Last updated September 14, 2026

PRIVACY

What we collect

Your email and password when you create an account (Supabase handles authentication and hashes your password — Rerack never sees or stores it in plain text). During sign-up we also email you a one-time code to confirm it's really your inbox.

Your training answers: which Cornell gym(s) you use, your goal, experience level, days per week, anything optional you tell us to work around, and any focus areas you pick. Once you're training, we store the workouts you log yourself — which session, which exercises, the weight and reps per set, and when you completed it. If you set unit preferences or leaderboard visibility in Settings, we store those choices too.

Why

Your training answers are what a plan gets built around. Your logged workouts are what let the app show your own history and progress back to you. Your email is how you sign back in and how we'd reach you about your account.

Where it's stored

Everything above lives in Supabase (our database and authentication provider), locked down per-row so only your own account can read or write your own data. The one-time codes we send during sign-up are delivered through Resend, which sees only the email address and the code — nothing else about you. The site itself is hosted on Vercel.

Who sees it

By default, other Rerack users can see your name and progress on the social leaderboard — you can turn this off any time in Settings. Outside of that, just the founder can see account data, and only for running the app. Nothing is sold, shared, or handed to a third party beyond the providers named above, and only for the purpose of running the service.

Your data, your call

There's no self-serve delete button yet. Email hello@rerack.app any time to see what we have on you or have your account and data deleted, and it'll get handled by hand.

Changes

This policy will keep getting more formal as Rerack grows. For now, this reflects exactly what happens with your data today.