In short: Xenomere is a personal wellness notebook. We collect the data you enter or connect, use it to provide the service, and do not sell it or use it for advertising. Health data requires your explicit consent.

1. Controller

The data controller is:

Xenomere OÜ
Narva mnt 5, 10117 Tallinn, Estonia
Registry code: 17507482 (Estonian Business Register / Äriregister)
D-U-N-S: 988011860
VAT: not registered
Privacy contact: contact@xenomere.com

Supervisory authority: Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn — aki.ee

2. What the app is

Xenomere is a consumer wellness and self-tracking application (iOS, Android, and web). It is not a medical device and is not intended to diagnose, treat, cure, or prevent disease.

3. Data we collect

CategoryDataSourcePurpose
Account Email address, password hash, display name, optional phone number, time zone, plan and entitlement flags You (at registration) Account creation, authentication, service delivery
Profile & onboarding Age, sex, height, weight, goals, training experience, self-reported conditions, logistics, budget band You (onboarding survey) Personalisation of wellness estimates
Health & fitness Vitals (HRV, resting heart rate, sleep, steps, respiratory rate, temperature), workouts, nutrition logs, lab panels and marker values (including assay, specimen, fasting flag), body-scan photographs and derived estimates, questionnaire scores (e.g. PHQ-9, GAD-7), life-event and n-of-1 notes, compound/dose/vial notes you type You (manual entry), connected wearables, Apple Health, Health Connect, camera (body scan) Wellness tracking, trend analysis, decision-support estimates
Coach Messages you send and AI-generated replies You (chat input) AI wellness coaching
Device & technical IP address, user-agent, session cookie, optional push token Automatic (browser/app) Security, session management, push notifications
Payments Subscription status, Stripe customer/subscription IDs (web), Apple/Google original transaction IDs (native) Stripe, Apple, Google Subscription management. We never receive your full card number.

We do not collect precise location. We do not use advertising identifiers for tracking.

4. Special category data (GDPR Art. 9)

Health and fitness data is special-category data under GDPR Article 9. We process it on the basis of your explicit consent (Art. 9(2)(a) and Art. 6(1)(a)), collected at onboarding and again before AI sharing or HealthKit connection.

You may withdraw consent at any time in Settings. Withdrawal does not erase previously processed data until you delete the account.

Other legal bases:

5. Apple Health / HealthKit and Health Connect

If you enable Apple Health or Health Connect, we read only the types described in the system permission sheet — typically heart-rate variability, resting heart rate, sleep analysis, step count, active energy, heart rate, and body mass.

Purpose: display them to you and compute in-app wellness estimates. We do not write false samples. We do not store HealthKit data in iCloud. Denying permission leaves manual entry available. Health data is never used for advertising.

6. Photos and body scans

Body-scan photos are stored to provide body-composition estimates and your visual history. They are deleted with your account. They are sent to an external vision/AI provider only if you have enabled AI health-data sharing in Settings.

7. Compound and dose notes

These are user-generated records. We do not use them to offer substances for sale or to contact suppliers on your behalf.

8. Third-party recipients

RecipientRoleData shared
Cloud hosting provider Infrastructure (service provider) All app data stored on the server. EEA region. [TODO: name provider before publish]
Stripe, Inc. Payment processing (service provider) Subscription status, customer ID. Web purchases only. Card numbers never touch our servers.
Apple Inc. In-app purchase, HealthKit, push notifications (service provider) Transaction IDs, HealthKit data (with your permission), push tokens
Google LLC In-app purchase, Health Connect, push notifications (service provider) Transaction IDs, Health Connect data (with your permission), push tokens
Wearable operators Data source (their terms apply) Sync tokens and samples from providers you connect (e.g. Garmin, Oura, Whoop)
AI inference provider Coach and vision analysis (processor) Health-related prompts only after you enable AI health-data sharing. [TODO: name current provider and country before publish]
Email delivery provider OTP and transactional email (service provider) Email address. [TODO: name provider when OTP email is wired]

We require processors to protect data at least to the standard described in this policy, consistent with Apple's third-party protection requirements.

9. International transfers

If a processor is located outside the EEA, we use Standard Contractual Clauses (SCCs) approved by the European Commission, or rely on an adequacy decision where applicable. [TODO: confirm mechanism for current AI provider before publish]

10. Retention

11. Your rights

Under GDPR you have the right to:

How to exercise your rights:

We may need to verify your identity before processing a request. We respond within 30 days.

Complaint: You have the right to lodge a complaint with the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn — aki.ee.

12. Children

Xenomere is for people aged 18 or older. We do not knowingly collect data from anyone under 18. If we learn an account belongs to someone under 18, we delete it.

13. Automated estimates

Recovery scores, strain, diet scores, PhenoAge-style estimates, health-area scores, and similar figures are produced from your inputs by documented formulae. They are wellness decision-support estimates — not solely automated decisions producing legal effects under GDPR Article 22. You can ignore them. Methodology is described in-app where each score appears.

14. No sale of personal data

We do not sell personal data. We do not use health or fitness data for advertising, marketing, or data-mining.

15. Cookies

See our Cookie Policy. In short: we use only a strictly necessary session cookie. No analytics or tracking cookies.

16. Changes

We will post a new effective date on this page. Material changes to health-data uses will ask for consent again.

17. Contact

Xenomere OÜ
Narva mnt 5, 10117 Tallinn, Estonia
Email: contact@xenomere.com