Repzy Terms

Legal

Privacy Policy

This policy explains what personal data Repzy handles, why we handle it, who else has access to it, how long we keep it, and how you have it deleted. It is written to meet the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025, and Google Play's User Data policy.

Last updated 16 August 2026 · Version 2.0
On this page
  1. Who this covers
  2. Who is responsible for what
  3. Data we handle
  4. Why we handle it
  5. Consent and withdrawal
  6. Who we share it with
  7. Where data is stored
  8. How long we keep it
  9. Delete your account
  10. Your rights
  11. If you are a gym member
  12. Under 18
  13. Security
  14. Data breaches
  15. Website and cookies
  16. Changes
  17. Contact and grievances

The short version

  • We do not sell personal data, and we do not run advertising inside Repzy.
  • A gym owner's account data is handled by us as a Data Fiduciary. Member records that a gym enters are handled by us as a Data Processor for that gym — the gym decides what goes in and what comes out.
  • We never see or store card, UPI or netbanking credentials. Subscription payments run through Google Play.
  • You can delete your account and its data from inside the app, or by writing to us. Deletion means deletion, not deactivation.
  • Fitness and diet entries are treated as sensitive. They are never used for advertising or profiling.

This summary is for orientation only. The numbered sections below are the operative policy.

01Who this policy covers

This Privacy Policy is issued by Repzy, a sole proprietorship of Ayush Kishore, registered under the Udyam scheme registered at Mahavir Asthan, Chowk Shikarpur, Patna City, Patna, Bihar 800009, India ("Repzy", "we", "us"). It applies to:

  • the Repzy Android application published on Google Play;
  • the website at repzy.in and our internal administrative tools;
  • support we provide over email, phone or WhatsApp.

It applies to two different kinds of people, and the difference matters throughout this document:

  • Gym operators — owners and their staff, who register with us and run a gym on Repzy.
  • Gym members — the people whose records a gym operator keeps in Repzy, whether or not they log in themselves.

Where this policy says "you" without qualification, it means whichever of the two is reading it.

02Who is responsible for what

Under the Digital Personal Data Protection Act, 2023 ("DPDP Act"), the party that decides the purpose and means of processing is the Data Fiduciary. The party that processes on its behalf is the Data Processor. Repzy occupies both roles, in different places.

DataData FiduciaryRepzy's role
Gym operator's own account: name, phone, email, gym name and address, login credentials, subscription status, support history Repzy Data Fiduciary. We decide why this is collected and we answer to you directly for it.
Member records created by a gym: member name, contact details, plan, fees, attendance, photographs, fitness and diet entries The gym operator Data Processor. We store and process it under the gym's instructions and do not use it for our own purposes.
Technical and diagnostic data: device model, operating system, app version, crash reports, security logs Repzy Data Fiduciary. Used to keep the service working and secure.
What this means in practice

If you are a gym member and you want your record corrected or erased, your gym is the first place to ask, because the gym controls that record. We will help the gym act on your request, and we will act directly if the gym does not — see section 11.

03Data we handle

We collect only what the product needs to work. We do not buy personal data from third parties and we do not enrich your records from outside sources.

3.1 Given to us by a gym operator

CategoryExamplesSource
Identity and contactName, mobile number, email address, gym name, gym addressYou, at registration
Account and accessLogin ID, password stored as a one-way hash, staff accounts you create, roles and permissionsYou, in the app
Member recordsMember name, mobile number, address, member ID, joining date, plan, plan expiry, membership status, member photograph if you upload oneEntered by you or your staff
Operational recordsAttendance, fee receipts, dues, expenses, notes you addEntered by you or your staff
Fitness and diet entriesFood logged against a meal, calorie totals, and any body measurement fields you choose to recordEntered by you, your staff, or the member

3.2 Collected automatically

CategoryExamplesPurpose
Device and appDevice model, Android version, app version, language, time zone, coarse network typeCompatibility, delivering the right update
DiagnosticsCrash reports and error traces, including the screen where a failure occurred and an internal account identifierFixing faults
Security logsIP address, timestamps, login attempts, administrative actionsDetecting misuse, meeting Rule 6 of the DPDP Rules, 2025
Push tokenThe notification token issued to your device by Google or ExpoSending you app notifications
Purchase stateGoogle Play purchase token, order identifier, product identifier, subscription start, renewal and expiryTurning paid features on and off

