SEXTANT ← back to sextant.run

Rekuro — Privacy Policy

Version 2.1.0 · Effective 2026-07-01 · Last updated 2026-06-26

This page is generated from the canonical policy document and is the version currently in effect. Prior versions are kept at stable archive URLs under /legal/.

Sextant is a running-analytics app operated by Rekuro LLC (Florida, USA) ("Rekuro," "we," "us"). When this policy says "Sextant" it means the app and service you use; "Rekuro" (or "we") means the company that operates it and is responsible for your data. This policy explains what we collect, why, who we share it with, how long we keep it, and the choices and rights you have. Questions: [email protected] · 4139 Moreland Drive, Valrico, FL 33596.

1. The short version

2. Who this applies to

Rekuro is for runners age 13 and older. Adults (18+) use self-managed accounts. Runners 13–17 use a guardian-managed account — a parent or legal guardian sets it up, consents, and can oversee it. Sextant is not intended for children under 13, and we do not knowingly collect data from anyone under 13. If we learn that a user is under 13, we will disable the account and delete the data. We apply the strongest privacy protections to minors by default, and we never sell anyone's data or use it for advertising — least of all a minor's.

3. What we collect

You provide / connect:

Collected automatically:

We do not receive your payment card details — payments are handled by Apple (and, for any web purchases, by our payment processor).

4. How we use your data

We never use your health data for advertising, and we never sell it.

5. Legal bases (GDPR-by-design)

Although Rekuro currently serves US users, we apply GDPR standards by design:

You can withdraw consent at any time in the app; we stop the related processing and you can delete your data.

6. AI features

7. Who we share data with

We share data only with service providers ("processors") who act on our instructions under contract. We describe them by category below; we'll name the specific providers on request (email [email protected]):

Category of provider Purpose Location
Cloud hosting / storage Hosting your data and running the service USA
Apple HealthKit source; in-app payments USA
AI inference provider(s) Sextant's AI coach inference — US-based provider(s) selected for your region, used on a dynamic/failover basis (commercial API and/or open-weight models); no training on your data; short, security-limited retention. Named on request. USA
Weather data service Weather/heat lookup (coarse location only) USA
Payment processor Web payments USA
Product analytics provider Pseudonymous product/usage analytics (configured to exclude health data) USA
Error-monitoring provider Error and crash monitoring (configured to scrub personal and health data) EU

We do not sell your personal data, and we do not share it for cross-context behavioral advertising. We may disclose data if required by law or to protect rights and safety. If we change a provider in a category, we update our internal records and will tell you the current provider on request.

8. Prompt and security logging

To operate the coach and detect attacks (including prompt-injection attempts), we keep:

9. Data retention

10. Where your data is stored

Your data is currently stored in the United States, with our cloud hosting provider, and our product analytics provider also processes data in the United States. Your AI-coach inference also happens in the United States: when you use Sextant's AI coach, your request is routed to a US-based inference provider, and it cannot leave the US region — each customer is served by a region-specific server whose inference router can only reach that region's providers. The routing boundary, not a configuration setting, is what keeps regions separate. We offer the service to US users and do not currently target or serve users in the EU or UK. If we later offer the service to EU/UK users, their personal data processed in the US will be protected by an appropriate Chapter V transfer mechanism — such as the EU–US Data Privacy Framework and/or standard contractual clauses (and the UK equivalent) — and EU users would be served by an EU server whose router reaches an EU-resident inference path, so their coach inference would stay in the EU; we do not claim EU residency for inference today. We will update this policy and its effective date to reflect any such change, and we will not pool EU users' data in the US without that safeguard in place. The other providers listed in §7 are also in the USA; where data moves internationally for those services, we rely on appropriate safeguards and minimize what is sent.

11. Security

We protect your data with: encryption in transit and at rest; strict access controls and least-privilege access to sensitive logs; US data residency (today), including coach inference; a no-training arrangement with our managed-AI inference provider(s) — US-based for US users, and region-routed so a request can't cross regions (your data is not used to train models); pseudonymized analytics; prompt-injection defenses; and backups with tested restore. No system is perfectly secure, but we treat health data as sensitive by default.

12. Your rights

Wherever you live, you can: access your data, get a copy/export, correct it, delete it, withdraw consent, and object to or restrict certain processing. Use the in-app controls or email [email protected]. We respond within the time required by applicable law. You may also complain to a data-protection authority.

Your export contains the data you provided — your workouts and their raw sensor streams (heart rate, beat-to-beat intervals, GPS, pace, elevation, cadence), and your own notes and corrections — in an open, machine-readable format. It does not include the analytics we compute from it (best efforts, fitness/threshold estimates, and similar), which are produced by Sextant rather than provided by you. The export is not limited by your subscription tier — you always get your complete history.


Consumer Health Data (Washington My Health My Data Act & similar)

This section is the standalone "consumer health data" disclosure required by MHMDA and comparable US state laws. It can be published as a separate notice, and is linked from the Rekuro homepage as MHMDA requires.


CCPA/CPRA (California) notice


13. Changes to this policy

We'll post changes here and update the effective date; material changes will be notified in-app. We keep prior versions available at stable URLs so you can see what the policy said at any past date.

14. Contact

Rekuro LLC[email protected] · 4139 Moreland Drive, Valrico, FL 33596.