Your privacy, our priority.
This policy explains what data Remi collects, why we collect it, how long we keep it, and the choices you have.
Last updated: May 7, 2026
Your privacy matters. We collect only what we need to make Remi work for you, never sell personal data, and give you full control over deletion at any time.
Information We Collect
Personal information
We collect information you provide directly:
- Account: name, email, nickname, profile photo and fitness goals. Sign-in uses a short-lived one-time code (OTP) sent to your email β we do not store passwords.
- Activity content: workouts, sets, reps, weights, and (for endurance workouts) GPS coordinates of your route, distance and pace.
- Photos and videos you upload: profile and team avatars, posts in the community feed, set-completion videos, progress images and bug-report screenshots.
- Community content: chat messages between users, captions, comments and likes on feed posts, team membership and team profile.
- Trainer verification (optional): CREF registration number and document image, only for users who choose to verify as trainers.
Automatically collected
- Device: model, OS version, language, time zone.
- Push notification token (only if you enable notifications) so we can deliver in-app notifications to your device.
- Usage: features used, screens viewed, session duration.
- Logs: IP address, error and crash reports collected by our backend.
- Location (only when you grant permission and only during an active endurance workout): GPS coordinates used to calculate route, distance and pace. Remi does not track your location in the background.
How We Use Your Information
- Service: deliver, maintain and improve the app and its features.
- Personalization: tailor your routines, missions and progress views.
- Communication: respond to support requests and send essential service updates.
- Security: detect abuse, protect accounts, and enforce our Terms.
- Analytics: understand aggregate usage to improve the product.
- Legal: comply with applicable laws and lawful requests.
Data Security
We apply appropriate technical and organizational safeguards, including:
- Encryption in transit (TLS) and at rest for sensitive fields.
- Access controls and least-privilege authentication.
- Authentication via short-lived one-time codes (OTP) sent to your email β Remi does not store passwords.
- Regular security reviews of dependencies and infrastructure.
No system is 100% secure. If we ever detect a breach affecting your data, we will notify you as required by law.
Data Retention
We keep your information only for as long as we need it. The specific periods we apply:
| Data type | Retention period |
|---|---|
| Account profile (name, email, nickname, photo) | While your account is active; deleted within 30 days of account deletion |
| Workout, activity and progress history | Lifetime of the account, so you can review your full history |
| Uploaded photos and videos | Until you delete them, or 30 days after account deletion |
| Endurance workout GPS routes | Lifetime of the account; deleted with the workout or account |
| Chat messages | Lifetime of the account; deleted within 30 days of account deletion (messages remain visible to other participants until they delete their copy) |
| Feed posts, comments and likes | Lifetime of the account; deleted within 30 days of account deletion |
| Push notification tokens | Until you revoke notifications or uninstall the app; deleted within 30 days of account deletion |
| One-time login codes (OTP) | Up to 15 minutes; deleted as soon as used or expired |
| Server and access logs | Up to 90 days |
| Encrypted backups | Purged within 90 days of the source data being deleted |
You can request earlier deletion at any time from the app's account settings or by contacting us at the address below. We may retain limited information when required to comply with legal obligations, resolve disputes, or enforce our agreements.
Your Rights & Choices
Depending on where you live (e.g., LGPD in Brazil, GDPR in the EU/UK, or applicable U.S. state laws), you have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Delete your account and associated data.
- Export a copy of your data in a portable format.
- Object to or restrict certain processing.
- Withdraw consent for permissions like location, camera or photo access at any time in your device settings.
Third-Party Services
Remi integrates with a limited set of trusted providers to deliver core functionality. Each is contractually required to protect your data:
- Cloud hosting and database infrastructure (Railway).
- Email delivery for one-time login codes.
- Push notification delivery (Apple Push, Google FCM, Expo).
Remi does not currently use third-party analytics or crash-reporting providers in the app. If that changes, we will update this policy and notify you in-app. When you follow a link from Remi to a third-party site, that site's privacy policy applies β not ours.
Children's Privacy
Remi is not intended for children under 13 (or the minimum age in your jurisdiction). We do not knowingly collect data from children. If you believe a child has provided us with personal data, please contact us and we will delete it.
International Data Transfers
Your information may be processed in countries other than the one you live in. When we transfer data internationally, we use safeguards consistent with applicable law, such as standard contractual clauses.
Changes to This Policy
We may update this policy as Remi evolves. When changes are material, we will notify you in the app or by email and update the "Last updated" date above. Continued use after the effective date means you accept the revised policy.
Questions about your data?
Reach out and we'll respond within a reasonable timeframe.
renan@remifitness.com