Privacy Policy for RepQuest
Operated by ChalkedZilla
1. Who operates RepQuest
ChalkedZilla (“we”, “us”, or “our”) operates the RepQuest mobile application for Android
(“RepQuest” or the “App”), application ID com.chalkedzilla.repquest.
Contact for privacy, support, and account requests: eray@chalkedzilla.com.
2. Scope
This policy explains what information RepQuest collects, why it is collected, which service providers process it, how long it is kept, and how you can delete your account.
RepQuest is a fitness organization and gamification app. It is not a medical device, does not provide medical diagnoses, and is not a substitute for professional medical advice. If you have an injury or a health condition, seek appropriate professional guidance before starting or changing exercise.
3. Information we collect
RepQuest stores the following categories in Google Firebase Authentication and Cloud Firestore when you create and use an account. We do not currently include Firebase Analytics, Crashlytics, or Cloud Messaging in the shipping app.
Account information
- Firebase user identifier (UID)
- Email address
- Display name you choose
- Authentication provider used to sign in (Google or email link)
- Account created and updated timestamps
- Onboarding-complete flag
If you sign in with Google, Google provides an ID token. RepQuest uses that token to create or restore a Firebase Authentication session and stores the email associated with the account. RepQuest does not store your Google profile photo.
If you sign in with email link, we process the email address you enter in order to send a one-time sign-in link through Firebase Authentication.
Fitness and profile information
Collected during onboarding and editable later in Hero / Settings:
- Age (the App requires a minimum age of 16)
- Biological sex
- Height and body weight
- Selected body-fat range
- Fitness goal, training experience, training location, session-duration preference
- Weekly training-day preference and selected training weekdays
- Optional injury-area selections (for program matching, not clinical records)
- Assigned or selected player class and built-in avatar identifier
Avatar images are selected from built-in artwork. RepQuest does not host a user photo gallery or camera profile picture.
Workout and progress information
- Selected workout split (Battle Plan), including split identifier, name, and match metadata
- Optional split-match scores used to rank programs
- Completed workout history: split and day, start/completion times, duration, planned and completed sets, repetition counts, movement names, activated muscle groups, estimated calories, intensity score, and XP gained
- Overall XP, level, rank name, per-muscle XP, total workouts, current streak, longest streak, and last workout date
RepQuest does not currently store logged exercise weights or a separate personal-records database. Estimated calories and intensity are calculated by the App from completed session data.
Leaderboard information visible to other signed-in users
A public leaderboard document stores: display name, player class, avatar identifier, level, total XP, current streak, and rank. Any signed-in RepQuest user can read that leaderboard data. Private profile fields such as email, age, weight, injuries, and workout history are not written to the leaderboard.
Purchase and subscription information
RepQuest offers a free Adventurer experience and a paid Ascendant subscription through Google Play Billing. When the RevenueCat SDK is configured with a public SDK key, RevenueCat receives an app user identifier (the Firebase UID) and the purchase/entitlement metadata needed to verify whether the Ascendant entitlement is active.
ChalkedZilla does not receive or store full payment-card numbers or card security codes. Google Play processes the payment. User profiles in Firestore do not contain a premium flag; entitlement is determined by RevenueCat when configured.
Support communications
Help & Support opens your device email app. The draft may include your UID, account email, app version, Android version, device model, timestamp, and an optional screenshot you attach. That message is sent by your email provider to eray@chalkedzilla.com. Screenshots are not uploaded to RepQuest servers or Firestore.
Local device data
The Android app stores a local session timestamp in on-device preferences so it can restore a recent login. That value is not a cloud profile field. Signing out clears the local session.
4. Why we collect this information
- Account management: authenticate you, restore your profile, and prevent account mix-ups.
- App functionality: save onboarding answers, Battle Plan, training days, and workout history.
- Personalization / progression: assign a class, score splits, calculate XP, levels, ranks, streaks, trophies, Today’s Quest, and Battles history.
- Subscription management: verify Ascendant access when RevenueCat and Google Play Billing are active.
