Privacy policy
RACK is a strength and running training app. This policy explains what we collect, why we collect it, who we share it with, and the rights you have over your information.
Who we are
RACK is operated by SABLE HOUSE LTD, registered in England and Wales (company number 17398195), with its registered office at Flat 68 Hudson House, Station Approach, Epsom, KT19 8DL. In this policy, "we", "us" and "our" refer to that entity. We are the data controller for personal data processed through the RACK app and this website.
You can contact us at privacy@joinrack.app about anything in this policy.
What we collect
Beta and Android waitlist
The beta link on this site sends you to Apple's beta install flow, which Apple handles under its own terms and privacy notices.
If you join the Android waitlist, we collect the email address you submit and the time you submitted it. We use it only to send you a notification when RACK is ready for Android, plus any essential follow-up about that notice — not a general marketing newsletter. Supabase stores the waitlist for us in its hosted Postgres service. To limit automated abuse, we also keep a salted, one-way hash of the request's network address for roughly 24 hours. An hourly cleanup deletes hashes once they are more than 24 hours old; we do not store the raw address in the waitlist.
RACK Journal newsletter
If you ask to join the RACK Journal, we collect the email address you submit, the time of the request and confirmation, and the current consent wording version. We send a confirmation link first and do not add the address to the Journal audience until that link is used. Confirmation links expire after 24 hours. As with the Android waitlist, a salted, one-way hash of the request's network address is retained for roughly 24 hours to limit automated abuse; the raw address is not stored.
Resend delivers the confirmation and new Journal pieces for us. Every Journal email identifies RACK and includes a one-click unsubscribe link. Resend keeps the suppression needed to prevent further marketing email after an unsubscribe. You can also withdraw consent by emailing privacy@joinrack.app.
Creator partnerships and outreach
We research potential creator partners using official platform APIs and authorised creator marketplaces, including the YouTube Data API, Instagram Creator Marketplace and TikTok One, together with public professional profiles and information a creator sends us directly. We may collect a creator's name, handle, profile URL and platform identifier; public bio, content category and audience, reach or engagement metrics; business contact details and their source; and our shortlist, review, outreach, opt-out, campaign, referral and subscriber-performance records. We do not intentionally collect special-category data for this work or infer sensitive traits from a creator's content.
We use this information to identify and assess suitable partners, manage contact and agreements, avoid repeat contact, honour objections, and measure creator campaigns and referrals. When we obtain personal data indirectly, we provide this privacy information in our first outreach or within one month, whichever happens first. Every marketing email includes a way to opt out, and we stop marketing to that address when asked.
Refer & Earn programme
If you take part in the cash-referral pilot, we process the payee identity and RACK account link; UK-residence and adult-eligibility status; accepted terms version and time; permanent referral code and attribution records; aggregate referral counts; and earnings, corrections, balance, payout and payment-reference records. The finance record may also include an eligibility or finance-hold status, a masked bank destination, evidence digests used for operator review, and annual tax-year statement totals.
Full bank details must not be submitted to or stored in RACK, Supabase, app logs, analytics or support tickets. RACK stores only the approved masked destination needed to identify the intended account during an independently reviewed payout. Member reporting is aggregate and paying referral counts below three are suppressed.
A participant can request their whole available balance once it reaches the stated threshold. An approved payout is made outside the app as a manual GBP bank transfer after independent review. Refer & Earn does not provide a separate subscription checkout, payment service or external purchase path.
For App Store review, we may issue Apple a time-limited, one-account reviewer token. The app temporarily retains the entered token on-device until successful validation or the reviewer clears it; our server stores only its one-way digest, its active window and operator evidence, and binds a successful use to the reviewer's RACK account and a one-way digest of Apple's Sandbox App Transaction. The reviewer view uses fixed synthetic referral and payout data, collects no bank or payment details, and is disabled when the window expires or an operator revokes it. We may retain the hashed admission and audit evidence for security, fraud-prevention and review accountability under the same approved retention controls described below. When the approved term expires and no hold or active review access remains, the same dual-controlled disposition process removes that reviewer App Transaction digest and retains only a receipt-linked one-way audit hash.
