Quantum Logic LLC, a Texas limited liability company, doing business as Xposed360 (“we,” “us,” or “our”), operates the xposed360.com website and the Xposed360 web and mobile application (collectively, the “Service”). This Privacy Policy explains how we collect, use, share, and protect information when you use our Service.
By using Xposed360, you agree to the collection and use of information in accordance with this Privacy Policy.
1. Information We Collect
We collect the following categories of information:
Account Information
- Name (optional, provided during onboarding)
- Email address (used for account creation and communication)
- Password (stored in encrypted and hashed form; we never store passwords in plain text)
Health-Related Information You Provide
When you use Xposed360 to track your well-being, you may log information including:
- Daily symptoms (e.g., allergy severity, fatigue, sleep quality, mood, respiratory symptoms)
- Self-reported severity levels
- Personal notes and observations
- Any other health-related information you choose to enter
This information is sensitive. We treat it with care and use it only to power the features of the Service described below.
Location Information
The Service uses location data to retrieve local environmental conditions (pollen, air quality, weather, humidity, UV). You can choose between two location modes in Settings:
- ZIP Code Mode (default for new accounts):You enter a 5-digit U.S. ZIP code. We do not access your device’s GPS in this mode. The location associated with your account is the ZIP code centroid.
- Live GPS Mode (optional, requires permission):With your explicit permission, we access your device’s precise geographic coordinates (latitude and longitude) approximately once per hour while you are using the Service. We use these coordinates only to retrieve local environmental data and to reverse-geocode them into a human-readable location label. Coordinates are transmitted to Open-Meteo, Google (Pollen API), and the OpenStreetMap Foundation (Nominatim) as described in Section 3. We do not store a continuous location history. You can switch back to ZIP Code Mode or revoke location permission at any time through device settings or the app’s Settings screen.
If location permission is denied or revoked, the Service can still function using ZIP Code Mode, but real-time location-based features will be unavailable.
Payment Information
Premium subscriptions are sold and processed by the Apple App Store or Google Play. We do not receive, collect, or store your payment card details, billing address, or other financial account information.
From Apple and Google, we receive only the limited transaction information needed to grant you access to Premium features and manage your subscription — specifically:
- A platform-specific transaction or subscription identifier (an opaque string assigned by Apple or Google)
- The product identifier (which plan you subscribed to)
- The subscription status (active, expired, in grace period, or cancelled)
- The subscription start date, renewal date, and expiration date
We use this information solely to verify your Premium access and to honor your subscription. Apple’s and Google’s privacy practices are governed by their own privacy policies, available on the Apple and Google websites.
Device and Usage Information
When you use the Service, we automatically collect:
- Device type, operating system, and browser
- IP address and general geographic region
- Pages viewed, features used, and timestamps
- Crash reports and diagnostic information
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, and improve the Service
- Correlate your logged symptoms with environmental conditions at your location
- Generate personalized AI-powered pattern analyses (Premium feature)
- Process subscription payments and manage billing
- Communicate with you about your account, the Service, and important updates
- Detect, prevent, and respond to fraud, abuse, and security incidents
- Comply with applicable laws and legal obligations
3. How We Share Your Information
We do not sell your personal information. We share information only as described below.
Service Providers
We use trusted third-party service providers to operate the Service. These providers have access to your information only to perform specific tasks on our behalf and are contractually obligated to protect it:
- Apple Inc. (App Store / In-App Purchase) — for users on iOS devices, Apple processes subscription payments and provides us with the limited transaction information described in Section 1.
- Google LLC (Google Play / Play Billing) — for users on Android devices, Google processes subscription payments and provides us with the limited transaction information described in Section 1.
- OpenMeteo — environmental data (weather, humidity, UV index)
- Google LLC (Pollen API) — pollen count data
- OpenStreetMap Foundation (Nominatim)— reverse geocoding service that converts your geographic coordinates into a human-readable place name (city, state, ZIP). This request is made directly from your browser, so your latitude, longitude, and your device’s IP address are sent to Nominatim; no symptom data, account identifiers, or other personal information is transmitted.
- Anthropic, PBC (Claude API)— AI-powered pattern analysis. Your symptom and environmental data, along with an approximate location reduced to roughly a 1-kilometer area, may be sent to Claude to generate your personalized analysis. Anthropic does not use this data to train its models.
- Render, Inc. — application hosting and database infrastructure
- Sentry (Functional Software, Inc.)— application error monitoring and crash reporting. When an error occurs in the Service, technical diagnostic information (such as the error type, stack trace, and the page or feature where the error occurred) is sent to Sentry to help us identify and fix bugs. We have configured Sentry to exclude direct personally identifiable information from these reports. Sentry does not receive your symptom logs or health data in the normal course of operation.
- Cloudflare, Inc. — content delivery, DNS, and security services
We may add or change service providers as the Service evolves. We will update this Privacy Policy to reflect any material change to our service providers and notify users in accordance with Section 12 before such changes take effect.
