Privacy Policy
Last updated 23 September 2026
This policy covers the ACEX app, the ACEX account site where you manage your subscription, and the waitlist. It sets out what we collect, why, who else sees it, and what you can do about it. ACEX is run by ACEX International Limited ("we", "us"), a company registered in England and Wales, and we are the data controller for everything described here.
Questions about your data go to privacy@acexos.com.
The short version
We collect your contact details, what you tell the app about your training and how you are performing, and how you use it. Some of that describes your state of mind, so we handle it carefully. Parts of the app use AI models to build your plan, answer your questions, and make sense of your debriefs, which means that text goes to the AI providers named below. We do not sell your data or use it for advertising. You can delete your account whenever you like.
What we collect
When you join the waitlist
We ask for an email address or a phone number. We use it to tell you when access is ready and, now and then, to update you on the launch. Nothing else.
When you create an account
- your email address or phone number, which you sign in with;
- your name;
- your time zone, so reminders arrive at a sensible hour;
- the invite code you joined with, if you used one. Every account also gets its own invite code to share. If someone opens your invite link, they will see your first name.
There are no passwords. You sign in with a one-time code or link sent by email or text. If you manage your subscription on the account site, we set a cookie there to keep you signed in.
Your performance audit
When you start, the app asks you to rate yourself from 0 to 10 on things like focus, emotional control, confidence, execution, and sleep and recovery. It also asks what tends to get in your way (pressure, frustration, self-doubt and so on), where you perform, when you have time to train, and, if you want to answer, what you think is holding you back. You can type or speak that last answer. We use all of this to build your plan and schedule your reminders.
What you record and write in the app
ACEX is a mental performance tool, so a lot of what you put into it reflects how you are feeling. This is the data we are most careful with. It includes:
- scores you give before and after a session, regular check-ins on how you are doing in each area, and the prompts you tap to say what improved;
- morning pre-briefs and daily debriefs: how you rate the day, and what you say about what went well, the pressure you faced, what you learned, and your focus for tomorrow;
- voice notes and text notes, including the audio, the transcript we make from it, and any rating you attach;
- your conversations with Ask ACEX, the in-app coach, whether typed or spoken;
- which sessions you play, how far you get, and which ones you save.
Recording and writing are optional. These features only hold what you choose to put in them.
What we work out from it
From the above we produce things that are about you: your plan and its priorities, session recommendations ranked by what you have played and liked, summaries and tags for your debriefs, short labels for your notes, longer-term insights once you have done enough debriefs, and progress scores such as your Neural Adaptation Score and rep records. These are stored on your account.
Subscriptions and payments
If you subscribe, we keep your plan, its status, prices and invoices, and the transaction records from whoever took the payment. If you pay on the web, Stripe collects your card details directly. We never see or store your full card number. If you pay through the App Store or Google Play, Apple or Google handle the payment and send us a record of the purchase. We also note which country's store you bought from.
How you use the app
We log each time you open the app, when sessions start and finish, how much you listen to, where you stop, the time of day you train, your streaks and points, and your notification settings. We also collect product analytics: the screens you visit, the buttons you tap, your device type, operating system, language and region. If you turn on notifications, we store a device token so we can reach you. We sometimes test two versions of a feature against each other, and we record which version you were shown.
Technical and diagnostic data
When the app crashes or hits an error, Sentry sends us a report. It can include your device and operating system, the steps leading up to the problem, and an identifier tied to your account. We also send Sentry timing data from a small sample of sessions so we can find slow spots. We use this to fix faults and nothing else.
Why we use your data
UK data protection law requires us to have a reason. Ours are:
- To provide the service you signed up for. Running your account, building your plan, playing sessions, saving your notes, answering you in Ask ACEX, and taking payment all depend on it.
- Your consent, for the waitlist, push notifications, and microphone access. You can withdraw it whenever you want.
- Our legitimate interests, for diagnostics, product analytics and feature tests. They help us keep the app stable and work out what is actually helping people, and we weigh that against your privacy.
- Legal obligations, such as keeping payment records for tax purposes.
Who we share it with
We do not sell your data and we do not share it for advertising. We use a small number of service providers who process data for us, under contract and only for the purposes below.
AI providers
- Google, through its Gemini models, writes your plan, replies in Ask ACEX, and prepares your pre-briefs and debrief summaries.
- Together AI runs the models that turn your pre-briefs and debriefs into plans, tags and insights.
- Cloudflare runs the model that gives your notes their short labels.
What they receive depends on the feature. For Ask ACEX it is your message, the conversation so far, your audit answers and plan, your latest check-in scores, and your recent sessions. For debriefs it is what you said and your pre-brief for that day. We send only what the feature needs.
Everyone else
- Deepgram turns your speech into text as you talk, for debrief answers, Ask ACEX, and your audit. It processes audio in the EU.
- Cloudflare stores uploaded files such as voice notes, transcribes recordings you upload, and can send our emails.
- Mailgun sends our emails, including sign-in codes and reminders.
- Amazon Web Services (AWS) sends our text messages, including sign-in codes.
- Apple and Google deliver push notifications to your phone.
- Stripe takes web payments and manages web subscriptions.
- Apple and Google take App Store and Google Play payments.
- PostHog holds our product analytics, on servers in the EU.
- Sentry receives crash and error reports, on servers in the EU.
- DigitalOcean hosts the servers and database that run the service.
Our website loads its fonts from Google, so Google sees your IP address when you visit.
We may also disclose data if the law requires it, or to protect our rights, our users, or the public.
AI and automated decisions
We would rather be upfront about this. A lot of ACEX is shaped by software looking at your data: your plan, the sessions we suggest, the labels on your notes, the insights on your debriefs, and every reply from Ask ACEX. Speech-to-text and AI models both get things wrong sometimes, so a transcript may not match what you said and a suggestion may miss the mark. None of it has legal consequences for you or decides anything about you outside the app. If something looks wrong, tell us.
Where your data is held
Our providers run data centres in the UK, the European Union, and the United States, so your data may leave the UK. When it does, we rely on safeguards that UK law recognises, such as the International Data Transfer Agreement or standard contractual clauses, so it keeps a similar level of protection.
How long we keep it
We keep your account data while your account is open. When you close it, we delete or anonymise your personal data within a reasonable period, apart from records the law makes us keep longer, such as payment records. Waitlist details are kept until you ask us to remove them or the waitlist closes.
Your rights
Under UK GDPR you can ask for a copy of your data, have it corrected or deleted, restrict or object to how we use it, or have it sent to another provider. You can also withdraw any consent you have given. Email privacy@acexos.com and we will reply within the time the law allows. You can delete your account yourself in the app (You tab → Advanced settings → Delete account). The steps, and what is deleted or kept, are on our delete account page. Deleting your account does not cancel an App Store or Google Play subscription, so cancel that in your store settings too.
If you think we have handled your data badly, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather hear from you first so we can put it right.
How we protect it
We encrypt data in transit, keep sign-in tokens short-lived, and limit who can reach the systems that hold your data. No service is perfectly secure, but we take this seriously and review our setup as the product grows.
Children
ACEX is not for anyone under 16, and we do not knowingly collect their data. If you think a child has given us their data, email us and we will delete it.
Changes to this policy
If we change how we handle your data, we will update this page and the date at the top. If the change is significant, we will tell you in the app or by email before it takes effect.
Contact
ACEX International Limited, England and Wales. Questions, requests, or complaints: privacy@acexos.com.