- Support: respond to email you send from Help & Support.
We do not sell personal information and do not use the shipping app for advertising SDKs or third-party analytics packages.
5. Authentication
Supported sign-in methods are Google Sign-In (Credential Manager on Android; Google Identity Services on this website’s delete-account page) and Firebase email-link sign-in. There is no password login and no authentication bypass for reviewers or any other special email address.
6. Firebase / cloud storage
Account, profile, workout history, and leaderboard documents are stored in Google Cloud Firestore in the Firebase project used by RepQuest. Authentication credentials are stored by Firebase Authentication. Data in transit uses TLS.
Firestore security rules are intended to allow each signed-in user to read and write only
their own users/{uid} document and users/{uid}/workouts
subcollection, and to allow signed-in users to read leaderboard rows while writing only their
own leaderboard row.
7. Subscription processing / RevenueCat
When configured, RevenueCat processes the identifiers and transaction metadata required to
restore purchases and check the ascendant entitlement. Google Play remains the
merchant of record for Android subscriptions. Refunds, renewals, and cancellations follow
Google Play’s policies and the Google Play subscription settings on your device or Google
account.
8. Sharing and service providers
We do not sell or rent personal information.
| Provider | Role | Data involved |
|---|---|---|
| Google / Firebase | Authentication and cloud database | Account identifiers, email, profile, workouts, leaderboard |
| Google Play | App distribution and billing | Purchase and subscription records processed by Google |
| RevenueCat, Inc. | Entitlement verification when the SDK is configured | App user ID (Firebase UID) and purchase/entitlement metadata |
| Email providers | Support mail you send from your device | Whatever you include in the outgoing message |
Google Privacy Policy: https://policies.google.com/privacy
RevenueCat Privacy Policy: https://www.revenuecat.com/privacy/
We may also disclose information if required by law, to protect users or the service, or in connection with a legitimate business transfer of the App.
9. Data retention
We keep account, profile, workout, and leaderboard data while the account exists so the App can function. Local session preferences remain on the device until you sign out or uninstall the App.
Support emails you send are retained in our mailbox only as needed to handle the request.
Google Play and RevenueCat may retain purchase records according to their own retention rules even after an in-app profile is deleted. Those records are not full card details.
10. Your rights
Depending on where you live, you may have rights to access, correct, delete, or export personal information, to restrict or object to certain processing, and to withdraw consent where processing is based on consent. You can correct much of your profile inside the App. For other requests, email eray@chalkedzilla.com.
11. Account deletion
You can delete your account in the App (Hero → Edit Profile → Delete Account) or on the Delete Account page. Both use the same authenticated backend. The backend identifies the account from your verified Firebase ID token and does not accept another user’s UID.
When deletion succeeds, RepQuest removes:
- Your Firestore profile, selected split, split scores, and workout history
- Your leaderboard row
- Your Firebase Authentication user
- Associated RevenueCat subscriber metadata, when a RevenueCat secret is configured on the deletion service
We then sign you out. Deletion cannot be undone. Google may still hold Play purchase history. If a legal or security obligation requires limited residual records (for example, a support email you already sent), we keep only what is reasonably necessary.
12. Security
Access to cloud data is protected by Firebase Authentication and Firestore rules. The account-deletion service requires a valid ID token. No method of electronic storage is completely secure, and we cannot guarantee absolute security.
13. Children and age
RepQuest is intended for a general adult fitness audience. The App’s onboarding requires users to be at least 16 years old. It is not directed at children, and we do not knowingly create accounts for children under 16. If you believe a child under 16 has created an account, contact us so we can delete it.
14. International processing
Google and RevenueCat may process information in countries other than your country of residence, including the United States. Transfers rely on the contractual and technical safeguards those providers offer under applicable law.
15. Changes
We may update this policy when the App, providers, or legal requirements change. The “Last updated” date at the top will change. Material changes may also be noted in the App or store listing where appropriate.
16. Contact
ChalkedZilla
Email: eray@chalkedzilla.com