ROXFIT Privacy Policy

Last updated: 4 October 2026 · Version: 3.1

General

This Privacy Policy ("Policy") describes how we collect and use your personal data in connection with ROXFIT website, application and services. The terms "ROXFIT", "we", "us", or "our" refer to ROXFIT LIMITED, registered under the laws of the United Kingdom.

Scope

This Policy applies to the ROXFIT website (https://www.roxfit.app/ - the "Website"); mobile application (the "App"); the service offerings available via the Website and App (collectively - the "Services"). The Services, together with our App and Website, are referred to as the "Platform".

This Privacy Policy does not constitute, create, or form part of any contract or warranty between you and ROXFIT. This Policy is provided for informational purposes under the applicable privacy laws and regulations.

Who is responsible for your data

For the purposes of applicable data protection laws (in particular, the General Data Protection Regulation (EU) 2016/679 ("GDPR")), your data will be controlled by the ROXFIT, which provides the Platform to you as a Controller of your personal data.

Controller details

Failure to provide personal data

Please read this Privacy Policy and our Terms of Use carefully before using the Services. If you do not agree with the Terms of Use, you should not use the Services. For information about how we process your personal data, please refer to the Privacy Policy.

If we are required by law to collect personal data, or if it is necessary to process your requests or fulfill a contract with you, and you do not provide the requested data, we may be unable to carry out your instructions or meet our contractual obligations. In such cases, we may need to terminate our engagement or the contract, but we will inform you of this decision at that time.

Key terms and definitions

Personal data: any information relating to an identified or identifiable natural person ("Data subject"). For the purposes of GDPR, personal data means any information relating to You such as a name, surname, gender, age, health information, preferences etc.

Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Data controller: means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

You: means any individual accessing the Platform ("Visitor") or obtaining the Services ("User"), or otherwise interacting with us directly or indirectly, including as a prospective ("Prospective user"), current, former User or suggested athlete ("Athlete").

Services: refers to all features, tools, content, and functionalities provided through the Platform. This includes, but is not limited to, enabling users to create, record, store, discover, share, and review workouts and related performance data, as well as access aggregated event and season-level race results.

Website: refers to the ROXFIT website accessible from https://www.roxfit.app/.

Website visitor: a person who visits ROXFIT's website.

Cookies: text files that are stored on a website visitor's computer or mobile device by a website's server.

Table of contents

Sources of personal data

We obtain personal data from the following sources:

ROXFIT also collects personal data from device and platform providers, such as authentication status, device information, and system settings, as well as from inferred sources, including performance trends and user percentiles derived from workout history, to support app functionality and feature personalization.

Why we process your data

We process personal data for the following purposes:

Types of personal data & legal basis for processing

Below is a list of the categories of personal data we may collect and process about you:

