Privacy Policy
Last updated: 15.07.2026 · Version: 2.1
General
This Privacy Policy ("Policy") describes how we collect and use your personal data in connection with ROXFIT website, application and services. The terms "ROXFIT", "we", "us", or "our" refer to ROXFIT LIMITED, registered under the laws of the United Kingdom.
Scope
This Policy applies to the ROXFIT website (https://www.roxfit.app/ - the "Website"); mobile application (the "App"); the service offerings available via the Website and App (collectively - the "Services"). The Services, together with our App and Website, are referred to as the "Platform".
This Privacy Policy does not constitute, create, or form part of any contract or warranty between you and ROXFIT. This Policy is provided for informational purposes under the applicable privacy laws and regulations.
Who is responsible for your data
For the purposes of applicable data protection laws (in particular, the General Data Protection Regulation (EU) 2016/679 ("GDPR")), your data will be controlled by ROXFIT, which provides the Platform to you as a Controller of your personal data.
Controller details
Registered name: ROXFIT LIMITED.
Registered address: 128 City Road, London, United Kingdom, EC1V 2NX
General contact address: hello@roxfit.app
Privacy support: support@roxfit.app
Failure to provide personal data
Please read this Privacy Policy and our Terms of Use carefully before using the Services. If you do not agree with the Terms of Use, you should not use the Services. For information about how we process your personal data, please refer to the Privacy Policy.
If we are required by law to collect personal data, or if it is necessary to process your requests or fulfill a contract with you, and you do not provide the requested data, we may be unable to carry out your instructions or meet our contractual obligations. In such cases, we may need to terminate our engagement or the contract, but we will inform you of this decision at that time.
Key terms and definitions
Personal data: any information relating to an identified or identifiable natural person ("Data subject"). For the purposes of GDPR, personal data means any information relating to you such as a name, surname, gender, age, health information, preferences etc.
Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Data controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.
You: any individual accessing the Platform ("Visitor") or obtaining the Services ("User"), or otherwise interacting with us directly or indirectly, including as a prospective user ("Prospective user"), current or former User, or suggested athlete ("Athlete").
Services: all features, tools, content, and functionalities provided through the Platform. This includes, but is not limited to, enabling users to create, record, store, discover, share, and review workouts and related performance data, as well as access aggregated event and season-level race results.
Advertising Effective Date: means 15 July 2026, being the date the version of this Privacy Policy that introduced the Meta advertising processing described below first took effect.
Website: the ROXFIT website accessible from https://www.roxfit.app/.
Website visitor: a person who visits ROXFIT's website.
Cookies: text files that are stored on a website visitor's computer or mobile device by a website's server.
Table of contents
- Sources of personal data
- Why we process your data
- Types of personal data & legal basis for processing
- The use of Cookies & other tracking technologies
- Automated decisions
- How and when we share your information
- International data transfers
- Data retention practices
- Information security
- Updating personal data
- Children's Privacy
- Your Rights and Choices
- Updates to this Privacy Policy
- Contact information
Sources of personal data
We obtain personal data from the following sources:
Directly from you: when you fill in the registration form on the Platform, create a user profile, enter your personal profile information, interact with the AI assistant in the chat, record race results, log your workouts or exercise your privacy rights (e.g. access, deletion of personal data).
Automatically through your use of our services: when users open or navigate the app, ROXFIT automatically logs usage events and feature interactions, records crash reports if errors occur, stores user preferences, workout data, and cached content as users update settings or complete workouts, and registers push notification tokens when notifications are enabled, all to ensure app functionality, improve user experience, and maintain stability, with optional analytics tracking that users can disable at any time.
ROXFIT also collects personal data from device and platform providers, such as authentication status, device information, and system settings, as well as from inferred sources, including performance trends and user percentiles derived from workout history, to support app functionality and feature personalization.
Third-party and partner sources: ROXFIT may also collect personal data from third-party integrations with user consent, including health and fitness metrics from Apple Health and Google Fit, workout data from Strava and Garmin Connect, and profile information from Google Sign-In and Apple Sign-In, to provide personalized workouts, track progress, and enable app functionality.
Why we process your data
We process personal data for the following purposes:
Advertising and audience matching: to promote ROXFIT and reach existing and prospective users, we use your contact details to create matched audiences ("Custom Audiences") and similar ("lookalike") audiences on Meta platforms (Facebook and Instagram).