Account information
When you create an account we collect the email address (and, where you provide one, name) you sign up with. If you use Sign in with Apple, we receive the identifier and email relay address that Apple supplies — we do not see your underlying Apple ID. Your training profile can also include body weight, gender, training experience, an optional birthday, and an optional maximum heart rate. We use these inputs for programme generation, strength standards, workout analysis and achievements; your birthday is not shown to other users.
Training data
Sessions you log — exercises, sets, reps, weights, RPE, notes, body-weight entries, programme progress — are stored against your account so you can retrieve them on any device you sign in on.
RACK Coach
When you use RACK Coach, we send OpenAI the message and any image you provide, relevant earlier conversation context, your configured Coach style, and the RACK data Coach retrieves to answer you. In a private Coach chat, that retrieved data can include your account profile, programme, readiness and training history. If you tag @coach in a feed comment, Coach receives the published post, the relevant comment thread and attached images visible to that post's audience. The public comment surface is not given access to private Coach conversations, saved memories, profile or body-weight data, readiness, private programme state or private training history.
Social features
If you use RACK's social features, we also process:
- Your connections — the friend requests you send and accept, and the people you block.
- Content you share — posts you publish to your feed, their captions, any photo you choose to attach to a cardio post, and the workouts or cardio sessions you share. Your profile — display name, avatar, and training stats — is visible to people you connect with and others who view it in the app.
- Interactions — likes and similar reactions to other people's posts, and any report you submit about another user.
- Notifications — if you allow notifications while signed in, RACK sends the Apple Push Notification service (APNs) device token and its sandbox or production environment to our Supabase service and associates it with the current RACK account. One physical token is claimed by one RACK account at a time. You can turn notifications off at any time in iOS Settings.
- Planning a session together — the host creates a short-lived code or QR and RACK sends the code through its Supabase-hosted Friends service. The room stores the host and participant account identifiers plus a bounded message log containing the roster, host nominations, ordered exercise identifiers, day and split keys, shared-exercise overlaps, and the host's start signal. Room participants can read that roster and message log. Only an existing accepted friend who is not blocked in either direction can join or read a room; joining does not create or change a friendship. Rooms stop being accessible about ten minutes after creation; expired room rows are deleted when a later room creation runs the cleanup. RACK does not use GPS for this feature. If you scan a QR, the camera image is not recorded or stored, but the code read from it is sent to the service.
- GIPHY comments — if the optional GIF picker is available and you use it, GIPHY receives your GIF search terms and view, selection and send interactions through its iOS SDK. RACK does not send GIPHY your RACK account identifier. When you post a GIF, RACK stores the GIPHY media identifier and bounded display details with the comment so other viewers can resolve it through GIPHY.
Before an ordinary sign-out or account deletion, RACK records a device-local revocation intent, attempts to remove that exact token from the signed-in account while its session is still valid, and asks iOS to unregister the app for remote notifications. If the device is offline or Apple or the network has not yet propagated the change, the server association or delivery state may not change immediately and a notification already in flight may still arrive. RACK retries a pending server deletion if the same account returns, transfers the physical token to a later account when that account successfully claims it, removes tokens APNs reports as invalid, and deletes token rows with the account. We cannot promise an exact platform propagation time.
Purchase information
Subscriptions and one-off purchases are processed by Apple through the App Store. We receive transaction identifiers and entitlement state so we can unlock features. For referral-offer preparation and abuse prevention, we also receive Apple's pseudonymous App Transaction ID. Apple keeps that ID stable for the same Apple Account and app across devices and redownloads; it is not your full Apple ID. We bind it to the RACK subscription subject that first presents verified Apple evidence so another RACK account cannot reuse that identity to reserve or consume one-time offer inventory. RACK stores a one-way cryptographic digest in the dedicated anti-abuse binding used for this comparison. RACK also keeps Apple-signed purchase and server- notification evidence in its access-controlled subscription audit records so it can reconcile entitlements and investigate refunds or disputes. Those signed payloads may contain the pseudonymous App Transaction ID. We do not see your card details or billing address.
