Your privacy is our priority. Learn how we collect, use, and protect your personal information.
All health data encrypted end-to-end with military-grade security
Full compliance with EU data protection regulations and rights
Export, modify, or delete your data anytime with one click
Who we are and what this policy covers
This Privacy Policy explains how Xenacious AB ("we," "us," or "our") collects, uses, discloses, and protects your personal information when you use our health and wellness platform (the "Service"). This policy applies to all users regardless of location and complies with GDPR, CCPA, and other applicable privacy regulations.
Company: Xenacious AB
Location: Stockholm, Sweden
Data Protection Officer: daniel@xenacious.io
EU Representative: [EU-REP-CONTACT]
What data we gather and why
Purpose: Account creation, authentication, and personalization
Purpose: Platform improvements, security, and analytics
Public blockchain addresses for OPXEN token transactions
Transaction history (publicly visible on blockchain)
Wallet connection data (we never store private keys)
Purposes and legal basis
How we safeguard your information
Control over your personal data
Under GDPR and other privacy laws, you have comprehensive rights regarding your personal data. We make it easy to exercise these rights through your account settings or by contacting our privacy team.
Request a copy of all personal data we hold about you
Correct any inaccurate or incomplete personal information
Request deletion of your account and all associated data
Receive your data in a structured, machine-readable format
Object to processing of your data for specific purposes
Limit how we use your data in certain circumstances
When and how we share information
We only share data in these limited circumstances:
Cloud hosting (AWS/Supabase), analytics, email delivery - all bound by strict data processing agreements
When you explicitly authorize sharing with coaches, community members, or third-party apps
When required by law, court order, or to protect rights and safety
Anonymized, aggregated data for research and platform improvements (no personal identification)
How we use cookies
We use cookies and similar technologies to enhance your experience, analyze usage, and improve our services.
Authentication, security, session management
Usage statistics, performance monitoring
Language, theme, notification settings
Age requirements and protections
If we discover that we have inadvertently collected data from a child under 18, we will delete it immediately. Parents or guardians who believe their child has provided us with personal information should contact daniel@xenacious.io.
How we protect your data globally
Xenacious is based in Sweden (EU), but our service providers may process data in other jurisdictions. We ensure all international transfers comply with GDPR through appropriate safeguards.
How long we keep your information
Duration of account + 30 days after deletion request
Duration of account + 30 days (fully encrypted)
7 years (legal requirement for financial records)
Indefinitely (no personal identification possible)
90 days rolling (for fraud detection and security)
Our Data Protection Officer and privacy team are here to help with any questions, concerns, or requests regarding your personal data.
Data Protection Officer
Xenacious AB
Stockholm, Sweden
EU Representative: [EU-REP-CONTACT]