TheRoxJoin Waitlist

Privacy Policy

Effective 2026-07-20 · Last updated July 21, 2026 · Version 1.0

We built one privacy program to the strictest global standard: GDPR (EU), CCPA/CPRA (US), and India's DPDPA 2023, so every user, everywhere, gets the same protection. We do not sell your data. We do not use it for advertising. We collect only what the Service needs.

1. Who We Are

TheRox("we," "us," or "our") operates the TheRox mobile application and the website at therox.app (together, the "Service"). The data controller responsible for your personal data is Anirban Das and Vinícius Ferreira Bandeira do Nascimento, joint data controllers operating TheRox as individuals resident in Poland, reachable at [email protected].

By creating an account or using TheRox, you agree to this Privacy Policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Website & Waitlist

When you join our waitlist at therox.app, we collect your email address and your confirmation that you are 18 or older, so we can notify you at launch. We use this only to contact you about TheRox; you can ask us to remove it at any time.

To confirm you own the address, we send a one-time confirmation email and only add you to the list once you click the link in it. To keep the waitlist secure and prevent abuse, we also process limited technical data such as your IP address, retained only as long as necessary for that purpose. We do not use this data for any other reason, and we do not store your location.

2.2 Account Information

  • Email address (required for authentication)
  • Password, stored as a cryptographic hash. We never store or see your actual password
  • Display name (first name and last initial, used in challenges)

2.3 Fitness Data You Create

  • Exercise folders and video links (your Vault)
  • Workout session logs (date, duration, folder used, optional notes)
  • Weekly workout plans and schedules
  • AI Form Tracker results (rep counts, form scores, check results)

2.4 Camera Data (AI Form Tracker)

When you use the AI Form Tracker, your device camera captures frames that are processed entirely on your device using TensorFlow Lite (BlazePose). No images, video frames, or camera data are ever uploaded, stored, or transmitted to us or any third party. Only the resulting numbers (rep counts, form scores, joint-angle check results) are saved to your account.

2.5 Challenge Data (Gym Rat)

When you join a challenge, limited data is visible to co-members:

  • Shared:display name (e.g. "Ana S."), points, and per-workout log details (folder name, optional note, duration, date)
  • Never shared: email, AI Form Tracker scores, Vault contents, workout plans, or any other profile data

This boundary is enforced server-side; our API is architecturally unable to return more than these fields to other users.

2.6 Technical Data

  • Device type and OS version (compatibility, crash reporting)
  • App version
  • Anonymous, aggregated usage events, only if you consent to analytics (see Section 6)

2.7 What We Do NOT Collect

  • Location data (no GPS, no check-ins)
  • Health data from wearables or HealthKit/Health Connect
  • Biometric identifiers (pose estimation produces geometry, not biometrics)
  • Photos or camera frames (processed on-device and discarded)
  • Contacts, social accounts, or financial/card data (Stripe handles payments)

3. How We Use Your Information

We use your information solely to:

  • Provide and maintain the Service
  • Notify you about the waitlist and launch, if you signed up
  • Show your stats, history, and streaks on your dashboard
  • Show your limited challenge data to co-members (Section 2.5)
  • Process subscription payments through Stripe
  • Send essential transactional emails (password reset, receipts)
  • Improve the Service through anonymous analytics (with consent)

We do not serve targeted ads, build ad profiles, sell or rent your data, or make automated decisions that affect you.

4. Legal Bases (EU/EEA, GDPR)

  • Consent: waitlist signup, account creation, challenge participation, analytics
  • Contract: providing the Service you signed up for
  • Legitimate interest: essential security and fraud-prevention

You may withdraw consent at any time (Section 8).

5. Third-Party Services

ServicePurposeData shared
SupabaseDatabase & authenticationAccount and fitness data (encrypted at rest)
VercelWebsite hostingStandard request logs (IP, user agent)
ResendTransactional & waitlist emailEmail address
StripePaymentsEmail for receipts; Stripe handles all card data
YouTube APIVideo metadataVideo URLs (to fetch title, thumbnail, duration)
PostHogPrivacy-friendly analytics (only if you consent)Anonymous usage events

We do not share your data with advertising networks, data brokers, or social media companies.

6. Cookies & Analytics

The website uses only essential cookies by default, which need no consent. Any privacy-friendly analytics are off until you explicitly accept them via our cookie banner, and can be declined with no loss of functionality. See our Cookie Policy. We never use advertising cookies.

7. Data Retention & Erasure

We keep your data while your account is active. If you delete your account or withdraw consent, we delete or anonymize your personal data within 7 days: the strictest global standard, applied to everyone regardless of location, except where law requires us to retain specific records. Challenge leaderboard entries for deleted accounts are anonymized (shown as "Deleted User") to preserve leaderboard integrity for remaining members.

8. Your Rights

8.1 Everyone

  • Access: a copy of the data we hold about you
  • Correction: fix inaccurate data
  • Deletion: delete your account and associated data
  • Export: your data in a machine-readable format
  • Withdraw: leave any challenge or withdraw consent

To exercise any right, email [email protected]. We action deletion requests within 7 days.

8.2 EU/EEA (GDPR)

You also have the right to restrict or object to processing, to data portability, and to lodge a complaint with your local supervisory authority (for us, the Polish Personal Data Protection Office (UODO)).

8.3 California (CCPA/CPRA)

You have the right to know, delete, correct, and to non-discrimination for exercising your rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and never have.

8.4 India (DPDPA 2023)

  • Right to access a summary of your personal data and how it is processed
  • Right to correction, completion, and erasure
  • Right to withdraw consent as easily as it was given; on withdrawal we erase associated data within 7 days
  • Right to nominate another person to exercise your rights
  • Right of grievance redressal: contact our grievance point at [email protected] before approaching the Data Protection Board of India

9. Age Requirement

TheRox is intended only for adults 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we learn we have, we delete it promptly. If you believe a minor has provided us data, contact [email protected].

10. International Transfers

Your data may be processed in countries other than your own, including the United States, via our infrastructure providers. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses. Our establishment for governing-law purposes is in Poland.

11. Security

Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is restricted by Row Level Security so each user can reach only their own data. Passwords are hashed with bcrypt. No system is perfectly secure, but we apply industry-standard measures and maintain a breach-response plan (notification within 72 hours where required).

12. Changes

We may update this policy. We will post changes here and update the "Last updated" date; material changes will be notified in-app. Continued use after changes constitutes acceptance.

13. Contact

Questions? Email [email protected].