Type of personal data processedData subjectsPurposeLegal basis
Core user data
Identity data: first name, last name, email, username, birthday, gender, profile photoUsers, AthletesAccount management & authentication; communication with Users; user support; compliance; legal claims; social and community features; marketingArt. 6(1)(a) (consent) - regarding marketing emails; Art. 6(1)(b) (contract performance); Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legitimate interests)
Authentication data: Firebase UID, OAuth tokens (Google Sign-In, Apple Sign-In, Strava, Garmin)UsersAccount management & authentication; security and fraud preventionArt. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests)
Communications data: emails, in-app chat messages, support tickets, user feedback, or attached files provided during support interactionsUsers, AthletesUser support; compliance; legal claimsArt. 6(1)(b) (contract performance); Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legitimate interests)
Payment data: first name, last name, payment history, subscription details, billing address (if applicable), and limited payment metadataUsersBilling and payment processing; compliance; legal claimsArt. 6(1)(b) (contract performance); Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legitimate interests)
Profile data: height (cm), weight, bio, country, city, Instagram handle, profile imageUsersAccount management & authenticationArt. 6(1)(b) (contract performance)
Location data: timezone, timezone offset (no precise GPS tracking)UsersAccount management & authentication; service deliveryArt. 6(1)(b) (contract performance)
Device data: platform (iOS/Android), brand, OS version, model name, app version, build numberUsers, Platform visitorsAccount management & authentication; service deliveryArt. 6(1)(b) (contract performance)
Health and fitness data
Workout data: completed workouts, duration, calories burned, exercise types, modalitiesUsersService deliveryArt. 6(1)(b) (contract performance)
Health metrics: weight, height, steps, workout energy burned (via Apple Health / Health Connect (Android) - READ_WRITE permissions)UsersService deliveryArt. 6(1)(b) (contract performance)
Performance data: race results, personal bests, workout history, streak trackingUsersService delivery; data anonymization for analytics and ML trainingArt. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests)
Biometric data: motion data, activity recognition (via device health integrations)UsersService deliveryArt. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent)
Social & community interaction data
Social & community interaction data: information about a user's profile visibility, connections, activity feed, posts, comments, and interactions within the app's social features, photosUsers, AthletesSocial and community featuresArt. 6(1)(f) (legitimate interests); Art. 6(1)(a) (consent)
When you choose to post feedback, reviews, or comments within the app or on our community channels, this information becomes publicly visible to other users. Please note that any personal data you choose to include in such posts will be visible to others. We recommend that you avoid including any sensitive or personal information in public feedback.
Cookie & tracking technologies data
Core identifiers and device information: minimal core identifiers and device information - such as user ID, app session state, device type, OS version, and notification permissionsUsers, Platform visitorsCookies & other tracking technologies implementation; service deliveryArt. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests)
AI & chat communications data
Chat sessions: user messages to AI coach, AI responses, conversation summariesUsersPlatform analytics and improvement; data anonymization for analytics and ML trainingArt. 6(1)(f) (legitimate interests)
Workout generation: user preferences, fitness level, physical limitations, workout requestsUsersPlatform analytics and improvementArt. 6(1)(f) (legitimate interests)
Behavioral data: app usage patterns, feature interactions, screen viewsUsers, Platform visitorsPlatform analytics and improvementArt. 6(1)(f) (legitimate interests)
Settings & preferences
User settings: unit preferences (metric/imperial), notification preferences, workout settings, profile visibilityUsersAccount management & authentication; service deliveryArt. 6(1)(b) (contract performance)
Notification tokens: push notification device tokensUsersCommunication with UsersArt. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests)
Analytics preference: user opt-out choice for analytics, privacy settingsUsersPlatform analytics and improvementArt. 6(1)(f) (legitimate interests)
Third-party integration data
Strava: athlete ID, activities, privacy settings, auto-sync preferencesUsersService deliveryArt. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent); Art. 6(1)(b) (contract performance)
Garmin: activities, manual sync dataUsersService deliveryArt. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent); Art. 6(1)(b) (contract performance)
Apple Health / Health Connect (Android): workout data, steps, weight, heightUsersService deliveryArt. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent); Art. 6(1)(b) (contract performance)
Advertising / audience-matching data
Meta Custom Audiences data: hashed email address and hashed first and last name, used to create and refresh Meta Custom Audiences and lookalike audiencesUsersAdvertising and audience matchingArt. 6(1)(f) UK GDPR (legitimate interests) - for UK users (regardless of registration date), subject to the unconditional right to object at any time under Art. 21(2) UK GDPR. Art. 6(1)(a) UK GDPR / EU GDPR (consent) - for all EEA users, regardless of registration date, captured through the in-app consent flow and withdrawable at any time. This consent basis does not apply to UK users, who are covered by the legitimate-interests basis above regardless of registration date. EEA users are excluded from the Meta Custom Audiences upload unless and until they have given consent through the in-app consent flow. ROXFIT does not process EEA users' data for this purpose on the basis of legitimate interests.
AppsFlyer and device advertising identifiers: Apple IDFA (iOS, subject to App Tracking Transparency consent); Google AAID (Android); device model and OS version; install and first-open timestamps; ad-click data received from ad networks; IP address at install (used briefly for fraud detection); and post-install conversion events configured by ROXFITUsersAdvertising and audience matchingArt. 6(1)(a) UK GDPR / EU GDPR (consent) - for all users, regardless of registration date or location, captured on iOS through Apple's App Tracking Transparency prompt and on Android through the in-app consent flow, and withdrawable at any time. Users who decline are not tracked; AppsFlyer's SDK falls back to platform-level privacy-preserving measurement (Apple SKAdNetwork / Google Privacy Sandbox) without personal-data processing.
We apply a single legal basis per user for the Meta Custom Audiences and lookalike processing described in the first row above, and we do not switch basis for the same processing of the same user. All UK users, regardless of registration date, are processed on the basis of our legitimate interests, subject to your unconditional right to object at any time under Art. 21(2) UK GDPR. All EEA users, regardless of registration date, are processed only where they have given consent through the in-app consent flow, which they can withdraw at any time; this consent basis does not apply to UK users. For the AppsFlyer / device-identifier row, all users are processed on the basis of consent regardless of location or registration date.
Analytics and technical data
Analytics events: user actions, feature usage, screen viewsUsersPlatform analytics and improvement; data anonymization for analytics and ML trainingArt. 6(1)(f) (legitimate interests)
Error tracking: crash reports, error logsUsers, Platform visitorsPlatform maintenance & performance; platform analytics and improvementArt. 6(1)(f) (legitimate interests)
Performance metrics: user percentile (0-99) for sampling and feature rolloutUsers, Platform visitorsPlatform maintenance & performance; platform analytics and improvementArt. 6(1)(f) (legitimate interests)

