Effective July 12, 2026

Privacy Policy

1. Overview

Xenos Fit is built on a straightforward principle: we collect as little data as possible, we store it as safely as we can, and we do not sell it, share it for advertising, or use it for any purpose other than providing you with a coaching service.

This Privacy Policy explains what data we collect, how we use it, who we share it with, and what rights you have over it. It applies to your use of the Xenos Fit web application at xenos.fit and any related services (collectively, the “Service”).

2. Who we are

The Service is operated by Xenos Solutions (“we,” “us,” or “our”). To contact us with privacy questions or requests, use the contact form.

3. Our approach to personal data

We believe the least-collected data is the safest data. Our design reflects this:

4. Data we collect

Data you provide directly

Data collected automatically

Data we do not collect

5. How we use your data

We use the data we collect for the following purposes:

We do not use your data to train AI models beyond what is necessary to provide your personalized coaching experience within the Service.

6. Third-party data processors

We use the following third-party services to operate the Service. Each receives only the data necessary for their specific function.

ProcessorPurposeData involved
SupabaseDatabase and authenticationAll stored user data; authentication tokens
AnthropicAI coaching responses and plan generationYour messages, workout logs, and coaching profile context sent to generate responses
OpenAISemantic search (embeddings) and voice transcriptionAnonymized text summaries of workout sessions; audio from voice input
Retell AIVoice call infrastructureAudio and transcripts of voice calls
ResendTransactional emailEmail address; email content (onboarding, notifications)
VercelApplication hosting and deliveryRequest logs; no persistent user data stored
StripePayment processingPayment card information and billing details; we never see or store raw card data

We do not share your data with any other third parties for commercial purposes. We select processors on the basis of their security and privacy practices and enter into data processing agreements where required.

7. Operator access to your data

The Service is operated by a small team. On rare occasions, an operator may need to access individual user data to investigate a bug, respond to a support request, or troubleshoot a problem.

We have implemented the following controls around this access:

We will never sell or share your personal data with advertisers, data brokers, or marketing companies.

8. Data retention

9. Data security

We take reasonable technical and organizational measures to protect your data, including:

No system is perfectly secure. We encourage you to use an alias email address and a pseudonym, as described in Section 3. This limits the value of your data in the event of a breach.

10. Your rights

You have the following rights with respect to your personal data:

To exercise any of these rights, use the contact form. We will respond within 7 days.

Virginia residents may also have additional rights under the Virginia Consumer Data Protection Act (VCDPA), including the right to appeal a decision we make about your data request.

11. Children’s privacy

The Service is intended for users 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from a user under 18, we will delete it promptly.

12. Changes to this policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email before the changes take effect. The effective date at the top of this page reflects the date of the most recent update.

13. Contact

For privacy questions, data requests, or any other inquiry, use our contact form. We aim to respond within 7 days.

Last updated: July 12, 2026 · Questions? Contact us.