Privacy Policy
Last updated: July 13, 2026
1. Introduction
Revivex ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, purchase our products, or use the Revivex mobile app. The mobile app is covered in detail in Section 9, which controls if anything in it differs from the general sections.
2. Information we collect on the website and store
- Personal information: name, email address, phone number, shipping and billing address, and payment information when you make a purchase or create an account.
- Usage data: IP address, browser type, pages visited, time on page, and referring URLs.
- Cookies & tracking: cookies, pixels, and similar technologies to operate the store and analyze site traffic. You can control cookies through your browser settings.
3. How we use website and store information
To process and fulfill orders; provide, maintain, and improve our products and services; communicate about orders, updates, and support; personalize your experience; comply with legal obligations; and detect and prevent fraud or security issues.
4. Sharing website and store information
We do not sell your personal information. We share it only with service providers who help us operate the store (payment processors, shipping carriers, analytics providers), when required by law, or in connection with a business transfer.
5. Data security
We use industry-standard measures including encryption in transit, secure hosting, and access controls. No method of transmission over the Internet is 100% secure, and we cannot guarantee absolute security.
6. Your rights
Depending on your location, you may have the right to access, correct, or delete your personal information; opt out of marketing; request a copy of your data; and withdraw consent where processing is based on consent. Contact us using Section 12 to exercise these rights. Mobile-app users can also delete their account and data directly in the app (Section 9.8).
7. Third-party links
Our website and app may link to third-party sites and services. We are not responsible for their privacy practices.
8. Children's privacy
Our services are not directed to children, and we do not knowingly collect personal information from children. If we learn we have collected data from a child, we will delete it promptly.
9. Revivex Mobile App
This section describes exactly what the Revivex iOS and Android app collects, how it is collected, how it is used, where it is stored, who receives it, and how you can delete it.
9.1 What the app collects
- Account and contact info — email address, name, optional username and profile photo, provided by you at sign-up (email/password or Sign in with Apple/Google). Used to create and secure your account.
- Health and fitness data — steps, workouts, heart rate, resting heart rate, heart-rate variability, respiratory rate, blood oxygen, sleep stages and duration, recovery/readiness and strain scores, VO₂ max, body temperature deviation, active energy, weight, and height — from Apple Health (HealthKit) or Health Connect on your device, and from WHOOP or Oura if you connect them. Used to compute your daily Readiness, Train, Restore, Nutrition, and related scores and show your trends.
- Profile and goals — age/birthday, sex, height, weight, training level, goals, dietary preferences, and allergies, provided by you during onboarding and in Profile. Used to personalize targets (for example calorie and protein goals) and guidance.
- Nutrition data — logged meals, food searches, barcodes, and meal photos you submit for scanning.
- Training data — logged workouts, exercises, sets/reps, and training sessions.
- Supplements — your supplement stack and daily check-offs.
- Location — approximate or precise device location, foreground only and only after you grant permission. Used to show local air quality, UV, pollen, and weather; optionally to find nearby community places; and optionally to pin a location you choose to share in Community.
- Community content — your community profile (display name, photo, bio, sports, level, city), clubs you create or join, and friend connections.
- Purchases — orders you placed on healthrevivex.com linked to your account email, so the app can show your order history.
- Device, identifiers, and usage — device model and OS, app version, anonymous device/user identifiers, screens viewed, and feature-interaction events, collected automatically to understand product usage and improve the app.
- Diagnostics — crash reports and performance data, collected automatically to find and fix bugs.
We do not collect contacts, browsing history outside the app, background location, or advertising identifiers. The app contains no third-party advertising.
9.2 How health data is collected
- Apple Health (HealthKit): with your permission, the app reads the health data types you approve on-device. The app computes daily aggregates (for example daily step totals, nightly sleep totals, daily heart-rate ranges) and workout summaries and uploads those aggregates to our backend so your scores and history are available across your devices. You choose which HealthKit types to share in the iOS permission sheet, and you can change this at any time in the iOS Settings app.
- Health Connect (Android): the equivalent read-only flow on Android.
- WHOOP and Oura: if you connect them, we receive your recovery, sleep, strain, and workout data from their APIs using the OAuth access you grant. You can disconnect at any time in Profile → Data sources.
9.3 Where app data is stored and who processes it
Your app data is stored in our backend database hosted by Convex (convex.dev) on infrastructure in the United States. The following service providers process app data on our behalf, each only for the purpose described:
- Convex — backend database and functions; all app data described in 9.1.
- Clerk — authentication; email, name, sign-in identity tokens, profile photo.
- Sentry — crash and error reporting; crash traces and device/OS info. We configure redaction so names, emails, tokens, and health values are stripped before sending.