The use of Cookies & other tracking technologies

ROXFIT uses "cookies" - small text files stored on your computer or mobile device by our website's server, and other limited tracking technologies to ensure smooth platform functionality and enhance your user experience.

Certain cookies and similar technologies are essential to enable performance of the Platform and are processed on the legal basis of contract performance (Art. 6(1)(b) of the GDPR).

Other cookies and tracking tools are used to improve our website and tailor content, based on our legitimate interest in optimizing functionality, performance, and security (Art. 6(1)(f) of the GDPR). Within the app, analytics tracking (via Mixpanel, Firebase and Datadog) is conducted under our legitimate interest (Art. 6(1)(f) of the GDPR) and includes a clear opt-out option in Settings → Privacy & Data → "Help Improve ROXFIT", allowing users to disable analytics at any time without affecting app functionality. Crash reporting (Sentry) is used solely to detect and fix technical issues, with all personally identifiable information automatically removed. Helium (Cloud Captain Inc.) is used to present subscription paywalls in the app and to run experiments on how those paywalls are presented. Its SDK reads a device identifier (Apple's identifierForVendor on iOS) and your device locale, and Helium's servers receive your IP address; it does not use an advertising identifier. This processing is based on our legitimate interest in presenting and improving our subscription offers (Art. 6(1)(f) of the GDPR), and you can object to it at any time by contacting support@roxfit.app.

On our Website we use the Meta Pixel, a technology provided by Meta that uses cookies and similar identifiers to measure the effectiveness of our advertising and to help build advertising audiences. For visitors in the United Kingdom and the European Economic Area, the Meta Pixel is not loaded and does not store or read any information on your device until you give your consent through our cookie banner (Art. 6(1)(a) GDPR; Regulation 6 PECR / Article 5(3) ePrivacy Directive). You can withdraw your consent at any time, as easily as you gave it, through the cookie settings.

Automated decisions

According to the Article 22 of the GDPR, the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

The Company does NOT make any decisions based solely on automated processing, including profiling, which produces legal effects concerning data subjects.

How and when we share your information

Below are the circumstances under which personal data may be shared:

Service providers and professional advisors: we may share your personal data with carefully selected providers and professional advisors, such as:

We do not sell your personal data for monetary consideration. All service providers engaged by us process personal data on our behalf under Data Processing Addendums that satisfy the requirements of Article 28 UK GDPR / EU GDPR, we apply data minimisation so that only the information necessary to deliver each service is shared, and third-party integrations that fall outside that scope are user-controlled and require your explicit consent.