Account management & authentication: to implement user authentication and login, manage and customize profile, reset password, recover account, track the acceptance of Terms of service.
Service delivery: to track workout and workout history, generate and coach AI-powered workouts, track race and personal best results, enable social features (following, activity feed, community), create and schedule training plans.
Platform analytics and improvement: to ensure usage analytics (with opt-out in Settings), adopt feature measurement, monitor performance.
Platform maintenance & performance: to report and fix bugs and crashes, monitor performance.
Communication with Users: to provide you with push notifications for workouts, races, community activity, send emails (both transactional and, where applicable, marketing communications about ROXFIT features, offers and updates), provide you with in-app messages and announcements and support (Crisp Chat).
User support: to implement your rights under GDPR and other applicable laws, including the right to access, correct, delete, or export your personal data, the right to object to or restrict processing, and the right to withdraw consent.
Billing and payment processing: to manage subscription, to process in-app purchases and track payment history.
Security and fraud prevention: to detect abuse (name change patterns, race result fraud), monitor errors and system alerts, detect suspicious activity.
Compliance with legal and regulatory requirements: to comply with legal obligations, such as responding to lawful requests from authorities, maintaining accurate records for accounting or tax purposes and fulfilling regulatory requirements.
Defending or resolving legal claims: to defend our rights, resolve disputes, including litigation, investigations, or regulatory inquiries.
Social and community features: to enable social interactions within the app, including profile visibility, following systems, comments, activity feeds, leaderboards, and other community features, in accordance with your privacy settings and preferences.
Cookies & other tracking technologies implementation: to enable the use of cookies and other tracking technologies which further will be used for authentication, analytics, remote config, crash analytics, user preferences, settings, cached data, feature adoption, bug detection, crash reports, push notification delivery, maintaining app state across sessions.
Data anonymization for analytics and ML training: to remove identifiers from personal data and preserve its integrity in order to improve the Platform and develop features (based on anonymized analytics with opt-out), ensure machine learning model training (anonymized data).
Types of personal data & legal basis for processing
Below is a list of the categories of personal data we may collect and process about you:
| Type of personal data processed | Data subjects | Purpose | Legal basis |
|---|---|---|---|
| Core user data | |||
| Identity data: first name, last name, email, username, birthday, gender, profile photo | Users, Athletes | Account management & authentication; communication with Users; user support; compliance; legal claims; social and community features; marketing | Art. 6(1)(a) (consent) - regarding marketing emails; Art. 6(1)(b) (contract performance); Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legitimate interests) |
| Authentication data: Firebase UID, OAuth tokens (Google Sign-In, Apple Sign-In, Strava, Garmin) | Users | Account management & authentication; security and fraud prevention | Art. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests) |
| Communications data: emails, in-app chat messages, support tickets, user feedback, or attached files provided during support interactions | Users, Athletes | User support; compliance; legal claims | Art. 6(1)(b) (contract performance); Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legitimate interests) |
| Payment data: first name, last name, payment history, subscription details, billing address (if applicable), and limited payment metadata | Users | Billing and payment processing; compliance; legal claims | Art. 6(1)(b) (contract performance); Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legitimate interests) |
| Profile data: height (cm), weight, bio, country, city, Instagram handle, profile image | Users | Account management & authentication | Art. 6(1)(b) (contract performance) |
| Location data: timezone, timezone offset (no precise GPS tracking) | Users | Account management & authentication; service delivery | Art. 6(1)(b) (contract performance) |
| Device data: platform (iOS/Android), brand, OS version, model name, app version, build number | Users, Platform visitors | Account management & authentication; service delivery | Art. 6(1)(b) (contract performance) |
| Health and fitness data | |||
| Workout data: completed workouts, duration, calories burned, exercise types, modalities | Users | Service delivery | Art. 6(1)(b) (contract performance) |
| Health metrics: weight, height, steps, workout energy burned (via Apple Health/Google Fit - READ_WRITE permissions) | Users | Service delivery | Art. 6(1)(b) (contract performance) |
| Performance data: race results, personal bests, workout history, streak tracking | Users | Service delivery; data anonymization for analytics and ML training | Art. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests) |
| Biometric data: motion data, activity recognition (via device health integrations) | Users | Service delivery | Art. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent) |
| Social & community interaction data | |||
| Social & community interaction data: information about a user's profile visibility, connections, activity feed, posts, comments, and interactions within the app's social features, photos | Users, Athletes | Social and community features | Art. 6(1)(f) (legitimate interests); Art. 6(1)(a) (consent) |