- PostHog — product analytics; feature-usage events, screens viewed, app version, anonymized identifiers. We do not send health values, meal contents, chat messages, or photos to analytics.
- OpenRouter, Inc. — AI request routing, only with your explicit consent (see 9.4).
- OpenAI and Anthropic — the AI model providers we currently use, routed via OpenRouter, only with your explicit consent (see 9.4).
- Open-Meteo — environment conditions; receives approximate coordinates only (no account identifiers) to fetch air quality, UV, pollen, and weather.
- USDA FoodData Central, Open Food Facts, FatSecret, Spoonacular, TheMealDB — food and recipe lookup; receive the food search text or barcode you enter, without account identifiers or health data.
- WHOOP and Oura — wearable data sources you connect; they provide data to us under the OAuth access you grant.
- Expo (EAS) — push notification delivery; push token and notification payloads.
- Apple / Google — Sign in with Apple / Google sign-in and push transport, per their own policies.
We do not sell app data, and we do not share it with data brokers or advertisers.
9.4 AI features and your explicit consent
Some Revivex features (the HealthGPT coach, training/sleep/ nutrition insights, meal-photo scanning, AI food estimates, meal suggestions, and weekly meal plans) are powered by third-party AI models.
- Nothing is sent to any AI provider until you explicitly allow it in the app. The first time you use an AI feature, the app shows a consent screen describing what will be sent and to whom, with "Allow" and "Not Now" choices. If you decline, every non-AI feature of Revivex continues to work.
- What is sent when you use an AI feature: the relevant slice of your data for that request — recent daily health aggregates from your connected sources (for example sleep, heart rate, HRV, recovery, workouts), your nutrition logs or a meal photo you submit, your profile basics (age, sex, height, weight, goals, dietary preferences, allergies), your supplement routine, local environment conditions (air quality, UV, weather) derived from your approximate location, upcoming travel you have synced, and the question or message you typed.
- Who receives it: OpenRouter, Inc. (which routes the request) and the AI model providers we currently use — OpenAI and Anthropic. Per their API terms, these providers state that API data is not used to train their models. We require providers we use to offer protections consistent with this policy, and the app enforces a provider allowlist so requests cannot be routed to a provider this policy does not name.
- Control and withdrawal: you can withdraw AI consent at any time in Profile → Settings → AI & Data. Withdrawal takes effect immediately — the app and our backend both block further AI requests until you allow them again. Consent is versioned: if what we send or who receives it changes materially, you will be asked again before any further AI processing.
9.5 HealthKit and health-data commitments
We use HealthKit and other health data only to provide the health and fitness features you request in the app. We do not — and will not — use health data for advertising, marketing, or similar services; sell it; share it with data brokers; or disclose it to third parties except service providers processing it for us as described in 9.3, with your explicit consent as described in 9.4, or as required by law.
9.6 Notifications
If you enable notifications, we send readiness/training/sleep nudges through Apple and Google push services using a device push token. You can turn categories off in the app (Profile → Notifications) or disable notifications in system settings.
9.7 Retention
App data is retained while your account is active so your history and trends work. If you disconnect a data source, we stop collecting from it. Diagnostic and analytics data are retained on the schedules of the processors above (typically 90 days to 12 months).
9.8 Deleting your account and data
In the app, go to Profile → Delete account. This permanently deletes your account and your app data — including uploaded health aggregates, nutrition logs, meal photos, chats with the AI coach, community profile and connections, and preferences — from our backend (Convex) and our authentication provider (Clerk). Copies held by processors are deleted per their retention schedules. Order records for purchases you made on our store are retained as required for tax and accounting law. You can also request deletion by contacting us (Section 12).
9.9 Not medical advice
Revivex provides general wellness information. It is not a medical device and does not diagnose, treat, cure, or prevent any disease. The app links to the sources and methodology behind its scores and guidance (Profile → Settings → Methodology & sources).
10. Changes to this policy
We may update this policy from time to time. Changes will be posted on this page with an updated date. Material changes affecting app data will also be surfaced in the app — material changes to AI processing re-trigger the consent described in 9.4.
11. California and EEA/UK notices
We process personal data as described above under the legal bases of contract performance (providing the service you request), consent (AI processing, location, health-data access), and legitimate interest (security, diagnostics). You may have rights to access, portability, correction, deletion, restriction, and objection, and to lodge a complaint with your supervisory authority. We do not "sell" or "share" personal information as defined by the CCPA/CPRA.
12. Contact us
If you have questions or concerns about this Privacy Policy, or want to exercise your rights, contact us at:
Revivex Health & Wellness
Email: support@revivex.store
Web: healthrevivex.com/contact


