Privacy policy
Who runs Last Rep
Last Rep is made and operated by its developer, an individual, not a company. For anything about your data, write to privacy@lastrep.app. The developer is the data controller for the purposes of data protection law.
What the app records
Everything below is created by you using the app, and stays on your device unless you turn on sync.
| Data | Why |
|---|---|
| Workouts: programme, date, duration, calories, sets, weights and reps, how hard it felt | It is your training log. |
| Heart rate, second by second, during a workout | Calories, effort and the trace on the History screen. Only if you connect a heart-rate strap or use the Apple Watch app. |
| Location during a run or walk: GPS fixes, distance, pace, splits, the route | Measuring the run and drawing it on a map. Only while an outdoor activity is running; the app does not track you at other times. |
| Body details you enter: age, sex, weight, height, resting heart rate | Calorie and fitness calculations. All optional; the app runs without them. |
| Settings, saved programmes, routines you build | So the app is yours. |
Sync: what leaves your phone, and where it goes
Sync is off until you turn it on. When it is on, the app sends a copy of the data above to Last Rep's own backend, which runs on Cloudflare's network. The copy is stored under an account identifier the app makes up on your device; there is no email address or name unless you choose to add one later. The purpose is restoring your history on a new phone and, if you opt in, appearing in a league under a display name you pick.
Sync data is kept for as long as your account exists. Deleting your account (Settings → Your data) deletes the server copy immediately; the backend keeps no separate backups of it.
Apple Watch and HealthKit
The Last Rep watch app reads your heart rate from HealthKit during a workout you have started, and records the workout session to HealthKit so your Activity rings and Health app reflect it. That is the whole of its HealthKit use. Specifically:
- Heart rate read from HealthKit is used to show your live heart rate, compute calories and effort, and save the heart-rate trace with that workout. It is stored with the workout on your phone and, only if sync is on, in your sync copy.
- HealthKit data is never used for advertising, marketing, or any purpose other than the workout you are doing. It is never sold, and never shared with any third party, data broker, or analytics service.
- The watch app reads nothing from HealthKit outside a workout, and reads no other HealthKit data types.
- You can revoke access at any time in the Health app under Sharing → Apps → Last Rep, and the workout still runs without it.
Services the app talks to
The app has no advertising, analytics or crash-reporting libraries. It contacts exactly these services:
| Service | What it receives | When |
|---|---|---|
| Last Rep's backend (Cloudflare) | Your sync copy, your account identifier, a report if you send one | Sync, and the report button |
| Map tiles (MapTiler, with OpenStreetMap data) | The map tile coordinates being viewed, which correspond to where your route is | Only when a route map is on screen |
| Open-Meteo | Your approximate location (rounded), to fetch the weather | When the run screen shows the weather |
Each of these sees your device's IP address as part of the request, the way any internet service does.
The report button
Settings has a "Send a report" button. Pressing it sends the developer your note, your app version, and a short technical record of what the workout engine was doing (segment timings and the like). It does not include your workout history, location, heart-rate data, or anything that identifies you unless you type it into the note. Reports reach the developer as a notification and are kept until the problem is dealt with.
What the app does not do
- No advertising, and no advertising identifiers.
- No analytics, tracking pixels, or third-party SDKs that phone home.
- No selling, renting, or sharing of your data with anyone.
- No reading of your contacts, photos, or other apps' data.
- No location tracking outside an activity you started.
Your choices and rights
- See it: everything the app holds is visible in History and Settings, and you can export your full sync copy from Settings → Your data.
- Delete it: Settings → Your data → Delete account removes the server copy at once. Uninstalling the app removes the on-device copy. You can also email privacy@lastrep.app and it will be done within 30 days.
- Correct it: every workout can be edited or deleted in History.
- Permissions: location, Bluetooth, and (on watch) HealthKit are each asked for when first needed and can be turned off in your device settings. The relevant feature stops; the rest of the app carries on.
If you are in the European Economic Area or United Kingdom, the legal basis for processing is the contract you have with the app when you use it (for your own data) and your consent (for sync, location, Bluetooth and HealthKit, each of which you switch on yourself). You have the right to access, correct, delete, and export your data, and to complain to your local supervisory authority.
Children
Last Rep is not directed at children under 13 (or the age of digital consent where you live) and does not knowingly collect their data. If you believe a child has created an account, email the address above and it will be removed.
Security
Sync traffic is encrypted in transit. The account secret that identifies your device is stored only on your device; the server keeps a one-way hash of it, so it cannot be recovered from the server side. No system is perfectly secure, and the app is designed so that the worst case of a breach is a copy of a training log, not an identity.
Changes
If this policy changes, the new version is posted here with a new effective date, and the app's What's New screen says so on the first launch after the change. Continued use after that is acceptance.