Privacy Policy

Last Updated: February 18, 2026 · Effective Date: February 18, 2026

This Privacy Policy describes how Jessica He ("we," "us," or "our"), operating as a sole proprietorship, collects, uses, discloses, and protects your information when you use the Rex mobile application (the "App"). By using the App, you agree to the collection and use of information in accordance with this Privacy Policy.

We take your privacy seriously. Rex is a fitness and nutrition tracking application, and we understand that health and fitness data is deeply personal. This policy is designed to be transparent about exactly what data we collect, why we collect it, who we share it with, and what rights you have.

If you do not agree with the terms of this Privacy Policy, please do not access or use the App.


1. Information We Collect

We collect information in the following categories:

1.1 Account Information

When you create an account, we collect:

1.2 Health and Fitness Data

If you choose to connect Apple Health (iOS) or Health Connect (Android), we may read the following data from your device's health platform:

Important: Health data access is entirely optional. You must explicitly grant permission through your device's system-level health permissions. You can revoke this permission at any time through your device settings. We only read health data — we do not write to or modify your device's health records.

1.3 User-Provided Fitness and Nutrition Data

When you use the App, you may manually enter:

1.4 AI Interaction Data

When you use the AI chat feature ("Ask Rex"), we collect:

1.5 Device and Technical Information

We automatically collect limited technical information for crash reporting and app stability:

We do not collect: device advertising identifiers, precise geolocation, browsing history, contacts, call logs, SMS messages, or information from other apps on your device.

1.6 Barcode Scan Data

If you scan food barcodes, the barcode number is sent to a third-party food database to retrieve nutritional information. We do not store barcode scan history.


2. How We Use Your Information

2.1 Core App Functionality

2.2 AI-Powered Features

2.3 App Stability and Improvement

2.4 What We Do NOT Use Your Data For


3. How We Share Your Information

We share your information only with the following third-party service providers, solely to operate the App:

3.1 Clerk (Authentication)

3.2 Google Gemini API (AI Features)

3.3 Sentry (Crash Reporting)

3.4 Open Food Facts (Barcode Lookups)

3.5 Render (Backend Hosting)

3.6 RevenueCat (Subscription Management)

3.7 Apple / Google (OAuth Providers & Payment Processing)

We do not share, sell, rent, or trade your personal information with any other third parties. We do not share any Apple HealthKit or Health Connect data with third parties for advertising, marketing, or data brokerage purposes.


4. Apple HealthKit and Health Connect Compliance

4.1 HealthKit Data Use

In compliance with Apple's HealthKit guidelines:

4.2 Health Connect Data Use

In compliance with Google Health Connect requirements:


5. Data Storage and Security

5.1 Local Storage

The majority of your fitness and nutrition data (meals, workouts, body measurements, goals, preferences, chat history, and AI memory) is stored locally on your device using the device's application storage. This data does not leave your device unless you use AI features that transmit context to our servers.

Authentication tokens are stored in your device's secure enclave (iOS Keychain or Android Keystore) using encrypted storage.

5.2 Data in Transit

All data transmitted between the App and our servers is encrypted using HTTPS (TLS 1.2 or higher).

5.3 Backend Security

Our backend server implements:

5.4 Security Limitations

While we implement reasonable security measures, no method of electronic storage or transmission over the Internet is 100% secure. We cannot guarantee absolute security of your data. You use the App at your own risk.


6. Data Retention

6.1 Local Data

Data stored locally on your device persists until:

6.2 Account Data

Your Clerk account data is retained as long as your account is active. You may request account deletion by contacting us at [email protected].

6.3 AI Service Data

Chat messages, images, and audio sent to Google's Gemini API are subject to Google's data retention policies. Please refer to Google's AI terms of service and privacy policy for details on how Google handles this data.

6.4 Crash Reports

Crash report data sent to Sentry is retained according to Sentry's data retention policies (typically 90 days for error events on the free tier).


7. Your Rights and Choices

7.1 Access and Control

You have the following rights regarding your data:

7.2 California Residents — CCPA Rights

If you are a California resident, you have the following additional rights under the California Consumer Privacy Act (CCPA):

To exercise your CCPA rights, contact us at [email protected]. We will respond within 45 days.

Categories of Personal Information Collected (per CCPA definitions):

CCPA CategoryExamplesSold?Shared for Business Purpose?
IdentifiersUser ID, email addressNoYes (Clerk, Google)
Health informationSteps, heart rate, sleep, weightNoYes (Google Gemini, for AI features only)
Internet/electronic activityCrash logs, device typeNoYes (Sentry)
Fitness activityMeals, workouts, goalsNoYes (Google Gemini, for AI features only)
Audio/visualVoice recordings, food photosNoYes (Google Gemini, for AI features only)
InferencesAI-generated fitness suggestionsNoNo

7.3 Additional State Privacy Rights

Residents of Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws may have additional rights including data portability and the right to opt out of profiling. Contact us at [email protected] to exercise these rights.

7.4 International Users

The App is primarily designed for users in the United States. If you access the App from outside the United States, your data may be transferred to and processed in the United States, where data protection laws may differ from those in your country. By using the App, you consent to this transfer. If you are located in the European Economic Area (EEA) or United Kingdom (UK), please note that we may not fully comply with GDPR requirements at this time. If GDPR compliance is important to you, please contact us at [email protected] before using the App.


8. Children's Privacy

The App is not intended for use by anyone under the age of 16. We do not knowingly collect personal information from children under 16. If we become aware that we have collected personal information from a child under 16, we will take steps to delete that information as quickly as possible.

If you are a parent or guardian and believe your child has provided us with personal information, please contact us at [email protected].


9. Third-Party Links and Services

The App may contain links to or integrations with third-party services (Apple Health, Health Connect, Google Sign-In, Apple Sign-In). These third-party services have their own privacy policies, which we encourage you to review. We are not responsible for the privacy practices of any third-party services.


10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by:

Your continued use of the App after any changes constitutes your acceptance of the revised Privacy Policy. We encourage you to review this Privacy Policy periodically.


11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:

Jessica He
Email: [email protected]

For privacy-specific inquiries, please include "Privacy" in the subject line.


12. Summary of Data Practices

Data TypeCollected?Stored WhereShared WithCan You Delete?
Email / User IDYesClerk (cloud)Clerk, OAuth providerYes (contact us)
HealthKit / Health Connect dataOnly if you opt inDevice only (not stored by us)Google Gemini (for AI features)Disconnect in Settings
Meals, workouts, goalsYes (you enter it)Your device (local)Google Gemini (when using AI)Yes (in-app)
Weight / body measurementsYes (you enter it)Your device (local)Not sharedYes (in-app)
Chat messagesYes (when using AI)Your device (local) + Google GeminiGoogle GeminiYes (in-app)
Voice recordingsTemporarilyNot stored after transcriptionGoogle GeminiAutomatic
Food photosTemporarilyNot stored after analysisGoogle GeminiAutomatic
Crash reportsAutomaticSentry (cloud)Sentry (PII stripped)N/A
Barcode scansTemporarilyNot storedOpen Food FactsAutomatic
Subscription statusYesRevenueCat (cloud) + deviceRevenueCat, AppleVia App Store