Arneox
AboutFeaturesContact

Products

Arneox FitnessClosed BetaArneox NutritionQ2 2026Arneox RunQ2 2026
AboutFeaturesContact

Table of Contents

Privacy Policy1. Introduction2. Information We Collect3. Legal Basis for Processing4. How We Use Your Information5. Data Sharing6. International Data Transfers7. International Privacy Rights (GDPR, CCPA, etc.)8. KVKK (For Users in Turkey)9. Age Restriction and 16+ Policy10. Data Retention11. Security12. Cookie and Tracking Policy13. AI Data Processing and Limitations14. Policy Changes15. Severability, Survival, and Jurisdiction16. Contact and Supervisory Authorities17. Automated Decision-Making and Profiling

Privacy Policy

Last Updated: March 30, 2026 Effective Date: March 2, 2026


1. Introduction

ARNEOX ("we", "us", "ARNEOX") provides a health and sports ecosystem that includes specialized applications such as ARNEOX Fitness, ARNEOX Nutrition, and ARNEOX Running (collectively, the "Ecosystem", "Service", or "ARNEOX Platform").

Single Account & Unified Subscription Policy: ARNEOX operates as a unified ecosystem. A single user account and subscription plan (Free, Pro, or Pro+) manages access rights and features across all current and future applications within the ARNEOX Platform.

This Privacy Policy explains how we collect, use, store, and protect your data when you use the ARNEOX Platform.

This document is an information notice, not a bundled acceptance/consent text. Where consent is legally required, we request it separately via dedicated consent flows. For users outside Turkey, consent and notice flows are handled under applicable local laws (e.g., GDPR, LGPD, CCPA/CPRA) through product-level controls.

ARNEOX processes sensitive health and fitness data. Under international data protection laws, this data is classified as "special category data" (under GDPR Article 9) and "special categories of personal data" (under Turkey's KVKK), which requires your explicit consent to process.


2. Information We Collect

ARNEOX is an integrated but data-segmented ecosystem made up of multiple specialized applications. Our data structure is divided into General Ecosystem Data (linked to your ARNEOX account) and Application-Specific Data (limited to the app you actually use).

Data Isolation Principle: If you only use one application (e.g., ARNEOX Fitness), no components from unused applications (e.g., Nutrition or Running) will access or collect your data. Each application operates in its own securely isolated environment. New applications integrated into the ecosystem adhere to this strict privacy boundary.

2.1 General Ecosystem Data

When you create an ARNEOX account, we collect the following basic data regardless of which application you use:

  • Account & Identity Information: Email address, password (stored as a cryptographic hash), username, email verification tokens, and basic authorization data from third-party sign-in methods (e.g., Google/Apple Sign-In).
  • Profile Information: Full name or display name, profile photo, biography, date of birth, gender, language preference, and timezone. (Note: Social features like workout program reviews are linked to this profile.)
  • Subscription Information: Your subscription plan (Free, Pro, or Pro+) and the access rights it provides.
  • Technical Data & System Logs: Device information, operating system, IP address, app version, login history, crash reports, and anonymized diagnostic data.
  • Preference Settings: Notification settings and privacy preferences.

2.2 Application-Specific Data (Sensitive Health Data)

The following data qualifies as "special category data" under GDPR Article 9 and similar international regulations and cannot be processed without your explicit consent. This data is only collected when you actively enter it within the relevant application.

2.2.1 ARNEOX Fitness

Designed for users ranging from beginners to professional athletes, this module provides detailed workout tracking and community program integration.

  • Data Categories Processed: Body measurements (height, weight, body fat percentage, muscle mass estimates, anatomical circumferences), progress photos, workout programs, exercise data (sets, reps, weight, effort tracking via RPE and RIR, rest periods between sets), muscle fatigue analysis, personal records, AI-powered form analysis (computer vision), and community interaction data (reviews, program sharing).

2.2.2 ARNEOX Running

A running tracker designed to precisely track running and outdoor cardio activities.

  • Data Categories Processed: GPS location tracking and elevation data, distance (km), speed/pace, stride data (cadence, stride length), step count data, active calories burned, heart rate (HR) zones, shoe tracking, and weather conditions during runs.

