15X Labs

15X Labs · 法律

隱私政策

我們刻意將處理的個人資料量保持在最小範圍,並準確說明它們會發生什麼事。本政策依照我們遵循的最嚴格標準撰寫,並將該標準適用於每一個國家的每一位使用者。

本頁面以你的語言提供,僅為方便閱讀。本文件的完整法律文字以英文發布,英文版本為具有約束力的正式版本。若譯文與英文文字有出入,以英文文字為準。 閱讀英文版.
This document applies to 15X Labs, a brand of Rekify Enterprises LLP, and to every mobile application, website and service we publish and distribute, collectively, the "Services". It applies uniformly across all of our apps on the Apple App Store, Google Play and any other distribution channel we use.

Draft version, pending professional legal review. Read the full notice.

生效日期
28 July 2026
最後更新
28 July 2026

1. Who we are (data controller)

Rekify Enterprises LLP (“we”, “us”, “our”), trading as 15X Labs, is the data controller for personal data processed through our Services. Our registered address is Bareilly, Uttar Pradesh, India. You can reach us for any privacy matter at hello@15xlabs.com.

We have appointed representatives for the purposes of Article 27 of the GDPR and Article 27 of the UK GDPR. Until the details of those representatives are published here, data subjects in the European Economic Area, the United Kingdom and Switzerland may contact us directly at hello@15xlabs.com, marking the subject line "GDPR representative", and we will route the request accordingly. Contacting us directly does not limit any right you have.

For the purposes of the Indian Digital Personal Data Protection Act, 2023, our Grievance Officer can be reached at hello@15xlabs.com with the subject line "DPDP grievance". We acknowledge grievances within 72 hours and aim to resolve them within 30 days.

Each of our apps declares its own data practices on its App Store privacy label and on its Google Play Data Safety form. Those store level declarations are the per app source of truth for that app, are kept consistent with this policy, and are updated when the app changes. Where an app collects less than this policy describes, the app listing and any in app notice govern for that app. This policy is the maximum scope, never the minimum.

2. What we collect

We collect only what an app needs to function, stay stable and improve. Depending on the app, this may include:

  • Device and technical data: device model, OS version, language, region, app version, and non-permanent device or installation identifiers.
  • Usage and analytics data: screens opened, features used, session length, and aggregated interaction events.
  • Diagnostic and crash data: crash logs, performance traces and error reports.
  • Purchase data: subscription and in-app-purchase status. Payments are processed entirely by Apple or Google; we never receive or store your card details.
  • Content you provide: anything you choose to enter in an app (notes, preferences, uploads), plus account details such as an email address where an app offers accounts.
  • Support correspondence: the contents of emails you send us and any details you include.

Sensitive and health related data. Some of our apps exist to help you record health, wellbeing, medication, body or lifestyle information, and some let you submit photographs or documents. Where an app processes data of that kind, it does so only because you chose to enter it, only for the function you asked for, and, in the European Economic Area, the United Kingdom and Switzerland, only on the basis of your explicit consent under Article 9(2)(a) of the GDPR. We do not use health related data for advertising, we do not sell it, and we do not share it with advertising partners under any circumstances. Wherever an app can keep such data on your device, it does.

For residents of Washington State and Nevada, the consumer health data laws, the My Health My Data Act and Nevada SB 370, apply to any consumer health data we hold. We collect it only with your consent, we do not sell it, we never sell it without the separate written authorisation those laws require, and you may exercise your rights, including confirmation, access, withdrawal of consent and deletion, by writing to hello@15xlabs.com with the subject line “Consumer health data”. We will delete the data, and instruct our processors to do the same, within the statutory period.

We do not knowingly collect biometric identifiers for identification purposes, and we do not collect data revealing racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union membership, genetic data, sexual orientation, precise geolocation or government identifiers, unless an app's core function plainly requires it and you have explicitly consented in the app. Under Apple's rules, data obtained from HealthKit or a Health related framework is never used for advertising, marketing or data broking, and is never disclosed to third parties for those purposes.

Signing in with Apple, Google or another provider. Where an app offers social or platform sign in, including Sign in with Apple, we receive only a stable user identifier, the display name you agree to share and an email address. If you choose to hide your email address, Apple gives us a private relay address instead, and we treat it exactly like any other contact address: we use it only for account and support messages, and we never try to resolve it back to your real address. We do not pull contacts, friend lists, posts or any other data from the sign in provider, and we do not post anything on your behalf. Sign in with Apple is offered wherever an app offers another third party sign in option.

