XREMS EMS Remote for Android · com.sromline.xremsems
Privacy Policy
Effective date: 19 August 2026
XREMS EMS Remote is designed to work without user accounts and without tracking. This policy describes exactly which data the app stores on your device, and the one single situation in which data leaves your phone.
1. In short
- No account, no registration, no login. You never give us an email address or a password.
- No analytics, no crash reporting, no advertising. The app contains no tracking SDKs of any kind.
- No user profiles on our servers. Your training data stays on your phone.
- Data leaves your device in exactly one situation: when you actively use the Remote Control feature. See section 5.
2. Controller
The controller responsible for data processing within the meaning of Art. 4(7) GDPR and Art. 5(j) of the Swiss Federal Act on Data Protection (FADP) is:
SROMLINE GmbHVorderi Böde 15452 OberrohrdorfSwitzerlandPhone: +41 56 534 17 53Email: contact@xrems.fitWe have not appointed a data protection officer; we are not required to do so under Art. 37 GDPR or under the FADP.
3. Data stored on your device
The following data is written to the app's private storage area (Android SharedPreferences, serialised as JSON). It is readable only by this app and is not transmitted to us.
| Category | Contents | Purpose |
|---|---|---|
| Training profiles | Display name you choose, avatar emoji, level, creation date, preferred device type | Letting several people use one phone with separate settings |
| Training history | Start time, duration, program name, training mode, device type, average intensity | Statistics and progress tracking inside the app |
| Training goals | Targets you define yourself | Progress display |
| Custom programs | Programs you create: frequency, pulse width, interval timings | Reusing your own programs |
| Channel settings | Per-channel intensity and on/off state | Restoring your setup between sessions |
| Last device used | Bluetooth device name and Bluetooth address (MAC) of your EMS device | Reconnecting automatically to your own equipment |
| Onboarding status | Whether you completed the safety briefing and accepted it | Not repeating the mandatory briefing on every launch |
| Room history | Room codes you previously entered for Remote Control | Convenience when reconnecting |
The display name is free text. We recommend not entering your full legal name — a first name or nickname is enough for the app to work.
4. Android backup
The app currently permits Android's system backup (allowBackup="true"). If you have enabled backup in your Android settings, the data listed in section 3 may be copied to your personal Google account and restored when you set up a new device.
This backup is performed by Google, not by us. We have no access to it. It is governed by Google's Privacy Policy and by your device's backup settings, which you can change at any time under Settings → Google → Backup.
5. Remote Control (WebRTC) — the only outbound data flow
The Remote Control feature lets an external application control your training session by connecting through a room code. This is the only part of the app that sends data off your device. If you never use Remote Control, no data ever leaves your phone.
a) Signalling server
When you enter a room code and connect, the app contacts our signalling server at eaglefit-remote-signal-server.up.railway.app. The following is transmitted to it:
- the room code you entered
- WebRTC connection descriptions (SDP offers and answers)
- ICE candidates — these contain your device's IP addresses, including local network addresses and your public IP address
The server's only job is to introduce the two participants to each other. It does not receive your training data and does not store a user profile. The connection is closed when you leave the room.
The server is hosted at Railway Corp., 80 Bogart St, Brooklyn, NY 11206, USA. This means a transfer of personal data (your IP address) to a third country. See section 9.
b) STUN servers
To determine how your device is reachable through your router, the app queries two public STUN servers operated by Google LLC, USA (stun.l.google.com:19302 and stun1.l.google.com:19302). These servers receive your public IP address.
c) Peer-to-peer connection
Once the connection is established, control commands travel directly between the two participants over an encrypted WebRTC data channel (DTLS-SRTP). This traffic does not pass through our servers.
Anyone who knows your room code can connect to your session and control your training device. Treat a room code like a password: share it only with people you trust, and end the session when you are finished.
