At Xeep, we believe your physiological intelligence data belongs to you. Our privacy policy ensures Malaysian-hosted, end-to-end encrypted protection of your most personal health information.
All your physiological data is encrypted from device to storage, ensuring only you can access your information.
Your data stays within Malaysia's borders, protected by local data protection laws and regulations.
We're transparent about how your anonymized data helps improve wellness for all Malaysians.
Welcome to Xeep. This Privacy Policy explains how XEEP PLT (Company Registration No. 202504002688) ("Xeep," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use our wellness intelligence platform, including our website (xeep.io), mobile applications (iOS and Android), and Xeep Device (smart wellness wearable).
Your privacy is important to us. We are committed to protecting your personal data and complying with the Personal Data Protection Act 2010 (PDPA) of Malaysia and other applicable data protection laws.
By using Xeep's services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with this Privacy Policy, please do not use our services.
We collect several types of information to provide you with our services and improve your wellness experience.
When you create an account or use our services, you provide us with:
When you use your Xeep Device and our platform, we automatically collect:
1. Heart Rate: Continuous measurements (288 readings per day, 5-minute intervals)
2. Blood Oxygen Saturation (SpO2): Periodic measurements (144 readings per day, 10-minute intervals)
3. Blood Pressure: Algorithmic estimates based on sensor data (60-85% confidence level) - NOT medical-grade measurements
4. Sleep Data: Duration, stages (light, deep, REM), efficiency, and quality metrics
5. Physical Activity: Steps, distance, calories burned, active minutes, exercise sessions
6. Stress Levels: Real-time stress indicators based on heart rate variability
7. Heart Rate Variability (HRV): Measurements indicating autonomic nervous system balance
8. XQ (Flow State) Scores: Our proprietary wellness intelligence metric calculated from your health data
9. Wellness Checks: Multi-metric manual assessments you perform
We automatically collect technical information about your device and how you use our services:
We use cookies and similar tracking technologies to enhance your experience. Please see our Cookie Policy for detailed information about:
We use your personal information for the following purposes, all lawfully processed under the Personal Data Protection Act 2010 (PDPA):
We process your health data through our proprietary algorithm to generate your personalized XQ (Flow State Intelligence) score, which predicts your optimal times for focused work, creativity, and wellness activities.
We use artificial intelligence and machine learning to analyze your health patterns and provide personalized recommendations for improving your wellness, sleep, stress management, and productivity.
We process continuous data from your Xeep Device to display your current health metrics, trends, and alerts in your dashboard.
We store and analyze your historical health data to identify long-term patterns, improvements, and areas needing attention.
We use aggregated and anonymized health data from all users to continuously improve the accuracy and reliability of our XQ algorithm, making it more effective for Malaysian users specifically.
We analyze how users interact with our platform (which features are used most, where users encounter difficulties) to improve the user experience and add requested features.
We use error logs and crash reports to identify and resolve technical issues, ensuring platform stability and reliability.
With your consent (opt-out available), we create anonymized datasets from your health data to advance wellness research in Malaysia. This helps us understand Malaysian health patterns, develop better wellness insights, and contribute to public health knowledge.
Commercial Data Licensing: We license anonymized datasets to academic institutions, healthcare providers, pharmaceutical companies, and government health agencies. Your identifiable personal information is NEVER shared with third parties. All data is irreversibly anonymized using industry-leading privacy techniques (k-anonymity ≥20, differential privacy, HIPAA Safe Harbor compliance).
Your contribution to our data flywheel enables us to keep subscription prices affordable (RM39 Lite, RM59 Pro) while building the largest Malaysian wellness intelligence dataset to improve health outcomes for all Malaysians.
Contributing your anonymized health data to research and our data flywheel is a mandatory, non-negotiable condition of using Xeep services. There is no opt-out mechanism available.
Why This Is Required: Your data contribution is what makes Xeep affordable. Our business model relies on the data flywheel:
While data contribution is mandatory, your privacy remains paramount:
If you are uncomfortable with mandatory data contribution for research:
This mandatory data license is explicitly stated in our Terms of Service Section 5.4 and is a condition of creating a Xeep account.
We take your privacy seriously and only share your information in limited circumstances:
We share limited data with trusted third-party service providers who help us operate our platform:
All our service providers are contractually obligated to:
We create anonymized datasets that CANNOT identify you and share them with:
Re-identification Risk: Our target is <0.05% (less than 1 in 2,000 chance of re-identifying any individual).
We may disclose your information if required by Malaysian law or in response to:
User Notification: We will notify you within 7 days of any legal disclosure request unless legally prohibited from doing so. We publish the number of legal requests received annually in our Transparency Report.
If Xeep is involved in a merger, acquisition, asset sale, or bankruptcy, your personal information may be transferred to the acquiring entity. We will:
We retain your information for different periods depending on the type of data and legal requirements:
While your account is active:
When you delete your account:
Confirmation: You will receive an email confirmation when your account deletion is complete (approximately 60 days after request).
Under the Personal Data Protection Act 2010, you have the following rights:
You can request:
How to Request:
Response Time: 14 days (PDPA requires 21 days; we commit to faster service)
Format: CSV, JSON, or PDF report
Cost: First request per year is FREE. Subsequent requests may incur RM20 fee (to prevent abuse).
You can request correction of:
Cannot be Corrected:
How to Request:
Response Time: 7 days
How to Delete Your Account:
Verification Required:
Timeline: 30-day cooling-off period, then permanent deletion within 60 days total.
What Happens:
Export Your Data:
Transfer to Another Platform:
You can opt out of:
You CANNOT opt out of:
If you're not satisfied with how we handle your data:
We implement industry-standard security measures to protect your personal information:
Firebase (Google Cloud Platform) data centers with:
If a Data Breach Occurs:
Cyber Insurance: We maintain RM5 million cyber liability insurance coverage.
Responsible Disclosure: If you discover a security vulnerability, please report it to security@xeep.io. We do NOT take legal action against security researchers who report vulnerabilities responsibly.
Your data may be stored and processed outside Malaysia:
When we transfer data internationally, we ensure:
If we expand to serve users in other countries (Singapore, EU, US), we will:
Xeep is intended for users aged 18 years and above only.
We do NOT knowingly collect personal information from children under 18.
If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately at dpo@xeep.io. We will delete such information within 30 days.
Age Verification: We require date of birth during registration and will reject accounts for users under 18.
Our platform may contain links to third-party websites, apps, or services not operated by Xeep:
We are NOT responsible for:
Recommendation: Review the privacy policies of any third-party services you access through Xeep.
We may update this Privacy Policy from time to time to reflect:
We maintain a complete version history of this Privacy Policy:
Your Rights: If you do not agree with updated Privacy Policy, you may delete your account within 30 days of notification.
XEEP PLT
Company Registration No. 202504002688
Registered Address: B-01-09 Savanna Lifestyle Retail, Jalan BBL2, Dengkil, Selangor, Malaysia
Personal Data Protection Commissioner, Malaysia
Personal Data Protection Department
Level 6, Menara MCMC, Jalan Impact, Cyber 6
63000 Cyberjaya, Selangor, Malaysia
• Email: pdp@pdp.gov.my
• Phone: +603-8911 7000
• Website: https://www.pdp.gov.my
By creating a Xeep account or using our services, you acknowledge that you have:
Your use of Xeep services constitutes acceptance of this Privacy Policy.
We are committed to radical transparency about data usage:
Last Updated: 24 October 2025 | Effective Date: 24 October 2025 | Version: 1.0
This Privacy Policy is governed by the laws of Malaysia.