Legal

Privacy Policy

Effective date: 9 September 2026 Last updated: 10 September 2026

This Privacy Policy explains how Axis X ("Axis X", "we", "us", or "our") collects, uses, shares, and protects your personal information when you visit our website, join the waitlist, or — once available — use the Axis X mobile application (collectively, the "Service").

We've tried to write this in plain language. Where we use defined terms, they're explained where they appear. If anything is unclear, you can always reach us at the contact address at the bottom of this page.

1.Who we are

Axis X is a wellbeing application designed to help women 35+ build and follow a personalized health system. The Service is operated by Axis X Limited, a company registered in England and Wales under company number 17435401, with its registered office at Crown House, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom.

Axis X Limited is the "controller" of your personal data — the entity that decides why and how it is processed. You can reach us about anything in this Policy at privacy@axisx.ai or by post at the address above.

If you're located in the European Economic Area (EEA), the United Kingdom, or Switzerland, references to GDPR apply equally to the UK GDPR and the Swiss FADP where relevant.

2.Information we collect

Information you give us directly

Information we receive from your device or third parties

3.How we use your information

We use your information to:

We do not sell your personal information. We do not use your health data, journal content, or voice transcripts to train AI models — ours or anyone else's — and our AI provider is contractually prohibited from doing so (see Section 5). We do not run third-party advertising inside the Service.

If you're in the EEA, UK, or Switzerland, we rely on the following legal bases under the GDPR / UK GDPR / FADP:

Consent (Art. 6(1)(a))
For the waitlist email, marketing communications, processing of health data (special category, Art. 9(2)(a)), connecting Apple Health, and sending your content to our AI provider for processing.
Contract (Art. 6(1)(b))
To provide the core Service you've requested once you become a user.
Legitimate interests (Art. 6(1)(f))
To improve the Service, prevent abuse, and keep our systems secure — balanced against your rights and freedoms.
Legal obligation (Art. 6(1)(c))
To comply with laws that apply to us.

You may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal.

5.How we share information

We share personal information only with the following categories of recipients, and only as needed:

We do not sell or rent your personal information, and we do not share health-related data with third-party advertisers.

Waitlist and email delivery by MailerLite

Our waitlist and launch emails are run through MailerLite (UAB "MailerLite", J. Basanavičiaus g. 15, Vilnius, Lithuania), a European email-marketing service. When you submit the waitlist form, your email address is sent directly to MailerLite, which stores it, sends the confirmation and launch emails on our behalf, and records your consent and any unsubscribe. MailerLite acts as our processor under a data-processing agreement, hosts the data in the European Union, and may not use it for any purpose of its own. No MailerLite code runs on our website and no cookies are set by the form.

AI processing by Anthropic

Axis X uses large language models provided by Anthropic, PBC to understand what you tell it, build your wellbeing system, generate insights and recaps, and answer your questions. To do this, the relevant parts of your content — such as your voice transcript, journal entries, tracked values, connected health data and uploaded documents — are sent to Anthropic's API and processed on our behalf.

We ask for your explicit permission before any of your health data is sent to Anthropic, and you can withdraw it at any time in the app's settings. Without it, features that depend on AI will not be available, but you can still use Axis X for manual tracking.

6.Data retention

7.Security

We use industry-standard technical and organizational measures to protect your information, including encryption in transit (TLS) and at rest, access controls, audit logging, and the principle of least privilege. Where possible, we process data on-device or in a privacy-preserving way.

No system is perfectly secure. If we ever experience a breach that affects your personal information, we will notify you and the relevant authorities as required by law.

8.Your privacy rights

Depending on where you live, you may have some or all of the following rights:

To exercise any of these rights, contact us at the address in Section 14. We will respond within the time limits set by applicable law (one month under the UK GDPR and GDPR, extendable by two further months for complex requests; 45 days under the CCPA).

California residents have specific rights under the CCPA/CPRA, including the right to know what personal information we collect, the right to delete it, the right to correct inaccuracies, and the right to opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information as defined by the CCPA). We do not discriminate against you for exercising any of these rights.

9.International data transfers

Your personal information may be transferred to and processed in countries other than the one where you live. Where we transfer personal data out of the EEA, UK, or Switzerland, we use appropriate safeguards — typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and (where applicable) supplementary measures.

10.Cookies & tracking

Our website currently sets no cookies and uses no analytics or advertising trackers. The waitlist form sends only the email address you type, directly to MailerLite (see Section 5).

The website loads the Inter and Fraunces typefaces from Google Fonts. When your browser fetches them, Google receives your IP address and standard request information, which Google processes under its own privacy policy. No cookies are set by this request.

If we add analytics or other non-essential cookies in the future, we will show a consent banner that lets you accept or reject them before they are set, as required by UK and EU law. You can also control cookies through your browser settings.

11.Children's privacy

The Service is intended for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will take prompt steps to delete it.

12.Health information

Some information you share with Axis X — symptoms, medications, cycle data, lab results — qualifies as "special category" personal data under GDPR (sometimes called sensitive personal information). We process it only with your explicit consent, only for the purposes described in this Policy, and we apply additional protections, including:

Apple Health (HealthKit) data

Data we receive from Apple Health is subject to additional commitments, in line with Apple's requirements for apps that use HealthKit:

Automated processing

Axis X analyses your data automatically — including with AI — to build your system, spot patterns, and generate routines, insights and suggestions. This analysis is offered for your information and you decide whether to act on it. It does not produce decisions with legal or similarly significant effects on you, and it is never used to determine your eligibility for, or the price of, any product or service. If you have a question about how a particular insight was produced, you can ask us at any time.

Axis X is a wellbeing app, not a medical device. Insights surfaced inside the Service are observations for your personal awareness and are not a substitute for advice from a qualified healthcare professional.

Beta programme (TestFlight)

Before general release we may offer Axis X through Apple's TestFlight. If you take part, please note:

13.Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we'll update the "Last updated" date at the top and notify you in the Service or by email at least 30 days before the changes take effect. Where a change involves processing that relies on your consent — for example a new use of your health data or a new AI provider — we will ask for your consent again before that processing begins, rather than assuming it from your continued use. For other changes, continuing to use the Service after the effective date means the updated Policy applies to you. Earlier versions are available on request.

14.How to contact us

If you have questions, want to exercise a privacy right, or want to report a concern, write to us — we read every email.

For privacy requests and data-protection matters, use privacy@axisx.ai. For general questions and support, write to hi@axisx.ai. You can also write to us by post: Axis X Limited, Crown House, 27 Old Gloucester Street, London, WC1N 3AX, United Kingdom.

Privacy questions?

We aim to respond within 5 working days, and always within the legal deadlines.

privacy@axisx.ai