App Store and Google Play privacy labels. The disclosures on this page are written to match the App Privacy labels on each App Store listing and the Data safety section on each Google Play listing. We use collected data only for the purposes declared there, and when a data practice changes we update the store labels and this policy together, before the change ships.

3. Why we process it, and our legal bases

  • To provide the Services: performance of a contract with you (GDPR Art. 6(1)(b)).
  • To keep apps secure, stable and free of abuse: our legitimate interests (Art. 6(1)(f)).
  • To measure and improve features: consent where required, otherwise legitimate interests.
  • For personalised advertising or tracking: only with your consent, requested through Apple's App Tracking Transparency prompt or an in-app consent banner.
  • To comply with law: legal obligation (Art. 6(1)(c)).

Where processing relies on consent, you can withdraw it at any time, in your device settings, in the app, or by emailing us. Withdrawal does not affect processing carried out before withdrawal.

4. Cookies and similar technologies

Our website uses only what is strictly necessary to serve pages. Our apps may use local storage, SDK identifiers and similar technologies for the purposes described above. Where consent is required, for example in the EEA, the UK, Switzerland and Brazil for non essential technologies, we ask for it before those technologies are used, and you may change your choice at any time. Full detail, including how to switch each category off, is in our Cookie and Tracking Policy.

5. Advertising, attribution and measurement

We advertise our apps. To know whether an advertisement worked, we and our partners measure installs, trials and subscriptions attributable to a campaign. Depending on the app and the channel, the partners involved may include Apple, through Apple Ads attribution, SKAdNetwork and AdAttributionKit, Meta Platforms, through the Meta software development kit and Conversions API, TikTok, through the TikTok Pixel, the TikTok software development kit and the TikTok Events API, Google, through Google Ads conversion measurement, Firebase and Google Analytics for Firebase, and a mobile measurement partner that consolidates attribution across channels. We also use RevenueCat for subscription entitlements, trials, renewals and receipt validation, and PostHog for product analytics and usage measurement. PostHog is treated as a consent gated technology for visitors and users in the European Economic Area, the United Kingdom and Switzerland, and we identify people to it by a pseudonymous identifier rather than by name wherever the feature allows it. The current list is on our subprocessors page.

Where an app uses tracking for advertising purposes on iOS, it presents the App Tracking Transparency prompt first, and no IDFA or other tracking identifier is accessed unless you allow it. Choosing "Ask App Not to Track" is honoured across our apps and across every SDK we integrate. Several of our apps do not use ATT at all because they perform no cross app or cross site tracking, and in that case no prompt is shown. You can change your choice at any time in iOS Settings, Privacy and Security, Tracking, or reset or limit your advertising ID in Android settings. Where the law requires consent, we ask before any advertising or measurement technology runs, and refusing is as easy as accepting.

We may also create audiences from hashed identifiers, such as a hashed email address or an advertising identifier, so that advertising platforms can show our apps to people likely to find them useful, or exclude existing users. We never include health related, financial or other sensitive attributes in such an audience. In the terminology of the CCPA as amended by the CPRA, this activity can amount to “sharing” for cross context behavioural advertising, and in the terminology of some other United States state laws to “targeted advertising”. We do not sell personal information for money. You may opt out at any time, as described in the rights section below, and we honour recognised universal opt out signals including Global Privacy Control.

We do not use any of the following for advertising or audience building: health, medical, medication or symptom data, images or documents you submit, content you write inside an app, or data from children's apps.

6. Service providers and third parties

We share personal data only with processors who help us run the Services, under contracts that restrict them to our instructions. Typical categories include:

  • Cloud hosting, storage and content delivery providers
  • AI model providers and gateways, where an app has AI powered features
  • Voice transcription providers, where an app offers voice input
  • Analytics and product-measurement providers
  • Crash reporting and performance monitoring providers
  • Customer support and email providers
  • Advertising partners, where an app is ad-supported
  • Apple and Google, for app distribution, billing and subscription management

The named providers behind these categories are listed on our subprocessors page, together with what each one does and where it processes data.

