Privacy Policy

Last updated: 15.07.2026 · Version: 2.1

General

This Privacy Policy ("Policy") describes how we collect and use your personal data in connection with ROXFIT website, application and services. The terms "ROXFIT", "we", "us", or "our" refer to ROXFIT LIMITED, registered under the laws of the United Kingdom.

Scope

This Policy applies to the ROXFIT website (https://www.roxfit.app/ - the "Website"); mobile application (the "App"); the service offerings available via the Website and App (collectively - the "Services"). The Services, together with our App and Website, are referred to as the "Platform".

This Privacy Policy does not constitute, create, or form part of any contract or warranty between you and ROXFIT. This Policy is provided for informational purposes under the applicable privacy laws and regulations.

Who is responsible for your data

For the purposes of applicable data protection laws (in particular, the General Data Protection Regulation (EU) 2016/679 ("GDPR")), your data will be controlled by ROXFIT, which provides the Platform to you as a Controller of your personal data.

Controller details

Registered name: ROXFIT LIMITED.
Registered address: 128 City Road, London, United Kingdom, EC1V 2NX
General contact address: hello@roxfit.app
Privacy support: support@roxfit.app

Failure to provide personal data

Please read this Privacy Policy and our Terms of Use carefully before using the Services. If you do not agree with the Terms of Use, you should not use the Services. For information about how we process your personal data, please refer to the Privacy Policy.

If we are required by law to collect personal data, or if it is necessary to process your requests or fulfill a contract with you, and you do not provide the requested data, we may be unable to carry out your instructions or meet our contractual obligations. In such cases, we may need to terminate our engagement or the contract, but we will inform you of this decision at that time.

Key terms and definitions

Personal data: any information relating to an identified or identifiable natural person ("Data subject"). For the purposes of GDPR, personal data means any information relating to you such as a name, surname, gender, age, health information, preferences etc.

Processing: any operation or set of operations which is performed on personal data or on sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.

Data controller: the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of the processing of personal data.

You: any individual accessing the Platform ("Visitor") or obtaining the Services ("User"), or otherwise interacting with us directly or indirectly, including as a prospective user ("Prospective user"), current or former User, or suggested athlete ("Athlete").

Services: all features, tools, content, and functionalities provided through the Platform. This includes, but is not limited to, enabling users to create, record, store, discover, share, and review workouts and related performance data, as well as access aggregated event and season-level race results.

Advertising Effective Date: means 15 July 2026, being the date the version of this Privacy Policy that introduced the Meta advertising processing described below first took effect.

Website: the ROXFIT website accessible from https://www.roxfit.app/.

Website visitor: a person who visits ROXFIT's website.

Cookies: text files that are stored on a website visitor's computer or mobile device by a website's server.

Table of contents

Sources of personal data

We obtain personal data from the following sources:

Directly from you: when you fill in the registration form on the Platform, create a user profile, enter your personal profile information, interact with the AI assistant in the chat, record race results, log your workouts or exercise your privacy rights (e.g. access, deletion of personal data).

Automatically through your use of our services: when users open or navigate the app, ROXFIT automatically logs usage events and feature interactions, records crash reports if errors occur, stores user preferences, workout data, and cached content as users update settings or complete workouts, and registers push notification tokens when notifications are enabled, all to ensure app functionality, improve user experience, and maintain stability, with optional analytics tracking that users can disable at any time.

ROXFIT also collects personal data from device and platform providers, such as authentication status, device information, and system settings, as well as from inferred sources, including performance trends and user percentiles derived from workout history, to support app functionality and feature personalization.

Third-party and partner sources: ROXFIT may also collect personal data from third-party integrations with user consent, including health and fitness metrics from Apple Health and Google Fit, workout data from Strava and Garmin Connect, and profile information from Google Sign-In and Apple Sign-In, to provide personalized workouts, track progress, and enable app functionality.