2.2.3 ARNEOX Nutrition

Designed for nutrition tracking, macro balancing, and dietary optimization.

  • Data Categories Processed: Daily calorie tracking, macro distributions (protein, carbohydrates, fat, fiber), micronutrient tracking, barcode scanning for nutritional data, cuisine preferences, custom recipes, intermittent fasting tracking, water intake tracking, meal times, medical/dietary restrictions (e.g., celiac disease, vegan diet), supplement scheduling, and Basal Metabolic Rate (BMR) calculations.

2.2.4 ARNEOX AGENT (AI Backend)

Currently being developed alongside the Fitness module and expanding across the ecosystem, ARNEOX AGENT serves as the platform's analytical backbone. It is designed to also function as a standalone application in the future.

  • Processing Security: ARNEOX AGENT does not access or process your personal health data unless Agent Data Access is explicitly enabled in Settings by an eligible user.
  • Active Data Processing: Live cross-app Agent processing and direct conversation history processing are enabled only for Pro+ users who turn Agent Data Access on.
  • Pro Tier Behavior: Pro includes passive backend-level AI orchestration for platform features, but does not include live, user-facing ARNEOX AGENT interaction.
  • Subscription-Based Processing: Live interaction with ARNEOX AGENT is exclusively available to Pro+ subscribers.
  • User Controls (All Plans): AI Data Usage and Agent Data Access controls can be turned off from the app (Settings -> Privacy) in Free, Pro, and Pro+.

2.3 Third-Party Device Integration (Optional)

With your explicit consent, we may connect to third-party health platforms (Apple Health on iOS, Google Fit on Android) to sync step counts, heart rate, sleep data, and workout logs. This integration is entirely optional.


3. Legal Basis for Processing

GDPR (For EU/EEA Users)

Under the General Data Protection Regulation (GDPR), we process your personal data based on the following legal grounds:

  • Performance of a Contract (Article 6(1)(b)): Processing your account information, subscription management, and providing access to the ARNEOX platform is necessary to fulfill our contractual obligations as outlined in our Terms of Use.
  • Explicit Consent (Article 9(2)(a) & Article 6(1)(a)): Since your health and fitness data (e.g., height, weight, workout history, body measurements) constitutes "special category data," we process this information based entirely on your free, informed, and explicit consent. You may withdraw this consent at any time. Third-party integrations like Apple Health or Google Fit also operate strictly on a consent basis.
  • Legitimate Interests (Article 6(1)(f)): We rely on our legitimate interests to analyze app performance (e.g., via Firebase and Sentry), fix software bugs, ensure platform security, and improve our in-house AI models in accordance with user privacy controls and plan-level protections described in Section 13. These processes are carried out with privacy-enhancing measures such as encryption and isolated environments.
  • Legal Obligation (Article 6(1)(c)): We are required to retain financial records for payments, billing, and tax compliance for legally mandated periods.

KVKK (For Users in Turkey)

Under the Turkish Personal Data Protection Law (KVKK) No. 6698:

  • General Personal Data: Processed when directly related to the establishment or performance of a contract (Article 5/2-c), necessary for the data controller to fulfill its legal obligations (Article 5/2-ç), and under our legitimate interests (Article 5/2-f) for app analytics and platform security.
  • Special Category Personal Data (Health Data): Your workout, nutrition, and body analysis data are processed exclusively based on your explicit consent under Article 6 of the Law.
  • Application of KVKK Principle Decision 2026/347 (Turkey): Where processing relies on explicit consent, the Information Notice and the Explicit Consent Text are presented separately with separate declarations. Where another legal basis applies, only the information notice is presented.

CCPA/CPRA (For California Users)

Under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA), your personal information is collected solely to provide the stated services (fitness tracking, analysis). Data Protection Commitment: We do not sell or share your personal information with data brokers, advertising networks, or any third party for cross-context behavioral advertising. As we do not engage in selling or sharing as defined under the CCPA/CPRA, providing a separate "Do Not Sell or Share My Personal Information" opt-out option is not required.