3.3 What we do not collect

  • No payment credentials. Card numbers, UPI IDs, CVVs and netbanking passwords never reach our servers. Google Play processes subscription payments and returns only the purchase state listed above.
  • No advertising identifiers. Repzy contains no advertising SDK and does not use the Android Advertising ID.
  • No background location tracking. Repzy does not track your position when the app is closed.
  • No selling or renting of data, ever, to anyone, in any form, including in aggregate.
Permissions

The app asks for device permissions only at the moment the corresponding feature is used — for example, camera or gallery access when you attach a member photograph, and notification permission when you enable reminders. Declining a permission disables only that feature; the rest of the app continues to work. The current permission list for the installed version is shown on the Repzy listing on Google Play under App permissions.

04Why we handle it, and on what legal footing

Section 4 of the DPDP Act permits processing of personal data only for a lawful purpose, and only either with consent or for a "certain legitimate use" under section 7. Our purposes and their footing:

PurposeFooting
Creating and running your account, and providing the features you asked forConsent given at registration, and performance of our contract with you
Storing and displaying member records on your behalfProcessing on documented instructions of the gym, which is the Data Fiduciary for those records
Billing, subscription state, invoices and tax recordsLegal obligation and contract
Service notifications — expiry reminders, receipts, security alertsConsent, and legitimate use for the purpose for which you voluntarily provided the data
Fixing crashes, preventing abuse, protecting accountsLegitimate use under section 7, and our obligation to maintain reasonable security safeguards
Responding to a lawful order of a court or a competent authorityCompliance with law
Product announcements and marketing messagesSeparate, optional consent that you can withdraw without losing access to the product

We do not use member records, fitness entries or diet entries for advertising, for profiling, or for training any model. If we ever want to use data for a genuinely new purpose, we will ask for fresh consent first.

06Who we share it with

We share personal data only with the service providers listed below, each engaged under a contract that limits them to processing on our instructions and requires them to protect the data. This list is complete as of the date at the top of this page.

ProviderWhat it does for RepzyData it can see
MongoDB Atlas (MongoDB, Inc.)Managed database hostingAll application data, encrypted at rest
Railway Corp.Backend application hostingApplication data in transit and in memory during processing
Hostinger International Ltd.Website and admin panel hostingWebsite request logs
Google LLC — Google Play BillingSubscription purchase, renewal and cancellationPurchase token, order ID, subscription state. Your payment instrument stays with Google.
Google LLC — Firebase Cloud Messaging, and Expo (650 Industries, Inc.)Delivering push notifications and over-the-air app updatesPush token, device and app version metadata
Functional Software, Inc. d/b/a SentryCrash and error reportingDevice model, OS, app version, stack traces, internal account identifier
WhatsApp (Meta Platforms)Support conversations, only if you choose to message us thereYour WhatsApp number and the content of your messages, governed by WhatsApp's own policy

Beyond that list, we disclose personal data only:

  • to a court, regulator, law enforcement agency or other authority, when compelled by law, and after satisfying ourselves that the demand is lawful and proportionate;
  • to our professional advisers, under a duty of confidentiality, where necessary for legal or accounting purposes;
  • to an acquirer, in a merger, acquisition or transfer of business — in which case we will give you notice before your data becomes subject to a different privacy policy, and this policy will continue to apply until then.

07Where data is stored, and transfers outside India

Repzy's backend runs on Railway in the US West (California, USA) region, and the database is hosted on managed MongoDB Atlas infrastructure. Crash reporting, push notification delivery and payment processing are also handled by providers that operate outside India. Your data is therefore stored and processed outside India.

Section 16 of the DPDP Act permits transfers outside India except to territories that the Central Government restricts by notification, and Rule 15 of the DPDP Rules, 2025 governs the conditions. We monitor those notifications and will change providers or regions if a provider's location becomes restricted. Wherever data goes, our contractual and security obligations under this policy follow it.

