The short version
- We do not sell personal data, and we do not run advertising inside Repzy.
- A gym owner's account data is handled by us as a Data Fiduciary. Member records that a gym enters are handled by us as a Data Processor for that gym — the gym decides what goes in and what comes out.
- We never see or store card, UPI or netbanking credentials. Subscription payments run through Google Play.
- You can delete your account and its data from inside the app, or by writing to us. Deletion means deletion, not deactivation.
- Fitness and diet entries are treated as sensitive. They are never used for advertising or profiling.
This summary is for orientation only. The numbered sections below are the operative policy.
01Who this policy covers
This Privacy Policy is issued by Repzy, a sole proprietorship of Ayush Kishore, registered under the Udyam scheme registered at Mahavir Asthan, Chowk Shikarpur, Patna City, Patna, Bihar 800009, India ("Repzy", "we", "us"). It applies to:
- the Repzy Android application published on Google Play;
- the website at repzy.in and our internal administrative tools;
- support we provide over email, phone or WhatsApp.
It applies to two different kinds of people, and the difference matters throughout this document:
- Gym operators — owners and their staff, who register with us and run a gym on Repzy.
- Gym members — the people whose records a gym operator keeps in Repzy, whether or not they log in themselves.
Where this policy says "you" without qualification, it means whichever of the two is reading it.
02Who is responsible for what
Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the party that decides the purpose and means of processing is the Data Fiduciary. The party that processes on its behalf is the Data Processor. Repzy occupies both roles, in different places.
| Data | Data Fiduciary | Repzy's role |
|---|---|---|
| Gym operator's own account: name, phone, email, gym name and address, login credentials, subscription status, support history | Repzy | Data Fiduciary. We decide why this is collected and we answer to you directly for it. |
| Member records created by a gym: member name, contact details, plan, fees, attendance, photographs, fitness and diet entries | The gym operator | Data Processor. We store and process it under the gym's instructions and do not use it for our own purposes. |
| Technical and diagnostic data: device model, operating system, app version, crash reports, security logs | Repzy | Data Fiduciary. Used to keep the service working and secure. |
If you are a gym member and you want your record corrected or erased, your gym is the first place to ask, because the gym controls that record. We will help the gym act on your request, and we will act directly if the gym does not — see section 11.
03Data we handle
We collect only what the product needs to work. We do not buy personal data from third parties and we do not enrich your records from outside sources.
3.1 Given to us by a gym operator
| Category | Examples | Source |
|---|---|---|
| Identity and contact | Name, mobile number, email address, gym name, gym address | You, at registration |
| Account and access | Login ID, password stored as a one-way hash, staff accounts you create, roles and permissions | You, in the app |
| Member records | Member name, mobile number, address, member ID, joining date, plan, plan expiry, membership status, member photograph if you upload one | Entered by you or your staff |
| Operational records | Attendance, fee receipts, dues, expenses, notes you add | Entered by you or your staff |
| Fitness and diet entries | Food logged against a meal, calorie totals, and any body measurement fields you choose to record | Entered by you, your staff, or the member |
3.2 Collected automatically
| Category | Examples | Purpose |
|---|---|---|
| Device and app | Device model, Android version, app version, language, time zone, coarse network type | Compatibility, delivering the right update |
| Diagnostics | Crash reports and error traces, including the screen where a failure occurred and an internal account identifier | Fixing faults |
| Security logs | IP address, timestamps, login attempts, administrative actions | Detecting misuse, meeting Rule 6 of the DPDP Rules, 2025 |
| Push token | The notification token issued to your device by Google or Expo | Sending you app notifications |
| Purchase state | Google Play purchase token, order identifier, product identifier, subscription start, renewal and expiry | Turning paid features on and off |
3.3 What we do not collect
- No payment credentials. Card numbers, UPI IDs, CVVs and netbanking passwords never reach our servers. Google Play processes subscription payments and returns only the purchase state listed above.
- No advertising identifiers. Repzy contains no advertising SDK and does not use the Android Advertising ID.
- No background location tracking. Repzy does not track your position when the app is closed.
- No selling or renting of data, ever, to anyone, in any form, including in aggregate.
The app asks for device permissions only at the moment the corresponding feature is used — for example, camera or gallery access when you attach a member photograph, and notification permission when you enable reminders. Declining a permission disables only that feature; the rest of the app continues to work. The current permission list for the installed version is shown on the Repzy listing on Google Play under App permissions.
04Why we handle it, and on what legal footing
Section 4 of the DPDP Act permits processing of personal data only for a lawful purpose, and only either with consent or for a "certain legitimate use" under section 7. Our purposes and their footing:
| Purpose | Footing |
|---|---|
| Creating and running your account, and providing the features you asked for | Consent given at registration, and performance of our contract with you |
| Storing and displaying member records on your behalf | Processing on documented instructions of the gym, which is the Data Fiduciary for those records |
| Billing, subscription state, invoices and tax records | Legal obligation and contract |
| Service notifications — expiry reminders, receipts, security alerts | Consent, and legitimate use for the purpose for which you voluntarily provided the data |
| Fixing crashes, preventing abuse, protecting accounts | Legitimate use under section 7, and our obligation to maintain reasonable security safeguards |
| Responding to a lawful order of a court or a competent authority | Compliance with law |
| Product announcements and marketing messages | Separate, optional consent that you can withdraw without losing access to the product |
We do not use member records, fitness entries or diet entries for advertising, for profiling, or for training any model. If we ever want to use data for a genuinely new purpose, we will ask for fresh consent first.
