Privacy Policy
Last updated: September 14, 2026
Data Controller
The data controller is MARECHAL OLIVIER EURL (SIREN: 991 984 477), operating under the trade name EVOX.
1. Data Collection
Evox is local-first: the app works without an account, and most of what you do never leaves your device. Here is everything we collect, and when:
- Workout data: Timer settings, workouts, completed sessions, personal records and benchmark results. Stored on your device. If you create an account, they are also sent to our servers so you can get them back on a new device.
- Account data (optional): Your email address, plus the identifier Apple or Google gives us if you use one of those sign-in buttons. Used for authentication, sync and account recovery — never for marketing.
- App preferences: Theme, language, accent color, and other settings you choose. Local to your device.
- AI coaching and generation (Vox): When you use Vox, generate a workout, or import one from text, the training data needed for that request (recent sessions, personal records, your stated goal) and the text you submit are sent to Anthropic's Claude API to produce the answer. Text only, and without your name or email address.
- Workout import from a photo: The text on your image is read directly on your device, and only the extracted text leaves the app — which is why import works offline. If on-device reading is unavailable, the image is sent to our server, read there, and the file is deleted immediately afterwards.
- Heart rate (Apple Watch): If you use the Evox watch app and allow it, we read your live heart rate from Apple Health during a session, in order to display it. It is shown on the watch and nowhere else: we never store it, never write anything back to Apple Health, and never send it to our servers.
- Workout videos: If you film yourself with the camera overlay, the video is saved to your device's photo library. It never reaches our servers.
- Analytics (PostHog): Usage events (screens opened, features used, timer types), attached to a random identifier rather than to your name or email. Processed by PostHog on EU servers.
- Advertising (AdMob): Google AdMob may collect device identifiers and usage data to serve ads to users without a subscription. On iOS 14.5+, you are asked for permission before any tracking occurs (App Tracking Transparency); if you decline, you still see ads, but non-personalized ones.
- Subscription (RevenueCat): Purchase history and subscription status are managed by RevenueCat. Your payment details are handled by Apple or Google and are never seen or stored by Evox.
- Crash reports and feedback: When the app hits an error, or when you send us feedback, we receive the error message, the screen involved, your device model, its OS version, the app version, and whatever you chose to write. These land in our private team messaging workspace.
- Newsletter (optional): If you subscribe on the website, we store your email address, the language of the edition you get and the page you signed up from. Those details also go to beehiiv, which sends the newsletter. Your address is not linked to your app account or to your usage data.
- No location data: We never access or store your location.
2. Data Storage
Evox is local-first, with cloud sync as an option you switch on by creating an account:
- Without an account, everything stays on your device. Nothing is sent to our servers.
- With an account, your workouts, sessions, personal records, scheduled sessions, programs and coaching data are also stored on our servers, so that changing device does not mean losing your history.
- Your data is never sold, and never shared with other athletes unless you deliberately share a workout.
- Uninstalling the app removes the local copy. If you have an account, use Athlete > Delete my account to erase the server copy as well.
3. Data Usage
Your data is used exclusively for:
- Running your timers, workouts and training history
- Backing up your data and syncing it across your devices, if you have an account
- Producing your coaching, generated workouts and imports, and counting the credits they consume
- Managing your subscription, and serving ads to users without one
- Understanding how the app is used so we can improve it
- Diagnosing crashes and answering the feedback you send us
4. Data Sharing
We never sell your data. We use the following third-party services, each for one specific job:
- Anthropic (AI): Runs Claude, the model behind Vox, workout generation and text import. Receives only the training data and text needed for the request, without your name or email. Anthropic is based in the United States, so this is a transfer outside the EEA, covered by the European Commission's standard contractual clauses. Anthropic states that data sent through their commercial API is not used to train their models.
- PostHog (analytics): Usage statistics that tell us which features actually get used. EU-hosted, and tied to a random identifier rather than to you.
- Google AdMob (advertising): Serves ads to users without a subscription. May use device identifiers for ad personalization if you grant permission via the iOS App Tracking Transparency prompt. You can withdraw that permission at any time in your device settings.