08How long we keep it

We keep personal data only as long as the purpose it was collected for still exists, or as long as a law requires — whichever is longer. Concretely:

DataKept for
Gym operator account and member recordsWhile the account is active. Erased on deletion, per section 9.
Records after a deletion requestRemoved from live systems within 30 days; purged from encrypted backups within 90 days.
Financial and tax records — invoices, subscription payments, GST recordsAs long as Indian tax and company law requires us to retain books of account, currently up to eight financial years.
Security and access logsOne year, the minimum period under Rule 6 of the DPDP Rules, 2025.
Crash and error reports90 days, after which Sentry deletes them automatically.
Support correspondenceThree years from the last message, so we can evidence what was asked and answered.

Where Rule 8 of the DPDP Rules, 2025 requires it, we will give you at least 48 hours' notice before erasing data on account of inactivity, so that you have a chance to log in and keep the account alive.

09Deleting your account and your data

You can delete your Repzy account and the data in it. Deletion is real deletion. Deactivating, disabling or freezing an account is not deletion, and we do not treat it as such.

How to delete

  • In the app: Profile → Settings → Delete account. Confirm when prompted.
  • On the web: use the request form at repzy.in/delete-account.html.
  • By email: write to support@repzy.in from the email address or with the mobile number registered on the account.

What happens next

  • We verify that the request comes from the account holder. We may ask you to confirm a one-time code sent to the registered number or email. We do not ask for identity documents for a routine deletion.
  • Deleting a gym operator account deletes the gym's member records, attendance, fee history, expense entries and fitness entries stored under that gym. This cannot be undone, so export what you need first.
  • Live systems are cleared within 30 days of verification. Encrypted backups roll off within 90 days.
  • We retain only what law requires — chiefly invoices and payment records for the statutory period — plus the minimum needed to prevent fraud and abuse. Retained records are locked down and are not used for any other purpose.
Before you delete

A Repzy subscription bought through Google Play is not cancelled by deleting your account. Cancel it in the Play Store under Payments and subscriptions → Subscriptions, or it will keep renewing. See section 7 of the Terms.

Request deletion

10Your rights

Under Chapter III of the DPDP Act you have the following rights, and we do not charge for exercising any of them:

  • Access — a summary of the personal data we process about you, what we do with it, and the identities of the other Data Fiduciaries and Processors it has been shared with.
  • Correction, completion and updating — of data that is inaccurate, incomplete or out of date.
  • Erasure — of data we no longer need for the purpose it was collected for, unless retention is required by law.
  • Grievance redressal — a readily available means of raising a complaint with us, before you approach the Data Protection Board.
  • Nomination — you may nominate another individual to exercise these rights on your behalf in the event of your death or incapacity. Write to us to record a nomination.

How to exercise them

Email support@repzy.in from your registered address, or write to the grievance officer in section 17. Tell us what you want and give us enough detail to find your account. Our commitments:

  • acknowledgement within 48 hours;
  • resolution within 30 days in the ordinary course, and in no case later than 90 days;
  • if we refuse, a written reason, and the route to escalate.

You also have duties under section 15 of the DPDP Act — most relevantly, not to impersonate another person when exercising a right, and not to file a false or frivolous complaint.

If you are not satisfied with our response, you may complain to the Data Protection Board of India, which is constituted and accepting complaints.

11If you are a gym member

Your gym decided to keep your record in Repzy. That makes your gym the Data Fiduciary for it and Repzy the Processor. In plain terms: the gym chose what to record about you, and the gym is accountable for having your consent.

  • Ask your gym first for access, correction or erasure of your record. They can do all three from inside the app.
  • If your gym does not respond within a reasonable period, write to us at support@repzy.in. We will contact the gym, and if the request remains unanswered we will act on it ourselves.
  • Fee and attendance records may be retained by your gym for its own accounting and legal reasons even after you leave. That decision is the gym's, not ours.
  • Your fitness and diet entries are visible to your gym's owner and to the staff the owner has authorised. They are not visible to other members.
  • If you have a member login, you may delete your own login and the data attached to it — see section 9. Deleting your login does not delete the gym's own commercial records of your membership.

12Members and users under 18

The DPDP Act treats every individual below 18 as a child, which is a wider net than most foreign privacy laws. Section 9 of the Act and Rule 10 of the DPDP Rules, 2025 require verifiable consent from a parent or lawful guardian before a child's personal data is processed, and prohibit tracking, behavioural monitoring and targeted advertising directed at children.

