Joyce Studios ("Company", "we") values the privacy of users and the Members they manage in «RepFit Coach» ("Service"), and complies with Korea's Personal Information Protection Act (PIPA), the Network Act, and, where applicable, the EU General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA/CPRA) and other applicable laws.
This Privacy Policy ("Policy") explains what personal data we process, on what legal basis and for what purposes, and how we collect, use, store, disclose and delete it, as well as your rights and how to exercise them. It applies to the Service and not to third-party services linked from it.
In processing personal data, we adhere to the following principles.
| Category | Items | When/How |
|---|---|---|
| Trainer account (required) | Sign in with Apple identifier, nickname | At sign-up / provided by Apple |
| Trainer account (optional) | Email, profile photo, phone number, website & socials (Instagram, YouTube, Threads, Facebook, TikTok) | When entered in profile/settings |
| Member Data (entered by you) | Member name, age, sex, height, weight, notes; membership type, session counts, prices; attendance, achievement ratings, session records, program assignment | Entered by you |
| Automatically generated | App-generated device identifier (UUID), app version/build, device/OS type, install/DAU logs, usage & diagnostic records | Automatically during use |
| Billing | Subscription status/receipts (via App Store). We do not collect or store card/bank details. | At subscription |
| Support | Email and content you provide when contacting us | On inquiry |
We process personal data on the following bases (for GDPR-subject users, the bracketed basis applies):
We do not use personal data beyond the stated purposes or disclose it to third parties, except:
For reliable operation we entrust processing to the following domestic/overseas processors:
| Processor | Entrusted work | Retention |
|---|---|---|
| Google LLC (Firebase) | Authentication, data storage/sync, analytics/diagnostics infrastructure | Until end of engagement or account deletion |
| Apple Inc. | Sign in with Apple, subscription billing | Per Apple policy |
Under Art. 26 of PIPA, our processor agreements set out, in writing, the prohibition of processing beyond the entrusted purpose, technical/administrative safeguards, restrictions on sub-processing, supervision and liability. Changes to entrusted work or processors will be disclosed via this Policy.
Given our cloud infrastructure, personal data may be processed and stored abroad. Under Art. 28-8 of PIPA we disclose:
| Recipient | Country | When/Method | Items | Purpose/Retention |
|---|---|---|---|---|
| Google LLC | USA and other Google data-center locations | Transmitted over the network during use | Account identifiers, user & Member data, usage/diagnostic logs | Storage/sync/analytics; until end of engagement |
| Apple Inc. | USA and others | Transmitted at login/billing | Login identifier, subscription receipts | Auth/billing; per Apple policy |
For GDPR users, where personal data is transferred outside the EEA, we and our processors apply lawful safeguards such as the EU Standard Contractual Clauses (SCCs). You may decline international transfer, in which case you can stop using the Service by deleting your account (note that sync and some features may be unavailable without transfer).
Data subjects (users and Members) have the following rights under applicable law:
You can view/edit your account data in the app and delete your account and all data via Settings → Delete account. Members' rights requests should first be directed to the trainer (controller) who manages them; we, as processor, assist on the trainer's lawful instructions. Other requests may be sent to our privacy officer below in writing or by email; we act without undue delay (in principle within 10 days) and notify you of the outcome.
You may exercise rights through a legal representative or authorized agent, and we may reasonably verify that the requester is the data subject or an authorized agent. Where a request falls within a statutory exception, we may refuse and will explain why.
For service improvement and statistics, we may use pseudonymized or anonymized (de-identified) information that cannot identify an individual. Such information is not personal data and may be processed for statistics, research and service improvement.
If we become aware of loss, theft, leakage, forgery, alteration or damage of personal data, we will notify affected data subjects and report to the relevant authorities without undue delay as required by applicable law (including PIPA), and take necessary measures to minimize harm.
The Service provides statistics and insights (e.g., renewal reminders) as supporting information to aid your judgment. It does not carry out solely automated decisions producing legal or similarly significant effects on you or Members.
The Service targets adult personal trainers and does not collect personal data from children under 14 (Korea). Where the GDPR applies, we do not knowingly collect data from children under 16; where U.S. COPPA applies, under 13. If we learn such data was collected without guardian consent, we delete it without undue delay.
If you enter data about a minor Member, you are responsible for obtaining the necessary consent from that minor's legal guardian.
If we transfer all or part of our business, or transfer personal data through a merger, division or similar, we will, following the procedures required by law, notify you in advance of the fact, the recipient and how to exercise your rights, and give you the opportunity to object to the transfer or withdraw consent.
We designate a privacy officer to oversee processing and handle inquiries, complaints and remedies.
You may contact us at the above for any privacy inquiry, complaint or remedy; we respond diligently without undue delay.
To seek remedies for privacy infringement, you may contact the following bodies (Korea), which are independent of the Company, if you are dissatisfied with our handling or need further assistance:
GDPR users have the right to lodge a complaint with the supervisory authority of their habitual residence or the place of the alleged infringement.
We process personal data on the legal bases stated above and apply lawful safeguards (e.g., SCCs) for transfers outside the EEA. You may exercise your rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent, and the right to lodge a complaint with a supervisory authority. Where we rely on legitimate interests, you may object based on your particular situation.
The categories of personal information we processed in the past 12 months are those listed under "Personal Data We Collect"; sources, purposes and recipients are described in the relevant sections. We do not sell or share personal information and have not done so in the past 12 months. You have the right to know, delete and correct, and to non-discrimination for exercising your rights, which may be exercised through an authorized agent. Submit requests via the contact above.
We may revise this Policy following legal or service changes. We will announce changes and the effective date in the Service or on this page in advance; for material changes (e.g., substantive changes to collected items, purposes, third-party disclosure, international transfer or retention) we give notice 30 days in advance and, where required by law, obtain your renewed consent. Continued use after the effective date may be deemed acceptance of the changes.