Recore · last updated 9 October 2026
Privacy Policy
Recore is a training log. It holds what you typed and the record built from it, and nothing else. There is no advertising, no cross-app tracking, no selling of data. On its own initiative it sends three things: a crash report when it breaks, usage events that say which screens were reached and which steps were taken, and a request for bug fixes to the update server when it launches. None of them carries anything you wrote. Usage events can be turned off in You. This policy says who is responsible, exactly what is collected and why, who else sees it and where, how long it is kept, and what you can ask of us.
1. Who is responsible
The controller of your personal data — the person who decides what Recore does with it, in the sense of the General Data Protection Regulation (GDPR) — is Edis Mizic, Slovenia, publishing as Recore.
Postal address: available on request at edismizic14@gmail.com.
Email: edismizic14@gmail.com
Recore has no data-protection officer, because the law does not require one for a service of this size and kind. Write to the email address above for anything in this policy; a person reads it.
This policy covers the Recore app on iOS and the Recore website, including its waitlist. Apple, Google and the other companies named in section 6 have their own policies for what they do as independent controllers — for example, Apple for your Apple Account and your App Store purchases.
2. What stays on your device
Everything, first. Your notes are written to a database on the phone in the same instant you type them, and the app is fully usable with no connection at all. Sync is a backup of your own data to your own account, never the place the app reads from.
Some things never leave the phone at all: the plain usage counters described in section 11, the notifications the app schedules for itself (the trial reminder, the weekly recap, a rest alert, a session-close notice), the Apple Health workouts it writes, the preference that says whether usage events are shared, and the small widget on your Home or Lock Screen, which reads its numbers from the app’s own storage on the device.
Signing in as a different account wipes the local copy first. Deleting the app deletes the local copy; your account on the server stays until you delete it.
3. What we collect, why, and on what legal basis
GDPR requires a legal basis for each purpose. Recore uses three: performing the contract with you (Article 6(1)(b)) — running the app you signed up for; our legitimate interests (Article 6(1)(f)) — keeping the service running, secure, affordable and improving, weighed against your interests; and your consent (Article 6(1)(a) and, for data about your health, Article 9(2)(a)), which you give by a deliberate action in the app and can withdraw at any time. Each category below names its basis.
- Account data — contract. When you sign in with Apple or Google, we create an account and store an account identifier, your email address, and your name if the provider gives it to us. Sign in with Apple can hide your email behind a relay address; that works fine here. The provider also hands the sign-in service a few technical fields (its own identifier for you, and for Google a link to your profile picture) that Recore stores but does not use or display.
- Your training content — contract. The text of each note, exactly as typed; the sessions, exercises, sets, reps and weights read out of it; the corrections you made; your saved shorthands; your prescriptions and plan days; your saved split; and the cached pre-filled suggestion for the day, with its one-line reason, built from your own record.
- Your check-in notes — contract. The optional few words you write after a session about how it went, and the optional note you can leave on a single exercise, stored with that session, in whatever language you wrote them, exactly as typed.
- Your setup answers — contract. What you train for, how long you have trained, whether you train in a gym or for a sport, the days you usually train, your units, the movement you care about most, how you heard about Recore, and — only if you chose to enter them — your bodyweight and height. Bodyweight, if you log it over time, is kept as a dated series.
- Health-related information — consent. Some of what you choose to write may say something about your health: a bodyweight, an injury mentioned in a note, how a session felt. Recore asks for none of it, and treats it as your own words. Where it is data concerning health under GDPR Article 9, you give explicit consent to its storage and processing by entering it, and you withdraw that consent by deleting it or your account. Recore never turns any of it into a calorie target, a body score, a diagnosis, a risk, or any kind of health or medical judgement, and never uses it for advertising, marketing, insurance, employment or data-mining.
- Subscription status — contract. Which subscription you hold, whether it is active, when the trial ends and when it renews, as Apple reports it through RevenueCat. We never see or store a card number.
- Service records of each reading — legitimate interest (controlling cost, enforcing the daily limit, detecting abuse). Which language model read a note, whether its reading was the one you got, how many tokens it used and when. If your account is in a test of a new model, also how long each of two models took and the line numbers where their readings differed. It never holds note text, exercise names or any number you logged.
