Last Rep

Privacy policy

Effective 17 September 2026 · Applies to the Last Rep app on Android, iPhone, Apple Watch and the web
The short version. Your workouts live on your phone. If you turn on sync, a copy goes to Last Rep's own server so you can restore it on a new phone. Nothing is sold, nothing is used for advertising, and there are no analytics or tracking libraries in the app. You can delete everything from inside the app.

Who runs Last Rep

Last Rep is made and operated by its developer, an individual, not a company. For anything about your data, write to privacy@lastrep.app. The developer is the data controller for the purposes of data protection law.

What the app records

Everything below is created by you using the app, and stays on your device unless you turn on sync.

DataWhy
Workouts: programme, date, duration, calories, sets, weights and reps, how hard it feltIt is your training log.
Heart rate, second by second, during a workoutCalories, effort and the trace on the History screen. Only if you connect a heart-rate strap or use the Apple Watch app.
Location during a run or walk: GPS fixes, distance, pace, splits, the routeMeasuring the run and drawing it on a map. Only while an outdoor activity is running; the app does not track you at other times.
Body details you enter: age, sex, weight, height, resting heart rateCalorie and fitness calculations. All optional; the app runs without them.
Settings, saved programmes, routines you buildSo the app is yours.

Sync: what leaves your phone, and where it goes

Sync is off until you turn it on. When it is on, the app sends a copy of the data above to Last Rep's own backend, which runs on Cloudflare's network. The copy is stored under an account identifier the app makes up on your device; there is no email address or name unless you choose to add one later. The purpose is restoring your history on a new phone and, if you opt in, appearing in a league under a display name you pick.

Sync data is kept for as long as your account exists. Deleting your account (Settings → Your data) deletes the server copy immediately; the backend keeps no separate backups of it.

Apple Watch and HealthKit

The Last Rep watch app reads your heart rate from HealthKit during a workout you have started, and records the workout session to HealthKit so your Activity rings and Health app reflect it. That is the whole of its HealthKit use. Specifically:

Services the app talks to

The app has no advertising, analytics or crash-reporting libraries. It contacts exactly these services:

ServiceWhat it receivesWhen
Last Rep's backend (Cloudflare)Your sync copy, your account identifier, a report if you send oneSync, and the report button
Map tiles (MapTiler, with OpenStreetMap data)The map tile coordinates being viewed, which correspond to where your route isOnly when a route map is on screen
Open-MeteoYour approximate location (rounded), to fetch the weatherWhen the run screen shows the weather

Each of these sees your device's IP address as part of the request, the way any internet service does.

The report button

Settings has a "Send a report" button. Pressing it sends the developer your note, your app version, and a short technical record of what the workout engine was doing (segment timings and the like). It does not include your workout history, location, heart-rate data, or anything that identifies you unless you type it into the note. Reports reach the developer as a notification and are kept until the problem is dealt with.

What the app does not do

Your choices and rights

If you are in the European Economic Area or United Kingdom, the legal basis for processing is the contract you have with the app when you use it (for your own data) and your consent (for sync, location, Bluetooth and HealthKit, each of which you switch on yourself). You have the right to access, correct, delete, and export your data, and to complain to your local supervisory authority.

Children

Last Rep is not directed at children under 13 (or the age of digital consent where you live) and does not knowingly collect their data. If you believe a child has created an account, email the address above and it will be removed.

Security

Sync traffic is encrypted in transit. The account secret that identifies your device is stored only on your device; the server keeps a one-way hash of it, so it cannot be recovered from the server side. No system is perfectly secure, and the app is designed so that the worst case of a breach is a copy of a training log, not an identity.

Changes

If this policy changes, the new version is posted here with a new effective date, and the app's What's New screen says so on the first launch after the change. Continued use after that is acceptance.

Last Rep · Terms of use · privacy@lastrep.app