Effective July 12, 2026
Privacy Policy
1. Overview
Xenos Fit is built on a straightforward principle: we collect as little data as possible, we store it as safely as we can, and we do not sell it, share it for advertising, or use it for any purpose other than providing you with a coaching service.
This Privacy Policy explains what data we collect, how we use it, who we share it with, and what rights you have over it. It applies to your use of the Xenos Fit web application at xenos.fit and any related services (collectively, the “Service”).
2. Who we are
The Service is operated by Xenos Solutions (“we,” “us,” or “our”). To contact us with privacy questions or requests, use the contact form.
3. Our approach to personal data
We believe the least-collected data is the safest data. Our design reflects this:
- —We ask only for information that is directly necessary to provide you with personalized coaching.
- —We actively encourage you to use an alias email address, a first name that is not your legal name, and an approximate year of birth rather than your exact birth date. Any name you give us is the name we use; we have no way to verify it and no interest in doing so.
- —We do not use your workout data, chat conversations, or other information you share with Casey to advertise to you. We do not sell your data. We do not share your coaching content with employers, insurers, or any third party for commercial purposes.
- —We operate on the assumption that stored data can be breached. That assumption shapes every decision about what we collect and how we store it.
4. Data we collect
Data you provide directly
- —Account information. An email address (which may be an alias), a display name (which may be any name you choose), and a year of birth (which may be approximate).
- —Health and fitness information. Information you share with Casey about your training history, physical condition, injuries, limitations, and goals. This may include sensitive health-related information. You choose what to share; nothing in this category is required beyond what you volunteer in conversation.
- —Workout logs. Records of exercise sessions you log through the Service, including exercises, sets, reps, weights, and any notes you add.
- —Voice call content. If you use the voice call feature, your call is processed to generate a transcript and extract coaching-relevant information. The transcript is used to build and update your coaching profile.
Data collected automatically
- —Usage data. Basic information about how you interact with the Service, such as which features you use and when. Most of this data is collected by our own infrastructure. We also use Vercel Web Analytics, a cookieless analytics service that reports aggregate page traffic without tracking you individually or across other sites.
- —Authentication data. Session tokens and related authentication information necessary to keep you logged in.
Data we do not collect
- —We do not collect your legal name.
- —We do not collect precise geolocation.
- —We do not place advertising tracking pixels or third-party analytics cookies.
- —We do not collect payment card information directly; payments are handled by our payment processor (see Section 6).
5. How we use your data
We use the data we collect for the following purposes:
- —Providing the Service. Processing your workout logs, generating and updating your training plan, enabling Casey to give you contextually relevant coaching, and sending you service-related communications (such as your onboarding code or account confirmation).
- —Improving safety and reliability. Monitoring for errors, investigating abuse, and maintaining the security of the Service.
- —Product feedback surveys. We may contact you to request feedback about your experience. You may opt out of these messages at any time.
- —Legal compliance. Retaining or disclosing data as required by applicable law, including in response to lawful requests from law enforcement.
We do not use your data to train AI models beyond what is necessary to provide your personalized coaching experience within the Service.
6. Third-party data processors
We use the following third-party services to operate the Service. Each receives only the data necessary for their specific function.
| Processor | Purpose | Data involved |
|---|
| Supabase | Database and authentication | All stored user data; authentication tokens |
| Anthropic | AI coaching responses and plan generation | Your messages, workout logs, and coaching profile context sent to generate responses |
| OpenAI | Semantic search (embeddings) and voice transcription | Anonymized text summaries of workout sessions; audio from voice input |
| Retell AI | Voice call infrastructure | Audio and transcripts of voice calls |
| Resend | Transactional email | Email address; email content (onboarding, notifications) |
| Vercel | Application hosting and delivery | Request logs; no persistent user data stored |
| Stripe | Payment processing | Payment card information and billing details; we never see or store raw card data |
We do not share your data with any other third parties for commercial purposes. We select processors on the basis of their security and privacy practices and enter into data processing agreements where required.
7. Operator access to your data
The Service is operated by a small team. On rare occasions, an operator may need to access individual user data to investigate a bug, respond to a support request, or troubleshoot a problem.
We have implemented the following controls around this access:
- —Every instance of direct access to your personal data is logged in an internal audit table before access occurs. The log records who accessed what, when, and why.
- —We use a privacy-first admin interface that shows system health information without personal content. Direct access to your data is only escalated when the system-level view is insufficient.
- —Access is limited to what is necessary for the specific purpose.
We will never sell or share your personal data with advertisers, data brokers, or marketing companies.
8. Data retention
- —Active accounts. We retain your data for as long as you have an active account with us.
- —Inactive accounts. If you stop using the Service, we retain your data for up to 1 year from your last activity, so that if you return, your workout history and coaching context are still there. Any activity on your account resets this period. If you do not return within 1 year, your data is deleted.
- —Account deletion by you. If you request deletion of your account, we will delete your personal data within 7 days of receiving and verifying your request. Submit requests via the contact form.
- —Account termination by us. If we terminate your account, we retain your data for up to 30 days for abuse investigation and dispute resolution purposes, after which it is deleted.
- —Legal requirements. We may retain data longer than the above periods if required to do so by law.
9. Data security
We take reasonable technical and organizational measures to protect your data, including:
- —Encryption of data in transit (HTTPS).
- —Row-level security on all database tables containing user data, ensuring users can only access their own records.
- —Server-side data access only; no personal data is queried directly from your browser using public-facing credentials.
- —An internal audit log for all administrative access to personal data.
No system is perfectly secure. We encourage you to use an alias email address and a pseudonym, as described in Section 3. This limits the value of your data in the event of a breach.
10. Your rights
You have the following rights with respect to your personal data:
- —Access. You may request a summary of what personal data we hold about you.
- —Correction. You may ask us to correct inaccurate data.
- —Deletion. You may request that we delete your account and associated data. See Section 8 for timing.
- —Opt out of survey and update emails. You may opt out of survey requests and product update emails at any time using the unsubscribe link in those emails or by contacting us.
To exercise any of these rights, use the contact form. We will respond within 7 days.
Virginia residents may also have additional rights under the Virginia Consumer Data Protection Act (VCDPA), including the right to appeal a decision we make about your data request.
11. Children’s privacy
The Service is intended for users 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we become aware that we have collected data from a user under 18, we will delete it promptly.
12. Changes to this policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by email before the changes take effect. The effective date at the top of this page reflects the date of the most recent update.
13. Contact
For privacy questions, data requests, or any other inquiry, use our contact form. We aim to respond within 7 days.