- Access codes — legitimate interest. If you redeem a beta or promotional code, the code, the time and whether it succeeded are recorded, so a code cannot be reused and guessing cannot be automated.
- Crash reports — legitimate interest (fixing faults). See section 12.
- Usage events — legitimate interest (improving the product from evidence), with an off switch in You that stops them at once. See section 11.
- Feedback board posts, comments, votes, reports and blocks — contract, and your own decision to publish. See section 10.
- Technical server logs — legitimate interest (security, fault-finding). Like every internet service, our database host and the content-delivery network in front of it record the network address, time, path and outcome of each request in short-lived technical logs. Recore does not add anything you wrote to them and does not use them to profile you.
- Website waitlist — consent. See section 17.
We do not collect your location, your contacts, your photos, your calendar, your Health records, your device advertising identifier, or any biometric data. We do not buy data about you from anyone, and we do not combine what you give Recore with data from other sources.
4. If you turn on Apple Health
Apple Health is off until you turn it on, in You → Apple Health, and it goes one way only.
With it on, each session you finish is added to the Health app on your iPhone as a workout: when it started, when it ended, and whether it was strength training or cardio. Nothing else. Recore does not write a calorie figure or a distance, because it cannot measure either, and it never writes a word you typed — not the note, not the check-in, not a lift name.
Recore reads nothing from Health. It does not ask for permission to read, and it holds none, so nothing in Health can change what your record says.
This happens entirely on your phone, between Recore and the Health app. It is not sent to us, it is not part of your account, it does not sync, and it is never used for advertising, marketing or any purpose other than the one you turned it on for, and never disclosed to anyone. Turning it off stops Recore adding anything new; the workouts already in Health are yours and stay there until you delete them from the Health app.
5. What leaves your device, and why
These things, all only when you are online:
- The text of a note, to read it into structure. It goes to Recore’s own server function, which forwards it to the language-model provider that returns the reading: Anthropic, or Google for the accounts Recore reads with Google’s Gemini model. With the note go your saved shorthands and the names of exercises you train, so a shorthand reads the way you taught it. The note is sent as data, Recore never writes it to a log or attaches it to an error report, and Recore does not use it to train anything.
- The numbers behind a next-session suggestion, together with up to six lines of the note they were computed from, when Recore writes the one-line reason under the suggestion in your language. The weight itself is always computed on your device by code, never chosen by a model, and the sentence that comes back is checked against those numbers before it is shown.
- The already-computed facts of your Next briefing — counts, loads, dates — when Recore rephrases them into a short paragraph. Every number in the paragraph is checked against the facts sent; if any does not match, the paragraph is discarded and the plain version is shown instead.
- Your Recore account identifier, to RevenueCat, so the app can ask whether your subscription is active. No note text, no training data and no name goes with it. This happens when you sign in, and again when you buy or restore.
- A request to Expo’s update server when the app launches, asking whether a bug fix has been published for this version: the app version, the platform, the update channel, and a random identifier that Expo’s library makes for this installation. Nothing about your account or your record goes with it.
- A crash report, to Sentry, if Recore stops working — the error, where in the code it happened, the app version, the operating system and the device model. Nothing you wrote and nothing that identifies you goes with it. See section 12.
- A post or a comment you write on the feedback board, at the moment you send it, and never before. It carries the words you typed and the name you chose, and nothing from your record goes with it — see section 10.
- Usage events, to PostHog, unless you turn them off in You → Share usage data — which screens you reached and which steps you took, under a random identifier that is not your account. Never anything you wrote, never a number you logged. See section 11.
- If you dictate a note, the audio goes to Apple’s speech recogniser built into iOS. Depending on your device and language, Apple may process it on its own servers, under Apple’s privacy policy; Recore never receives, stores or sends the audio, and keeps only the text that comes back, as a note you can edit.
Your account’s own rows also sync to your account when a connection is available. That is a copy of your data for you, on servers in the European Union, not a disclosure to anyone.