| When you choose to post feedback, reviews, or comments within the app or on our community channels, this information becomes publicly visible to other users. Please note that any personal data you choose to include in such posts will be visible to others. We recommend that you avoid including any sensitive or personal information in public feedback. | |||
| Cookie & tracking technologies data | |||
| Core identifiers and device information: minimal core identifiers and device information - such as user ID, app session state, device type, OS version, and notification permissions | Users, Platform visitors | Cookies & other tracking technologies implementation; service delivery | Art. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests) |
| AI & chat communications data | |||
| Chat sessions: user messages to AI coach, AI responses, conversation summaries | Users | Platform analytics and improvement; data anonymization for analytics and ML training | Art. 6(1)(f) (legitimate interests) |
| Workout generation: user preferences, fitness level, physical limitations, workout requests | Users | Platform analytics and improvement | Art. 6(1)(f) (legitimate interests) |
| Behavioral data: app usage patterns, feature interactions, screen views | Users, Platform visitors | Platform analytics and improvement | Art. 6(1)(f) (legitimate interests) |
| Settings & preferences | |||
| User settings: unit preferences (metric/imperial), notification preferences, workout settings, profile visibility | Users | Account management & authentication; service delivery | Art. 6(1)(b) (contract performance) |
| Notification tokens: push notification device tokens | Users | Communication with Users | Art. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests) |
| Analytics preference: user opt-out choice for analytics, privacy settings | Users | Platform analytics and improvement | Art. 6(1)(f) (legitimate interests) |
| Third-party integration data | |||
| Strava: athlete ID, activities, privacy settings, auto-sync preferences | Users | Service delivery | Art. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent); Art. 6(1)(b) (contract performance) |
| Garmin: activities, manual sync data | Users | Service delivery | Art. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent); Art. 6(1)(b) (contract performance) |
| Apple Health / Google Fit: workout data, steps, weight, height | Users | Service delivery | Art. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent); Art. 6(1)(b) (contract performance) |
| Advertising / audience-matching data | |||
| Meta Custom Audiences data: hashed email address and, where used, hashed first name, used to create and refresh Meta Custom Audiences and lookalike audiences | Users | Advertising and audience matching | Art. 6(1)(f) UK GDPR (legitimate interests) - for UK users in the existing base (registered before the Advertising Effective Date), subject to the unconditional right to object at any time under Art. 21(2) UK GDPR. Art. 6(1)(a) UK GDPR / EU GDPR (consent) - for (i) UK users registered on or after the Advertising Effective Date, and (ii) all EEA users, regardless of registration date, captured through the in-app consent flow and withdrawable at any time. EEA users in the existing base (registered before the Advertising Effective Date) are excluded from the Meta Custom Audiences upload until they have given consent through the in-app consent flow. ROXFIT does not process EEA users' data for this purpose on the basis of legitimate interests. |
| AppsFlyer and device advertising identifiers: Apple IDFA (iOS, subject to App Tracking Transparency consent); Google AAID (Android); device model and OS version; install and first-open timestamps; ad-click data received from ad networks; IP address at install (used briefly for fraud detection); and post-install conversion events configured by ROXFIT | Users | Advertising and audience matching | Art. 6(1)(a) UK GDPR / EU GDPR (consent) - for all users, regardless of registration date or location, captured on iOS through Apple's App Tracking Transparency prompt and on Android through the in-app consent flow, and withdrawable at any time. Users who decline are not tracked; AppsFlyer's SDK falls back to platform-level privacy-preserving measurement (Apple SKAdNetwork / Google Privacy Sandbox) without personal-data processing. |
| We apply a single legal basis per user for the Meta Custom Audiences and lookalike processing described in the first row above, and we do not switch basis for the same processing of the same user. UK users in the existing base are processed on the basis of our legitimate interests, subject to your unconditional right to object at any time under Art. 21(2) UK GDPR. UK users registering on or after the Advertising Effective Date, and all EEA users regardless of registration date, are processed only where they have given consent through the in-app consent flow, which they can withdraw at any time. For the AppsFlyer / device-identifier row, all users are processed on the basis of consent regardless of location or registration date. | |||
| Analytics and technical data | |||
| Analytics events: user actions, feature usage, screen views | Users | Platform analytics and improvement; data anonymization for analytics and ML training | Art. 6(1)(f) (legitimate interests) |
| Error tracking: crash reports, error logs | Users, Platform visitors | Platform maintenance & performance; platform analytics and improvement | Art. 6(1)(f) (legitimate interests) |
| Performance metrics: user percentile (0-99) for sampling and feature rollout | Users, Platform visitors | Platform maintenance & performance; platform analytics and improvement | Art. 6(1)(f) (legitimate interests) |
The use of Cookies & other tracking technologies
ROXFIT uses "cookies" - small text files stored on your computer or mobile device by our website's server, and other limited tracking technologies to ensure smooth platform functionality and enhance your user experience.
