Legal
Privacy Policy
Last updated: September 23, 2026
1. Who we are
ROX-strat ("the app," "we," "us") is a personal pacing tool for HYROX® and hybrid-fitness athletes, built for iOS and Apple Watch. ROX-strat is not affiliated with HYROX® or Hyrox World GmbH. HYROX® is a registered trademark of Hyrox World GmbH.
2. What data the app handles
Identity
- Apple Sign-In identifier — an opaque, app-specific user ID issued by Apple, which is what ties your account to you. Our server verifies the sign-in token your device sends it. That token can carry your email address; the server reads it only to complete the check, and does not store or log it. We never receive your name or your Apple ID password.
Data stored on our server
Signing in creates an account on the ROX-strat server at api.roxstrat.com, which runs on AWS in Frankfurt, in the EU. It holds:
- A random ROX-strat user id
- Your Apple Sign-In identifier
- Your engine profile — your division (sex, age group, Open or Pro), the benchmarks you enter, your race date, and your readiness score
- Your station personal records
- Your locked race plan
- Your PFT history
- Your race history
- Sign-in tokens — Apple's token for your account, kept only so we can revoke ROX-strat's Sign in with Apple access when you delete the account, and our own session tokens, stored hashed, which expire after 90 days
That is the whole list, and it is what lets your data follow you to a second device and come back after a reinstall. Your name, your email address, and your raw Apple Health samples — HRV, sleep, heart rate, workouts — never reach it. Like any web service, the server also keeps request logs, including your IP address, for 14 days to keep it secure and running. Your app preferences, such as the selected language, stay on the phone.
Health data (read-only, from Apple Health)
- Heart rate variability (HRV / SDNN)
- Sleep analysis
- Resting heart rate
- Running workouts and walking + running distance
Health data is read directly from Apple Health, used on your device to compute your readiness score and refine pacing projections. The samples themselves are never transmitted off your device; only the result, a single 0–100 readiness score, syncs to your account. You can revoke HealthKit permissions at any time in iOS Settings → Privacy & Security → Health → ROX-strat.
Strava data (optional, read-only)
If you connect Strava, the app reads your recent running activities to refine your pacing plan. The OAuth handshake goes through our Cloudflare Worker at strava-worker.roxstrat.workers.dev, which exists only to perform the token exchange so that the Strava client secret never lives in the app binary. The Worker does not log, persist, or forward any user data — it relays tokens straight back to your device.
Strava tokens are stored locally in the iOS Keychain. You can disconnect Strava at any time from the Profile screen, which deletes the tokens from your device.
Subscription state
ROX-strat uses RevenueCat to manage in-app purchases for ROX-strat Pro. RevenueCat receives your random ROX-strat user id and the Apple-issued purchase receipt — enough to verify your subscription. It does not receive any of your training data. See RevenueCat's privacy policy for details.
Push notifications (optional)
If you turn on notifications, three kinds are scheduled entirely on your device: a countdown as your race gets close, a reminder to re-run your PFT, and a heads-up before your free Pro trial ends. Nothing is sent anywhere to schedule them. Your race date and PFT results sync to your account like the rest of your training data; your trial start date stays on your phone. You can turn each of these three on or off individually in Settings.
Separately, you can opt in to occasional product announcements (a new feature, a new language). To make that possible, your device registers an anonymous push token with our Cloudflare Worker, along with your app version and in-app language — never your name, your Apple ID, or anything about your training. You can opt out of announcements on their own, without affecting the other three. Deleting your account removes this token from our systems.
3. What we do NOT collect
- No analytics SDKs (Firebase, Mixpanel, Amplitude, etc.)
- No advertising identifiers (IDFA)
- No crash-reporting third parties (we rely on Apple's built-in crash logs you opt into via iOS Settings)
- No location data
- No microphone, camera, or contacts access
- No tracking across other apps or websites
4. How your data is used
Everything described above is used for a single purpose: to give you a personalized pacing plan. There is no secondary use, no profiling for ads, no data brokers, and no sale of any data to third parties.
5. Data retention & deletion
You decide what is kept. You can:
- Sign out to remove the Apple ID association and session tokens from this device. The session on our server expires within 90 days.
- Delete the app, which removes all on-device caches.
- Delete your account via Profile → Delete Account. That wipes the app's data on your phone, deletes everything stored for you on our server, and revokes ROX-strat's Sign in with Apple access.
6. Children
ROX-strat is intended for users 13 years or older. We do not knowingly collect data from children under 13. If you believe a child has used the app, contact us and we will help walk through deleting their account.
7. International users
ROX-strat is available worldwide. Account data is stored on our server in the AWS Frankfurt region (eu-central-1), in the European Union, wherever you live.
8. Your rights (GDPR, CCPA, etc.)
Under GDPR, CCPA, and similar frameworks, you have the right to access, correct, port, or delete personal data we hold about you. Section 2 lists everything we hold. You can delete all of it yourself from Profile → Delete Account, as described in Section 5. For access, correction, or a copy of it, write to us at the address below.
9. Changes to this policy
If we materially change how data is handled, this page will be updated and the "Last updated" date at the top will move. Substantial changes will also be communicated inside the app on next launch.
10. Contact
Questions, requests, or concerns: hello@roxstrat.com