6. Who processes data for us, and where
These companies process data on our behalf as processors under GDPR Article 28, bound by contract to use it only for the service they provide to us. Each is named with what it receives, where it processes it, and — for a provider outside the European Economic Area — the safeguard that makes the transfer lawful under GDPR Chapter V.
- Supabase, Inc. — hosts the database, the sign-in service and the server functions. Everything in section 3 is stored here, in the European Union (Stockholm, Sweden), encrypted at rest and in transit. Its content-delivery network, Cloudflare, terminates connections at an edge near you and holds short-lived technical logs. Supabase and Cloudflare are United States companies; data stays in the EU, and their contracts include the European Commission’s standard contractual clauses for any support access from elsewhere.
- Cloudflare, Inc. (United States) — hosts the website and the waitlist database, in the European Union, and terminates every connection to the site at an edge near you, keeping the short-lived technical logs described in section 17. The waitlist database holds only what section 17 lists. Transfer safeguard: standard contractual clauses, and the EU–US Data Privacy Framework.
- Anthropic, PBC (United States) — processes note text, with your shorthands and exercise names, to return the structured reading described above, and the facts of a suggestion or a briefing to return one sentence or paragraph. It receives no name, email or account identifier. Under its commercial API terms Anthropic does not use this data to train its models and retains it only briefly for abuse detection and operations — at the time of writing, up to 30 days. Transfer safeguard: standard contractual clauses, and the EU–US Data Privacy Framework where Anthropic is certified.
- Google LLC (United States, with facilities worldwide) — for the accounts Recore reads with Google’s Gemini model, processes note text, with the same shorthands and exercise names, to return the same structured reading, and nothing else. It is Google’s paid Gemini API: Google does not use your notes to improve its products, keeps them only for a limited time to detect misuse of its service (at the time of writing, up to 55 days), and may process them in any country where it has facilities. It receives no name, email or account identifier. Transfer safeguard: standard contractual clauses, and the EU–US Data Privacy Framework.
- Apple Inc. — handles sign-in, every payment, dictation, notifications and Apple Health. For these Apple acts under its own terms and privacy policy, largely as an independent controller; Recore never sees your card.
- Google — if you sign in with Google, Google handles that sign-in under its own privacy policy and gives Recore your email, name and profile-picture link.
- RevenueCat, Inc. (United States) — records which subscription you hold, so the app can tell whether it is active on any device you sign in on. It receives your Recore account identifier, the purchase details Apple returns, and the basic device information its library collects (such as the iOS version and an app-scoped device identifier, never the advertising identifier). It never receives your notes, your training, your name or your email. Transfer safeguard: standard contractual clauses, and the EU–US Data Privacy Framework.
- Expo (650 Industries, Inc., United States) — serves the update check described in section 5 to every build, and, where coaching exists, delivers the notification when a coach comments. It receives the update request’s fields and, for a notification, the comment’s text, the sender’s chosen name and your device’s push token. It never receives your training, your email or your account identifier. Transfer safeguard: standard contractual clauses.
- Functional Software, Inc. (Sentry) — receives a report when the app crashes, and nothing at any other time, on its servers in the European Union (Germany). It never receives your notes, your training, your name, your email or your account identifier.
- PostHog, Inc. — receives the usage events described in section 11, and stores them in the European Union. It never receives your notes, your training, your name, your email or your account identifier.
That is the whole list. We do not sell personal data, we do not share it for advertising or cross-app tracking, and we do not give it to data brokers. We disclose it beyond this list only if the law requires it — a court order, a lawful request from an authority — or to protect someone from imminent harm, and then only what is required; or to a successor who takes over Recore and this policy, in which case the app tells you.
7. Transfers outside the European Economic Area
Your account and your record are stored in the European Union. Four processors in section 6 are in the United States and may process data there: Anthropic and Google receive note text to read it; RevenueCat receives your account identifier and purchase details; Expo receives the update request and, where coaching exists, a comment to deliver. Apple processes your Apple Account, payment and dictation under its own arrangements.
Each transfer rests on the European Commission’s standard contractual clauses in that provider’s data-processing terms, or on the EU–US Data Privacy Framework where the provider is certified under it, together with the provider’s own technical measures. Write to us for a copy of the clauses that apply.