Certain cookies and similar technologies are essential to enable performance of the Platform and are processed on the legal basis of contract performance (Art. 6(1)(b) of the GDPR).
Other cookies and tracking tools are used to improve our website and tailor content, based on our legitimate interest in optimizing functionality, performance, and security (Art. 6(1)(f) of the GDPR). Within the app, analytics tracking (via Mixpanel, Firebase and Datadog) is conducted under our legitimate interest (Art. 6(1)(f) of the GDPR) and includes a clear opt-out option in Settings → Privacy & Data → "Help Improve ROXFIT", allowing users to disable analytics at any time without affecting app functionality. Crash reporting (Sentry) is used solely to detect and fix technical issues, with all personally identifiable information automatically removed.
On our Website we use the Meta Pixel, a technology provided by Meta that uses cookies and similar identifiers to measure the effectiveness of our advertising and to help build advertising audiences. For visitors in the United Kingdom and the European Economic Area, the Meta Pixel is not loaded and does not store or read any information on your device until you give your consent through our cookie banner (Art. 6(1)(a) GDPR; Regulation 6 PECR / Art. 5(3) ePrivacy Directive). You can withdraw your consent at any time, as easily as you gave it, through the cookie settings.
See our Cookie Policy for details.
Automated decisions
According to Art. 22 of the GDPR, the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.
The Company does NOT make any decisions based solely on automated processing, including profiling, which produces legal effects concerning data subjects.
How and when we share your information
Below are the circumstances under which personal data may be shared:
Corporate transaction: in the event of a potential or actual corporate transaction (e.g., a merger, acquisition, reorganization, sale of assets, or insolvency proceeding), we may transfer your personal data to relevant parties involved in the transaction. Such transfers will occur only to the extent necessary and subject to appropriate confidentiality and data protection safeguards, in compliance with Art. 6(1)(f) GDPR (legitimate interests) or other applicable lawful bases.
Compliance with the laws: we may disclose your personal data to third parties where necessary to comply with legal obligations under Art. 6(1)(c) GDPR, including to comply with applicable laws and regulatory requirements (e.g., tax reporting) and respond to valid legal requests, such as court orders, subpoenas, or lawful requests from public authorities.
Protection and safety: we may disclose your personal data to third parties where necessary to protect vital interests, including to act in emergency situations to safeguard life or physical integrity under Art. 6(1)(d) GDPR (vital interests).
Service providers and professional advisors
We may share your personal data with carefully selected providers and professional advisors, such as:
- Authentication & Infrastructure: Firebase (Google), MongoDB Atlas, AWS S3
- Analytics & Monitoring: Mixpanel, Sentry, Datadog, Google Analytics for Firebase
- Data warehousing: Google BigQuery
- Attribution & deep-linking: AppsFlyer, Branch Metrics
- Session recording: Datadog Session Replay
- Advertising platforms: Meta Platforms
- Communications: Pushwoosh, Crisp Chat
- Payments: RevenueCat, Apple App Store, Google Play Store
- AI Services: Google Gemini, OpenAI (Fallback), ROXFIT AI API (Primary)
- Third-Party Integrations (User-Initiated): Strava, Garmin Connect, Apple Health, Google Fit
- Search & Social: Typesense, GetStream
- Development & Operations: Cloudflare Workers, Slack
We do not sell your personal data for monetary consideration. All service providers engaged by us process personal data on our behalf under Data Processing Addendums that satisfy the requirements of Art. 28 UK GDPR / EU GDPR, we apply data minimisation so that only the information necessary to deliver each service is shared, and third-party integrations that fall outside that scope are user-controlled and require your explicit consent.
