This page is generated from the canonical policy document and is the version currently in effect. Prior versions are kept at stable archive URLs under /legal/.
Sextant is a running-analytics app operated by Rekuro LLC (Florida, USA) ("Rekuro," "we," "us"). When this policy says "Sextant" it means the app and service you use; "Rekuro" (or "we") means the company that operates it and is responsible for your data. This policy explains what we collect, why, who we share it with, how long we keep it, and the choices and rights you have. Questions: [email protected] · 4139 Moreland Drive, Valrico, FL 33596.
1. The short version
- Rekuro turns your running data into a clear, structured read of your training.
- We process health and location data only with your explicit consent, to provide the app.
- We do not sell your data, and we do not use it for advertising.
- Your data is stored in the United States; we keep it while your account is active and delete it when you ask.
- AI features run on your own AI (you connect it) or, optionally, Sextant's AI coach — which is routed to one or more inference providers chosen for your region (for US users, US-based providers), where your data is not used to train AI models and is retained only briefly for security purposes.
- You can access, export, correct, and delete your data at any time.
2. Who this applies to
Rekuro is for runners age 13 and older. Adults (18+) use self-managed accounts. Runners 13–17 use a guardian-managed account — a parent or legal guardian sets it up, consents, and can oversee it. Sextant is not intended for children under 13, and we do not knowingly collect data from anyone under 13. If we learn that a user is under 13, we will disable the account and delete the data. We apply the strongest privacy protections to minors by default, and we never sell anyone's data or use it for advertising — least of all a minor's.
3. What we collect
You provide / connect:
- Account data — email, and authentication identifiers.
- Health & fitness data (from Apple Health / HealthKit, with your consent) — workouts, heart rate, beat-to-beat (R-R) heart intervals, cadence, running power, vertical oscillation, stride length, ground contact time, calories, and metrics we derive from them (pace/threshold/fitness estimates, stress and recovery readings).
- Precise location — GPS routes for your runs. Only a coarse, reduced-precision version is used to attach weather/heat context (see §7).
- Device data — the names and models of devices you record with (e.g., watch, chest strap).
- Free text — workout titles, notes, and messages you send to the coach.
Collected automatically:
- Usage/telemetry — pseudonymous app-usage events (screens, taps). This never includes your health values, precise location, or message content.
- Error/diagnostic data — crash and error reports (such as stack traces and recent diagnostic log lines) used to keep the app working. Today these are sent to our own backend; if we later add a third-party error-monitoring service, we will configure it to scrub personal and health data before anything is sent. We design these reports to exclude your health values, precise location, and message content, though diagnostic data can occasionally capture more than intended.
- Security logs — limited records used to detect abuse and security threats (see §8).
We do not receive your payment card details — payments are handled by Apple (and, for any web purchases, by our payment processor).
4. How we use your data
- Provide the core app: ingest, organize, enrich, and display your runs.
- Generate per-run reports and comparisons across your history.
- Power AI coaching (see §6).
- Operate your account and keep you signed in.
- Keep the service secure (abuse/prompt-injection detection).
- Diagnose crashes and errors to keep the app working.
- Process subscriptions.
- Understand and improve the product (pseudonymous analytics).
We never use your health data for advertising, and we never sell it.
5. Legal bases (GDPR-by-design)
Although Rekuro currently serves US users, we apply GDPR standards by design:
- Explicit consent (Art. 9(2)(a)) — for all health and location data, and for your coach messages (which may contain health details). Enabling Sextant's AI coach is a separate, specific consent you can give or withdraw on its own. For users 13–17, a parent or guardian provides consent. We do not knowingly process data of anyone under 13.
- Contract (Art. 6(1)(b)) — to provide the service you signed up for.
- Legitimate interests (Art. 6(1)(f)) — security/abuse prevention; pseudonymous analytics.
- Legal obligation (Art. 6(1)(c)) — to keep financial records.
You can withdraw consent at any time in the app; we stop the related processing and you can delete your data.
