This Privacy Policy explains how Axis X ("Axis X", "we", "us", or "our") collects, uses, shares, and protects your personal information when you visit our website, join the waitlist, or — once available — use the Axis X mobile application (collectively, the "Service").
We've tried to write this in plain language. Where we use defined terms, they're explained where they appear. If anything is unclear, you can always reach us at the contact address at the bottom of this page.
1.Who we are
Axis X is a wellbeing application designed to help women 35+ build and follow a personalized health system. The Service is operated by Axis X Limited, a company registered in England and Wales under company number 17435401, with its registered office at Crown House, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom.
Axis X Limited is the "controller" of your personal data — the entity that decides why and how it is processed. You can reach us about anything in this Policy at privacy@axisx.ai or by post at the address above.
If you're located in the European Economic Area (EEA), the United Kingdom, or Switzerland, references to GDPR apply equally to the UK GDPR and the Swiss FADP where relevant.
2.Information we collect
Information you give us directly
- Waitlist email address. When you join the waitlist, we collect your email address, the fact that you ticked the consent box, and the date and time you confirmed your subscription by clicking the link in our confirmation email (double opt-in).
- Account information. Once Axis X launches, we collect the information you provide when you create an account — for example, name, age range, and broad goals you describe.
- Health and wellbeing inputs. Information you choose to share inside the Service — including journal entries, mood logs, symptoms, cycle and hormone-related data, medications, supplements, sleep, food, exercise, and any uploaded documents such as lab results.
- Voice or text descriptions. If you describe your situation by voice or text, the content you submit is used to build your system. Voice recordings are used only to produce a transcript and are deleted from your device immediately after transcription; we do not store audio on our servers. Only the transcript is kept, as part of your account data.
- Communications. If you write to us, we keep a record of the message and any reply.
Information we receive from your device or third parties
- Device and usage information. Technical details such as device type, operating system version, app version, language, time zone, and information about how you use the Service.
- Apple Health. If you choose to connect Apple Health, we read only the categories you authorize in the iOS permission prompt. Axis X may request access to: sleep analysis, steps and distance, heart rate (including resting heart rate and heart rate variability), workouts and active energy, body weight, and cycle tracking (menstrual flow, symptoms and related data). Axis X does not write any data back to Apple Health. See Section 12 for the additional rules that apply to this data. If a similar platform becomes available on another operating system, the same approach will apply.
- Calendar. If you grant access, we may write reminders to your default calendar — we do not read calendar contents at MVP.
- Analytics. Aggregated, non-identifying analytics that help us understand how the Service is used.
3.How we use your information
We use your information to:
- Send you launch updates and a welcome email when Axis X is ready — only if you ticked the consent box when joining the waitlist and confirmed your address. Every email includes a one-click unsubscribe link.
- Provide and personalize the Service — including building your wellbeing system, generating routines, dashboards, and starting suggestions for movement and supplements.
- Surface insights, weekly recaps, and pattern analysis that depend on your tracked parameters.
- Improve the Service through aggregated, de-identified analysis of usage patterns and unmet needs.
- Communicate with you about the Service, security notices, and legal changes.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with applicable law, court orders, and lawful requests from public authorities.
We do not sell your personal information. We do not use your health data, journal content, or voice transcripts to train AI models — ours or anyone else's — and our AI provider is contractually prohibited from doing so (see Section 5). We do not run third-party advertising inside the Service.
4.Legal basis (for users in the EEA, UK, and Switzerland)
If you're in the EEA, UK, or Switzerland, we rely on the following legal bases under the GDPR / UK GDPR / FADP:
- Consent (Art. 6(1)(a))
- For the waitlist email, marketing communications, processing of health data (special category, Art. 9(2)(a)), connecting Apple Health, and sending your content to our AI provider for processing.
- Contract (Art. 6(1)(b))
- To provide the core Service you've requested once you become a user.
- Legitimate interests (Art. 6(1)(f))
- To improve the Service, prevent abuse, and keep our systems secure — balanced against your rights and freedoms.
- Legal obligation (Art. 6(1)(c))
- To comply with laws that apply to us.
You may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal.