Legal Compliance
We may disclose your information if required to do so by law, subpoena, court order, or similar legal process, or if we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
Business Transfers
If Xposed360 is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy.
With Your Consent
We may share information in other ways with your explicit consent.
4. Data Retention
We retain your information for as long as your account is active. When you delete your account, we immediately and permanently delete your account and all associated data — including your symptom check-ins, environmental history, and profile — from our active systems. Because we maintain encrypted database backups for disaster recovery, residual copies of deleted data may persist in those backups for up to 3 days, after which they are permanently overwritten and become unrecoverable. We may retain limited records where required for legal, accounting, tax, or security purposes (for example, payment records required for tax compliance).
5. Your Rights
Depending on where you live, you may have the right to:
- Access the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your account and associated personal data
- Export a copy of your data in a portable format
- Withdraw consent for certain processing at any time
- Object to certain uses of your information
To exercise these rights, email [email protected]. We will respond within 45 days.
6. California Residents (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (“CCPA”) as amended by the California Privacy Rights Act (“CPRA”):
Right to Know. You may request that we disclose what personal information we have collected about you, the categories of sources, the business or commercial purposes for collecting it, the categories of third parties with whom we share it, and the specific pieces of personal information we hold.
Right to Delete. You may request that we delete personal information we have collected from you, subject to certain exceptions (such as legal compliance or completing a transaction).
Right to Correct. You may request that we correct inaccurate or incomplete personal information about you.
Right to Opt Out of Sale or Sharing.We do not sell your personal information for monetary consideration. We do not “share” your personal information for cross-context behavioral advertising as those terms are defined in the CCPA/CPRA.
Right to Limit Use of Sensitive Personal Information.Some of the information you provide to Xposed360 — including your health symptoms, severity ratings, and precise geolocation when Live GPS Mode is enabled — qualifies as “Sensitive Personal Information” under the CPRA. We use this Sensitive Personal Information only for the purposes you would reasonably expect (operating the Service, generating AI analyses, and the other purposes described in Section 2). We do not use it to infer characteristics about you for profiling or advertising. You may request that we limit our use of Sensitive Personal Information by emailing [email protected] with the subject line “CCPA Sensitive PI Request.”
Right to Non-Discrimination. We will not retaliate against you for exercising any of these rights.
Categories of Personal Information Collected (in the last 12 months). Identifiers (email, account ID); customer records (name); commercial information (subscription history); internet or device activity (IP address, device type, pages viewed); geolocation data (precise, with permission); inferences drawn from health-related data; and Sensitive Personal Information (health information, precise geolocation when enabled). We retain each category as described in Section 4.
How to submit a request.Email [email protected] from the email address associated with your account with the subject line “CCPA Request.” We will verify your identity by confirming your account email and may ask for additional verification for sensitive requests. We will respond within 45 days. We may extend our response time by an additional 45 days for complex requests and will notify you of the extension.
Appeal rights. If we deny your request, you may appeal by replying to our denial email. We will respond to your appeal within 45 days.
Authorized Agents. You may designate an authorized agent to submit requests on your behalf. Authorized agents must provide a signed permission or power of attorney, and we may require you to verify your identity directly.
California Shine the Light.California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes. We do not share personal information with third parties for their direct marketing purposes.
6a. Other U.S. State Privacy Rights
Residents of Texas (Texas Data Privacy and Security Act, TDPSA), Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Utah (UCPA), Iowa (ICDPA), Indiana (ICPA), Tennessee (TIPA), Montana (MCDPA), Oregon (OCPA), Delaware (DPDPA), Maryland (MODPA), Minnesota (MCDPA), New Hampshire (NHPA), New Jersey (NJDPA), and Rhode Island (RIDTPPA) have privacy rights substantially similar to those described in Section 6, including the rights to access, delete, correct, and port personal information, and the right to opt out of targeted advertising, sale of personal information, and certain forms of profiling.
To exercise any of these rights, email [email protected] from the email associated with your account, with the subject line “State Privacy Request” and the name of your state. We will respond within 45 days. If we deny your request, you may appeal by replying to our denial email. If your appeal is denied, you may file a complaint with your state Attorney General.
6b. Washington Consumer Health Data Rights (MHMDA)
If you are a Washington State resident or if we collect your consumer health data while you are in Washington, additional rights apply under the Washington My Health My Data Act (“MHMDA”).
Consumer Health Data.Under MHMDA, “Consumer Health Data” means personal information that is linked or reasonably linkable to you and that identifies your past, present, or future physical or mental health status. This includes the symptoms, severity levels, conditions, treatments, notes, and similar health-related information you log in Xposed360, as well as precise geolocation data that could indicate your use of health services.
Our Consumer Health Data Privacy Policy. This Privacy Policy serves as our Consumer Health Data Privacy Policy as required by MHMDA. We do not sell your consumer health data. We share consumer health data only with the service providers listed in Section 3, who process it solely on our behalf under contract and may not use it for their own purposes.