Why we process your data

We process personal data for the following purposes:

Advertising and audience matching: to promote ROXFIT and reach existing and prospective users, we use your contact details to create matched audiences ("Custom Audiences") and similar ("lookalike") audiences on Meta platforms (Facebook and Instagram).

Account management & authentication: to implement user authentication and login, manage and customize profile, reset password, recover account, track the acceptance of Terms of service.

Service delivery: to track workout and workout history, generate and coach AI-powered workouts, track race and personal best results, enable social features (following, activity feed, community), create and schedule training plans.

Platform analytics and improvement: to ensure usage analytics (with opt-out in Settings), adopt feature measurement, monitor performance.

Platform maintenance & performance: to report and fix bugs and crashes, monitor performance.

Communication with Users: to provide you with push notifications for workouts, races, community activity, send emails (both transactional and, where applicable, marketing communications about ROXFIT features, offers and updates), provide you with in-app messages and announcements and support (Crisp Chat).

User support: to implement your rights under GDPR and other applicable laws, including the right to access, correct, delete, or export your personal data, the right to object to or restrict processing, and the right to withdraw consent.

Billing and payment processing: to manage subscription, to process in-app purchases and track payment history.

Security and fraud prevention: to detect abuse (name change patterns, race result fraud), monitor errors and system alerts, detect suspicious activity.

Compliance with legal and regulatory requirements: to comply with legal obligations, such as responding to lawful requests from authorities, maintaining accurate records for accounting or tax purposes and fulfilling regulatory requirements.

Defending or resolving legal claims: to defend our rights, resolve disputes, including litigation, investigations, or regulatory inquiries.

Social and community features: to enable social interactions within the app, including profile visibility, following systems, comments, activity feeds, leaderboards, and other community features, in accordance with your privacy settings and preferences.

Cookies & other tracking technologies implementation: to enable the use of cookies and other tracking technologies which further will be used for authentication, analytics, remote config, crash analytics, user preferences, settings, cached data, feature adoption, bug detection, crash reports, push notification delivery, maintaining app state across sessions.

Data anonymization for analytics and ML training: to remove identifiers from personal data and preserve its integrity in order to improve the Platform and develop features (based on anonymized analytics with opt-out), ensure machine learning model training (anonymized data).

Types of personal data & legal basis for processing

Below is a list of the categories of personal data we may collect and process about you:

Type of personal data processedData subjectsPurposeLegal basis
Core user data
Identity data: first name, last name, email, username, birthday, gender, profile photoUsers, AthletesAccount management & authentication; communication with Users; user support; compliance; legal claims; social and community features; marketingArt. 6(1)(a) (consent) - regarding marketing emails; Art. 6(1)(b) (contract performance); Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legitimate interests)
Authentication data: Firebase UID, OAuth tokens (Google Sign-In, Apple Sign-In, Strava, Garmin)UsersAccount management & authentication; security and fraud preventionArt. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests)
Communications data: emails, in-app chat messages, support tickets, user feedback, or attached files provided during support interactionsUsers, AthletesUser support; compliance; legal claimsArt. 6(1)(b) (contract performance); Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legitimate interests)
Payment data: first name, last name, payment history, subscription details, billing address (if applicable), and limited payment metadataUsersBilling and payment processing; compliance; legal claimsArt. 6(1)(b) (contract performance); Art. 6(1)(c) (legal obligation); Art. 6(1)(f) (legitimate interests)
Profile data: height (cm), weight, bio, country, city, Instagram handle, profile imageUsersAccount management & authenticationArt. 6(1)(b) (contract performance)
Location data: timezone, timezone offset (no precise GPS tracking)UsersAccount management & authentication; service deliveryArt. 6(1)(b) (contract performance)
Device data: platform (iOS/Android), brand, OS version, model name, app version, build numberUsers, Platform visitorsAccount management & authentication; service deliveryArt. 6(1)(b) (contract performance)
Health and fitness data
Workout data: completed workouts, duration, calories burned, exercise types, modalitiesUsersService deliveryArt. 6(1)(b) (contract performance)
Health metrics: weight, height, steps, workout energy burned (via Apple Health/Google Fit - READ_WRITE permissions)UsersService deliveryArt. 6(1)(b) (contract performance)
Performance data: race results, personal bests, workout history, streak trackingUsersService delivery; data anonymization for analytics and ML trainingArt. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests)
Biometric data: motion data, activity recognition (via device health integrations)UsersService deliveryArt. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent)
Social & community interaction data
Social & community interaction data: information about a user's profile visibility, connections, activity feed, posts, comments, and interactions within the app's social features, photosUsers, AthletesSocial and community featuresArt. 6(1)(f) (legitimate interests); Art. 6(1)(a) (consent)
When you choose to post feedback, reviews, or comments within the app or on our community channels, this information becomes publicly visible to other users. Please note that any personal data you choose to include in such posts will be visible to others. We recommend that you avoid including any sensitive or personal information in public feedback.
Cookie & tracking technologies data
Core identifiers and device information: minimal core identifiers and device information - such as user ID, app session state, device type, OS version, and notification permissionsUsers, Platform visitorsCookies & other tracking technologies implementation; service deliveryArt. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests)
AI & chat communications data
Chat sessions: user messages to AI coach, AI responses, conversation summariesUsersPlatform analytics and improvement; data anonymization for analytics and ML trainingArt. 6(1)(f) (legitimate interests)
Workout generation: user preferences, fitness level, physical limitations, workout requestsUsersPlatform analytics and improvementArt. 6(1)(f) (legitimate interests)
Behavioral data: app usage patterns, feature interactions, screen viewsUsers, Platform visitorsPlatform analytics and improvementArt. 6(1)(f) (legitimate interests)
Settings & preferences
User settings: unit preferences (metric/imperial), notification preferences, workout settings, profile visibilityUsersAccount management & authentication; service deliveryArt. 6(1)(b) (contract performance)
Notification tokens: push notification device tokensUsersCommunication with UsersArt. 6(1)(b) (contract performance); Art. 6(1)(f) (legitimate interests)
Analytics preference: user opt-out choice for analytics, privacy settingsUsersPlatform analytics and improvementArt. 6(1)(f) (legitimate interests)
Third-party integration data
Strava: athlete ID, activities, privacy settings, auto-sync preferencesUsersService deliveryArt. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent); Art. 6(1)(b) (contract performance)
Garmin: activities, manual sync dataUsersService deliveryArt. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent); Art. 6(1)(b) (contract performance)
Apple Health / Google Fit: workout data, steps, weight, heightUsersService deliveryArt. 6(1)(a) (consent); Art. 9(2)(a) (explicit consent); Art. 6(1)(b) (contract performance)
Advertising / audience-matching data
Meta Custom Audiences data: hashed email address and, where used, hashed first name, used to create and refresh Meta Custom Audiences and lookalike audiencesUsersAdvertising and audience matchingArt. 6(1)(f) UK GDPR (legitimate interests) - for UK users in the existing base (registered before the Advertising Effective Date), subject to the unconditional right to object at any time under Art. 21(2) UK GDPR. Art. 6(1)(a) UK GDPR / EU GDPR (consent) - for (i) UK users registered on or after the Advertising Effective Date, and (ii) all EEA users, regardless of registration date, captured through the in-app consent flow and withdrawable at any time. EEA users in the existing base (registered before the Advertising Effective Date) are excluded from the Meta Custom Audiences upload until they have given consent through the in-app consent flow. ROXFIT does not process EEA users' data for this purpose on the basis of legitimate interests.
AppsFlyer and device advertising identifiers: Apple IDFA (iOS, subject to App Tracking Transparency consent); Google AAID (Android); device model and OS version; install and first-open timestamps; ad-click data received from ad networks; IP address at install (used briefly for fraud detection); and post-install conversion events configured by ROXFITUsersAdvertising and audience matchingArt. 6(1)(a) UK GDPR / EU GDPR (consent) - for all users, regardless of registration date or location, captured on iOS through Apple's App Tracking Transparency prompt and on Android through the in-app consent flow, and withdrawable at any time. Users who decline are not tracked; AppsFlyer's SDK falls back to platform-level privacy-preserving measurement (Apple SKAdNetwork / Google Privacy Sandbox) without personal-data processing.
We apply a single legal basis per user for the Meta Custom Audiences and lookalike processing described in the first row above, and we do not switch basis for the same processing of the same user. UK users in the existing base are processed on the basis of our legitimate interests, subject to your unconditional right to object at any time under Art. 21(2) UK GDPR. UK users registering on or after the Advertising Effective Date, and all EEA users regardless of registration date, are processed only where they have given consent through the in-app consent flow, which they can withdraw at any time. For the AppsFlyer / device-identifier row, all users are processed on the basis of consent regardless of location or registration date.
Analytics and technical data
Analytics events: user actions, feature usage, screen viewsUsersPlatform analytics and improvement; data anonymization for analytics and ML trainingArt. 6(1)(f) (legitimate interests)
Error tracking: crash reports, error logsUsers, Platform visitorsPlatform maintenance & performance; platform analytics and improvementArt. 6(1)(f) (legitimate interests)
Performance metrics: user percentile (0-99) for sampling and feature rolloutUsers, Platform visitorsPlatform maintenance & performance; platform analytics and improvementArt. 6(1)(f) (legitimate interests)