Subscription purchase and referral-offer redemption use Apple's in-app purchase system only; RACK has no external subscription checkout or link to one. If Apple confirms eligibility and offer availability, an eligible new subscriber starts with one introductory month free. Monthly subscribers can then redeem 10% off the next 12 monthly subscription periods, while annual subscribers can redeem 10% off the first annual subscription period. Apple's purchase sheet shows the authoritative offer and renewal terms. Saving or sharing a RACK referral code alone does not apply or promise an Apple offer.
Usage information
We collect information about how the app and this website are used — pages and screens viewed, taps, approximate region inferred from IP, device type, and app version. RACK does not record session replays. App usage is linked to a random account identifier rather than your name or email, and is analysed in aggregate to understand where people get stuck.
Support correspondence
If you email us or use the in-app feedback form, we keep your message and our reply so we can follow up and improve the product. In-app feedback also carries its category, app/build version, a random report identifier, and any diagnostic screenshot you choose to attach (including a screenshot prefilled after the two-shake feedback gesture). We copy the message, category, app/build version and random report identifier, together with your public RACK handle when you have set one, to our private Discord support channel so authorised operators can identify the conversation, investigate and reply. If you attach diagnostic screenshots, we also upload copies to that private support channel so they are visible with the report. We do not send Discord your RACK account identifier, email address, programme identifier, screenshot storage path or screenshot URL. The originals remain in private app storage and are not part of your social feed.
Apple Health (opt-in)
RACK's use of Apple Health is opt-in and limited to the workout-related categories described below — we do not request access to your broader Health history. Apple controls HealthKit authorization for the app on the device. RACK separately records the current consent version and feature preferences against the RACK account using that installation. A second RACK account on the same device does not inherit the first account's RACK import, auto-detect or workout-export choices and must make its own choice, even if iOS still holds an app-level HealthKit grant.
When you choose to connect Apple Health, RACK makes one combined request to read workouts, workout routes, walking/running, cycling and swimming distance, heart rate, active energy, step count and, on supported systems, running power; and to write workouts and active energy. Apple lets you decide which requested categories to allow. Apple does not reveal denied read categories to apps, so RACK does not treat the request as proof that every read was granted: unavailable or denied values simply are not imported. You can turn the RACK features off in your profile and change Apple Health access through Apple's Health or Settings controls.
- Writing strength workouts. If the current RACK account enables Apple Health recording and Apple grants write access, RACK writes completed strength workout summaries and, where permitted, their active-energy sample to Apple Health. You do not need a separate Apple Workout session — when recording is enabled, RACK's own session is written for you.
- Importing cardio workouts. If you enable cardio import, RACK reads outdoor cardio workouts you logged in Apple's Workout app (or a connected device) — duration, distance, pace, and, where recorded, the GPS route. This data is stored in RACK so it can sync across your devices, appear in your training history, and, if you choose to share that session, be shown to people you share it with (including the route on a map).
- Workout analysis. Where available for an imported workout, RACK reads heart rate, active energy, step count and running power to calculate and display workout analysis such as heart-rate summaries and cadence. Imported values and derived analysis are stored against your RACK account so they can sync across your devices.
Why we use it
- To provide the service — your account, your training history, your subscription entitlements.
- To provide RACK Coach — generating a response from your request and the relevant RACK context described above.
- To run RACK's social features — showing your posts and profile to the people you share them with, delivering friend requests and notifications, and keeping the community safe through reporting and blocking.
- To support you — answering questions, investigating bugs, recovering data on request.
- To notify Android waitlist members — sending the Android availability notice they requested.
- To send the RACK Journal — after double opt-in, sending newly published Journal pieces and recording delivery so an issue is not repeated.
- To run creator partnerships — finding and assessing potential partners, managing proportionate outreach and agreements, and measuring creator-attributed campaigns and subscriptions.
- To run Refer & Earn — checking eligibility and attribution, calculating and correcting earnings, reviewing payout requests, making approved payments and preparing tax-year records.