6. AI features
- Bring your own AI (default). You can connect an AI assistant you already use (e.g., Claude or ChatGPT). When you do, your data is shared with that provider under your own account and their terms — that relationship is yours; we disclose it to you when you connect.
- Sextant's AI coach, optional. If you choose Sextant's AI coach, we route the relevant data to one or more inference providers selected for your region. For US users, these are US-based providers, used on a dynamic/failover basis — so a given request may be served by either of them, and we don't promise a single named provider for every request. They may include a provider we reach through its commercial API and a US-based inference host that serves open-weight models; we'll name the current providers on request (email [email protected]). Across all of them, your inputs and outputs are not used to train any AI models, and we do not enable any setting that would allow that. Retention is short and security-limited: for example, our commercial-API provider deletes inputs and outputs within about 30 days, except where content is flagged for a policy or safety review, which it may retain longer to investigate abuse. We treat this as a no-training arrangement with short, security-limited retention — not a zero-retention arrangement. Your inference region follows your account region: US users' coach inference happens in the US (see §10). We will keep this description accurate as our providers, their terms, or our configuration change.
- Not medical advice. Rekuro's reports and coaching are for training and informational purposes only and are not medical advice. Consult a qualified professional for health decisions.
7. Who we share data with
We share data only with service providers ("processors") who act on our instructions under contract. We describe them by category below; we'll name the specific providers on request (email [email protected]):
| Category of provider |
Purpose |
Location |
| Cloud hosting / storage |
Hosting your data and running the service |
USA |
| Apple |
HealthKit source; in-app payments |
USA |
| AI inference provider(s) |
Sextant's AI coach inference — US-based provider(s) selected for your region, used on a dynamic/failover basis (commercial API and/or open-weight models); no training on your data; short, security-limited retention. Named on request. |
USA |
| Weather data service |
Weather/heat lookup (coarse location only) |
USA |
| Payment processor |
Web payments |
USA |
| Product analytics provider |
Pseudonymous product/usage analytics (configured to exclude health data) |
USA |
| Error-monitoring provider |
Error and crash monitoring (configured to scrub personal and health data) |
EU |
We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We may disclose data if required by law or to protect rights and safety. If we change a provider in a category, we update our internal records and will tell you the current provider on request.
8. Prompt and security logging
To operate the coach and detect attacks (including prompt-injection attempts), we keep:
- Conversation history — your coach messages, kept while your account is active.
- A limited security log — minimal records (no raw message content; offending snippets are stored only as a hash) kept for a short period (60 days) to investigate threats. We keep this log on the basis of our legitimate interest in security (not consent), and to establish or defend legal claims.
- Internal coaching-quality diagnostics — when the AI coach analyzes a run or answers a chat, we keep an internal record of the model's own reasoning notes and token usage for that interaction. We use this only to evaluate and improve the quality of the coach (on the basis of our legitimate interest in improving the product); it is never shown to you or anyone else, never shared, and never used to train AI models. It is deleted together with the data it came from — when you delete the run, the chat, or your account (see §9).
9. Data retention
- Account, health, location, and conversation data — kept while your account is active. When you ask us to delete your account we close it right away and permanently delete your data within 14 days (you can undo it within that window by signing back in). Copies that remain in our backups are erased within the following backup cycle, so everything is gone within about 44 days.
- Security logs — 60 days.
- Internal coaching-quality diagnostics (the coach's reasoning notes + token usage) — kept while the run, chat, or account they relate to exists; deleted with it.
- Error/diagnostic data — 90 days.
- Pseudonymous analytics — 24 months, in aggregate.
- Financial records — as required by tax/accounting law.