5.How we share information
We share personal information only with the following categories of recipients, and only as needed:
- Service providers ("processors"). Hosting, email delivery, analytics, error monitoring, and the AI provider described below. They act under our instructions and are bound by data-processing agreements.
- Professional advisors. Lawyers, accountants, and auditors when needed.
- Authorities. When legally required to comply with valid requests, court orders, or to protect our rights, your safety, or the safety of others.
- Successors. If Axis X is involved in a merger, acquisition, or sale of assets, your information may transfer to the successor entity, which will continue to be bound by this Policy unless you're notified otherwise.
We do not sell or rent your personal information, and we do not share health-related data with third-party advertisers.
Waitlist and email delivery by MailerLite
Our waitlist and launch emails are run through MailerLite (UAB "MailerLite", J. Basanavičiaus g. 15, Vilnius, Lithuania), a European email-marketing service. When you submit the waitlist form, your email address is sent directly to MailerLite, which stores it, sends the confirmation and launch emails on our behalf, and records your consent and any unsubscribe. MailerLite acts as our processor under a data-processing agreement, hosts the data in the European Union, and may not use it for any purpose of its own. No MailerLite code runs on our website and no cookies are set by the form.
AI processing by Anthropic
Axis X uses large language models provided by Anthropic, PBC to understand what you tell it, build your wellbeing system, generate insights and recaps, and answer your questions. To do this, the relevant parts of your content — such as your voice transcript, journal entries, tracked values, connected health data and uploaded documents — are sent to Anthropic's API and processed on our behalf.
- Anthropic acts as our processor under a data-processing agreement and may use your data only to provide the service to us.
- Anthropic does not use your data to train its models. Under our commercial terms, inputs and outputs are not used for model training.
- Anthropic retains API inputs and outputs only for the limited period needed to operate the service and detect abuse, after which they are deleted. We do not send Anthropic your name, email address or account identifiers alongside your content.
- Anthropic processes data in the United States; the transfer safeguards in Section 9 apply.
We ask for your explicit permission before any of your health data is sent to Anthropic, and you can withdraw it at any time in the app's settings. Without it, features that depend on AI will not be available, but you can still use Axis X for manual tracking.
6.Data retention
- Waitlist emails: kept until launch; afterwards converted to your account email or deleted within 90 days if you don't sign up.
- Account and health data: kept while your account is active. You can export or delete your data at any time from in-app settings.
- Voice recordings: deleted from your device immediately after transcription; never stored on our servers. Transcripts are kept as part of your account data.
- Uploaded documents (e.g. lab result PDFs): kept while your account is active, or until you delete the individual upload in the app.
- Backups: deleted data may persist in encrypted backups for up to 30 days before being purged.
- Logs and operational data: typically retained 30–90 days, longer where required for security investigations.
7.Security
We use industry-standard technical and organizational measures to protect your information, including encryption in transit (TLS) and at rest, access controls, audit logging, and the principle of least privilege. Where possible, we process data on-device or in a privacy-preserving way.
No system is perfectly secure. If we ever experience a breach that affects your personal information, we will notify you and the relevant authorities as required by law.
8.Your privacy rights
Depending on where you live, you may have some or all of the following rights:
- Access — request a copy of the personal information we hold about you.
- Correction — ask us to correct information that is inaccurate or incomplete.
- Deletion — ask us to delete your information, subject to certain legal exceptions.
- Portability — receive a structured, machine-readable copy of your data.
- Objection & restriction — object to certain processing or request that we restrict it.
- Withdraw consent — at any time, where we rely on consent.
- Lodge a complaint — with your data protection authority. In the UK this is the Information Commissioner's Office (ICO): ico.org.uk/make-a-complaint, helpline 0303 123 1113, Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF. EEA residents can contact the supervisory authority of their country of residence. We'd appreciate the chance to address your concern first, but you don't have to contact us before going to the regulator.
To exercise any of these rights, contact us at the address in Section 14. We will respond within the time limits set by applicable law (one month under the UK GDPR and GDPR, extendable by two further months for complex requests; 45 days under the CCPA).
California residents have specific rights under the CCPA/CPRA, including the right to know what personal information we collect, the right to delete it, the right to correct inaccuracies, and the right to opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information as defined by the CCPA). We do not discriminate against you for exercising any of these rights.