We do not sell personal data for money, and we never sell or share health related data, content you submit, or children's data. Where our advertising measurement amounts to “sharing” for cross context behavioural advertising or “targeted advertising” under United States state law, section 5 explains it and you can opt out at any time. We may disclose data where legally required, to respond to a lawful request from an authority, to enforce our terms, to protect rights and safety, or in connection with a merger or acquisition, in which case this policy continues to apply until superseded. We assess every government request for validity and disclose only the minimum required.

7. International data transfers

We are based in India and use providers that may process data in the United States, the European Economic Area and elsewhere. Where personal data leaves the EEA, UK or Switzerland, we rely on appropriate safeguards, principally the European Commission's Standard Contractual Clauses (with the UK Addendum and the Swiss adaptations where applicable), together with technical and organisational measures. A copy of the relevant safeguards is available on request at hello@15xlabs.com.

  • Adequacy first: where the European Commission or the UK Government has recognised a destination country as providing an adequate level of protection, we rely on that adequacy decision and do not layer unnecessary paperwork on top of it.
  • Transfer impact assessments: before relying on Standard Contractual Clauses for a new provider, we assess the law and practice of the destination country, the nature of the data, and whether any supplementary measure such as encryption, pseudonymisation or storage region pinning is needed. We repeat that assessment when a provider materially changes where or how it processes data.
  • India and Brazil: transfers are made on the basis of contract, and on your consent where the DPDP Act or the LGPD requires consent, with the ANPD's standard clauses used where they apply.
  • Where processing happens: the providers we use and the regions they process in are listed on our subprocessors page, which we keep current.

If a safeguard we rely on is invalidated, we suspend the affected transfer or move the processing rather than continue without a lawful basis.

8. How long we keep data

We keep personal data only as long as needed for the purpose it was collected for. The table below sets our default retention periods. Where a specific app or a specific legal duty requires a shorter or a longer period, that specific rule prevails.

CategoryDefault retention
Account data, where an app offers accountsFor as long as the account is active, plus a 30 day grace period after closure
Support correspondence24 months from the last message, then deleted or irreversibly anonymised
Diagnostic, crash and product analyticsUp to 24 months in identifiable form, then aggregated or deleted
Transactional and billing recordsAs long as tax, accounting and consumer protection law require, typically 7 to 10 years
Consent and preference recordsFor as long as we rely on the consent, plus the retention period the local regulator recommends for proof of consent
Server access and security logsUp to 12 months, longer only where an active investigation requires it
BackupsDeleted on the normal backup expiry cycle, typically within 35 days of the source deletion

After the applicable period, data is deleted or irreversibly anonymised. Where a shorter period is required by a specific law or by an app's own privacy declaration, that shorter period prevails.

9. Security and breach notification

We use encryption in transit (TLS), access controls, least-privilege administration and reputable infrastructure providers. No system is perfectly secure, but we take reasonable and appropriate measures proportionate to the risk.

If a personal data breach happens, here is what we commit to, whether or not a particular law compels it:

  • Regulators: where the GDPR or UK GDPR applies, we notify the competent supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of the breach, unless it is unlikely to result in a risk to your rights and freedoms.
  • You: where a breach is likely to result in a high risk to you, we tell you directly and without undue delay, in plain language.
  • What we tell you: what happened, which categories of data were involved, what the likely consequences are, what we have done to contain it, what you can do to protect yourself, and a contact point for questions.
  • Shorter deadlines win: where a US state law, the India DPDP Act, Brazil's LGPD or any other regime sets a shorter notification deadline or a wider notification duty than the one above, we meet the stricter requirement.
  • Our processors: our contracts require providers to report a breach to us without undue delay so that we can meet these deadlines.

To report a suspected vulnerability or a possible breach to us, write to hello@15xlabs.com with “Security report” in the subject. We acknowledge within 72 hours.

10. Children and age appropriate design

Our applications and this website are intended for and directed to people aged 18 and over. They are not directed to children, are not marketed to children, and we do not knowingly collect personal data from anyone under 18. Under the United States Children's Online Privacy Protection Act (COPPA), our services are not directed to children under 13 and we do not knowingly collect their data. Under the UK Age Appropriate Design Code and Ireland's Fundamentals for a Child Oriented Approach, we build with privacy protective defaults, data minimisation and no dark patterns. Under Article 8 of the GDPR and the parental consent thresholds each Member State has set, our 18 and over floor sits above every one of them. Under the EU Digital Services Act, we do not present advertisements based on profiling using personal data of a person we know or reasonably suspect is a minor.

