1. Who We Are
TheRox("we," "us," or "our") operates the TheRox mobile application and the website at therox.app (together, the "Service"). The data controller responsible for your personal data is Anirban Das and Vinícius Ferreira Bandeira do Nascimento, joint data controllers operating TheRox as individuals resident in Poland, reachable at [email protected].
By creating an account or using TheRox, you agree to this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Website & Waitlist
When you join our waitlist at therox.app, we collect your email address and your confirmation that you are 18 or older, so we can notify you at launch. We use this only to contact you about TheRox; you can ask us to remove it at any time.
To confirm you own the address, we send a one-time confirmation email and only add you to the list once you click the link in it. To keep the waitlist secure and prevent abuse, we also process limited technical data such as your IP address, retained only as long as necessary for that purpose. We do not use this data for any other reason, and we do not store your location.
2.2 Account Information
- Email address (required for authentication)
- Password, stored as a cryptographic hash. We never store or see your actual password
- Display name (first name and last initial, used in challenges)
2.3 Fitness Data You Create
- Exercise folders and video links (your Vault)
- Workout session logs (date, duration, folder used, optional notes)
- Weekly workout plans and schedules
- AI Form Tracker results (rep counts, form scores, check results)
2.4 Camera Data (AI Form Tracker)
When you use the AI Form Tracker, your device camera captures frames that are processed entirely on your device using TensorFlow Lite (BlazePose). No images, video frames, or camera data are ever uploaded, stored, or transmitted to us or any third party. Only the resulting numbers (rep counts, form scores, joint-angle check results) are saved to your account.
2.5 Challenge Data (Gym Rat)
When you join a challenge, limited data is visible to co-members:
- Shared:display name (e.g. "Ana S."), points, and per-workout log details (folder name, optional note, duration, date)
- Never shared: email, AI Form Tracker scores, Vault contents, workout plans, or any other profile data
This boundary is enforced server-side; our API is architecturally unable to return more than these fields to other users.
2.6 Technical Data
- Device type and OS version (compatibility, crash reporting)
- App version
- Anonymous, aggregated usage events, only if you consent to analytics (see Section 6)
2.7 What We Do NOT Collect
- Location data (no GPS, no check-ins)
- Health data from wearables or HealthKit/Health Connect
- Biometric identifiers (pose estimation produces geometry, not biometrics)
- Photos or camera frames (processed on-device and discarded)
- Contacts, social accounts, or financial/card data (Stripe handles payments)
3. How We Use Your Information
We use your information solely to:
- Provide and maintain the Service
- Notify you about the waitlist and launch, if you signed up
- Show your stats, history, and streaks on your dashboard
- Show your limited challenge data to co-members (Section 2.5)
- Process subscription payments through Stripe
- Send essential transactional emails (password reset, receipts)
- Improve the Service through anonymous analytics (with consent)
We do not serve targeted ads, build ad profiles, sell or rent your data, or make automated decisions that affect you.
4. Legal Bases (EU/EEA, GDPR)
- Consent: waitlist signup, account creation, challenge participation, analytics
- Contract: providing the Service you signed up for
- Legitimate interest: essential security and fraud-prevention
You may withdraw consent at any time (Section 8).
5. Third-Party Services
| Service | Purpose | Data shared |
|---|---|---|
| Supabase | Database & authentication | Account and fitness data (encrypted at rest) |
| Vercel | Website hosting | Standard request logs (IP, user agent) |
| Resend | Transactional & waitlist email | Email address |
| Stripe | Payments | Email for receipts; Stripe handles all card data |
| YouTube API | Video metadata | Video URLs (to fetch title, thumbnail, duration) |
| PostHog | Privacy-friendly analytics (only if you consent) | Anonymous usage events |
We do not share your data with advertising networks, data brokers, or social media companies.
6. Cookies & Analytics
The website uses only essential cookies by default, which need no consent. Any privacy-friendly analytics are off until you explicitly accept them via our cookie banner, and can be declined with no loss of functionality. See our Cookie Policy. We never use advertising cookies.
7. Data Retention & Erasure
We keep your data while your account is active. If you delete your account or withdraw consent, we delete or anonymize your personal data within 7 days: the strictest global standard, applied to everyone regardless of location, except where law requires us to retain specific records. Challenge leaderboard entries for deleted accounts are anonymized (shown as "Deleted User") to preserve leaderboard integrity for remaining members.
8. Your Rights
8.1 Everyone
- Access: a copy of the data we hold about you
- Correction: fix inaccurate data
- Deletion: delete your account and associated data
- Export: your data in a machine-readable format
- Withdraw: leave any challenge or withdraw consent
To exercise any right, email [email protected]. We action deletion requests within 7 days.
8.2 EU/EEA (GDPR)
You also have the right to restrict or object to processing, to data portability, and to lodge a complaint with your local supervisory authority (for us, the Polish Personal Data Protection Office (UODO)).
8.3 California (CCPA/CPRA)
You have the right to know, delete, correct, and to non-discrimination for exercising your rights. We do not sell or share personal information as those terms are defined under the CCPA/CPRA, and never have.
8.4 India (DPDPA 2023)
- Right to access a summary of your personal data and how it is processed
- Right to correction, completion, and erasure
- Right to withdraw consent as easily as it was given; on withdrawal we erase associated data within 7 days
- Right to nominate another person to exercise your rights
- Right of grievance redressal: contact our grievance point at [email protected] before approaching the Data Protection Board of India
9. Age Requirement
TheRox is intended only for adults 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we learn we have, we delete it promptly. If you believe a minor has provided us data, contact [email protected].
10. International Transfers
Your data may be processed in countries other than your own, including the United States, via our infrastructure providers. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses. Our establishment for governing-law purposes is in Poland.
11. Security
Data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Access is restricted by Row Level Security so each user can reach only their own data. Passwords are hashed with bcrypt. No system is perfectly secure, but we apply industry-standard measures and maintain a breach-response plan (notification within 72 hours where required).
12. Changes
We may update this policy. We will post changes here and update the "Last updated" date; material changes will be notified in-app. Continued use after changes constitutes acceptance.
13. Contact
Questions? Email [email protected].