10. Where your data is stored
Your data is currently stored in the United States, with our cloud hosting provider, and our product analytics provider also processes data in the United States. Your AI-coach inference also happens in the United States: when you use Sextant's AI coach, your request is routed to a US-based inference provider, and it cannot leave the US region — each customer is served by a region-specific server whose inference router can only reach that region's providers. The routing boundary, not a configuration setting, is what keeps regions separate. We offer the service to US users and do not currently target or serve users in the EU or UK. If we later offer the service to EU/UK users, their personal data processed in the US will be protected by an appropriate Chapter V transfer mechanism — such as the EU–US Data Privacy Framework and/or standard contractual clauses (and the UK equivalent) — and EU users would be served by an EU server whose router reaches an EU-resident inference path, so their coach inference would stay in the EU; we do not claim EU residency for inference today. We will update this policy and its effective date to reflect any such change, and we will not pool EU users' data in the US without that safeguard in place. The other providers listed in §7 are also in the USA; where data moves internationally for those services, we rely on appropriate safeguards and minimize what is sent.
11. Security
We protect your data with: encryption in transit and at rest; strict access controls and least-privilege access to sensitive logs; US data residency (today), including coach inference; a no-training arrangement with our managed-AI inference provider(s) — US-based for US users, and region-routed so a request can't cross regions (your data is not used to train models); pseudonymized analytics; prompt-injection defenses; and backups with tested restore. No system is perfectly secure, but we treat health data as sensitive by default.
12. Your rights
Wherever you live, you can: access your data, get a copy/export, correct it, delete it, withdraw consent, and object to or restrict certain processing. Use the in-app controls or email [email protected]. We respond within the time required by applicable law. You may also complain to a data-protection authority.
Your export contains the data you provided — your workouts and their raw sensor streams (heart rate, beat-to-beat intervals, GPS, pace, elevation, cadence), and your own notes and corrections — in an open, machine-readable format. It does not include the analytics we compute from it (best efforts, fitness/threshold estimates, and similar), which are produced by Sextant rather than provided by you. The export is not limited by your subscription tier — you always get your complete history.
Consumer Health Data (Washington My Health My Data Act & similar)
This section is the standalone "consumer health data" disclosure required by MHMDA and comparable US state laws. It can be published as a separate notice, and is linked from the Rekuro homepage as MHMDA requires.
- What "consumer health data" means here: your running, fitness, heart-rate, location, and derived health-related metrics described above.
- How we collect it: from Apple Health/HealthKit and your devices, only with your consent. Exception: we retain limited, hashed security records (no raw content) to detect abuse/attacks and to establish or defend legal claims, on the basis of our legitimate interest in security.
- Why we use it: to provide the app and the features you choose (reports, comparisons, AI coaching), and — internally only — to evaluate and improve the quality of the AI coach (we keep the coach's own reasoning notes for an interaction; never shown, never shared, never used to train AI; deleted with the run, chat, or account).
- Who we share it with: the processors in §7, under contract, to provide the service. We do not sell consumer health data, and we will not share it for purposes you haven't consented to.
- Your consumer-health-data rights: to confirm whether we process it, access it, withdraw consent, and delete it (including asking our processors to delete it). Email [email protected].
- We will not collect, use, or share consumer health data beyond what's needed to provide the service without obtaining your separate consent (or, for any sale, your written authorization — which we do not seek, because we do not sell it).
CCPA/CPRA (California) notice
- Categories collected: identifiers (email), health/medical information, precise geolocation, internet/usage activity, device information, commercial (subscription) information. (See §3.)
- Purposes: as described in §4.
- Sale/Share: We do not sell or "share" (for cross-context behavioral advertising) your personal information.
- Sensitive personal information: we use health and precise-location data only to provide the service — not for inferring characteristics. You may limit our use of sensitive personal information, though we already restrict it to service provision.
- Your rights: know, access, correct, delete, opt out of sale/share (N/A — we don't), and non-discrimination. Submit requests via the in-app controls or [email protected]; an authorized agent may submit a request on your behalf with proof of authorization. We will not discriminate against you for exercising these rights.
13. Changes to this policy
We'll post changes here and update the effective date; material changes will be notified in-app. We keep prior versions available at stable URLs so you can see what the policy said at any past date.
14. Contact
Rekuro LLC — [email protected] · 4139 Moreland Drive, Valrico, FL 33596.