Legal
Privacy Policy
DialedRx — Privacy Policy
Last updated: July 29, 2026
Biaxis Technology LLC ("DialedRx," "we") explains here what we collect, why, and the choices you have. This policy is part of our Terms of Service.
1. Information we collect
- Account data: email, password (stored hashed by our auth provider), display name.
- Fitness & health-related data you provide: training constraints and limitations (e.g., injury/mobility notes), equipment, workout sessions, sets, loads, RPE, and — if you choose to enter or import it — cardio and heart-rate data. Some of this is health-related and treated as sensitive (see §5).
- Coach–athlete data: when you connect with a coach (or, as a coach, with athletes), the connection and the shared training data described above.
- Usage & device data: app interactions, and technical data such as device type and approximate location derived from IP, used for security and to operate the app.
- Payment data: processed by our payment processor; we do not store full card numbers.
- AI processing inputs: text/photos you submit for workout parsing are sent to an AI processing provider to return structured results.
- Connected-service data (optional): if you choose to connect Strava, we import the activity data your Strava account makes available to us — activity records (such as type, date, duration, distance and pace where present) and heart-rate data. We import nothing from Strava unless you connect it. See §4.
2. How we use your information
To provide, personalize, and improve the Service (including the constraint-aware engine); to enable coach–athlete features you opt into; to process payments; to secure the Service and prevent abuse; to communicate with you; and to comply with law.
3. Legal bases (EEA/UK users)
We rely on: performance of a contract (to run the Service you signed up for); consent (for sensitive health data and certain communications); legitimate interests (security, product improvement); and legal obligation. You may withdraw consent at any time.
4. How we share information
- With your coach / athletes — only the data required for the connection you opted into, and only while that connection is active.
- With service providers (processors) — a small, named set of vendors that run parts of the Service for us. They may process your data only on our instructions and only for the purpose listed below. The current list:
| Provider | What they do for us | What they process |
|---|---|---|
| Supabase | Database, authentication, and file storage. Data is hosted in the United States. | Account data, training and health-related data, uploaded files. |
| Netlify | Application hosting, CDN, and serverless functions. | Requests to the app, technical/device data, and data passing through our functions. |
| Anthropic | AI processing of the text and photos you submit for workout parsing and generation. Inputs submitted through the API are not used to train models. | The text and photos you submit, and the structured result returned. |
| Stripe | Payment processing. Stripe receives your payment details directly, and we never store full card numbers. | Payment, subscription, and billing data. |
| Strava (optional — only if you connect it) | Imports your activity and heart-rate data into DialedRx. | The activity and heart-rate data held in your Strava account. |
| Microsoft 365 | Email correspondence. | Your email address and the contents of messages you exchange with us. |
- For legal reasons — to comply with law or protect rights and safety.
- We do not sell your personal information and do not share it for cross-context behavioral advertising.
Strava (optional). Connecting Strava is entirely your choice, and DialedRx works fully without it. If you connect it, we request read access to your activity data and import your activities and, where present, your heart-rate data, so that cardio work appears alongside your DialedRx training. We do not post to Strava, and we do not import your Strava social data such as followers, comments, or kudos. You can disconnect at any time in DialedRx, which stops any further import, and you can independently revoke DialedRx's access from within your Strava account settings, where connected applications are listed. Data already imported stays in your DialedRx account until you delete it, or until your account is deleted (§7).
5. Sensitive / health-related data
Fitness constraints, injury notes, and heart-rate data may qualify as sensitive personal information (CPRA) or special-category data (GDPR). We collect and use it only with your consent, only to provide the Service, and you can withdraw consent or delete this data at any time (§7). We are a consumer fitness product and are not a HIPAA-covered entity; this data is not "protected health information" in the HIPAA sense, but we still treat it as sensitive.
6. Data retention
We keep data only as long as we need it. These are the periods we apply:
- Account and training data — retained while your account is active.
- After a deletion request — a 14-day grace window you can cancel at any time (§7). When the window closes, we purge your training and log data, sever your coach connections and credit ledger, and scrub or anonymize the identity data on your account.
- Legal acceptance records — which document version you accepted, its content hash, the method, and when, are retained for the applicable statute-of-limitations period so we can evidence that consent was given. These records are kept in anonymized form: the IP address and user-agent captured at acceptance are nulled when the account is deleted.
- Billing and tax records — retained for as long as tax and accounting law requires, generally 7 years.
- Backups — data removed from the live system may remain in routine encrypted backups until those backups age out on their normal cycle.
7. Your rights & choices
Regardless of where you live, you can, from within the app (Settings → Legal & data):
- Access / export a machine-readable copy of your data (portability).
- Delete your account and data — starts a 14-day grace window you can cancel; after it, we scrub or anonymize your data.
- Correct inaccurate data (edit your profile).
- Withdraw consent to sensitive-data processing (which may limit features).
California (CCPA/CPRA): rights to know, delete, correct, and to limit use of sensitive personal information; we do not sell or "share" your data; no discrimination for exercising rights. EEA/UK (GDPR): rights of access, rectification, erasure, restriction, portability, objection, and to lodge a complaint with a supervisory authority. To exercise rights you can also contact us at contact@dialedrx.ai or by mail at the address in §13.
8. Children
The Service is not intended for anyone under 18, and we do not knowingly collect data from children under 13. If you believe a child provided us data, contact us and we will delete it.
9. Security
We use industry-standard safeguards (encryption in transit, access controls, row- level security scoping each user's data). No system is perfectly secure.
Reporting a vulnerability. If you believe you have found a security vulnerability or an exposure of data in DialedRx, report it to contact@dialedrx.ai with enough detail for us to reproduce it. We will acknowledge your report and work to resolve confirmed issues. Please do not access, change, or delete anyone else's data while testing, and please give us a reasonable opportunity to fix an issue before disclosing it publicly.
10. International transfers
Your data may be processed in countries other than yours (including the United States). Our primary infrastructure and data storage are located in the United States. Where required, we use appropriate safeguards for such transfers.
11. Cookies / local storage
The app is a PWA. It uses your browser's local storage — not advertising cookies — for the small number of values it needs to work:
| What we store | Why |
|---|---|
| Authentication session | Keeps you signed in between visits; set and managed by our authentication provider. |
Theme preference (drx-theme) | Remembers your light/dark appearance choice. |
| Pending coach-invite token | Holds a coach's invite token across sign-up so you land connected to the right coach; cleared once it is redeemed. |
We also store a few small interface preferences (for example, whether you dismissed the "add to home screen" prompt), and we cache application files through a service worker so the app loads and works offline. We do not use third-party advertising trackers, and we do not run third-party analytics. Clearing your browser's storage for the site removes these values and signs you out.
12. Changes
We may update this policy. Material changes will require your re-acceptance before you continue using the Service; the version you accepted and the date are recorded.
13. Contact
Privacy questions and requests can be made from within the app (Settings → Legal & data), by email to contact@dialedrx.ai, or by mail to the data controller: Biaxis Technology LLC, Attn: Billing, 3423 Piedmont Road NE, Atlanta, GA 30305. Security reports also go to contact@dialedrx.ai (§9).