Legal

Privacy Policy

Effective date: 5 May 2026 Last updated: 5 May 2026
Note for the team: this is a starting-point Privacy Policy template. Before going live to the public — especially before launching the iOS app or running paid traffic in the EU/UK or California — please review with qualified privacy counsel and adapt for your specific data practices, sub-processors, and jurisdictions.

This Privacy Policy explains how Axis ("Axis", "we", "us", or "our") collects, uses, shares, and protects your personal information when you visit our website, join the waitlist, or — once available — use the Axis mobile application (collectively, the "Service").

We've tried to write this in plain language. Where we use defined terms, they're explained where they appear. If anything is unclear, you can always reach us at the contact address at the bottom of this page.

1.Who we are

Axis is a wellbeing application designed to help women 35+ build and follow a personalized health system. The "controller" of your personal data — the entity that decides why and how it is processed — is the company operating the Service.

If you're located in the European Economic Area (EEA), the United Kingdom, or Switzerland, references to GDPR apply equally to the UK GDPR and the Swiss FADP where relevant.

2.Information we collect

Information you give us directly

Information we receive from your device or third parties

3.How we use your information

We use your information to:

We do not sell your personal information. We do not use your health data, journal content, or voice recordings to train third-party advertising models, and we do not run third-party advertising inside the Service.

If you're in the EEA, UK, or Switzerland, we rely on the following legal bases under the GDPR / UK GDPR / FADP:

Consent (Art. 6(1)(a))
For the waitlist email, marketing communications, processing of health data (special category, Art. 9(2)(a)), and any optional integrations or AI processing of uploaded documents.
Contract (Art. 6(1)(b))
To provide the core Service you've requested once you become a user.
Legitimate interests (Art. 6(1)(f))
To improve the Service, prevent abuse, and keep our systems secure — balanced against your rights and freedoms.
Legal obligation (Art. 6(1)(c))
To comply with laws that apply to us.

You may withdraw consent at any time. Withdrawal does not affect processing carried out before withdrawal.

5.How we share information

We share personal information only with the following categories of recipients, and only as needed:

We do not sell or rent your personal information, and we do not share health-related data with third-party advertisers.

6.Data retention

7.Security

We use industry-standard technical and organizational measures to protect your information, including encryption in transit (TLS) and at rest, access controls, audit logging, and the principle of least privilege. Where possible, we process data on-device or in a privacy-preserving way.

No system is perfectly secure. If we ever experience a breach that affects your personal information, we will notify you and the relevant authorities as required by law.

8.Your privacy rights

Depending on where you live, you may have some or all of the following rights:

To exercise any of these rights, contact us at the address in Section 14. We will respond within the time limits set by applicable law (typically 30 days under GDPR, 45 days under CCPA).

California residents have specific rights under the CCPA/CPRA, including the right to know what personal information we collect, the right to delete it, the right to correct inaccuracies, and the right to opt out of the "sale" or "sharing" of personal information (we do not sell or share personal information as defined by the CCPA). We do not discriminate against you for exercising any of these rights.

9.International data transfers

Your personal information may be transferred to and processed in countries other than the one where you live. Where we transfer personal data out of the EEA, UK, or Switzerland, we use appropriate safeguards — typically the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, and (where applicable) supplementary measures.

10.Cookies & tracking

On our website we use a small number of cookies and similar technologies:

If we add advertising or remarketing cookies in the future, we will surface a consent banner allowing you to accept or reject non-essential cookies before they are set. You can also control cookies through your browser settings.

11.Children's privacy

The Service is intended for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a child has provided us with personal information, please contact us and we will take prompt steps to delete it.

12.Health information

Some information you share with Axis — symptoms, medications, cycle data, lab results — qualifies as "special category" personal data under GDPR (sometimes called sensitive personal information). We process it only with your explicit consent, only for the purposes described in this Policy, and we apply additional protections, including:

Axis is a wellbeing app, not a medical device. Insights surfaced inside the Service are observations for your personal awareness and are not a substitute for advice from a qualified healthcare professional.

13.Changes to this policy

We may update this Privacy Policy from time to time. When we make material changes, we'll update the "Last updated" date at the top, and — where required — notify you in the Service or by email at least 30 days before the changes take effect. Continued use of the Service after the effective date means you accept the updated Policy.

14.How to contact us

If you have questions, want to exercise a privacy right, or want to report a concern, write to us — we read every email.

Privacy questions?

We aim to respond within 5 working days, and always within the legal deadlines.

privacy@axis.app