- To improve the product — understanding which features get used, where people get stuck, what to build next.
- To prevent abuse — detecting fraud, automated sign-ups, and breaches of our terms.
- To meet our legal obligations — tax, accounting, and responding to lawful requests.
Legal bases
Under UK GDPR we rely on the following legal bases:
- Contract — to deliver the service you signed up for.
- Legitimate interests — to keep the service secure, prevent abuse, improve it, and identify and contact suitable business creator partners where the Privacy and Electronic Communications Regulations permit. We balance these interests against your rights, limit the data and contact used, and honour objections. Where those regulations require consent for electronic marketing, we do not send it without consent.
- Consent — for the Android launch notification, the RACK Journal and non-essential analytics cookies on this website. You can leave the Android waitlist by emailing us, unsubscribe from the Journal through any issue, and withdraw analytics consent by clearing site data or declining the banner.
- Legal obligation — where the law requires us to retain or disclose information.
Who we share it with
We do not sell your personal information. Some information is visible to other people by design when you use RACK's social features; beyond that, we share your information only with the processors and counterparties we need to run the service:
- Other users — content you choose to share (feed posts, captions and photos, your profile, shared workouts, and GIPHY comments) is visible to the people you share it with. Accepted friends who join a Plan Together room can see its roster and the bounded workout-planning messages described above.
- Supabase Inc. — hosted Postgres database and authentication for the app, including storage of Android waitlist, Journal, creator-partnership, outreach and Refer & Earn records.
- Discord Inc. — private operator-channel delivery of the in-app support message, category, app/build version, random report identifier, your public RACK handle when set, and copies of diagnostic screenshots you choose to attach. Your RACK account identifier, email address and private Storage paths or URLs are not sent to Discord.
- Resend, Inc. — confirmation-email, RACK Journal and approved creator-outreach delivery, audience management and unsubscribe suppression.
- OpenAI — AI response generation for RACK Coach using the inputs and relevant RACK context described above.
- GIPHY — optional GIF search, delivery and interaction measurement in feed comments.
- Apple Inc. — App Store distribution, Sign in with Apple, in-app purchase processing.
- Google LLC — anonymised website analytics (only loaded after you accept the consent banner) and public YouTube creator discovery through the YouTube Data API.
- Meta Platforms, Inc. — provider-authorised Instagram creator discovery through Instagram Creator Marketplace.
- TikTok — provider-authorised creator discovery through TikTok One.
- PostHog, Inc. — in-app usage analytics, hosted in the EU. Session replay is disabled.
- Functional Software, Inc. (Sentry) — crash, hang and non-fatal error reporting. Reports may carry your random RACK account identifier, but not your name or email.
- Professional advisers — accountants, auditors, and lawyers, where reasonably required.
- Authorities — where compelled by law or to protect our rights or those of others.
International transfers
Some of our processors are based outside the UK. Where personal data is transferred outside the UK or EEA, we rely on the UK Government's adequacy regulations, the UK International Data Transfer Agreement, or Standard Contractual Clauses with the UK Addendum, as appropriate.
How long we keep it
We keep account and training data for as long as you have an active account. If you delete your account we delete or anonymise associated personal data within 30 days, except where we are required to retain it for legal, accounting, or fraud-prevention reasons. Anonymous, aggregated statistics may be retained indefinitely.
Deleting a RACK account detaches it from the durable Refer & Earn payee record and stops new member referral exposure. Payee identity, accepted terms and eligibility, attribution, earnings journal, payout and payment records, masked destination, operator evidence digests and tax-year records may remain after account deletion where they are needed for legal, accounting, tax, fraud-prevention or dispute purposes. We keep those records only for the applicable approved retention period; account deletion does not cancel lawful accrued liabilities, holds or corrections. If you have only entered a referral code and have not prepared or made a purchase, we delete that temporary referral capture and its purchaser record. We also release any handle reserved only by your account. If you enrolled as a referral partner, your permanent payee-linked code may remain for attribution and financial records, but we remove your deleted RACK account identifier from the shared code namespace.