  • Repzy accounts are for adults. A gym operator or staff account may only be created by a person aged 18 or over.
  • Gyms very often have members under 18. Where a gym records such a member in Repzy, the gym is the Data Fiduciary and is responsible for obtaining and holding verifiable consent from the member's parent or guardian, in a form that can be produced if questioned. The Terms make this a contractual obligation of the gym.
  • We do not profile children, do not run behavioural analytics on them, and show no advertising to anyone. Repzy carries no advertising at all.
  • If a parent or guardian tells us that a child's data is in Repzy without their verifiable consent, write to support@repzy.in. We will notify the gym and, if valid consent cannot be shown, erase the record.

The same protections apply to an individual with a disability who has a lawful guardian.

13Security

Section 8(5) of the DPDP Act requires reasonable security safeguards, and Rule 6 sets out what they look like. The measures we maintain:

  • traffic between the app and our servers is encrypted in transit with TLS;
  • the database is encrypted at rest by our hosting provider;
  • passwords are stored only as one-way hashes, never in a readable form;
  • access to production systems is limited to named individuals, protected by separate credentials, and reviewed after any personnel change;
  • credentials are rotated on a schedule and immediately on any suspicion of exposure;
  • logs of access and administrative action are retained for one year to allow detection and investigation;
  • member data is separated by gym, so one gym cannot read another's records;
  • our processors are bound by contract to equivalent safeguards.

No system is perfectly secure, and we do not claim otherwise. What we do claim is that we treat a breach as an emergency and that the measures above are actually in place, not aspirational.

If you believe you have found a vulnerability, report it to support@repzy.in. We will not pursue action against anyone who reports a genuine issue in good faith, does not access more data than necessary to demonstrate it, and gives us a reasonable opportunity to fix it before disclosure.

14If there is a data breach

Rule 7 of the DPDP Rules, 2025 sets the drill, and we follow it:

  • every affected person is informed without delay, in plain language, describing the nature and extent of the breach, when it happened, its likely consequences, what we have done about it, and what they should do;
  • the Data Protection Board of India is informed without delay, with fuller particulars — including the events leading up to the breach, mitigation measures and remedial action — provided within 72 hours;
  • if the breach touches member records, we inform the affected gym so that it can meet its own obligations to its members.

We will not delay notification to protect our reputation.

15Website, cookies and links

repzy.in uses only cookies and local storage that are strictly necessary to serve the site and keep an administrative session logged in. We do not use Google Analytics, any other third-party analytics service, or any advertising cookie on repzy.in. The usage figures we see internally are generated from your app activity described in section 3, not from website tracking. If we later add analytics or any cookie that is not strictly necessary, we will ask for your consent first and update this policy.

The site links out to Google Play, and offers a WhatsApp contact button. Once you follow such a link you are on someone else's service, under their privacy policy, and we have no control over what they collect.

16Changes to this policy

We update this policy when the product or the law changes. The version and date at the top always reflect the current text. For any change that materially affects your rights or expands what we do with your data, we will give notice in the app or by email at least 15 days before it takes effect, and where the law requires consent for the new processing, we will ask for it rather than assume it.

Superseded versions are kept and can be requested at support@repzy.in.

17Contact and grievances

Rule 9 of the DPDP Rules, 2025 requires us to publish the contact details of the person who answers questions about the processing of your personal data. That person is:

Grievance Officer and Data Protection contact

Name: Ayush Kishore
Designation: Proprietor and Grievance Officer
Email: support@repzy.in
Phone: +91 73600 99598
Postal address: Mahavir Asthan, Chowk Shikarpur, Patna City, Patna, Bihar 800009, India

We acknowledge every complaint within 48 hours and aim to resolve it within 30 days.

For anything that is not a grievance — a question, a correction, a request for this notice in another language — write to support@repzy.in.

If we have not resolved your complaint to your satisfaction, you may approach the Data Protection Board of India under section 13(3) of the DPDP Act.

This policy takes effect on 16 August 2026 and replaces all earlier versions. It should be read with the Terms and Conditions.