Receive your data in structured, machine-readable format.
- Right to Object: Object to processing based on legitimate interests.
- Right to Withdraw Consent: Withdraw consent at any time without affecting prior processing.
Legal Basis for Processing: We process your data based on: (a) your consent (especially for health data), (b) performance of our contract with you, (c) compliance with legal obligations, and (d) legitimate interests (security, service improvement).
Contact support@tailwindstud.io to exercise your rights. We will respond within 30 days.
8.3 California Residents — CCPA Rights
If you are a California resident, you have rights under the CCPA:
- Right to Know: Request disclosure of personal information collected, used, and disclosed.
- Right to Delete: Request deletion of your personal information.
- Right to Opt-Out of Sale: We do not sell personal information.
- Right to Non-Discrimination: We will not discriminate for exercising your rights.
9. Children's Privacy
RepBase is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If we learn that we have collected personal data from a child under 13, we will promptly delete that information. If you believe a child under 13 has provided us with personal information, contact us at support@tailwindstud.io.
10. Third-Party Services
11. International Data Transfers
Your information may be transferred to and maintained on servers located outside your country of residence. For EEA, UK, or Swiss residents, we ensure appropriate safeguards such as Standard Contractual Clauses are in place.
12. Push Notifications
We may send push notifications including rest timer alerts, daily workout reminders, challenge notifications, and social activity updates. You can manage notifications in the app settings or your device settings.
13. Offline Mode and Local Data
RepBase supports offline functionality. Your workout data, cached programs, and preferences are stored locally on your device. This local data is not encrypted separately from your device's own storage encryption. Clearing the app cache or uninstalling the app will remove locally stored data.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the new policy within the app or sending you a notification. Your continued use of the Service after changes constitutes acceptance of the updated policy.
15. Contact Us
If you have questions or concerns about this Privacy Policy:
For GDPR-related inquiries, you may also lodge a complaint with your local data protection authority.