Partner offers (pliability). If you take an annual Ultra subscription and switch on the partner-offer option at checkout, we send your first name, last name and email address to pliability, LLC, together with technical details of the event (an event identifier and whether the event is a subscription or a cancellation), and nothing else. pliability uses this information to create your pliability account and provide your complimentary access, to communicate with you about your account, onboarding and redemption, to end your complimentary access if your Ultra subscription ends early, and to operate, support, secure and improve its services. We do not share your information with pliability for marketing purposes: if pliability wishes to send you marketing, it will ask for your consent itself, including when you activate your pliability account. pliability is not our service provider: it decides for itself how it uses that information once it receives it, and it is an independent controller of your personal data from that point. Its own privacy policy (https://pliability.com/privacy-policy) governs what it does with the information, and you should exercise any rights in respect of that processing against pliability directly. We send nothing unless you switch the option on, and switching it on is not a condition of your subscription. If you switch the option on, two further exchanges take place as part of the offer: we tell pliability if your Ultra subscription ends early, so that your complimentary pliability access ends at the same time, and pliability may tell us whether your pliability account was created and activated, the start and end dates of your complimentary access, and whether you converted to a paid pliability subscription, which we use only to measure how the offer performs, to check eligibility for the offer and to support you, and not for marketing or profiling. The send to pliability is based on your consent (Art. 6(1)(a) GDPR); these two further exchanges are based on our legitimate interest in running the offer (Art. 6(1)(f) GDPR). pliability stores and processes your information in the United States (see "International data transfers" below). If you withdraw your consent, we will tell pliability within five business days; this does not by itself close a pliability account you have already activated or require pliability to delete information it holds as a controller, and you can ask pliability directly to do so or withdraw any marketing consent you gave to pliability. We keep the information pliability sends back to us only for as long as we need it for the purposes above, and we delete it when our arrangement with pliability ends unless the law requires us to keep it.

If you are a California resident, please note that the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), defines "sale" and "share" more broadly than the ordinary meaning of those words. In particular, our disclosure of hashed identifiers to Meta Platforms for the purpose of building Custom Audiences and lookalike audiences for cross-context behavioural advertising may be treated as a "share" under the CCPA/CPRA notwithstanding the absence of monetary consideration. You have the right to opt out of this activity at any time, without affecting your access to the Services, by using the "Personalised ads" control in Settings → Privacy & Data (which functions as our "Do Not Sell or Share My Personal Information" opt-out) or by emailing hello@roxfit.app.

With your consent: where you explicitly consent (Art. 6(1)(a) GDPR), we may share your personal data with third parties or entities of your choosing.

International data transfers

The Company has service providers and other recipients in the European Union, United States and UK. Personal information may be transferred to or from the United States or other locations outside of your state, province, country or other governmental jurisdiction where privacy laws may not be as protective as those in your jurisdiction.

Primary data processing locations in the EU and UK:

Primary data processing locations in the USA:

Health Connect (Android) is not a processing location: data is read on your device and is not transferred to Google by ROXFIT.

Legal mechanism for international data transfers

In case your personal data is provided to third parties outside the EEA, we will implement appropriate safeguards to protect your personal data, including Standard Contractual Clauses as adopted by the European Commission. Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

All United States-based service providers and other recipients to whom ROXFIT transfers personal data rely on EU-approved Standard Contractual Clauses (SCCs) to ensure that such international transfers are carried out lawfully. Specific arrangements include:

United States transfers under UK GDPR. For UK users, our upload of hashed identifiers to Meta Platforms, Inc. for Customer List Custom Audiences is a restricted transfer to the United States. The transfer safeguard we rely on is the UK Data Transfer Addendum inside Meta's Data Processing Terms, which is incorporated by reference into our Meta Business Tools relationship. Meta Platforms, Inc. is currently certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework for Non-HR data; where the UK Extension to the DPF is not listed for Meta Platforms, Inc., the UK Data Transfer Addendum is the operative safeguard.

The United States transfers to other processors. AppsFlyer, Datadog, Google Cloud (BigQuery), Google Analytics for Firebase, Mixpanel and Sentry may process data in the United States. Where any such transfer is a restricted transfer under UK GDPR, we rely on the UK IDTA or the UK Addendum to the EU Standard Contractual Clauses, and, where applicable, the DPF certification of the recipient. Datadog is certified under the EU-U.S. DPF. We check that each recipient's transfer mechanism, and its Data Privacy Framework certification where we rely on one, remains valid before we begin using that recipient and whenever we become aware of a change.