The use of Cookies & other tracking technologies

ROXFIT uses "cookies" - small text files stored on your computer or mobile device by our website's server, and other limited tracking technologies to ensure smooth platform functionality and enhance your user experience.

Certain cookies and similar technologies are essential to enable performance of the Platform and are processed on the legal basis of contract performance (Art. 6(1)(b) of the GDPR).

Other cookies and tracking tools are used to improve our website and tailor content, based on our legitimate interest in optimizing functionality, performance, and security (Art. 6(1)(f) of the GDPR). Within the app, analytics tracking (via Mixpanel, Firebase and Datadog) is conducted under our legitimate interest (Art. 6(1)(f) of the GDPR) and includes a clear opt-out option in Settings → Privacy & Data → "Help Improve ROXFIT", allowing users to disable analytics at any time without affecting app functionality. Crash reporting (Sentry) is used solely to detect and fix technical issues, with all personally identifiable information automatically removed.

On our Website we use the Meta Pixel, a technology provided by Meta that uses cookies and similar identifiers to measure the effectiveness of our advertising and to help build advertising audiences. For visitors in the United Kingdom and the European Economic Area, the Meta Pixel is not loaded and does not store or read any information on your device until you give your consent through our cookie banner (Art. 6(1)(a) GDPR; Regulation 6 PECR / Art. 5(3) ePrivacy Directive). You can withdraw your consent at any time, as easily as you gave it, through the cookie settings.

See our Cookie Policy for details.

Automated decisions

According to Art. 22 of the GDPR, the data subject shall have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning him or her or similarly significantly affects him or her.

The Company does NOT make any decisions based solely on automated processing, including profiling, which produces legal effects concerning data subjects.

How and when we share your information

Below are the circumstances under which personal data may be shared:

Corporate transaction: in the event of a potential or actual corporate transaction (e.g., a merger, acquisition, reorganization, sale of assets, or insolvency proceeding), we may transfer your personal data to relevant parties involved in the transaction. Such transfers will occur only to the extent necessary and subject to appropriate confidentiality and data protection safeguards, in compliance with Art. 6(1)(f) GDPR (legitimate interests) or other applicable lawful bases.

Compliance with the laws: we may disclose your personal data to third parties where necessary to comply with legal obligations under Art. 6(1)(c) GDPR, including to comply with applicable laws and regulatory requirements (e.g., tax reporting) and respond to valid legal requests, such as court orders, subpoenas, or lawful requests from public authorities.