LGPD (For Users in Brazil)

Under the Brazilian General Data Protection Law (LGPD, Lei nº 13.709/2018), our legal bases for processing are: (i) performance of a contract to deliver the Service, (ii) explicit consent for sensitive health data, and (iii) legitimate interests such as infrastructure security and service improvement. Our designated Encarregado (Data Protection Officer under the LGPD) can be reached at: privacy@arneox.com. If you believe your data protection rights under the LGPD have been violated, you may file a complaint with the Brazilian National Data Protection Authority (ANPD) at www.gov.br/anpd.


4. How We Use Your Information

We process your data primarily to deliver our services to you:

  • Service Delivery: Workout tracking, progress analysis, performance calculations, route tracking, personalized programs, and macro/calorie counting.
  • Account Management: Authentication, subscription management, customer support.
  • Personalization: Creating recommendations tailored to your health and fitness profile.
  • Security & Improvement: Analyzing app performance, detecting bugs, and fulfilling legal obligations.
  • Fraud Prevention & Abuse Detection: Identifying and addressing suspicious activity, unauthorized access attempts, Terms violations, and potentially fraudulent transactions in order to protect all users and the integrity of the platform.

Strict Commitment to Health Data Privacy: Your body measurements, workout history, nutrition habits, health metrics, and any other sensitive data generated by the app will not be sold, rented, or shared with advertisers, data brokers, or third-party marketing networks under any circumstances. Furthermore, this data will never be utilized for targeted advertising purposes.


5. Data Sharing

Commercial Isolation of Personal Data: ARNEOX completely prohibits the sale of personal data as a commercial commodity.

We share your data with the following categories of third parties to operate our Service:

  • Database & Authentication: Supabase (Frankfurt, Germany, EU-hosted) — core database and user authentication. Data transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission.
  • API & Edge Computing: Cloudflare — API gateway, edge computing, and DDoS protection.
  • AI Infrastructure: For our artificial intelligence capabilities, we do not use third-party generalized APIs (such as OpenAI, Gemini, Claude, etc.). We use our own internally developed and trained AI models running on the Modal cloud infrastructure in secure, isolated environments. Your health data is not sent to external generic AI APIs and is not shared to train third-party AI models.
  • Analytics: Firebase Analytics by Google (usage analytics and crash reporting), Sentry by Functional Software (error tracking).
  • Subscription Management: RevenueCat — subscription status, entitlement management, and revenue tracking.
  • Payments: Google Play Store (Android) and Apple App Store (iOS, planned) — purchase transactions. We do not store your payment card information.
  • Email: Transactional email delivery service (e.g., verification emails, account notices).

We may also disclose your information to relevant authorities when required by law (court orders, government requests).


6. International Data Transfers

Your data is managed by our entity in Turkey and stored on servers in Germany (Frankfurt, EU).

Since Turkey does not have a GDPR adequacy decision, we use Standard Contractual Clauses (SCCs) approved by the European Commission for transfers between Turkey and Germany.

ARNEOX may relocate its corporate entity to a different country in the future. In such a case, we will notify all users at least 30 days in advance via email. Any relocation will not diminish your privacy rights, and your data will remain at its current location unless you request otherwise.


7. International Privacy Rights (GDPR, CCPA, etc.)

GDPR Rights (EU/EEA Users)

  • Access: Request a copy of the data we hold about you
  • Rectification: Have inaccurate or incomplete data corrected
  • Erasure ("Right to be Forgotten"): Request deletion of your data
  • Restriction: Restrict data processing in certain circumstances
  • Portability: Receive your data in a machine-readable format
  • Object: Object to processing based on legitimate interest
  • Withdraw Consent: Withdraw consent for health data processing at any time
  • Automated Decision-Making: Request human review of decisions made solely through automated processing that significantly affect you, and object to such processing under GDPR Article 22
  • Complaint: File a complaint with your local data protection authority

CCPA/CPRA Rights (California Users)

  • Right to know about personal information collected
  • Right to request deletion of your data
  • We do not sell your personal information — no opt-out needed
  • We will not discriminate against you for exercising your rights

LGPD Rights (Brazil Users)

  • Access, correction, anonymization, or deletion of your data
  • Data portability and withdrawal of consent

How to Exercise Your Rights

  • In-App: Edit your profile, update measurements, Settings → Account → "Delete Account"
  • Email: privacy@arneox.com — subject line: "Data Request - [Your Right]"
  • Response Time: Handled in accordance with statutory timeframes (generally within 30 days).

