Rexx — Privacy Policy
Last updated: 16 September 2026
1. Who We Are
Rexx ("we", "us") is the controller of personal data processed through the Rexx mobile application and its backend services (the "App").
Questions, requests or complaints: support@rexx.com. Data Protection Officer / representative: support@rexx.com.
This policy explains what we collect, why, how long we keep it, who we share it with, and the rights you have. It should be read together with our Terms and Conditions.
2. Our Privacy Position in One Paragraph
Rexx is offline-first. Your health and activity data is read from your wearable over Bluetooth and written to an encrypted database on your phone, which is the source of truth. Where you have an account and sync enabled, we also send snapshots of that data to our servers so you can restore it and use it across devices. We do not sell your personal or health data, and we do not use your health data for advertising.
3. Data We Collect
3.1 Health and wellness data (special-category data)
Read from your wearable device or entered by you:
- Heart rate, resting heart rate, heart-rate variability (HRV)
- Blood oxygen (SpO₂), respiratory rate
- Blood pressure estimates, body temperature
- ECG / single-lead waveform captures
- Blood component estimates
- Sleep: duration, stages (deep / light / REM / awake), sleep score
- Stress index
- Steps, distance, calories, activity minutes
- Workouts and sport sessions, including GPS route, pace and duration
- Body composition (weight, body fat, muscle mass and related metrics)
- Derived scores we compute: Recovery Score, Fitness Age, readiness
3.2 Profile and account data
- Name, email address, profile photo (if you add one)
- Date of birth, sex, height, weight, country
- Goals and preferences (step goal, sleep goal, units, reminders)
- Authentication identifiers, including Google Sign-In and Sign in with Apple identifiers where you use them
3.3 Device and connection data
- Wearable model, firmware version, MAC/identifier, battery level, supported capabilities
- Phone model, OS version, app version, language, timezone, app install ID
- Bluetooth pairing and sync logs used for diagnostics
3.4 Location data
- Precise location is used for GPS workout tracking (route, pace, distance), including in the background while a run is active on Android via a foreground service.
- Android additionally requires location permission for Bluetooth scanning. We do not use scan-derived location to track you.
- Route data is stored on your device and, if sync is enabled, with your workout record on our servers.
3.5 Notifications, calls and contacts (Android only, optional)
If you enable band notifications, the App may request access to phone state, call log and contacts so the wearable can display incoming calls and caller names, and may request the ability to answer or reject calls from the band. This data is used only to render the alert on your band in real time. It is not uploaded to our servers and not stored beyond what is needed to deliver the alert. You can decline these permissions and still use the rest of the App.
3.6 Camera and photo library
Used only when you choose a profile photo or attach an image. Images are not scanned or analysed.
3.7 Diagnostics and analytics
Through Firebase Analytics, Crashlytics and Performance Monitoring: crash reports and stack traces, performance traces, feature-usage events, device and OS metadata, and pseudonymous identifiers. We configure these for product diagnostics — health measurements are not sent to analytics.
3.8 Push notification data
Through Firebase Cloud Messaging: a device push token used to deliver reminders and service notifications.
3.9 Support correspondence
Anything you send us by email or through in-app support.
4. Third Parties and SDKs
- Google Firebase (Auth, Analytics, Crashlytics, Performance, Messaging) — Purpose: Sign-in, crash and performance diagnostics, push notifications — Data involved: Account identifiers, device/app metadata, crash and usage events, push token
- Google Sign-In — Purpose: Optional sign-in — Data involved: Google account identifier, email, name, photo
- Apple — Sign in with Apple — Purpose: Optional sign-in — Data involved: Apple user identifier, email (or private relay address), name
- Google Maps — Purpose: Rendering workout routes — Data involved: Map tile requests, approximate viewport
- Wearable SDKs (HBand / Veepoo, QWatchPro) — Purpose: Bluetooth communication with your band — Data involved: Device identifiers, sensor data read over BLE
- Cloud hosting provider — Purpose: Backend hosting and storage for account and synced data — Data involved: Account and synced health data
These providers process data under their own privacy policies. We do not authorise them to use your health data for their own advertising.
Third parties you choose. If you export a report, or share it to an AI assistant, messaging app, email or cloud storage, that transfer is initiated by you and leaves our control. The receiving service's policies then apply. Please review what a report contains before sharing it.