Protection and safety: we may disclose your personal data to third parties where necessary to protect vital interests, including to act in emergency situations to safeguard life or physical integrity under Art. 6(1)(d) GDPR (vital interests).

Service providers and professional advisors

We may share your personal data with carefully selected providers and professional advisors, such as:

We do not sell your personal data for monetary consideration. All service providers engaged by us process personal data on our behalf under Data Processing Addendums that satisfy the requirements of Art. 28 UK GDPR / EU GDPR, we apply data minimisation so that only the information necessary to deliver each service is shared, and third-party integrations that fall outside that scope are user-controlled and require your explicit consent.

If you are a California resident, please note that the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), defines "sale" and "share" more broadly than the ordinary meaning of those words. In particular, our disclosure of hashed identifiers to Meta Platforms for the purpose of building Custom Audiences and lookalike audiences for cross-context behavioural advertising may be treated as a "share" under the CCPA/CPRA notwithstanding the absence of monetary consideration. You have the right to opt out of this activity at any time, without affecting your access to the Services, by using the "Personalised ads" control in Settings → Privacy & Data (which functions as our "Do Not Sell or Share My Personal Information" opt-out) or by emailing hello@roxfit.app.

With your consent: where you explicitly consent (Art. 6(1)(a) GDPR), we may share your personal data with third parties or entities of your choosing.

International data transfers

The Company has service providers in the European Union, United States and UK. Personal information may be transferred to or from the United States or other locations outside of your state, province, country or other governmental jurisdiction where privacy laws may not be as protective as those in your jurisdiction.

Primary data processing locations in the EU and UK

Primary data processing locations in the USA

Legal mechanism for international data transfers

In case your personal data is provided to third parties outside the EEA, we will implement appropriate safeguards to protect your personal data, including Standard Contractual Clauses as adopted by the European Commission. Please contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

All United States-based service providers engaged by ROXFIT utilize EU-approved Standard Contractual Clauses to ensure lawful international data transfers. Specific arrangements include:

United States transfers under UK GDPR. For UK users, our upload of hashed identifiers to Meta Platforms, Inc. for Customer List Custom Audiences is a restricted transfer to the United States. The transfer safeguard we rely on is the UK Data Transfer Addendum inside Meta's Data Processing Terms, which is incorporated by reference into our Meta Business Tools relationship. Meta Platforms, Inc. is currently certified under the EU-U.S. Data Privacy Framework and the Swiss-U.S. Data Privacy Framework for Non-HR data; where the UK Extension to the DPF is not listed for Meta Platforms, Inc., the UK Data Transfer Addendum is the operative safeguard.

The United States transfers to other processors. AppsFlyer, Branch, Datadog, Google Cloud (BigQuery), Google Analytics for Firebase, Mixpanel and Sentry may process data in the United States. Where any such transfer is a restricted transfer under UK GDPR, we rely on the UK IDTA or the UK Addendum to the EU Standard Contractual Clauses, and, where applicable, the DPF certification of the recipient. Datadog is certified under the EU-U.S. DPF; the DPF Extension status of each recipient is reviewed on our vendor register at least annually.

Adequacy Decisions

Transfers of personal data to countries recognized as providing an adequate level of data protection are permitted based on adequacy decisions issued by the European Commission or relevant authorities:

Data retention practices

ROXFIT implements comprehensive data deletion and retention procedures to respect user privacy and comply with applicable data protection regulations, including the right to erasure. This involves a) user-requested deletion and b) automatic data retention and deletion.

User-requested deletion

Users may delete their accounts at any time. When you initiate account deletion via the "Delete Account", that deletion is permanent and cannot be undone. Upon confirmation, ROXFIT deletes all user-related data, including but not limited to:

External service cleanup: data stored on third-party services is also removed as part of the deletion process:

Anonymization (non-deletion): certain information may be anonymized to preserve data integrity, including:

The complete user-requested deletion process is executed within approximately one minute. Data is immediately removed from primary systems. Database backups containing deleted accounts are securely overwritten within 30 days.