9.International data transfers
Your personal information may be transferred to and processed in countries other than the one where you live. Where we transfer personal data out of the EEA, UK, or Switzerland, we use appropriate safeguards — typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and (where applicable) supplementary measures.
10.Cookies & tracking
Our website currently sets no cookies and uses no analytics or advertising trackers. The waitlist form sends only the email address you type, directly to MailerLite (see Section 5).
The website loads the Inter and Fraunces typefaces from Google Fonts. When your browser fetches them, Google receives your IP address and standard request information, which Google processes under its own privacy policy. No cookies are set by this request.
If we add analytics or other non-essential cookies in the future, we will show a consent banner that lets you accept or reject them before they are set, as required by UK and EU law. You can also control cookies through your browser settings.
11.Children's privacy
The Service is intended for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will take prompt steps to delete it.
12.Health information
Some information you share with Axis X — symptoms, medications, cycle data, lab results — qualifies as "special category" personal data under GDPR (sometimes called sensitive personal information). We process it only with your explicit consent, only for the purposes described in this Policy, and we apply additional protections, including:
- Storing health data in encrypted form, separated from non-sensitive identifiers where feasible.
- Restricting internal access to authorized personnel on a need-to-know basis.
- Never using health data to train AI models, ours or a third party's.
- Never sharing health data with advertisers, data brokers, or any third party for marketing purposes.
Apple Health (HealthKit) data
Data we receive from Apple Health is subject to additional commitments, in line with Apple's requirements for apps that use HealthKit:
- We use it solely to provide health and wellbeing features to you — dashboards, trends, correlations and personalised routines.
- We never use it for advertising, marketing, or similar purposes, never sell it, and never disclose it to data brokers, information resellers, advertising platforms or analytics providers.
- We share it with a third party only as needed to provide those features to you (our hosting provider and, with your permission, Anthropic as described in Section 5), and never for any other purpose.
- We do not store Apple Health data in iCloud.
- We do not write data to Apple Health.
- You can revoke access at any time in the iOS Health app (Sharing → Apps → Axis X) or in Axis X's settings. Revoking access stops new data flowing; you can delete already-imported data by deleting it in the app or deleting your account.
Automated processing
Axis X analyses your data automatically — including with AI — to build your system, spot patterns, and generate routines, insights and suggestions. This analysis is offered for your information and you decide whether to act on it. It does not produce decisions with legal or similarly significant effects on you, and it is never used to determine your eligibility for, or the price of, any product or service. If you have a question about how a particular insight was produced, you can ask us at any time.
Axis X is a wellbeing app, not a medical device. Insights surfaced inside the Service are observations for your personal awareness and are not a substitute for advice from a qualified healthcare professional.
Beta programme (TestFlight)
Before general release we may offer Axis X through Apple's TestFlight. If you take part, please note:
- Apple collects certain information from beta testers — including your email address, device and iOS version, crash logs, and any screenshots or feedback you submit through TestFlight — under Apple's Privacy Policy. Apple shares crash logs and feedback with us so we can fix problems.
- Beta builds may collect more detailed diagnostic data than the released app, so we can find and fix bugs. This data is used only for that purpose and is retained for no longer than 90 days after the beta ends.
- Data you enter during the beta may be reset or deleted when the beta ends or between builds. Everything else in this Policy — including your rights and our commitments about health data — applies during the beta exactly as it will afterwards.
13.Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we'll update the "Last updated" date at the top and notify you in the Service or by email at least 30 days before the changes take effect. Where a change involves processing that relies on your consent — for example a new use of your health data or a new AI provider — we will ask for your consent again before that processing begins, rather than assuming it from your continued use. For other changes, continuing to use the Service after the effective date means the updated Policy applies to you. Earlier versions are available on request.
14.How to contact us
If you have questions, want to exercise a privacy right, or want to report a concern, write to us — we read every email.
For privacy requests and data-protection matters, use privacy@axisx.ai. For general questions and support, write to hi@axisx.ai. You can also write to us by post: Axis X Limited, Crown House, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom.
Privacy questions?
We aim to respond within 5 working days, and always within the legal deadlines.
privacy@axisx.ai