- RevenueCat (subscriptions): Manages in-app purchases and subscription status. Processes the purchase receipts issued by Apple and Google.
- Apple and Google (payments): Subscriptions and one-off purchases are sold and billed by the App Store or Google Play, which act as the seller. They set the price shown in your country and handle your payment method; we never see it.
- Resend (email): Sends the verification email when you sign in with an email address. That address is never used for marketing or added to the newsletter.
- beehiiv (newsletter): Sends the newsletter, the confirmation email that activates your subscription, and the one-click unsubscribe link in every email. Receives your email address, the language of your edition and the page you signed up from.
- Slack (support): Receives crash reports and the feedback you send from the app, in our private workspace. Slack is based in the United States, so this too is a transfer outside the EEA under standard contractual clauses.
5. Your Rights (GDPR)
Under GDPR, you have the right to:
- Access: Ask for a copy of the data attached to your account, and see your local data directly in the app.
- Rectification: Correct your workouts, records and preferences yourself, in the app.
- Erasure: Delete your account from Athlete > Delete my account. Your workouts, sessions, records, registered devices and coaching data are deleted with it.
- Portability: Get your training data in a reusable format — contact us and we will send it to you.
- Restriction and objection: Ask us to limit or stop a given processing. Ad tracking in particular can be switched off at any time in your device settings.
- Complaint: If you believe your rights are not being respected, you can lodge a complaint with the CNIL (cnil.fr), the French data protection authority, or with the supervisory authority of the country you live in.
6. Data Security
Traffic between the app and our servers is encrypted in transit with HTTPS, and reaching your account data requires a signed token tied to that account. The data that stays on your device is protected by your device's own security. No system is perfect, so we also keep the amount of data we hold down to what the features genuinely need.
7. Data Retention
We keep data only as long as it has a job to do:
- Account and training data: for as long as your account exists, and deleted when you delete it.
- Local data: on your device until you delete the item, or uninstall the app.
- AI request logs: we keep the text you submitted and the result, so we can diagnose bad answers and improve the prompts. They are attached to your account and deleted with it.
- Analytics events: kept by PostHog under their own retention policy, with no link to your identity.
- Crash reports and feedback: kept in our team workspace for as long as it takes to fix the problem.
- Newsletter: your email address is kept, by us and by beehiiv, while you are subscribed. One click in any email unsubscribes you; we then keep only a record that you did, so you are never emailed again, and erase it entirely on request.
8. Connected apps (MCP)
You may connect external AI assistants (Claude, ChatGPT, ...) to your Evox account via the Model Context Protocol (MCP). When you do so, the following applies:
Data accessible by the AI assistant:
- Read your training data: your profile, personal records, recent sessions, training aggregates, and active program. Only data tied to your account, never anyone else's.
- Create workouts in your library: the AI can add new workouts to your Evox library on your behalf. You can edit or delete them from the app at any time.
- Schedule sessions in your calendar: the AI can place workouts on future dates in your Evox calendar. You stay in control: you can remove or reschedule them from the app.
Your consent and control:
- You explicitly grant access via an OAuth login screen when connecting each AI assistant. You can grant only a subset of permissions if the assistant supports it.
- You can revoke any connection at any time from the Evox app: Athlete > Connected apps > Disconnect. Revocation is immediate and the AI loses access on its next call.
- Each AI assistant is a separate connection. Disconnecting one does not affect the others.
Third-party AI providers:
Once you connect an assistant, the data accessed by that assistant is sent to its provider (Anthropic for Claude, OpenAI for ChatGPT, etc.) for processing. We are not responsible for how each provider handles your data on their side — please refer to their privacy policy.
MCP-specific data retention:
- OAuth access tokens: 1 hour TTL, automatically rotated.
- OAuth refresh tokens: 30 days TTL, deleted when you disconnect.
- Connection records (OAuth client metadata): deleted when no active token remains.
- Workouts and sessions created via MCP are stored like any other workout in your library — they follow the general Evox data retention (deleted when you delete your account).
9. Contact
For any questions about this privacy policy or to exercise your rights, contact us at: contact@getevox.fit