Effective August 21, 2026
Privacy Policy
Reform Cue is operated by Kyle Worrall in the United States. This policy covers the Reform Cue website, iPhone, iPad, Apple Watch, Android, Wear OS and Garmin experiences, and connected integrations.
Controller and contact
Kyle Worrall, trading as Reform Cue, is the controller for the processing described here. Contact the controller at privacy@reformcue.com or by mail at 4201 W 4th Street, Reno, NV 89523, United States. We use service providers as processors where they handle information on our instructions. A studio may separately be a controller for information it asks its staff to put in Reform Cue.
Data we process and why
| Purpose | Data | Legal basis |
|---|---|---|
| Provide the service | Account identifiers, profile details, timers, moves, routines, studio records, memberships, schedules, shared links, and settings. | Performance of our contract with you. |
| Optional features you request | Notification tokens, selected contacts or photos, music and calendar connection details, Garmin transfers, Apple Watch workout access, and routine-generation input. | Performance of our contract or your consent where required. Device permissions can be withdrawn in system settings. |
| Security and reliability | Limited device, browser, network, authentication, crash, and error information. Sentry is configured not to send default PII, screenshots, view hierarchy, traces, or network-request breadcrumbs. | Our legitimate interests in securing and maintaining Reform Cue. You may object as described below. |
| Studio outreach | Publicly available studio business details, business contact details, country, claim status, and—only with optional-cookie consent—an anonymous setup-visit identifier. | Our legitimate interest in relevant business-to-business outreach. You may object at any time. |
| Billing and legal compliance | Subscription status, product and transaction identifiers, purchase tokens, entitlement dates, and records required for disputes or tax obligations. | Performance of our contract and compliance with legal obligations. |
We receive information from you, your device, a studio administrator who invites you, an integration you connect, and publicly available studio business websites or directories. We do not sell personal data, use it for third-party advertising, or make decisions with legal or similarly significant effects solely by automation.
Local data, sharing, and sensitive features
- Timers, moves, folders, preferences, Spotify connection details, and any OpenAI key you add are primarily kept on your device unless you sign in, share, or use a cloud feature. Your operating-system backup settings may also copy local app data.
- Anyone with a public timer or studio link can open the information in that link. Avoid sensitive information in names, notes, spring notes, and movement notes.
- Selected contact details are used to prepare an invitation you choose to send. A selected studio photo is used only for the studio image.
- HealthKit is accessed on Apple Watch only after permission and while you use workout mode. Heart-rate and active-energy samples stay in Apple’s HealthKit workout flow and are not uploaded to the Reform Cue cloud database.
- Calendar, music, Garmin, notification, and AI features process data only after you take the action to connect or use them. Disconnect the provider or change device permissions to stop future access.
Recipients and service providers
- Clerk: Authentication, account profiles, and session security.
- Convex: Cloud data storage, synchronization, server functions, and deletion workflows.
- Vercel: Website hosting, delivery, and infrastructure security logs.
- Sentry: Minimized iOS crash and stability diagnostics.
- Apple and Google: App distribution, purchases, push delivery, platform sign-in, and optional device services.
- OpenAI: Routine information you submit when you deliberately use an OpenAI-powered feature, including the Reform Cue ChatGPT integration.
- Spotify, Garmin, and schedule or calendar providers: Only the connection and content needed for an integration you choose to enable.
We also disclose information if reasonably necessary to comply with law, protect users, investigate abuse, or complete a business transaction subject to appropriate confidentiality and notice requirements.
International transfers
Reform Cue and several providers operate in the United States, so information from the EEA, United Kingdom, or Switzerland may be transferred outside its country of origin. Where required, transfers use an adequacy decision, an applicable data-privacy framework certification, or contractual safeguards such as the European Commission’s Standard Contractual Clauses, together with supplementary protections where appropriate. Contact us to request information about the safeguard relevant to your data.
Retention
- Account and cloud content is retained while your account is active, then queued for deletion when you use the account-deletion control or make a valid erasure request.
- Deleted timer and move synchronization tombstones are removed after 30 days.
- Optional anonymous studio-setup visit identifiers and visit aggregates are removed after 30 days; unclaimed studio-outreach records are removed after 180 days.
- AI request-status events are removed after 90 days. They do not contain your prompt. Disabled push tokens not seen for 180 days are removed.
- The cookie-consent choice lasts up to 180 days. The optional homepage-animation cookie expires at local midnight. See the Cookie Policy.
- Security, crash, hosting, authentication, billing, backup, dispute, and legal records are retained for the shortest period needed for their stated purpose or applicable legal requirement, then deleted or anonymized under the relevant provider’s retention process.
Your privacy rights
Depending on where you live, you may ask us to access, correct, erase, restrict, or provide a portable copy of your data; object to processing based on legitimate interests; and withdraw consent at any time without affecting earlier lawful processing. Use the Privacy Center for an immediate export, browser cleanup, cookie withdrawal, or account deletion, or email privacy@reformcue.com. We may verify your identity and ordinarily respond within one month, subject to lawful extensions.
You may also complain to the data-protection authority where you live or work, or where you believe an infringement occurred. EEA authorities are listed by the European Data Protection Board. You will not be discriminated against for exercising a privacy right.
Security and incidents
We use encrypted connections, managed authentication, access controls, secret separation, data minimization, signed webhooks, and deletion workflows. No service is perfectly secure. If a personal-data breach creates a legally reportable risk, we will notify the appropriate authority and affected people within the periods required by law.
Children
Reform Cue is for instructors, studios, and people creating workout timers. It is not directed to children under 16, and children under 16 should not create a cloud account. If you believe a child provided personal data, email us so we can investigate and delete it.
Changes and questions
We will update the effective date and provide additional notice when a change materially affects your rights or how we use personal data. For privacy questions or requests, email privacy@reformcue.com.