If you are a California resident, please note that the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), defines "sale" and "share" more broadly than the ordinary meaning of those words. In particular, our disclosure of hashed identifiers to Meta Platforms for the purpose of building Custom Audiences and lookalike audiences for cross-context behavioural advertising may be treated as a "share" under the CCPA/CPRA notwithstanding the absence of monetary consideration. You have the right to opt out of this activity at any time, without affecting your access to the Services, by using the "Personalised ads" control in Settings → Privacy & Data (which functions as our "Do Not Sell or Share My Personal Information" opt-out) or by emailing hello@roxfit.app.
With your consent: where you explicitly consent (Art. 6(1)(a) GDPR), we may share your personal data with third parties or entities of your choosing.
International data transfers
The Company has service providers in the European Union, United States and UK. Personal information may be transferred to or from the United States or other locations outside of your state, province, country or other governmental jurisdiction where privacy laws may not be as protective as those in your jurisdiction.
Primary data processing locations in the EU and UK
- MongoDB Atlas: can be configured for EU regions
- GetStream: EU regions available
- Crisp Chat: France (EU)
- Typesense: configurable location
- Meta Platforms Ireland Limited (Ireland, EEA)
Primary data processing locations in the USA
- Firebase/Google Cloud: USA (EU regions available)
- AWS S3: configurable region
- Mixpanel: USA
- Sentry: USA
- Pushwoosh: USA
- RevenueCat: USA
- Google Gemini: USA
- OpenAI: USA
- ROXFIT AI API: USA (Render.com)
- Strava: USA
- Garmin: USA
- Google Fit: USA
- Meta Platforms, Inc.: USA
- Datadog, Inc.: USA
- AppsFlyer: USA
- Branch Metrics, Inc.: USA
- Google BigQuery: USA
- Cloudflare: global network
Legal mechanism for international data transfers
In case your personal data is provided to third parties outside the EEA, we will implement appropriate safeguards to protect your personal data, including Standard Contractual Clauses as adopted by the European Commission. Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.
All United States-based service providers engaged by ROXFIT utilize EU-approved Standard Contractual Clauses to ensure lawful international data transfers. Specific arrangements include:
- Google: data processing terms incorporate EU-approved Standard Contractual Clauses.
- AWS: GDPR compliance is ensured through the AWS Data Processing Addendum.
- Meta Inc.: Meta Platforms Ireland Limited (EEA users): for the Meta Pixel and other Business Tools processing where Meta Ireland is the counterparty, the transfer from ROXFIT to Meta Ireland is intra-EEA and no additional transfer safeguard is required for that leg. Any onward transfer by Meta from the EEA to the United States is made by Meta under its own safeguards, including Meta's intra-group EU Standard Contractual Clauses and Meta Platforms, Inc.'s certification under the EU-U.S. Data Privacy Framework.
- AppsFlyer: mobile-attribution and install-measurement processor. AppsFlyer is engaged under its published Data Processing Addendum (available at https://www.appsflyer.com/legal/dpa/), which is incorporated by reference into the AppsFlyer Terms of Use and includes the EU Standard Contractual Clauses and UK IDTA / UK Addendum for international transfers.
- Datadog, Inc.: application-performance monitoring, error tracking, and Session Replay processor. Datadog is engaged under its published Data Processing Addendum (available at https://www.datadoghq.com/legal/data-processing-addendum/), incorporated by reference into its Master Subscription Agreement. Datadog is certified under the EU-U.S. Data Privacy Framework; the DPA additionally includes the EU SCCs and UK IDTA / UK Addendum.
- Branch Metrics, Inc.: deep-linking and mobile-attribution processor. Branch is engaged under its published DPA, incorporated by reference into its Terms of Service, with the SCCs and UK Addendum for international transfers.