8. KVKK (For Users in Turkey)

In accordance with the Turkish Personal Data Protection Law (KVKK) No. 6698, you may apply to ARNEOX as the data controller to exercise the following rights:

  • Learn whether your personal data is being processed,
  • Request information if your personal data has been processed,
  • Learn the purpose of processing and whether data is used in accordance with its purpose,
  • Know the third parties to whom your personal data is transferred domestically or abroad,
  • Request correction of incomplete or inaccurate personal data,
  • Request deletion or destruction of your personal data within the framework of KVKK Article 7 conditions,
  • Request notification of the operations made regarding correction or deletion to third parties to whom your personal data has been transferred,
  • Object to any unfavorable result arising from the analysis of your data exclusively through automated systems,
  • Claim compensation for damages arising from unlawful processing of your personal data.

You can submit these requests by emailing privacy@arneox.com with the subject "KVKK Data Request". Your requests will be processed free of charge within a maximum of 30 (thirty) days in accordance with the KVKK.


9. Age Restriction and 16+ Policy

All applications within the ARNEOX ecosystem are intended for individuals aged 16 and older.

  • Declaration Upon Registration: By registering for our app, you confirm and warrant that you are over the age of 16.
  • Violation Protocol: If we detect or are notified that a person under 16 has registered and provided personal data, their account will be immediately terminated without prior notice. All personal, health, and financial data associated with that account will be permanently deleted from our servers.
  • We do not knowingly collect data from users under 16. Violation of this policy is the user's responsibility.

10. Data Retention

Active Accounts

Your personal and fitness data is retained for as long as your account is active.

Inactive Accounts: If your account has had no logins, purchases, or data activity for 3 consecutive years, we may treat it as inactive. In such cases, we will send a notice to your registered email address at least 60 days in advance before taking any action, giving you an opportunity to reactivate your account.

Account Deletion

When you request account deletion:

  • Your data is soft-deleted for 30 days (recoverable)
  • A reminder email is sent 7 days before permanent deletion
  • After 30 days, your personal data is permanently deleted

Legal exceptions: Financial records are retained for 7 years (tax law requirement). Anonymized analytics data may be retained (cannot be linked back to you).


11. Security

We implement industry-standard security measures to protect your data:

  • All data is encrypted at rest and in transit (HTTPS/TLS)
  • Users can only access their own data in the database
  • Passwords are hashed, not stored in plaintext
  • Regular security reviews are conducted

In the event of a data breach, we will notify affected users via email within 72 hours.


12. Cookie and Tracking Policy

12.1 Mobile Applications

ARNEOX mobile applications do not use traditional browser cookies. To maintain your login session and ensure device security, we use only encrypted session tokens and local device storage.

12.2 Website (arneox.com)

Our website (arneox.com) uses Firebase Analytics to understand how visitors interact with our pages (such as page views and navigation patterns). This service may place cookies or use similar tracking technologies in your browser. Website analytics are activated only after you give your consent through a cookie notice displayed on your first visit. You can withdraw this consent at any time through your browser settings or by clearing your cookies.

12.3 Excluded Tracking Technologies

We do not employ third-party advertising networks (e.g., Google Ads, Facebook Pixel), external tracking pixels, or retargeting tools across our platforms. We do not engage in cross-site tracking or behavioral ad profiling. No data derived from cookies or analytics is sold or otherwise transferred to any third party.


13. AI Data Processing and Limitations

ARNEOX uses specially trained artificial intelligence (AI) models and Large Language Models (LLMs) running directly on the Modal cloud infrastructure to improve the platform. These models generate fitness analyses, form assessments, dietary calculations, and interactions through ARNEOX AGENT. We do not use third-party AI APIs such as OpenAI, Gemini, or Claude in our services, meaning your data is never included in the training processes of those external platforms. To protect your privacy, AI data usage is governed by user controls and subscription protections:

  • User Controls (Management via Settings): You can opt out of AI Data Usage and ARNEOX AGENT Data Access at any time from the app (Settings -> Privacy). Disabling these controls does not limit your access to the core features of the Service.
  • Default Aggregated Learning: Unless the AI Data Usage setting is disabled by the user, collected data (including analytics, metrics, and AI interactions) may be processed after being entirely stripped of personal identifying information. These anonymized datasets are used exclusively to improve and train the AI models developed and controlled by ARNEOX.