Automatic data retention and deletion

ROXFIT retains personal data only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, comply with legal obligations, resolve disputes, and enforce our agreements and policies. Once data reaches the end of its retention period, ROXFIT either securely deletes it or anonymizes it to ensure that it can no longer be used to identify any individual.

Inactive users.

Data is immediately removed from primary systems. Database backups containing deleted accounts are securely overwritten within 30 days.

General data retention practices

We will retain and use your personal data to the extent necessary to comply with our legal obligations (for example, if we are required to retain your data to comply with applicable laws), resolve disputes, and enforce our legal agreements and policies. Please see the table below:

Purpose of personal data retentionRetention period
Account management & authenticationFor the duration of your ROXFIT account, plus 12 months following account deletion for backup, audit and reactivation purposes
Advertising audiencesWe refresh the uploaded audience approximately every 30 days and retain it only while the advertising purpose continues. When you object, withdraw consent, delete your account, or are placed on our suppression list, we remove you from the active audience within approximately 30 days.
Service deliveryFor the duration of your ROXFIT account, plus 12 months following account deletion
Platform analytics and improvementAnalytics events are retained for 25 months from collection (aligned to Google Analytics for Firebase default retention); user identifiers are removed on account deletion and only aggregate data is retained thereafter
Platform maintenance & performanceCrash reports and error logs are retained for 90 days from collection; performance metrics are retained for 13 months
Communication with UsersFor the duration of your ROXFIT account
User support3 years from the last interaction with the support team, or such longer period as is necessary to resolve any open matter or comply with legal obligations
Billing and payment processing6 years from the end of the accounting period in which the transaction occurred, in line with UK statutory record-retention requirements under the Companies Act 2006 and VAT legislation
Security and fraud prevention12 months from collection for security event logs; longer where required to investigate an incident or defend a legal claim
Compliance with legal and regulatory requirementsFor the period required by the applicable law (typically 6 years for tax and accounting records, and shorter or longer periods for other regulatory obligations)
Defending or resolving legal claimsFor the applicable statutory limitation period plus one year (in the United Kingdom, 6 years for contractual claims under the Limitation Act 1980)
Social and community featuresFor the duration of your ROXFIT account; on account deletion, social posts are anonymised (identifiers removed, content preserved for community integrity) or deleted where anonymisation is not appropriate
Cookies & other tracking technologies implementationSession cookies expire on session end. Persistent cookies expire at intervals disclosed in our Cookie Policy, and in any event no later than 13 months from the date of your consent
Data anonymization for analytics and ML trainingAnonymised aggregate data is retained indefinitely for model improvement; the underlying identifiable data is deleted or anonymised at the point of anonymisation and in any event on account deletion

Information security

We employ industry standard security measures designed to protect the security of all information submitted through the Services. We implement a comprehensive set of technical and organizational security measures to ensure the confidentiality, integrity, and availability of personal data, in accordance with the General Data Protection Regulation (GDPR). These measures include, but are not limited to:

Data encryption and secure transmission: all data is encrypted in transit and at rest, ensuring that information is protected when transmitted over networks and when stored. For example, sensitive data is always encrypted end-to-end while in transit.

Access control: access to personal data is restricted on a need-to-know basis. Only authorized personnel can access user data according to their role and responsibilities.

Account and authentication security: user accounts are protected by secure authentication processes, and sensitive credentials are stored and managed safely.

Database and file storage protection: databases and file storage systems are secured with encryption, network safeguards, and routine backups to prevent data loss.

Monitoring and incident detection: systems are continuously monitored to detect and respond to potential security incidents promptly.

Third-party service management: all third-party service providers are carefully selected, and agreements are in place to ensure they comply with applicable data protection regulations. We conduct regular security audits regarding vendor compliance. ROXFIT concludes Data Processing Agreements (DPAs) with all third-party service providers who process personal data on our behalf. These agreements ensure that:

While we take reasonable steps to protect your personal data, no system can be completely secure. Therefore, we encourage users to take precautions to protect their own information, including maintaining the confidentiality of login credentials. In order to protect you and your data, we may suspend your use of any of the Services, without notice, pending an investigation, if any breach of security is suspected.