- Google BigQuery (Google LLC / Google Cloud EMEA Limited): analytics data warehouse; server-side event storage for our own product analytics. Google BigQuery is engaged under the Google Cloud Data Processing Addendum, which is auto-incorporated into the Google Cloud Terms of Service.
- Google Analytics for Firebase (Google LLC): app analytics. Governed by the Google Cloud Data Processing Addendum and the Google Analytics Data Processing Terms.
United States transfers under UK GDPR. For UK users, our upload of hashed identifiers to Meta Platforms, Inc. for Customer List Custom Audiences is a restricted transfer to the United States. The transfer safeguard we rely on is the UK Data Transfer Addendum inside Meta's Data Processing Terms, which is incorporated by reference into our Meta Business Tools relationship. Meta Platforms, Inc. is currently certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework for Non-HR data; where the UK Extension to the DPF is not listed for Meta Platforms, Inc., the UK Data Transfer Addendum is the operative safeguard.
The United States transfers to other processors. AppsFlyer, Branch, Datadog, Google Cloud (BigQuery), Google Analytics for Firebase, Mixpanel and Sentry may process data in the United States. Where any such transfer is a restricted transfer under UK GDPR, we rely on the UK IDTA or the UK Addendum to the EU Standard Contractual Clauses, and, where applicable, the DPF certification of the recipient. Datadog is certified under the EU-U.S. DPF; the DPF Extension status of each recipient is reviewed on our vendor register at least annually.
Adequacy Decisions
Transfers of personal data to countries recognized as providing an adequate level of data protection are permitted based on adequacy decisions issued by the European Commission or relevant authorities:
- United Kingdom: adequacy decision in place.
- Switzerland: adequacy decision in place.
Data retention practices
ROXFIT implements comprehensive data deletion and retention procedures to respect user privacy and comply with applicable data protection regulations, including the right to erasure. This involves a) user-requested deletion and b) automatic data retention and deletion.
User-requested deletion
Users may delete their accounts at any time. When you initiate account deletion via the "Delete Account", that deletion is permanent and cannot be undone. Upon confirmation, ROXFIT deletes all user-related data, including but not limited to:
- User profile and account information
- User settings and preferences
- Completed workouts, workout history, performance data, personal bests, and streaks
- Created workout plans and scheduled workouts
- Device registrations and OAuth tokens (e.g., Strava, Garmin)
- Synced workout data and event registrations
- Collections, deep link history, and chat sessions
External service cleanup: data stored on third-party services is also removed as part of the deletion process:
- Firebase authentication: user account deleted
- AWS S3: profile images deleted
- Pushwoosh: user unregistered
- Typesense: user removed from search functionality
- GetStream: user feed deleted
- Analytics: future tracking stopped
Anonymization (non-deletion): certain information may be anonymized to preserve data integrity, including:
- Race results (user identifiers removed, results preserved for leaderboard integrity)
- Chat messages (user identifiers removed while maintaining conversation context)
- Deep links (user identifiers removed for analytics attribution)
The complete user-requested deletion process is executed within approximately one minute. Data is immediately removed from primary systems. Database backups containing deleted accounts are securely overwritten within 30 days.
Automatic data retention and deletion
ROXFIT retains personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements and policies. Once data reaches the end of its retention period, ROXFIT either securely deletes it or anonymizes it to ensure that it can no longer be used to identify any individual.
Inactive users.
- Accounts are considered inactive after 4 (four) years of no login or app usage.
- Inactive accounts are marked for deletion, and users are notified via email with the option to reactivate the account.
- Users are given a 30-day grace period to reactivate their account.
- If no reactivation occurs within the grace period, the account is permanently deleted following the comprehensive deletion procedures.
Data is immediately removed from primary systems. Database backups containing deleted accounts are securely overwritten within 30 days.