05Consent, notice and withdrawal
Where we rely on consent, that consent is free, specific, informed, unconditional and unambiguous, given by a clear affirmative action, and limited to the data necessary for the stated purpose — the standard set by section 6 of the DPDP Act.
You may withdraw consent at any time, and withdrawing it must be as easy as giving it. Write to support@repzy.in or use the controls in the app. Withdrawal is not retrospective: processing done before withdrawal remains lawful. Where the withdrawn consent covers data we need to run the service, withdrawal will end your ability to use that part of the service, and we will tell you plainly before it takes effect.
On request, we will provide this notice in English or in any language listed in the Eighth Schedule to the Constitution of India.
07Where data is stored, and transfers outside India
Repzy's backend runs on Railway in the US West (California, USA) region, and the database is hosted on managed MongoDB Atlas infrastructure. Crash reporting, push notification delivery and payment processing are also handled by providers that operate outside India. Your data is therefore stored and processed outside India.
Section 16 of the DPDP Act permits transfers outside India except to territories that the Central Government restricts by notification, and Rule 15 of the DPDP Rules, 2025 governs the conditions. We monitor those notifications and will change providers or regions if a provider's location becomes restricted. Wherever data goes, our contractual and security obligations under this policy follow it.
08How long we keep it
We keep personal data only as long as the purpose it was collected for still exists, or as long as a law requires — whichever is longer. Concretely:
| Data | Kept for |
|---|---|
| Gym operator account and member records | While the account is active. Erased on deletion, per section 9. |
| Records after a deletion request | Removed from live systems within 30 days; purged from encrypted backups within 90 days. |
| Financial and tax records — invoices, subscription payments, GST records | As long as Indian tax and company law requires us to retain books of account, currently up to eight financial years. |
| Security and access logs | One year, the minimum period under Rule 6 of the DPDP Rules, 2025. |
| Crash and error reports | 90 days, after which Sentry deletes them automatically. |
| Support correspondence | Three years from the last message, so we can evidence what was asked and answered. |
Where Rule 8 of the DPDP Rules, 2025 requires it, we will give you at least 48 hours' notice before erasing data on account of inactivity, so that you have a chance to log in and keep the account alive.
09Deleting your account and your data
You can delete your Repzy account and the data in it. Deletion is real deletion. Deactivating, disabling or freezing an account is not deletion, and we do not treat it as such.
How to delete
- In the app: Profile → Settings → Delete account. Confirm when prompted.
- On the web: use the request form at repzy.in/delete-account.html.
- By email: write to support@repzy.in from the email address or with the mobile number registered on the account.
What happens next
- We verify that the request comes from the account holder. We may ask you to confirm a one-time code sent to the registered number or email. We do not ask for identity documents for a routine deletion.
- Deleting a gym operator account deletes the gym's member records, attendance, fee history, expense entries and fitness entries stored under that gym. This cannot be undone, so export what you need first.
- Live systems are cleared within 30 days of verification. Encrypted backups roll off within 90 days.
- We retain only what law requires — chiefly invoices and payment records for the statutory period — plus the minimum needed to prevent fraud and abuse. Retained records are locked down and are not used for any other purpose.
A Repzy subscription bought through Google Play is not cancelled by deleting your account. Cancel it in the Play Store under Payments and subscriptions → Subscriptions, or it will keep renewing. See section 7 of the Terms.
10Your rights
Under Chapter III of the DPDP Act you have the following rights, and we do not charge for exercising any of them:
- Access — a summary of the personal data we process about you, what we do with it, and the identities of the other Data Fiduciaries and Processors it has been shared with.
- Correction, completion and updating — of data that is inaccurate, incomplete or out of date.
- Erasure — of data we no longer need for the purpose it was collected for, unless retention is required by law.
- Grievance redressal — a readily available means of raising a complaint with us, before you approach the Data Protection Board.
- Nomination — you may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Write to us to record a nomination.
How to exercise them
Email support@repzy.in from your registered address, or write to the grievance officer in section 17. Tell us what you want and give us enough detail to find your account. Our commitments:
- acknowledgement within 48 hours;
- resolution within 30 days in the ordinary course, and in no case later than 90 days;
- if we refuse, a written reason, and the route to escalate.
You also have duties under section 15 of the DPDP Act — most relevantly, not to impersonate another person when exercising a right, and not to file a false or frivolous complaint.
If you are not satisfied with our response, you may complain to the Data Protection Board of India, which is constituted and accepting complaints.
