privacy policy

your data.
yours.

xaelr holds some of the most sensitive data about you that any app could hold. we take that seriously.

last updated: may 2026

xaelr's business model is subscription. you pay us directly. that means your data has no commercial value to us beyond making the product work better for you.

we will never sell your data, share it with advertisers, or use it to build profiles for anyone other than you. the three commitments below are non-negotiable and will never change without you explicitly agreeing to new terms.

three commitments. non-negotiable.

these are not aspirations. they are the foundation the product is built on. if xaelr ever changed ownership, these commitments would be contractually binding on any acquirer.

what we collect

xaelr collects only what it needs to build your personal health-wealth picture. nothing more.

health data

financial data

account data

apple health is read-only. xaelr reads from apple health but never writes to it. we request only the specific data types listed above. we do not access any other health records, medical data, or information held by apple health that is not listed here.

what we do with your data

every piece of data xaelr collects is used for one purpose: building your personal health-wealth picture and making the intelligence in xaelr work for you specifically.

we use AI to generate your monthly portrait and power ask xaelr. when data is processed it is handled securely and is not used to train any AI models. we send only the minimum data necessary to generate each response.

what we will never do

where your data is stored

your data is stored securely on your device and on encrypted servers in the UK and EU. we do not store data in jurisdictions without adequate data protection laws.

transaction data, health history, mood logs, and your xaelr index are stored on your device where possible. data that requires server processing (monthly portrait generation, ask xaelr responses) is transmitted over encrypted connections and not retained on our servers after processing.

you can see everything xaelr knows about you in the memory view screen inside the app. nothing is hidden. if something looks wrong you can correct or delete it.

your rights

under UK GDPR you have the following rights. xaelr is designed to make exercising them as easy as possible.

to exercise any of these rights contact us at the address below. we will respond within 30 days.

data retention

we keep your data for as long as your account is active. when you delete your account all personal data is permanently deleted within 30 days. anonymised aggregate data (with no connection to your identity) may be retained for product improvement.

if you stop using xaelr but do not delete your account, your data is retained until you choose to delete it. we will send a reminder after 12 months of inactivity.

third parties

xaelr uses a small number of third-party services to operate. each is listed below with what data they receive.

we do not use advertising networks, social media trackers, or analytics platforms that share data with third parties.

children

xaelr is not intended for users under 18. we do not knowingly collect data from anyone under 18. if you believe a minor has created an account please contact us and we will delete it immediately.

changes to this policy

if we make material changes to this policy we will notify you by email at least 30 days before the changes take effect. you will have the option to delete your account if you do not agree with the changes.

the three commitments at the top of this page will never change without your explicit agreement. all other terms may evolve as the product develops.

contact

for any privacy-related questions, data requests, or complaints:

xaelr

email: privacy@xaelr.com
website: xaelr.com

if you are not satisfied with our response you have the right to lodge a complaint with the Information Commissioner's Office (ICO) at ico.org.uk.