If you are in the United Kingdom or Switzerland, the equivalent transfer mechanisms under those countries’ laws apply.
8. Security
Every row in the database is scoped to the account that owns it, enforced by the database itself, so no other user can read it — unless you deliberately link a coach, where a build has that feature, or deliberately post on the feedback board. The same scoping is mirrored on the device.
Data travels only over encrypted connections and is encrypted at rest by our database host. The keys that call the language models exist only on the server, never in the app. Every server function verifies who is calling before it does anything, and none of them writes your notes, your email or your identity to a log. Account deletion is one verified call that removes everything at once.
No system is perfectly secure. If a breach ever affects your personal data in a way that is likely to put your rights at risk, we tell the supervisory authority within 72 hours and you without undue delay, as GDPR Articles 33 and 34 require.
9. If you link a coach
Coaching is not in every release of Recore. If your app has no coach row in You, nothing in this section applies to you and nothing described here can happen to your record.
Nothing is shared with anybody until you type a coach’s invite code. Typing it is the consent — there is no other way for someone to attach themselves to your account, and you can have one coach at a time. The legal basis is your consent, and you withdraw it by ending the link.
Before you confirm, the app shows you the name the coach chose, so you know whose code it is. If you coach, the same holds the other way: anybody holding one of your invite codes sees that name before they decide, and nothing else about you.
From then on, that coach can read, for each of your sessions: the text you typed, the movements, sets, reps and weights read out of it, how hard you rated the session, your check-in note about the session, and your note on a single exercise. They also see the name you chose and when you last trained.
They can write comments on a session, and you can write back. That is the whole of what they can do: a coach can never change, delete or add anything to your record, and Recore never lets them log on your behalf. Comments are stored on our servers with the session they were written on, and are deleted with the account of the person who wrote them.
What they never see: your email address, your setup answers, your bodyweight or height, your subscription, or anything from any other coach.
Either of you can end the link at any time, from the app, without the other agreeing. Ending it stops all further access immediately. Comments already written stay readable to you — ending a link is not a way to erase what was said.
If you have a coach and notifications are on, the text of a new comment and the sender’s chosen name are handed to Expo’s push service, and by it to Apple, so it can reach your phone. That is the only thing that leaves the server for this feature, and only at the moment a comment is written. Your device’s push token is stored on our servers for this purpose and deleted with your account.
A coach is a separate controller of what they learn about you through Recore. Recore gives them access only as described here; what they do with it outside the app is governed by their own obligations to you.
10. If you post on the feedback board
You → Send feedback opens a board that every Recore account can read. Nothing appears on it until you write something and send it, and nothing is ever posted on your behalf. Your training, your notes and your numbers are not on the board and cannot be put there.
What becomes readable by every other person using Recore: the title and text you wrote, whether you filed it as an idea, a problem or a crash, the name you gave during setup, and when you posted it. The same is true of a comment you write under someone else’s post. A vote is counted, but it is never shown as yours — only you can see which posts you voted for.
The name is copied onto the post at the moment you send it, and the composer shows you which name that is beforehand. Renaming yourself later does not rewrite words people have already read, and an account with no name — or a name that reads as Recore’s own, as staff, or as “You” — posts as “Someone”. Nothing else about your account reaches the board: not your email address, not your training, not your subscription, and not your account identifier.
The composer has a switch, on unless you turn it off, that attaches your app version, your iOS version and your iPhone model to a post, and shows you exactly those three things before you send. They help match a problem to a build. They are stored with the post for Recore to read and are not shown to other people on the board.
The board lives inside the app and is readable only by signed-in Recore accounts. It is not published on the web and it is not indexed by search engines.
You can delete your own post or comment at any time, and it goes with the votes and replies attached to it. You can report a post or a comment, and you can block an author, which hides everything they have written from you. A report records which post you reported and when; a block records whom you blocked; both are visible only to you and to us. When four different people, each with an account at least three days old, report the same thing it is hidden automatically, before anyone has had to wake up and read it. A post or comment with a link, or with language the board refuses, is not accepted.