11If you are a gym member
Your gym decided to keep your record in Repzy. That makes your gym the Data Fiduciary for it and Repzy the Processor. In plain terms: the gym chose what to record about you, and the gym is accountable for having your consent.
- Ask your gym first for access, correction or erasure of your record. They can do all three from inside the app.
- If your gym does not respond within a reasonable period, write to us at support@repzy.in. We will contact the gym, and if the request remains unanswered we will act on it ourselves.
- Fee and attendance records may be retained by your gym for its own accounting and legal reasons even after you leave. That decision is the gym's, not ours.
- Your fitness and diet entries are visible to your gym's owner and to the staff the owner has authorised. They are not visible to other members.
- If you have a member login, you may delete your own login and the data attached to it — see section 9. Deleting your login does not delete the gym's own commercial records of your membership.
12Members and users under 18
The DPDP Act treats every individual below 18 as a child, which is a wider net than most foreign privacy laws. Section 9 of the Act and Rule 10 of the DPDP Rules, 2025 require verifiable consent from a parent or lawful guardian before a child's personal data is processed, and prohibit tracking, behavioural monitoring and targeted advertising directed at children.
- Repzy accounts are for adults. A gym operator or staff account may only be created by a person aged 18 or over.
- Gyms very often have members under 18. Where a gym records such a member in Repzy, the gym is the Data Fiduciary and is responsible for obtaining and holding verifiable consent from the member's parent or guardian, in a form that can be produced if questioned. The Terms make this a contractual obligation of the gym.
- We do not profile children, do not run behavioural analytics on them, and show no advertising to anyone. Repzy carries no advertising at all.
- If a parent or guardian tells us that a child's data is in Repzy without their verifiable consent, write to support@repzy.in. We will notify the gym and, if valid consent cannot be shown, erase the record.
The same protections apply to an individual with a disability who has a lawful guardian.
13Security
Section 8(5) of the DPDP Act requires reasonable security safeguards, and Rule 6 sets out what they look like. The measures we maintain:
- traffic between the app and our servers is encrypted in transit with TLS;
- the database is encrypted at rest by our hosting provider;
- passwords are stored only as one-way hashes, never in a readable form;
- access to production systems is limited to named individuals, protected by separate credentials, and reviewed after any personnel change;
- credentials are rotated on a schedule and immediately on any suspicion of exposure;
- logs of access and administrative action are retained for one year to allow detection and investigation;
- member data is separated by gym, so one gym cannot read another's records;
- our processors are bound by contract to equivalent safeguards.
No system is perfectly secure, and we do not claim otherwise. What we do claim is that we treat a breach as an emergency and that the measures above are actually in place, not aspirational.
If you believe you have found a vulnerability, report it to support@repzy.in. We will not pursue action against anyone who reports a genuine issue in good faith, does not access more data than necessary to demonstrate it, and gives us a reasonable opportunity to fix it before disclosure.
14If there is a data breach
Rule 7 of the DPDP Rules, 2025 sets the drill, and we follow it:
- every affected person is informed without delay, in plain language, describing the nature and extent of the breach, when it happened, its likely consequences, what we have done about it, and what they should do;
- the Data Protection Board of India is informed without delay, with fuller particulars — including the events leading up to the breach, mitigation measures and remedial action — provided within 72 hours;
- if the breach touches member records, we inform the affected gym so that it can meet its own obligations to its members.
We will not delay notification to protect our reputation.
15Website, cookies and links
repzy.in uses only cookies and local storage that are strictly necessary to serve the site and keep an administrative session logged in. We do not use Google Analytics, any other third-party analytics service, or any advertising cookie on repzy.in. The usage figures we see internally are generated from your app activity described in section 3, not from website tracking. If we later add analytics or any cookie that is not strictly necessary, we will ask for your consent first and update this policy.
The site links out to Google Play, and offers a WhatsApp contact button. Once you follow such a link you are on someone else's service, under their privacy policy, and we have no control over what they collect.
16Changes to this policy
We update this policy when the product or the law changes. The version and date at the top always reflect the current text. For any change that materially affects your rights or expands what we do with your data, we will give notice in the app or by email at least 15 days before it takes effect, and where the law requires consent for the new processing, we will ask for it rather than assume it.
Superseded versions are kept and can be requested at support@repzy.in.
17Contact and grievances
Rule 9 of the DPDP Rules, 2025 requires us to publish the contact details of the person who answers questions about the processing of your personal data. That person is:
Grievance Officer and Data Protection contact
Name: Ayush Kishore
Designation: Proprietor and Grievance Officer
Email: support@repzy.in
Phone: +91 73600 99598
Postal address: Mahavir Asthan, Chowk Shikarpur, Patna City, Patna, Bihar 800009, India
We acknowledge every complaint within 48 hours and aim to resolve it within 30 days.
For anything that is not a grievance — a question, a correction, a request for this notice in another language — write to support@repzy.in.
If we have not resolved your complaint to your satisfaction, you may approach the Data Protection Board of India under section 13(3) of the DPDP Act.
This policy takes effect on 16 August 2026 and replaces all earlier versions. It should be read with the Terms and Conditions.