Affirmative Consent. When you create an account, we ask for your affirmative, opt-in consent to the collection and processing of consumer health data as described in this Privacy Policy. You may withdraw that consent at any time by deleting your account through Settings, which removes your consumer health data from our active systems in accordance with Section 4. We do not share consumer health data with any third party other than the service providers listed in Section 3 without separate, additional authorization from you.
Your MHMDA Rights. If you are a Washington resident, you have the right to:
- Confirm and access whether we are collecting, sharing, or selling your consumer health data, and to access the consumer health data we hold about you;
- Withdraw consent to our collection and sharing of your consumer health data at any time;
- Delete your consumer health data, including from our service providers and any backups, subject to legally required retention periods (see Section 4);
- Non-discriminationfor exercising any of these rights — we will not deny you services, charge you a different price, or provide a lesser level of service because you exercised an MHMDA right.
How to exercise your rights.Email [email protected] with the subject line “MHMDA Request” from the email associated with your account. We will respond within 45 days. If your request is complex, we may extend our response time by an additional 45 days and will notify you of the extension.
Appeal rights. If we deny your request, you may appeal by replying to our denial email. We will respond to your appeal within 45 days. If your appeal is denied, you may file a complaint with the Washington State Attorney General at atg.wa.gov/file-complaint.
7. International Users (GDPR)
If you are located in the European Economic Area, United Kingdom, or Switzerland, you have rights under the General Data Protection Regulation (GDPR), including the rights listed in Section 5. The legal bases on which we process your information include:
- Performance of our contract with you (providing the Service)
- Your consent (for health and location data)
- Our legitimate interests (improving and securing the Service)
- Compliance with legal obligations
Our Service is operated from the United States. By using the Service, you consent to the transfer of your information to the United States.
8. Children’s Privacy
Xposed360 is intended for and available only to users 18 years of age and older. Account creation requires confirmation that you are at least 18.
We do not knowingly collect personal information or health data from anyone under 18. If we learn that we have collected information from anyone under 18, we will delete it as promptly as practicable. If you believe we may have collected information from someone under 18, please contact [email protected].
9. Security and Breach Notification
We implement industry-standard technical and organizational safeguards to protect your information:
- HTTPS/TLS 1.2 or higher encryption for all data in transit
- AES-256 encryption at rest for the database and sensitive data
- Restricted internal access to personal data on a need-to-know basis
- Regular security updates to our hosting, application, and dependency infrastructure
- Encrypted database backups with point-in-time recovery
No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Breach Notification.If we discover a breach of unsecured personally identifiable health information, we will notify affected individuals, the U.S. Federal Trade Commission, and, where required, the media in accordance with the FTC Health Breach Notification Rule (16 CFR Part 318). Notification will be made without unreasonable delay and no later than 60 calendar days after discovery of the breach. Notifications will include the categories of information involved, the approximate date of the breach, a description of what we are doing in response, and recommended steps you can take to protect yourself. For breaches of other personal information (such as account credentials) that do not constitute personally identifiable health information, we will notify affected individuals as required by applicable state breach notification laws. We will also comply with breach notification requirements under applicable state laws, including the Washington My Health My Data Act, California Civil Code § 1798.82, and Texas Business and Commerce Code § 521.053.
10. Health Privacy Framework — HIPAA, FTC HBNR, and State Health Privacy Laws
Xposed360 is a direct-to-consumer wellness application. We are:
- NOT a “covered entity” or “business associate” under HIPAA.HIPAA’s Privacy Rule, Security Rule, and Breach Notification Rule do not apply to your relationship with Xposed360. The information you log is not “Protected Health Information” (PHI) as defined by HIPAA.
- Subject to the FTC Health Breach Notification Rule (16 CFR Part 318) as amended in 2024. We will notify you, the Federal Trade Commission, and, where required, the media in the event of any breach of your unsecured personally identifiable health information. See Section 9.
- Subject to applicable state consumer health data laws, including the Washington My Health My Data Act, Nevada SB 370, and the consumer health data provisions of state comprehensive privacy laws.
- Subject to the FTC Act § 5 prohibition on unfair or deceptive practices, which applies to all our health-related representations.
We treat the information you provide as sensitive and apply protections commensurate with its sensitivity, even where not strictly required by HIPAA.
11. Not Medical Advice
Xposed360 is a wellness and tracking tool. It does not provide medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider regarding medical concerns.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or through a notice within the Service before the changes take effect. Continued use of the Service after the effective date of the updated policy constitutes your acceptance of the changes.
13. Contact Us
If you have questions about this Privacy Policy or our privacy practices, contact us at:
Quantum Logic LLC, doing business as Xposed360
5900 Balcones Drive, STE 100
Austin, TX 78731
Email: [email protected]
Website: https://xposed360.com