Adequacy Decisions

Transfers of personal data to countries recognized as providing an adequate level of data protection are permitted based on adequacy decisions issued by the European Commission or relevant authorities:

Data retention practices

ROXFIT implements comprehensive data deletion and retention procedures to respect user privacy and comply with applicable data protection regulations, including the right to erasure. This involves a) user-requested deletion and b) automatic data retention and deletion.

User-requested deletion

Users may delete their accounts at any time. When you initiate account deletion via the "Delete Account", that deletion is permanent and cannot be undone. Upon confirmation, ROXFIT deletes all user-related data, including but not limited to:

External service cleanup: data stored on third-party services is also removed as part of the deletion process:

Anonymization (non-deletion): certain information may be anonymized to preserve data integrity, including:

The complete user-requested deletion process is executed within approximately one minute.

Data is immediately removed from primary systems. Database backups containing deleted accounts are securely overwritten within 30 days.

Automatic data retention and deletion

ROXFIT retains personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements and policies. Once data reaches the end of its retention period, ROXFIT either securely deletes it or anonymizes it to ensure that it can no longer be used to identify any individual.

Inactive users.

Data is immediately removed from primary systems. Database backups containing deleted accounts are securely overwritten within 30 days.

General data retention practices

We will retain and use Your personal data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Please, see the table below:

№Purpose of personal data retentionRetention period
1.Account management & authenticationFor the duration of your ROXFIT account, plus 12 months following account deletion for backup, audit and reactivation purposes
2.Advertising audiencesWe refresh the uploaded audience approximately every 30 days and retain it only while the advertising purpose continues. When you object, withdraw consent, delete your account, or are placed on our suppression list, we remove you from the active audience within 30 days.
3.Service deliveryFor the duration of your ROXFIT account, plus 12 months following account deletion
4.Platform analytics and improvementAnalytics events are retained for 25 months from collection (aligned to Google Analytics for Firebase default retention); user identifiers are removed on account deletion and only aggregate data is retained thereafter
5.Platform maintenance & performanceCrash reports and error logs are retained for 90 days from collection; performance metrics are retained for 13 months
6.Communication with UsersFor the duration of your ROXFIT account
7.User support3 years from the last interaction with the support team, or such longer period as is necessary to resolve any open matter or comply with legal obligations.
8.Billing and payment processing6 years from the end of the accounting period in which the transaction occurred, in line with UK statutory record-retention requirements under the Companies Act 2006 and VAT legislation
9.Security and fraud prevention12 months from collection for security event logs; longer where required to investigate an incident or defend a legal claim
10.Compliance with legal and regulatory requirementsFor the period required by the applicable law (typically 6 years for tax and accounting records, and shorter or longer periods for other regulatory obligations)
11.Defending or resolving legal claimsFor the applicable statutory limitation period plus one year (in the United Kingdom, 6 years for contractual claims under the Limitation Act 1980)
12.Social and community featuresFor the duration of your ROXFIT account; on account deletion, social posts are anonymised (identifiers removed, content preserved for community integrity) or deleted where anonymisation is not appropriate
13.Cookies & other tracking technologies implementationSession cookies expire on session end. Persistent cookies expire at intervals disclosed in our Cookie Policy, and in any event no later than 13 months from the date of your consent
14.Data anonymization for analytics and ML trainingAnonymised aggregate data is retained indefinitely for model improvement; the underlying identifiable data is deleted or anonymised at the point of anonymisation and in any event on account deletion

Information security

We employ industry standard security measures designed to protect the security of all information submitted through the Services.

We implement a comprehensive set of technical and organizational security measures to ensure the confidentiality, integrity, and availability of personal data, in accordance with the General Data Protection Regulation (GDPR). These measures include, but are not limited to:

Data encryption and secure transmission: all data is encrypted in transit and at rest, ensuring that information is protected when transmitted over networks and when stored. For example, sensitive data is always encrypted end-to-end while in transit.

Access control: access to personal data is restricted on a need-to-know basis. Only authorized personnel can access user data according to their role and responsibilities.

Account and authentication security: user accounts are protected by secure authentication processes, and sensitive credentials are stored and managed safely.

