Vexa Vexa LLC

Privacy Policy

Vexa is a movement-monitoring app operated by Vexa LLC, a Minnesota limited liability company (“Vexa,” “we,” “us”). This policy explains what data the app handles, where it lives, and the limited circumstances in which any of it leaves your device. Vexa is a wellness and self-tracking tool. It is not a medical device and does not diagnose, treat, or prevent any condition.

Effective date: September 11, 2026 · Last updated: September 11, 2026

The short version

Almost everything Vexa records stays on your iPhone. We do not run an account system, we do not have a server that collects your sessions, and we do not sell or share your data for advertising. There are two exceptions, both described below. The text transcript of a voice note is sent to an AI service to suggest a one-word context tag, and only if you have given permission. And if you choose to take part in data sharing for research, an export file that you create is shared with us — never automatically. Reports and data files leave your device only when you choose to share or export them.

What the app handles

When you use Vexa, the app creates and stores the following on your device:

  • Head-motion data from your AirPods Pro, processed into movement and tremor-severity metrics for each session.
  • Session metadata — date, time, duration, the condition profile and treatment settings you enter, and self-reported ratings.
  • Voice notes — if you record one, the app captures the audio, transcribes it to text on your device, and stores the transcript with the session.
  • Heart-rate context — if you grant permission, Vexa reads recent heart-rate samples from Apple HealthKit to add context to a recording.

Where your data is stored

All of the above is stored locally on your device, in the app’s private storage. Vexa does not upload your sessions, metrics, voice recordings, transcripts, or health data to a Vexa server, because Vexa operates no such server for this data. There is no Vexa account, and your data is not associated with an online profile.

The one copy of your session data that we may hold is a file you create and upload yourself, if you choose to take part in data sharing for research. That is described in its own section below.

The one time data leaves your device automatically

When you record a voice note, the audio is transcribed to text on your device using Apple’s on-device speech recognition. To suggest a short context tag for that note (for example, “stress” or “fatigue”), the app can send the text transcript to a third-party AI service, Anthropic, through a Vexa-operated proxy that holds the API credentials. The service returns a suggested tag.

This happens only with your permission: the app asks before your first voice note, and you can turn AI tagging off at any time in Settings. If you decline or turn it off, your voice notes still record, transcribe, and save on your device — no transcript is transmitted, and the note simply has no AI-suggested tag.

The proxy passes the text through and does not store it. The text is processed by Anthropic to generate the tag, under Anthropic’s API terms; Anthropic’s commercial API terms state that data submitted through the API is not used to train its models. The audio never leaves your device. You can use Vexa without recording voice notes; if you never record one, no transcript is ever transmitted.

Data you choose to share for research

Separately from the app, Vexa runs an optional programme in which testers can send their session data to help improve how the app measures head movement. Taking part is voluntary. Nothing about the app changes if you don’t.

Nothing is sent automatically. The app does not upload anything on its own. You create an export file yourself, under Settings → Export my data, and you decide whether to upload it. If you never create and upload a file, nothing in this section applies to you.

What you would be sharing. The export contains your session measurements, your own self-ratings, the treatment settings you entered, and raw motion recordings from the sessions you choose to include. Identifying and free-text content is removed before the file is created, and every date in it is shifted. The full list of what is included and what is removed is set out on the consent page at vexahealth.app/share, which is the authoritative description and which you read and agree to before sharing anything.

How it is identified. The file carries an eight-character code generated on your device. It contains no name, email address or device identifier. This makes the data pseudonymous, not anonymous — the code links your own exports to one another, and the consent page sets out the residual re-identification risk plainly.

Where it is held. Files are uploaded over an encrypted connection to a folder held with our storage provider, Sync.com, in their United States data region, and are stored encrypted there. Anyone uploading can add a file but cannot see or download anything already in that folder.

How long it is kept. Retained for up to five years from upload, then deleted. May be deleted sooner.

What it is used for. Developing and testing how Vexa measures head movement, and research that may be published or presented to clinicians. Results are reported in aggregate or under your code, never under your name. It may also support future applications to regulators or research funders. Vexa LLC is a commercial company and this work may inform a product we sell; you receive no payment or share of proceeds. We do not sell this data and we do not share it with advertisers or data brokers.

Withdrawing. Email LFinlay@vexahealth.app with your code and your files will be deleted. One limit, stated plainly: analysis that has already been published or submitted cannot be unpicked. We delete the files and leave you out of anything future.

Age. You must be 18 or older to share data for research, even though the app itself is 17+.

Apple HealthKit

If you enable it, Vexa reads heart-rate data from HealthKit to provide context for your recordings. This is optional, and Vexa works without it. Health data read from HealthKit is used only inside the app to annotate your sessions. We do not use HealthKit data for advertising or marketing, we do not sell it, and we do not share it with third parties. Vexa requests read access only and does not write data back to HealthKit.

Reports and exports you initiate

Vexa can generate a PDF report and can export your session data to a file. These leave your device only when you take an explicit action — sharing a report with your clinician, or exporting via AirDrop, Files, Mail, or another destination you choose. Once you share a file, what happens to it is governed by the service or person you sent it to.

What we do not do

We do not sell your data. We do not share it with advertisers or data brokers. We do not show ads. We do not build an advertising or marketing profile of you. We do not use third-party analytics or crash-reporting services that collect your usage or personal data.

Children

Vexa is not directed to children. You must be at least 17 to use the app, and at least 18 to share data with us for research. We do not knowingly collect data from anyone under those ages.

Deleting your data

Because your data is stored on your device, deleting the Vexa app removes the data the app has stored there — except the participant code, which is kept so that a later deletion request can still be matched to your files. Vexa does not keep a separate server copy of your sessions to delete. Voice-note transcripts sent for tagging are not retained by Vexa anywhere off your device — the tagging proxy is a stateless pass-through and stores nothing.

If you have shared an export file for research, that copy is held by us and is not removed by deleting the app. Email LFinlay@vexahealth.app with your participant code and it will be deleted. In any case those files are kept for no more than five years from upload.

Changes to this policy

We may update this policy as the app changes. Material changes will be reflected by updating the effective date above and, where appropriate, noted in the app.

This version adds the section on data you choose to share for research. The previous version was effective July 11, 2026.

Contact

Questions about this policy: LFinlay@vexahealth.app