DuoRep Privacy Policy
- Effective date
- 2026-09-23
- Controller
- Jovan Jovanoski, Gjuro Salaj 61/2, Skopje, North Macedonia
- Privacy contact
- support@duorep.app
This document is available in English and Macedonian. The English version is the authoritative one: if the two versions differ, the English text governs.
1. Introduction
DuoRep is a workout and nutrition tracking app for two people training together. It stores the training and body data you enter so that you can follow your own progress and stay accountable to the partner you link with.
This policy explains what personal data DuoRep collects, why, who it is shared with, how long it is kept, and how you can exercise your rights over it. The English version of this policy is the authoritative version.
2. Data controller
The data controller responsible for the processing described here is Jovan Jovanoski, Gjuro Salaj 61/2, Skopje, North Macedonia.
No Data Protection Officer has been appointed. DuoRep does not process personal data at a scale that requires one; privacy queries go to the contact address above and are answered by the controller directly.
3. Data we collect
DuoRep collects the following categories of personal data.
- Account information, your email address and display name, received from Google Sign-In when you create an account.
- Body weight entries, the weight, and optionally the waist measurement, that you record.
- Workout history, the exercises, sets, reps and weights you log, together with session notes and effort ratings.
- Meal logs and nutrition targets, the meals you record, and the calorie and macronutrient targets calculated from the details you give during onboarding (sex, age, height, weight, activity level and goal).
- Injury flags, the body areas you mark as needing care, so that DuoRep can warn you about exercises that load them.
- Couple link data, your partner's user identifier and the shared activity feed, generated when two accounts are linked.
- Technical data, IP address, session identifiers and access logs, collected automatically by the hosting infrastructure.
Body weight, workout history, meal logs and injury flags are health-related data and are treated as special category data under Article 9 GDPR and the equivalent provisions of the North Macedonia Law on Personal Data Protection.
4. Why we collect it, and our legal basis
Each category is processed for a stated purpose on a stated legal basis.
- Email address, display name and the couple link, to provide the service you signed up for. Legal basis: performance of a contract, Article 6(1)(b).
- Body weight, workout history, meal logs and injury flags, to track your training, calculate your daily targets, warn you about exercises that load a flagged area, and show your progress to the partner you have linked with. Legal basis: your explicit consent, Article 6(1)(a) and Article 9(2)(a).
- Your age, to confirm that you meet the minimum age of 16, and to calculate your calorie target. Legal basis: performance of a contract, and your explicit consent.
- IP address and access logs, to keep the service secure and to detect abuse. Legal basis: legitimate interest, Article 6(1)(f).
Health data is processed only on the explicit consent you give during onboarding, on a screen separate from your acceptance of the Terms of Service. You may withdraw that consent at any time by deleting your account, which erases the data it covered.
DuoRep carries out no automated decision-making or profiling that produces legal effects for you. Your generated training programme and calorie target are calculated from values you entered and can be changed by you at any time.
5. How we share your data
- With the partner you link with, once you accept a couple link, your workout history, activity feed entries, meal plans and body weight trend direction become visible to them. You are never obliged to link with anyone.
- With Supabase, Inc., our database, authentication and file storage provider, acting as a data processor under a Data Processing Agreement.
- With Google, for authentication, when you sign in with your Google account.
- With GitHub, Inc., our backup storage provider, acting as a data processor. Encrypted backups of your data are stored there, containing your full account data including health information such as body weight and workout records. Every backup is encrypted with age encryption before upload, the encryption key is held solely by DuoRep and is never accessible to GitHub, and backups are deleted automatically after 7 days.
- With a regulator, court or law enforcement authority, only where we are legally required to.
DuoRep does not sell personal data, does not share it with advertisers or data brokers, and does not use your health or fitness data for advertising, marketing or data mining. The app loads no third-party advertising or analytics code; if any further third-party processor is added, this policy will be updated before the change is enabled.
6. International data transfers
Your data is stored in the European Union. Supabase, Inc. is incorporated in the United States, so its personnel may have technical access to the data from outside the EU, and it uses sub-processors located outside the EU.
These transfers are governed by the Standard Contractual Clauses approved by the European Commission, Implementing Decision (EU) 2021/914, incorporated into our agreement with Supabase. You may request a copy of the applicable clauses at the contact address above.
Database backups are stored with GitHub, Inc., San Francisco, United States. Those transfers are covered by GitHub's Data Protection Agreement, which incorporates the Standard Contractual Clauses under Article 46(2)(c) GDPR.
7. How long we keep it
- Account and training data, kept for as long as your account exists.
- Data after account deletion, erased immediately. Deleting your account is a hard delete, not a deactivation: your account record, training history, body weight entries, meal logs, injury flags, progress photos and login record are removed at once. There is no grace period during which they could be restored.
- Backup snapshots, the hosting provider keeps rolling encrypted backups for up to 7 days. Data you have deleted may still exist in those snapshots until they are overwritten. This is the one exception to immediate erasure, and it is stated here rather than glossed over.
- Server and access logs, retained for up to 90 days for security purposes.
Progress photos included in a data export are shared as links valid for 1 hour(s) from the moment the export is generated, after which they stop working. The exact validity period is also stated inside the export file.
8. Your rights
You have the following rights over your personal data. Requests are answered within 30 days; if a request is complex we will tell you within that period and may extend it by up to two further months.
- Access, you can download everything DuoRep holds about you from Me, then Data & privacy, then Export my data, as machine-readable JSON.
- Rectification, you can correct your display name, body data, targets and injury flags in the app at any time.
- Erasure, you can delete your account and all personal data from Me, then Data & privacy, then Delete my account.
- Portability, the export described above is the structured, machine-readable copy of the data you provided.
- Restriction of processing, write to the contact address above and we will pause processing while a dispute is resolved.
- Objection, you can object to processing based on legitimate interest, such as the security logging of IP addresses.
- Withdrawal of consent, deleting your account withdraws your consent to health data processing and erases the data it covered. Withdrawal does not affect processing that has already taken place.
You also have the right to lodge a complaint with a supervisory authority. If you are in the EU, that is the authority in your own member state.
For North Macedonia, it is the Agency for Personal Data Protection (DZLP), https://dzlp.mk/.
9. Children
DuoRep is not intended for people under 16. Onboarding asks your age and cannot be completed below that threshold, and the check is enforced on the server as well as in the app. We do not knowingly collect data from children. If we learn that a user is under 16, their account and all associated data are deleted.
10. Security
- Data is encrypted in transit with TLS and at rest with AES-256 by the hosting provider.
- Row-level security is enabled on every table that holds personal data, so a request can only reach your own rows and those your linked partner is entitled to see.
- Data export and account deletion run inside server-side functions scoped to your own authenticated identity, so neither can reach another user’s data.
- If a personal data breach occurs we notify the supervisory authority within 72 hours of becoming aware of it, and affected users where the breach is likely to present a risk to them.
11. Cookies and local storage
DuoRep stores an authentication token in your browser so that you stay signed in, plus a small amount of operational state: your language choice, the onboarding step you reached, and offline caches of your own data. All of it is strictly necessary for the app to work, so no consent banner is required.
There are no advertising cookies and no third-party tracking scripts. If analytics or error tracking is added, this section will be updated and a consent mechanism added where the law requires one.
12. Changes to this policy
We will tell you about material changes in the app at least 30 days before they take effect. Continued use after the effective date means that you accept the updated policy. If a change affects how your health data is processed we will ask for fresh explicit consent rather than rely on your continued use.
13. Contact
For any privacy question, or to exercise any of the rights above, write to Jovan Jovanoski at support@duorep.app. We answer within 30 days.