Deleting your account deletes your posts and comments with it. The cost is stated rather than hidden: the replies other people wrote under your post go too, because the alternative is leaving your words on a page everyone can read after you asked to be forgotten.
11. Usage events
Recore keeps a handful of plain counters on your phone — how far you got in setup, whether you imported a history, how many readings you corrected, whether a prescription was followed. They live in the same local database as your training and are included in your export so you can read exactly what they say. The counters themselves never leave the phone.
It also sends usage events to PostHog, so the product can be improved from evidence instead of guesses — above all, to see which setup screen people stop on. An event says that something happened: a screen was opened (by its name, such as “Progress”, never what was on it), a setup step was finished, a plan was chosen, a session was finished, a purchase succeeded or was cancelled. With it go the app version, the iOS version, which setup answer you gave to “how did you hear about Recore”, and the option you picked where a step is a choice — for example which of the lifts Recore lists you said you care about, or kilograms or pounds.
What an event never carries: a word you wrote, a note, a check-in, an exercise from your record, a weight or any other number you logged, your name, your email, your account identifier, your bodyweight or height, or anything from Apple Health.
Events are sent under a random identifier made on your phone the first time one is needed. It is not your account and cannot be traced to it. PostHog keeps no profile of you — each event stands on its own — and Recore tells it not to work out a location from the network address a request comes from. Events are held on the phone until PostHog has received them, then removed.
The legal basis is our legitimate interest in improving the product. We rely on it because the events are few, carry nothing you wrote, are not tied to your account, are stored in the EU, build no profile, and can be stopped with one switch. You have the right to object at any time, and the switch is the way to do it.
You → Share usage data turns this off at once: nothing more is recorded or sent, and events not yet sent are deleted from the phone. Deleting your account, or signing in as a different account, starts a new random identifier. The identifier your events were sent under is in your JSON export; write to edismizic14@gmail.com with it and the events already sent are erased.
12. If Recore crashes
A crash report is sent without you asking, and only when something has actually broken. Nothing is sent this way while the app is working, and how you use Recore is never measured through it — that is what usage events are, described above, and they are kept apart.
What a report contains: the error, the place in the code it came from, the app version, the operating system version and the device model.
What it does not contain: your notes, your training, your check-in notes, your name, your email, or any identifier that would let two reports be recognised as the same person. An account is never attached to a crash report.
The reports go to Sentry and to nobody else, and they are kept only for as long as it takes to fix the fault, and in any case no longer than 90 days. This build has no switch to turn them off; if that changes, the date at the top of this page changes with it.
13. Notifications and dictation
Recore asks for notification permission only when you turn on something that needs it: the trial reminder, the weekly recap, a rest alert, or coach comments where a build has coaching. Every notification except a coach comment is scheduled by the app on your phone and never passes through a server. You can turn them off in iOS Settings at any time.
Dictation uses the speech recogniser built into iOS. Recore asks for microphone and speech-recognition permission the first time you tap the microphone, and listens only while you hold the field open. The audio is handled by Apple, which may process it on its own servers depending on your device and language, under Apple’s privacy policy. Recore never receives, stores or sends the audio; it keeps only the text that comes back, as a note you can edit or delete like any other.
14. How long it is kept
- Your account, your record, your setup answers, your check-in notes, your bodyweight series and your feedback posts — until you delete them or your account. Recore does not expire accounts or quietly prune old training, because a training log with a five-year history is the point. A lapsed subscription does not shorten this.
- After you delete your account — gone from the live database immediately. Our database host keeps routine encrypted backups for disaster recovery; a deleted account drops out of them within 30 days at the latest, and a backup is never used to bring anything back for anyone but the person whose data it is.
- Subscription records — at RevenueCat, until you ask us to delete them (write to us after deleting your account and we delete the RevenueCat record too). Apple keeps its own record of your purchases under its own policy; we cannot delete that.
- Service records of each reading, and access-code attempts — up to 12 months, then deleted.
- Note text at Anthropic or Google — only for the provider’s short abuse-detection window named in section 6; never used for training.
- Crash reports — until the fault is fixed, and no longer than 90 days.
- Usage events — up to 12 months, then deleted; sooner if you send us your identifier.