General data retention practices
We will retain and use your personal data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Please see the table below:
| Purpose of personal data retention | Retention period |
|---|---|
| Account management & authentication | For the duration of your ROXFIT account, plus 12 months following account deletion for backup, audit and reactivation purposes |
| Advertising audiences | We refresh the uploaded audience approximately every 30 days and retain it only while the advertising purpose continues. When you object, withdraw consent, delete your account, or are placed on our suppression list, we remove you from the active audience within approximately 30 days. |
| Service delivery | For the duration of your ROXFIT account, plus 12 months following account deletion |
| Platform analytics and improvement | Analytics events are retained for 25 months from collection (aligned to Google Analytics for Firebase default retention); user identifiers are removed on account deletion and only aggregate data is retained thereafter |
| Platform maintenance & performance | Crash reports and error logs are retained for 90 days from collection; performance metrics are retained for 13 months |
| Communication with Users | For the duration of your ROXFIT account |
| User support | 3 years from the last interaction with the support team, or such longer period as is necessary to resolve any open matter or comply with legal obligations |
| Billing and payment processing | 6 years from the end of the accounting period in which the transaction occurred, in line with UK statutory record-retention requirements under the Companies Act 2006 and VAT legislation |
| Security and fraud prevention | 12 months from collection for security event logs; longer where required to investigate an incident or defend a legal claim |
| Compliance with legal and regulatory requirements | For the period required by the applicable law (typically 6 years for tax and accounting records, and shorter or longer periods for other regulatory obligations) |
| Defending or resolving legal claims | For the applicable statutory limitation period plus one year (in the United Kingdom, 6 years for contractual claims under the Limitation Act 1980) |
| Social and community features | For the duration of your ROXFIT account; on account deletion, social posts are anonymised (identifiers removed, content preserved for community integrity) or deleted where anonymisation is not appropriate |
| Cookies & other tracking technologies implementation | Session cookies expire on session end. Persistent cookies expire at intervals disclosed in our Cookie Policy, and in any event no later than 13 months from the date of your consent |
| Data anonymization for analytics and ML training | Anonymised aggregate data is retained indefinitely for model improvement; the underlying identifiable data is deleted or anonymised at the point of anonymisation and in any event on account deletion |
Information security
We employ industry standard security measures designed to protect the security of all information submitted through the Services. We implement a comprehensive set of technical and organizational security measures to ensure the confidentiality, integrity, and availability of personal data, in accordance with the General Data Protection Regulation (GDPR). These measures include, but are not limited to:
Data encryption and secure transmission: all data is encrypted in transit and at rest, ensuring that information is protected when transmitted over networks and when stored. For example, sensitive data is always encrypted end-to-end while in transit.
Access control: access to personal data is restricted on a need-to-know basis. Only authorized personnel can access user data according to their role and responsibilities.
Account and authentication security: user accounts are protected by secure authentication processes, and sensitive credentials are stored and managed safely.
Database and file storage protection: databases and file storage systems are secured with encryption, network safeguards, and routine backups to prevent data loss.
Monitoring and incident detection: systems are continuously monitored to detect and respond to potential security incidents promptly.
Third-party service management: all third-party service providers are carefully selected, and agreements are in place to ensure they comply with applicable data protection regulations. We conduct regular security audits regarding vendor compliance. ROXFIT concludes Data Processing Agreements (DPAs) with all third-party service providers who process personal data on our behalf. These agreements ensure that:
- personal data is processed only in accordance with ROXFIT's instructions and GDPR requirements.
- service providers implement appropriate technical and organizational measures to protect personal data.
- data is not used for unauthorized purposes, shared with others, or retained longer than necessary.
- any subcontractors used by the service provider are also bound by equivalent data protection obligations.
While we take reasonable steps to protect your personal data, no system can be completely secure. Therefore, we encourage users to take precautions to protect their own information, including maintaining the confidentiality of login credentials. In order to protect you and your data, we may suspend your use of any of the Services, without notice, pending an investigation, if any breach of security is suspected.
Updating personal data
If any of the personal data that you have provided to us changes, for example if you change your email address or if you wish to cancel any request you have made of us, or if you become aware we have any inaccurate personal data about you, please let us know by sending an email to hello@roxfit.app. We will not be responsible for any losses arising from any inaccurate, inauthentic, deficient or incomplete personal data that you provide to us.
Children's Privacy
ROXFIT does not knowingly collect any Personal Data from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.
Our priority is adding protection for children while using the Internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.
If you are under the age of majority in your jurisdiction of residence, you may use the Services only with the consent of or under the supervision of your parent or legal guardian. Consistent with the requirements of the GDPR, if we learn that we have received any information directly from a child under age 13 without first receiving his or her parent's verified consent, we will use that information only to respond directly to that child (his or her parent or legal guardian) to inform the child that he or she cannot use the Sites and subsequently we will delete that information.