If you believe a person under 18 has provided us personal data, contact hello@15xlabs.com with the subject line "Minor account" and we will delete it without undue delay, and in any event within 30 days, and we will confirm the deletion to you in writing.

  • Design codes: we build to the standards in the UK Age Appropriate Design Code, Ireland's Fundamentals for a Child-Oriented Approach to Data Processing and the California Age Appropriate Design Code, which means privacy-protective defaults, data minimisation and no dark patterns that nudge a young person into giving up more data.
  • No ads to minors: we never knowingly serve personalised, behavioural or cross-context advertising to anyone we know or reasonably suspect is a minor, and we do not sell or share their data for advertising.
  • No profiling: we do not profile minors, and we do not use their data to build interest segments or to optimise engagement.
  • Parents and guardians: write to hello@15xlabs.com with “Child data request” in the subject to review, correct or delete a child's data, or to withdraw a consent you previously gave. We respond within 30 days and usually much sooner, and we do not require you to create an account to ask.

If you believe a child has provided us personal data, contact hello@15xlabs.com and we will delete it promptly.

11. Your rights

Depending on where you live, you have some or all of the following rights: access, a copy of your data, correction, deletion, restriction, objection, portability, withdrawal of consent, and the right not to be subject to solely automated decision-making with legal effects (we do not carry out such decision-making).

  • EEA & UK (GDPR / UK GDPR): all rights above, plus the right to lodge a complaint with your local supervisory authority or the UK Information Commissioner's Office.
  • California (CCPA/CPRA): rights to know, access, delete, correct and port, and to limit the use of sensitive personal information. We do not sell personal information for money. Our advertising measurement can amount to “sharing” for cross context behavioural advertising, and you may opt out at any time by emailing us or by sending a recognised universal opt out signal such as Global Privacy Control, which we honour. We never sell or share health related data. We do not discriminate against you for exercising a right, and authorised agents may submit requests on your behalf.
  • Canada (PIPEDA): access and correction rights, and the right to complain to the Office of the Privacy Commissioner of Canada.
  • Quebec (Law 25): access, correction, portability, de-indexation and the right to withdraw consent, plus the right to be informed when a decision is based exclusively on automated processing. No feature of ours makes such a decision. Complaints may be made to the Commission d'accès à l'information du Québec.
  • Australia (Privacy Act / APPs): access and correction rights, and the right to complain to the OAIC.
  • New Zealand (Privacy Act 2020): access and correction rights, and the right to complain to the Privacy Commissioner.
  • Japan (APPI): disclosure, correction and suspension-of-use rights.
  • South Korea (PIPA): access, correction, deletion, suspension of processing and withdrawal of consent, and the right to complain to the Personal Information Protection Commission.
  • China (PIPL): access, copy, correction, deletion, withdrawal of consent, portability, and an explanation of our processing rules. Where an app is made available in mainland China, cross border transfers are made only on a lawful basis and with separate consent where required.
  • Singapore (PDPA) and Thailand (PDPA): access, correction, withdrawal of consent, and, in Thailand, deletion, objection and portability, with a right to complain to the PDPC or the Thai PDPC respectively.
  • Switzerland (revFADP): rights equivalent to those above, and the right to contact the FDPIC.
  • Turkey (KVKK): to learn whether your data is processed, to request information, correction, erasure and notification to third parties, and to complain to the KVKK authority.
  • South Africa (POPIA): access, correction, deletion, objection, and the right to complain to the Information Regulator.
  • Nigeria (NDPA), Saudi Arabia (PDPL) and the United Arab Emirates (PDPL): access, correction, deletion, withdrawal of consent and objection, with a right to complain to the relevant national authority.
  • India (DPDP Act, 2023): rights to access, to correction and erasure, to grievance redressal, and to nominate another person to exercise your rights.
  • Brazil (LGPD): confirmation of processing, access, correction, anonymisation, portability, deletion, information about sharing, and the right to complain to the ANPD.
  • Everywhere else: if you live in a country not named above, we still give you the substance of these rights. Where your local law grants you something stronger than what is described here, your local law applies and we will honour it. We do not require you to prove which law covers you before we act on a request.

We do not make decisions about you by automated means alone where those decisions produce legal effects or similarly significant effects, in any country. Where an app uses a model to generate a score, a suggestion or a summary, it is presented to you as information for you to judge, never applied to you as a decision.