The one-way digest of the pseudonymous Apple App Transaction ID and its first RACK subscription-subject binding may also remain after account deletion where needed to prevent repeated account or referral-offer abuse. We keep that binding only for the fraud-prevention period approved by our privacy owner, then dispose of it under the approved retention process unless a longer legal or dispute hold applies. The same approval must cover the copy that may be embedded in retained signed purchase or server-notification evidence and specify its controlled disposition before referral offers are activated. Our systems do not preselect that legal retention period: referral claims and offers remain blocked until a current approval records the exact bounded term. After expiry, the controlled process checks referral, subscription, financial and dispute dependencies, removes the binding and matching raw signed evidence when safe, and preserves only required transaction facts and non-identifying audit hashes. Each retained transaction family is linked to the exact disposition record proved by its signed evidence, so disposing one identity does not dispose a different identity or override its hold. If Apple later redelivers evidence after the equality binding has been disposed, it inherits that earlier receipt only when the incoming identifier digest, realm, durable subscription subject, original bound time and request record reconstruct the receipt's immutable audit commitment. Exact renewal or refund facts and content hashes are then retained while the raw payload is removed; any mismatch is rejected. Older subscription records with missing realm or family fields are never assigned guessed values: we use an exact value from retained signed evidence where available, otherwise record the unresolved state and keep the evidence for review.
We keep private Discord support messages and their diagnostic screenshot copies only while they are needed to investigate and respond to the report. They are deleted when no longer needed or after a valid deletion request, subject to the same 30-day operational period above and any legal retention requirement.
We keep an Android waitlist email until we send the Android availability notice, you ask us to remove it, or 24 months pass without an Android launch — whichever happens first. We delete it within 30 days after that point. Email privacy@joinrack.app from the address you submitted to leave the waitlist. We have not selected an Android launch-email delivery provider. Waitlist submissions are currently stored only in Supabase and are not sent to Resend for collection. Before we share an address with a provider to send the launch notice, we will update this policy to identify that provider.
Unconfirmed Journal requests expire after 24 hours. We keep a confirmed Journal subscription while you remain subscribed. If you unsubscribe, we stop marketing email and retain the minimum suppression record needed to honour that choice. You can request deletion of the underlying opt-in record by emailing privacy@joinrack.app.
Provider discovery results are cached for no more than 30 days for YouTube and seven days for Instagram and TikTok. A creator added to the shortlist is assigned a retention-review date and cannot be contacted after that date without a new review. We erase or pseudonymise creator records when required, while keeping the minimum suppression record needed to honour an opt-out and any contract, payment or legal evidence we must retain.
Your rights
Under UK GDPR you have the right to:
- access the personal data we hold about you;
- correct inaccurate personal data;
- request that we delete your personal data;
- restrict or object to certain processing;
- receive your data in a portable format;
- withdraw consent where we rely on it; and
- complain to the UK Information Commissioner's Office at ico.org.uk.
To exercise any of these rights, email support@joinrack.app. We aim to respond within one month.
Cookies and similar technologies
This website uses a small number of cookies and similar storage:
- Essential — to remember your consent preference. These do not require consent.
- Analytics — set only after you accept the consent banner. Used to understand aggregate site usage.
You can decline analytics cookies at any time by clearing site data in your browser, which will surface the consent banner again.
Children
RACK is not directed at children under 13, and we do not knowingly collect personal data from anyone under that age. If you believe a child has provided us with personal data, please contact us and we will delete it.
Security
We use industry-standard measures — encryption in transit, hashed credentials, access controls, and audit logging — to protect your information. No system is perfectly secure; if we ever become aware of a breach affecting your data we will notify you and the relevant authorities as required by law.
Changes to this policy
We may update this policy from time to time. When we make material changes we will update the "last updated" date at the top of this page and, where appropriate, notify you in the app or by email.
Contact
Questions, requests, or complaints? Email privacy@joinrack.app or write to us at Flat 68 Hudson House, Station Approach, Epsom, KT19 8DL.