6. Permissions and why the app needs them
| Permission | Why |
|---|---|
BLUETOOTH, BLUETOOTH_ADMIN (Android 11 and older) | Connecting to your EMS device |
BLUETOOTH_SCAN, BLUETOOTH_CONNECT (Android 12+) | Finding and connecting to your EMS device |
ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION | Required by Android itself to scan for Bluetooth LE devices on Android 11 and older. The app does not determine, use, store or transmit your geographic position. |
INTERNET, ACCESS_NETWORK_STATE | Remote Control only (section 5) |
POST_NOTIFICATIONS | Showing training status while the app runs in the background |
7. What we do not do
- We do not collect analytics or usage statistics.
- We do not use crash or performance reporting services.
- We do not display advertising and do not use advertising identifiers.
- We do not use cookies or comparable tracking technologies in the app.
- We do not sell, rent or share your data with third parties for their own purposes.
- We do not create user profiles and do not perform automated decision-making or profiling within the meaning of Art. 22 GDPR.
8. Legal bases
| Processing | Legal basis |
|---|---|
| Local storage of profiles, training data and settings | Art. 6(1)(b) GDPR — performing the contract of providing the app's functionality |
| Bluetooth connection to your device | Art. 6(1)(b) GDPR |
| Remote Control incl. transmission of IP addresses | Art. 6(1)(a) GDPR — your consent, given by deliberately entering a room code and connecting. You may withdraw it at any time by ending the session and not using the feature. |
| Storing that you completed the safety briefing | Art. 6(1)(c) and Art. 6(1)(f) GDPR — documenting the safety warning is in our legitimate interest and serves product safety |
As a company established in Switzerland we process personal data in accordance with the Swiss Federal Act on Data Protection (FADP). Where we offer the app to users in the EU or EEA, the GDPR applies in addition under its Art. 3(2), and the legal bases above are stated accordingly.
9. International transfers
Using Remote Control transfers your IP address to the USA (Railway Corp. as our hosting provider, Google LLC as STUN operator). Such transfers are based on the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework and the corresponding Swiss-U.S. Data Privacy Framework where the recipient is certified, and otherwise on Standard Contractual Clauses pursuant to Art. 46(2)(c) GDPR together with the transfer safeguards of Art. 16 f. FADP.
If you do not use Remote Control, no international transfer takes place.
10. Retention and deletion
Data stored on your device is kept until you delete it. You can:
- delete individual profiles, training records, goals and custom programs inside the app,
- clear all app data at once under Settings → Apps → XREMS EMS Remote → Storage → Clear data,
- remove everything by uninstalling the app.
Uninstalling does not automatically remove an existing Google backup. Delete that through your Google account settings.
Signalling server data (room code, connection metadata) exists only for the duration of a session and is discarded when the session ends.
11. Your rights
Under the GDPR you have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object (Art. 21). Where processing is based on consent, you may withdraw it at any time with effect for the future (Art. 7(3)). Users in Switzerland have equivalent rights of access, rectification and erasure under Art. 25 ff. FADP.
Because we do not operate user accounts and hold no personal data about you on our systems, we are in most cases unable to identify you from a request alone (Art. 11 GDPR). The data is under your own control on your device. For questions, contact us at contact@xrems.fit.
You also have the right to lodge a complaint with a supervisory authority. For us, the competent authority is:
Federal Data Protection and Information Commissioner (FDPIC)Feldeggweg 13003 BernSwitzerlandwww.edoeb.admin.chIf you are located in the EU or EEA, you may alternatively lodge a complaint with the supervisory authority of your country of residence, place of work or the place of the alleged infringement (Art. 77 GDPR).
12. Children
The app is not intended for children and must not be used by persons under 18 without medical supervision. See the Medical and Safety Disclaimer. We do not knowingly process data from children.
13. Changes to this policy
We may update this policy when the app changes. The current version is always available at xrems.fit/android/policy/privacy/. Material changes affecting outbound data flows will be announced in the app.
Questions about these documents?
Write to us — we answer every message about data protection and app safety.
contact@xrems.fit