To exercise any right, email hello@15xlabs.com from the address associated with your request. We respond within 30 days (or sooner where the law requires), and we may ask for information to verify your identity. There is no charge unless a request is manifestly unfounded or excessive.

12. Artificial intelligence and automated processing

Some features send the content you provide to a model provider so that a suggestion, summary, score or image can be generated and returned to you. When you are interacting with an AI system, we tell you so in the interface, consistent with the transparency duties in the EU Artificial Intelligence Act. Providers act as our processors, are contractually barred from using your content to train their own general purpose models, and retain it only for the short period needed to return a result and prevent abuse.

We do not use AI to make decisions producing legal or similarly significant effects about you, and no feature performs biometric categorisation, emotion inference in a workplace or educational setting, social scoring, or any other practice prohibited under that Act. If you would prefer that a piece of content is not processed by an AI feature, do not submit it to that feature.

Which providers receive your content. Where an app offers an AI feature, the content you submit to that feature is sent to Anthropic (Claude), which generates the response. OpenAI is used as a fallback provider only when Anthropic is unavailable. Where an app offers voice input, ElevenLabs converts your recording into text. These requests are routed through the Vercel AI Gateway and our infrastructure provider, Rork. Not every app uses every provider, and an app that has no AI feature sends nothing to any of them.

What is sent. Only the content you submit to that feature, together with the settings needed to answer it, such as your chosen output language and region. Where an app offers voice input, the audio recording you make is sent as well.

What is not sent. Your name, your account or profile details, and your saved history in the app are not sent to these providers. Our contracts prohibit them from using your content to train their own models. They retain content only for the short period needed to return a result and prevent abuse.

Your permission. Where an app sends your content to these providers, it asks for your explicit permission in the app first, and sends nothing until you grant it. You can withdraw that permission at any time in that app's settings, which stops its AI features until you allow it again.

13. United States state privacy rights

If you are a resident of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, Montana, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky, Rhode Island or another state with a comprehensive privacy law, you may request to know, access, correct, delete and port your personal information, opt out of targeted advertising and profiling, and limit the use of sensitive personal information. We do not use your data for profiling with legal or similarly significant effects.

We honour Global Privacy Control and other recognised universal opt out signals. We do not discriminate against you for exercising a right, and where a state provides an appeal, you may appeal a refusal by replying to our decision, after which you may contact your state Attorney General. Authorised agents may submit requests with proof of authority. Send all requests to hello@15xlabs.com.

14. Deleting your data or account

You can delete most data simply by deleting the app, which removes data stored on your device. Where an app offers an account, in-app account deletion is provided and removes associated server-side data. You can also email hello@15xlabs.com with the subject line “Data deletion request” and we will process it, subject to any records we must retain by law.

Every app of ours that lets you create an account also lets you delete that account from inside the app, in line with App Store Review Guideline 5.1.1(v), and deletion removes the account and its associated server side data rather than merely deactivating it. Writing to hello@15xlabs.com is an alternative route, not the only one. The account deletion page sets out the in app path and the timelines that apply.

15. Changes to this policy

We may update this policy as our Services evolve or the law changes. The “last updated” date at the top always reflects the current version, and material changes will be announced in-app or by email where appropriate. Continuing to use the Services after an update means you accept the revised policy.

16. Contact and complaints

Rekify Enterprises LLP, Bareilly, Uttar Pradesh, India. Privacy contact: hello@15xlabs.com. If you are not satisfied with our response, you may complain to your local data protection authority.

These matters, and any dispute, claim or proceeding arising out of or connected with them, whether contractual or non contractual, are governed by the laws of India, without regard to conflict of law rules. The competent courts at Bareilly, Uttar Pradesh, India shall have exclusive jurisdiction and shall be the exclusive venue, and you submit to the personal jurisdiction of those courts and waive any objection based on venue or inconvenient forum. To the fullest extent the law allows, disputes must be brought individually, and class, collective, consolidated and representative proceedings are waived. Nothing here prevents us from seeking injunctive or equitable relief in any competent court to protect our intellectual property or to stop unauthorised use of the Services. If you are a consumer resident in a country whose mandatory law does not permit this choice of court, that law prevails to that limited extent, and only to that extent, so you keep any right you have to bring proceedings where you live and to the protection of the mandatory consumer laws of that place.

Questions about this document? Write to hello@15xlabs.com. Rekify Enterprises LLP, Bareilly, Uttar Pradesh, India.