Encryption in Transit
All data moving between your device and RepCraft servers travels over HTTPS with TLS 1.2+. No exceptions.
Your client data is sensitive. We treat it that way. Encryption, compliance, and infrastructure security built into every layer.
All data moving between your device and RepCraft servers travels over HTTPS with TLS 1.2+. No exceptions.
Stored data is encrypted at rest through our cloud infrastructure. We're strengthening our key-management practices as we move toward production.
We respect user data rights — access, portability, deletion, and consent — and build our privacy practices around GDPR principles. See our Privacy Policy.
We build our controls and monitoring around SOC 2 principles. We have not yet completed a third-party audit; pursuing formal certification is on our roadmap.
Client profiles include goals, experience level, equipment, and injury notes — the information you provide to build a program. Client profiles never include client names or emails — only the training details you choose to enter.
Your data powers the draft: RepCraft uses the profile to generate a program tailored to that client. We do not use your data to train models, share it with third parties, or sell it. Period.
Drafts and profiles stay in your account as long as your account is active. You can export or delete any client record at any time. Deletion is permanent.
We maintain encrypted backups for disaster recovery. Backups are stored separately from primary systems and follow the same encryption and access controls.
Global CDN with built-in DDoS mitigation. Requests route through threat detection before reaching our servers.
Least-privilege principle: teams only access the data they need. API tokens rotate regularly. Admin actions are logged.
Administrative access and key data operations are logged with timestamps. We're expanding our logging and retention as we move toward production.
No. Client profiles and programs are stored exclusively in your RepCraft account. We don't share data with third parties, use it to train models, or sell it. The only exception is if required by law, in which case we notify you unless legally prohibited.
Export is core to how we build: you'll be able to export any client profile or program draft as a structured file, so your data is never locked in.
We'll give you reasonable notice to export your data. We're also building export-first: all client records and drafts are designed to be portable, so you're never stranded.
No. Client profiles and programs are never used to train or improve our AI. Your data stays your data. The RepCraft AI model is pre-trained and frozen — it doesn't learn from your use.
Passwords are hashed with modern algorithms and never stored in plain text. We support strong password practices, with two-factor authentication on our roadmap. We also never store API keys or tokens unencrypted.
Yes. If you discover a security vulnerability, email us at [email protected]. We take responsible disclosure seriously and respond promptly to credible reports.
Your client data is protected. Start drafting programs today.