5. Why We Process Your Data, and on What Legal Basis
- Provide core tracking, dashboards and scores — Data: Health, device, profile — Legal basis (GDPR): Explicit consent (Art. 9(2)(a)); contract (Art. 6(1)(b))
- Create and manage your account — Data: Account, authentication — Legal basis (GDPR): Contract
- Sync and back up your data — Data: Health, profile, device — Legal basis (GDPR): Consent; contract
- GPS workout tracking — Data: Location — Legal basis (GDPR): Explicit consent
- Reminders and push notifications — Data: Push token, reminder settings — Legal basis (GDPR): Consent; contract
- Band notification mirroring — Data: Call/contact data (on-device only) — Legal basis (GDPR): Consent
- Diagnostics, crash fixing, performance — Data: Device, usage, crash data — Legal basis (GDPR): Legitimate interests (Art. 6(1)(f))
- Security, abuse and fraud prevention — Data: Account, device, logs — Legal basis (GDPR): Legitimate interests; legal obligation
- Support — Data: Correspondence, diagnostics — Legal basis (GDPR): Contract; legitimate interests
- Product improvement using aggregated, de-identified data — Data: Aggregated only — Legal basis (GDPR): Legitimate interests
- Legal compliance and defence of claims — Data: As required — Legal basis (GDPR): Legal obligation; legitimate interests
Where we rely on consent, you may withdraw it at any time — in the App's settings, in your OS permission settings, or by contacting us. Withdrawal does not affect processing already carried out, and may disable the related feature.
6. What We Do Not Do
- We do not sell your personal or health data, and we do not "share" it for cross-context behavioural advertising as those terms are defined under U.S. state privacy laws.
- We do not use health data to target ads.
- We do not disclose your health data to employers, insurers or data brokers.
- We do not require an internet connection for you to read your own data.
7. Storage, Security and Location
- On your device. Health and activity data is stored in a local database on your phone. Authentication tokens are stored in the OS secure store (iOS Keychain / Android Keystore-backed storage).
- On our servers. Synced data is stored on secure cloud servers, encrypted in transit (TLS) and at rest.
- Access control. Server access is limited to personnel who need it, under authentication and audit logging.
- International transfers. Where data leaves your country (for example to Firebase infrastructure), transfers are made under appropriate safeguards such as the EU Standard Contractual Clauses. A copy is available on request.
- No absolute guarantee. No system is perfectly secure. You are responsible for your device's lock screen, OS updates and account credentials.
- Breach notification. If a breach is likely to result in a risk to your rights, we will notify you and the relevant supervisory authority as required by law.
8. How Long We Keep Data
- Local health data on your device — Retention: Until you delete it, clear app data, or uninstall the App
- Synced health data — Retention: While your account is active, then deleted or anonymised within a reasonable period after account deletion
- Account and profile data — Retention: Life of the account, then deleted or anonymised
- Crash and performance data — Retention: Per Firebase defaults (typically up to 90 days for crash data)
- Analytics events — Retention: Per configured Firebase retention (typically 2–14 months)
- Push tokens — Retention: Until the App is uninstalled or the token is refreshed
- Support correspondence — Retention: As long as needed to resolve your request
- Records required by law (tax, disputes) — Retention: As required by applicable law
9. Your Rights
Depending on where you live, you may have the right to:
- Access the data we hold about you and receive a copy
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict or object to certain processing
- Portability — receive your data in a structured, machine-readable format
- Withdraw consent at any time
- Not be subject to solely automated decisions with legal or similarly significant effects (we do not make such decisions)
- Complain to your local data protection authority
How to exercise them. Use the in-app account settings where available (including account deletion), or email support@rexx.com. We respond within 30 days (extendable where the law permits), and may need to verify your identity first. We do not charge for these requests unless they are manifestly unfounded or excessive.
Deleting your account removes your server-side account and synced data as described in §8. Data stored locally on your phone is removed by deleting it in the App or uninstalling the App.
U.S. state residents (California and similar). You have the right to know, delete, correct and opt out of sale/sharing. We do not sell or share personal information as defined by those laws, so no opt-out mechanism is required, but you may still contact us. We will not discriminate against you for exercising your rights.
10. Children
The App is not directed to children below the age of digital consent in their country, and we do not knowingly collect their personal data. If you believe a child has provided us data, contact support@rexx.com and we will delete it.
11. Your Controls
- OS permissions — Bluetooth, location, notifications, camera, photos, contacts and phone can be revoked at any time in your device settings.
- Sync — turn cloud sync off in the App to keep data local only.
- Analytics — opt out of optional analytics collection in the App's privacy settings where offered.
- Notifications — manage reminders in the App and notification delivery in your OS settings.
- Export — generate and export a report of your data from the App.
- Delete — delete individual records, or your entire account, from the App.
12. Health Data Disclaimer
Rexx is a wellness product, not a medical device. Readings and derived scores are estimates from consumer sensors and are not a diagnosis. See the Terms and Conditions, Section 2, for the full disclaimer.
13. Changes to This Policy
We may update this policy. Material changes will be notified in the App or by email before they take effect, and the "Last updated" date above will change. Continued use after the effective date constitutes acceptance. Where the change requires it, we will ask for fresh consent.
14. Contact
Rexx
Privacy enquiries: support@rexx.com
Data Protection Officer / EU-UK representative: support@rexx.com
You also have the right to lodge a complaint with the supervisory authority in your country of residence.
© 2026 Rexx. All rights reserved.