Privacy Policy — Rebuild
Last updated: 16 September 2026
Rebuild is an exercise-habit app for people with back pain. This policy describes exactly what the app collects, why, and what you can do about it. It is written to match what the code actually does.
The short version
- You can use Rebuild without an account. Apart from the YouTube video thumbnails on Today (next point), nothing leaves your phone until you sign in.
- The Why exercise relieves back pain list on Learning shows thumbnails loaded from YouTube (Google), signed in or not, so YouTube sees your IP address the way any website's images do. We send it nothing else. Tapping a video opens YouTube, whose own privacy policy applies from there.
- Signing in with Apple adds the community board. From then on, your name, photo, condition line, workout history and anything you write are stored on our server so the board can show them.
- Motion data never leaves your phone. Rep detection runs entirely on the device; only the result (a session, its reps and points) is saved.
- We do not track you, run ads, or sell data. There are no analytics SDKs and no third-party trackers in the app.
- You can delete your account and all its data from inside the app at any time: Me → gear → Delete account.
What we collect, and when
Before you sign in — nothing leaves the device
Your profile, sessions, points, streak, weekly check-ins and journal entries are stored locally on your iPhone. We cannot see them.
After you sign in with Apple
Sign in with Apple gives us a unique user identifier and, if you allow it, your name and email address (which may be Apple's private relay address). We store:
| Data | Why |
|---|---|
| Name | Shown next to you on the community board |
| Email address | Identifies your account; shown to you in Settings |
| Profile photo (optional) | Shown next to you on the board |
| Your "line" (e.g. "Can't tie my shoes") | Shown on the board so people with similar problems recognise each other |
| Workout history — day, exercises, reps, sets, points | Your progress, and your position on the weekly board |
| Weekly check-ins (better / same / worse) | Your progress trend, shared on the board |
| Anything you write in a note or journal entry | Shown on the board to other signed-in members |
When you sign in for the first time, history already stored on your phone is uploaded so it isn't lost. If you sign in on a device with no history, your account's history is downloaded to it.
If you report or block someone
- Reports. When you report content, we store your account identifier, who and what you reported, the reason you chose, and when. Reports exist only so we can review them — they are never visible to other members, and the person you reported is not told who reported them.
- Blocks. When you block someone, we store the pair (you → them) so the server can keep you off each other's board and feed. The blocked person is not notified.
What we do not collect
- Motion and accelerometer data. Used only in memory, on your device, while a session is running.
- Location, contacts, health records, HealthKit data, or advertising identifiers. The app requests none of these.
- Analytics or crash-reporting data. The app contains no such SDK.
Who can see your data
- Other signed-in members see your name, photo, line, weekly and lifetime points, days active, weekly check-in result, and any notes or journal entries you write. Treat anything you write as public to the community.
- Nobody else. We do not share, sell or rent data to third parties, and we do not use it for advertising.
Where it is stored
On Supabase (PostgreSQL and object storage) in the Asia-Pacific (Tokyo) region, behind row-level security: your rows are readable and writable only by your account, and the community board is served by restricted server-side functions that expose only the fields listed above.
Data is encrypted in transit (HTTPS) and at rest by the hosting provider.
Retention and deletion
We keep your data until you delete it. Me → gear → Delete account removes your account, your profile, your check-ins, your notes, your photo, and any reports or blocks you made from the server, and wipes the app's local data on that device. This is immediate and cannot be undone.
Signing out (without deleting) leaves your account data on the server so you can sign back in later.
Your rights
Depending on where you live, you may have rights to access, correct, export or delete your personal data, and to object to processing. Account deletion in the app covers deletion. For anything else, contact us at the address below and we will respond within 30 days.
Children
Rebuild is not directed at children under 13, and we do not knowingly collect data from them.
Medical disclaimer
Rebuild is not a medical device and does not provide medical advice, diagnosis or treatment. It is an exercise-habit tool. Always consult a qualified clinician about back pain, especially with any of the red flags the app lists during onboarding.
Changes
If this policy changes materially, we will update the date above and note the change in the app's release notes.
Contact
Email: hi@letsrebuild.xyz