Updating personal data

If any of the personal data that you have provided to us changes, for example if you change your email address or if you wish to cancel any request you have made of us, or if you become aware we have any inaccurate personal data about you, please let us know by sending an email to hello@roxfit.app. We will not be responsible for any losses arising from any inaccurate, inauthentic, deficient or incomplete personal data that you provide to us.

Children's Privacy

ROXFIT does not knowingly collect any Personal Data from children under the age of 13. If you think that your child provided this kind of information on our website, we strongly encourage you to contact us immediately and we will do our best efforts to promptly remove such information from our records.

Our priority is adding protection for children while using the Internet. We encourage parents and guardians to observe, participate in, and/or monitor and guide their online activity.

If you are under the age of majority in your jurisdiction of residence, you may use the Services only with the consent of or under the supervision of your parent or legal guardian. Consistent with the requirements of the GDPR, if we learn that we have received any information directly from a child under age 13 without first receiving his or her parent's verified consent, we will use that information only to respond directly to that child (his or her parent or legal guardian) to inform the child that he or she cannot use the Sites and subsequently we will delete that information.

Advertising

We do not use your account information to direct advertising to anyone under 18, and we exclude users we know to be under 18 from the audiences we share with Meta.

Your Rights and Choices

Under the General Data Protection Regulation (GDPR), you have certain rights concerning your personal information. You may request that we take the following actions in relation to the personal data we hold about you:

Opt-out:

Access: provide details about how we process your personal information and give you access to it. You can view the following data in-app:

Complete data export available via support request (JSON format).

Request: you have the right to receive your personal data in a structured, commonly used, and machine-readable format. If you wish, you can also request that we transfer this data directly to another data controller, where technically feasible.

Correct: update or correct any inaccuracies in your personal data. You can edit your data directly in-app:

Delete: remove your personal information from our records. In certain circumstances, you have the right to request the deletion of your personal data. This may apply if:

Please note that this right is not absolute and may be subject to exceptions, such as compliance with legal obligations or the establishment, exercise, or defense of legal claims. Some data is anonymized rather than deleted for data integrity (race leaderboards retain anonymized results). The in-app "Delete Account" button in Settings deletes user profile and account:

Transfer: send you or a third party a machine-readable copy of your personal data. A JSON export of all user data is available via support request, including profile, workouts, races, settings and training plans, in a machine-readable format for transfer to other services.

Restrict: you have the right to request the restriction of processing of your personal data in certain situations, such as:

While the processing is restricted, we will only store your personal data and will not process it further unless specific conditions apply.

Object: you have the right to object to the processing of your personal data based on our legitimate interests (Art. 6(1)(f) of the GDPR), unless we can demonstrate compelling legitimate grounds for the processing that override your rights and freedoms. In particular, you can manage your data directly in-app:

To further exercise any of these rights, you may contact us at hello@roxfit.app. We may need to request specific information from you to verify your identity and process your request. In some cases, applicable laws may require or allow us to decline your request. If we are unable to comply, we will explain the reason, subject to any legal restrictions.

If you have concerns about how we handle your personal information or our response to your requests, you may contact us at hello@roxfit.app or file a complaint with the data protection authority in your jurisdiction.

Updates to this Privacy Policy

We reserve the right to update and change this Policy in order to reflect any changes to the way in which we process your personal data or changing legal requirements. We regularly update our Privacy Policy. We will notify you of any changes by posting the new Privacy Policy on this page. We will let you know prior to the change becoming effective and update the "Last updated" date at the top of this Privacy Policy. You are advised to review this Privacy Policy periodically for any changes. Changes to this Privacy Policy are effective when they are posted on this page.

Contact information

We welcome your comments or questions about this Policy, and you may contact us at the following address: hello@roxfit.app

ROXFITFree on Google Play Get