- Technical server logs — no longer than 30 days.
- Push tokens (where coaching exists) — until you turn notifications off, end the link, or delete your account.
- Website waitlist — until the launch email is sent and 30 days have passed, or until you ask, whichever is earlier.
- Correspondence with us — for as long as needed to answer you and to keep a record of what was agreed, then no longer than three years, unless the law requires longer.
15. Your rights
Under GDPR and the laws that follow it, you have the right to:
- access the personal data we hold about you, and get a copy — the app itself is the access interface, every stored word is on screen, and the JSON export is the copy;
- have it corrected — edit it in the app, or write to us;
- have it erased — You → Delete account does this immediately, for everything, and the account is not recoverable afterwards;
- restrict or object to processing based on our legitimate interests — the usage-events switch is the objection for that purpose; for anything else, write to us;
- data portability — the JSON and CSV exports are your data in a structured, commonly used, machine-readable format, free, at any time, including after a subscription ends;
- withdraw consent at any time, for anything that rests on it — delete the bodyweight, end the coaching link, delete the waitlist entry — without affecting what was done before;
- not be subject to a decision based solely on automated processing that has legal or similarly significant effects on you — Recore makes none; see the next section;
- lodge a complaint with a supervisory authority.
For anything the app cannot do for you, write to edismizic14@gmail.com. We answer within one month, and sooner where we can; a complex request may take up to two further months, in which case we tell you why. We may ask you to confirm that the account is yours — normally by writing from the email address on it. Exercising a right costs nothing.
The supervisory authority for Recore is the Information Commissioner of the Republic of Slovenia (Informacijski pooblaščenec), Dunajska cesta 22, 1000 Ljubljana, Slovenia, gp.ip@ip-rs.si:
You may also complain to the authority of the country where you live or work. We would rather hear from you first, but you do not have to.
If you live outside the European Economic Area, we give you the same rights, and the same answer. Residents of the United Kingdom have these rights under the UK GDPR; residents of California and other US states with privacy laws have the rights to know, delete, correct and port their data, and the right not to be discriminated against for using them — and, for the avoidance of doubt, we do not sell or share personal information as those laws define it.
16. Automated decisions and profiling
Recore makes no decision about you by automated means that has a legal effect or a similarly significant effect. A suggested load is arithmetic over your own sets, shown as a suggestion for you to take or ignore; a reading of a note is a transcription you can correct; a Next briefing is a restatement of your own record. None of it changes your price, your access, or your rights, and none of it is a judgement about you.
We build no profile of you for advertising or for any other purpose. The usage events are personless by design, and your record is never analysed across users.
17. The website and the waitlist
The Recore website sets no cookies, runs no analytics, loads nothing from an advertising network, and uses no social-media buttons or embedded trackers. The pages are static files; what the hosting provider records is the ordinary technical log of each request — network address, time, page — kept for security for no longer than 30 days.
If you leave your email address on the waitlist, we store it, together with which form on the page you used and when, in a database at Cloudflare in the European Union that only the website’s own form can write to, and that only we can read. We use it for one purpose: to send you one email on the day Recore opens. We do not add you to a newsletter, we do not share the address, and we do not send anything else. The legal basis is your consent, given by submitting the form.
To be removed, write to edismizic14@gmail.com from that address, and it is deleted. It is deleted in any case within 30 days of the launch email.
These legal pages are hosted on the website. Reading them sends nothing to us beyond the technical log above.
18. Children
Recore is for adults. It is not directed at anyone under 18, we do not knowingly create accounts for anyone under 18, and we do not knowingly collect personal data from a child. If you believe a child has an account, write to us and we delete it.
19. Changes to this policy
If this policy changes in a way that affects what leaves your device, who receives it, or how long it is kept, the app says so before the change takes effect, and where the change rests on consent we ask for it again. The date at the top tells you which version you are reading, and earlier versions are available from us on request.
A change that only adds detail, corrects wording, or reflects a change in the law may take effect when it is published.
20. Contact
Recore is published by Edis Mizic, Slovenia.
Postal address: available on request at edismizic14@gmail.com.
Email: edismizic14@gmail.com
Effective: 9 October 2026.