Database and file storage protection: databases and file storage systems are secured with encryption, network safeguards, and routine backups to prevent data loss.

Monitoring and incident detection: systems are continuously monitored to detect and respond to potential security incidents promptly.

Third-party service management: all third-party service providers are carefully selected, and agreements are in place to ensure they comply with applicable data protection regulations. We conduct regular security audits regarding vendor compliance. ROXFIT concludes Data Processing Agreements (DPAs) with all third-party service providers who process personal data on our behalf. These agreements ensure that:

While we take reasonable steps to protect your personal data, no system can be completely secure. Therefore, we encourage users to take precautions to protect their own information, including maintaining the confidentiality of login credentials.

In order to protect you and your data, we may suspend your use of any of the Services, without notice, pending an investigation, if any breach of security is suspected.

Updating personal data

If any of the personal data that you have provided to us changes, for example if you change your email address or if you wish to cancel any request you have made of us, or if you become aware we have any inaccurate personal data about you, please let us know by sending an email to hello@roxfit.app. We will not be responsible for any losses arising from any inaccurate, inauthentic, deficient or incomplete personal data that you provide to us.

Children's Privacy

ROXFIT does not knowingly collect any Personal Data from children under the age of 16. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.

Our priority is adding protection for children while using the Internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.

If you are under the age of majority in your jurisdiction of residence, you may use the Services only with the consent of or under the supervision of your parent or legal guardian. Consistent with the requirements of the GDPR, if we learn that we have received any information directly from a child under age 16, we will use that information only to respond directly to that child (his or her parent or legal guardian) to inform the child that he or she cannot use the Sites and subsequently we will delete that information.

Advertising

We do not use your account information to direct advertising to anyone under 18, and we exclude users we know to be under 18 from the audiences we share with Meta.

Your Rights and Choices

Under the General Data Protection Regulation (GDPR), you have certain rights concerning your personal information. You may request that we take the following actions in relation to the personal data we hold about you:

Opt-out:

Access: provide details about how we process your personal information and give you access to it. You can view the following data in-app:

You may request a copy of your personal data by contacting support@roxfit.app. Your right of access is separate from the right to data portability described below.

Correct: update or correct any inaccuracies in your personal data. You can edit your data directly in-app:

Delete: remove your personal information from our records. In certain circumstances, you have the right to request the deletion of your personal data. This may apply if:

*Please note that this right is not absolute and may be subject to exceptions, such as compliance with legal obligations or the establishment, exercise, or defense of legal claims. Some data is anonymized rather than deleted for data integrity (race leaderboards retain anonymized results).

In-app "Delete Account" button in Settings deletes user profile and account:

Transfer (data portability): Where the right to data portability applies, we provide the relevant personal data in a structured, commonly used and machine-readable format, such as CSV or JSON. This right applies to personal data you have provided to us, including data observed through your use of the Services, where we process it by automated means on the basis of your consent or a contract with you. You may also request that we transfer this data directly to another data controller, where technically feasible.

Exports need not reproduce ROXFIT's internal database structure, including how we store workouts, or its software. We may provide your personal data in a separate, understandable export format. This does not exclude your personal workout records or limit your statutory data protection rights.

Restrict: You have the right to request the restriction of processing of your personal data in certain situations, such as:

While the processing is restricted, we will only store your personal data and will not process it further unless specific conditions apply.

Object: You have the right to object to the processing of your personal data based on our legitimate interests (Art. 6(1)(f) of the GDPR), unless we can demonstrate compelling legitimate grounds for the processing that override your rights and freedoms. In particular, You can manage your data directly in-app:

To further exercise any of these rights, you may contact us at hello@roxfit.app. We may need to request specific information from you to verify your identity and process your request. In some cases, applicable laws may require or allow us to decline your request. If we are unable to comply, we will explain the reason, subject to any legal restrictions.

If you have concerns about how we handle your personal information or our response to your requests, you may contact us at hello@roxfit.app or file a complaint with the data protection authority in your jurisdiction.

Updates to this Privacy Policy

Contact information

We welcome your comments or questions about this Policy, and you may contact us at the following address: hello@roxfit.app

ROXFITFree on Google Play Get