Important Warnings About AI Outputs:

  • Not Medical Advice: All recommendations, workout programs, form assessments, and nutrition suggestions from ARNEOX AGENT are for general informational purposes only. They should not be considered medical diagnosis, treatment, or professional health advice under any circumstances.
  • Liability Limitation: AI-generated recommendations are provided "AS IS." To the fullest extent permitted by law, ARNEOX is not liable for injuries, health issues, or any damages resulting from applying AI-generated recommendations. Always consult a doctor before starting intensive exercise programs.
  • Data Ownership: The data powering our AI models remains ARNEOX's property. This data is not sold, licensed, or used to train third-party AI models.

14. Policy Changes

ARNEOX reserves the right to modify this Privacy Policy in response to regulatory changes or platform updates.

For changes that significantly affect your rights or obligations, we will send a 30-day advance notice to the email address linked to your account. Continued use of the ARNEOX Platform after the changes take effect means you accept the updated terms.


15. Severability, Survival, and Jurisdiction

  • Severability: If any provision of this Privacy Policy is found invalid or unenforceable by a court, the remaining provisions will continue to apply. The policy will remain in effect to the fullest extent permitted by law.
  • Governing Law: The interpretation and enforcement of this document are governed by the laws of the Republic of Turkey (excluding conflict of law rules).
  • Jurisdiction: Any dispute arising from this policy is subject to the jurisdiction of the Courts and Execution Offices of Istanbul (Anatolian Courthouse), Turkey. This clause does not affect the right of consumers in the EU/EEA to bring proceedings in their country of habitual residence under Regulation (EU) No 1215/2012 (Brussels I bis).

16. Contact and Supervisory Authorities

Privacy & Data Protection Requests: privacy@arneox.com General Support: support@arneox.com

Data Controller: ARNEOX YAZILIM Merdivenköy Mah. Dikyol Sk. B Blok No: 2 İç Kapı No: 179 Kadıköy / İstanbul, Turkey

For EU/EEA users: You may contact us directly at privacy@arneox.com for any data protection concerns. We respond to all inquiries within the timeframes required by applicable law.

Supervisory Authorities for Complaints:

  • Republic of Turkey: Kişisel Verileri Koruma Kurumu (KVKK)
  • European Union / EEA: European Data Protection Board (EDPB)
  • Brazil: Autoridade Nacional de Proteção de Dados (ANPD)
  • United States (California): California Privacy Protection Agency (CPPA)

17. Automated Decision-Making and Profiling

ARNEOX does not make decisions that significantly affect you based solely on automated processing or profiling — such as eligibility determinations, account access decisions, or other high-impact outcomes — without human oversight.

AI-powered features (e.g., ARNEOX AGENT, workout recommendations, strength analysis) are advisory tools. You are always free to review, question, or disregard any AI-generated output. These outputs are informational in nature and never constitute binding decisions about your access, health, or legal status.

Under GDPR Article 22, you have the right to request human review of any automated assessment and to object to such processing where it produces significant effects on you. To exercise this right, contact: privacy@arneox.com.


This document is provided to fulfill information obligations under applicable data protection laws. Where explicit consent is required, we present a separate consent flow; your right to refuse or withdraw consent is preserved.

Legal Operator: Fatih Alay Arneox Yazılım (sole proprietorship, Turkey), trading as "ARNEOX".

Back to top

Product

  • Arneox Fitness
  • Arneox Nutrition
  • Arneox Run

Company

  • About
  • Contact
  • Features

Legal

  • Privacy Policy
  • Terms of Use
  • Explicit Consent
Arneox

Three precision-engineered apps for fitness, nutrition, and running. One unified ecosystem built for athletes.

© 2026 ARNEOX. All rights reserved.

Sport Ecosystem
Also known as: arnx, arnox, arneox fitness, arneox platform, arneox run, arenox, sport ecosystem app