Advertising
We do not use your account information to direct advertising to anyone under 18, and we exclude users we know to be under 18 from the audiences we share with Meta.
Your Rights and Choices
Under the General Data Protection Regulation (GDPR), you have certain rights concerning your personal information. You may request that we take the following actions in relation to the personal data we hold about you:
Opt-out:
- stop using your personal data for direct marketing and advertising, including matched and lookalike audiences on Meta, whether that use relies on your consent or on our legitimate interests. We may still send you service-related and other non-marketing messages.
- opt out of analytics and session recording. You can turn off analytics tracking (Mixpanel, Firebase, Datadog) and Datadog Session Replay at any time via Settings → Privacy & Data → Analytics.
Access: provide details about how we process your personal information and give you access to it. You can view the following data in-app:
- profile information in Settings
- workout history and performance data
- race results and personal bests
- training plans and schedules
Complete data export available via support request (JSON format).
Request: you have the right to receive your personal data in a structured, commonly used, and machine-readable format. If you wish, you can also request that we transfer this data directly to another data controller, where technically feasible.
Correct: update or correct any inaccuracies in your personal data. You can edit your data directly in-app:
- profile information (name, email, birthday, gender, height, weight)
- bio and social profile
- privacy settings (profile visibility, workout/race sharing)
- notification preferences
- unit preferences (metric / imperial)
Delete: remove your personal information from our records. In certain circumstances, you have the right to request the deletion of your personal data. This may apply if:
- your data is no longer necessary for the purposes for which it was collected.
- you object to the processing, and there are no overriding legitimate grounds for the processing.
- your data has been unlawfully processed.
Please note that this right is not absolute and may be subject to exceptions, such as compliance with legal obligations or the establishment, exercise, or defense of legal claims. Some data is anonymized rather than deleted for data integrity (race leaderboards retain anonymized results). The in-app "Delete Account" button in Settings deletes user profile and account:
- Removes all workouts and training data
- Deletes race results and performance history
- Clears OAuth tokens and third-party connections
- Removes from search indices (Typesense)
- Deletes activity feed presence (GetStream)
- Cancels subscriptions (RevenueCat)
- Unregisters from push notifications (Pushwoosh)
- Process completes in < 1 minute
- Covers 20+ database collections and external services
Transfer: send you or a third party a machine-readable copy of your personal data. A JSON export of all user data is available via support request, including profile, workouts, races, settings and training plans, in a machine-readable format for transfer to other services.
Restrict: you have the right to request the restriction of processing of your personal data in certain situations, such as:
- when you contest the accuracy of the data, for a period enabling us to verify its accuracy.
- when you object to the processing, pending verification of whether our legitimate grounds override your rights.
- when the processing is unlawful, and you request restriction instead of erasure.
While the processing is restricted, we will only store your personal data and will not process it further unless specific conditions apply.
Object: you have the right to object to the processing of your personal data based on our legitimate interests (Art. 6(1)(f) of the GDPR), unless we can demonstrate compelling legitimate grounds for the processing that override your rights and freedoms. In particular, you can manage your data directly in-app:
- Analytics Opt-Out
- Advertising (you have the right to object at any time to our use of your personal data for direct marketing and advertising, including the creation of matched and lookalike audiences on Meta)
- Push Notifications
- Social Features
- Third-Party Integrations
To further exercise any of these rights, you may contact us at hello@roxfit.app. We may need to request specific information from you to verify your identity and process your request. In some cases, applicable laws may require or allow us to decline your request. If we are unable to comply, we will explain the reason, subject to any legal restrictions.
If you have concerns about how we handle your personal information or our response to your requests, you may contact us at hello@roxfit.app or file a complaint with the data protection authority in your jurisdiction.
Updates to this Privacy Policy
We reserve the right to update and change this Policy in order to reflect any changes to the way in which we process your personal data or changing legal requirements. We regularly update our Privacy Policy. We will notify you of any changes by posting the new Privacy Policy on this page. We will let you know prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.
Contact information
We welcome your comments or questions about this Policy, and you may contact us at the following address: hello@roxfit.app