Privacy Policy
Rex · Last updated July 15, 2026
This policy explains how The Likeli Lab LLC (“Likeli Lab,” “we,” or “us”) handles information in the Rex app and on the Rex website. It is written for the services Rex uses today.
At a glance
- You can use Rex as a guest or sign in. Guest use creates a Firebase anonymous identifier. Guest saved places stay on the device, and visit logging requires sign-in.
- If you sign in, Rex can sync your profile, saved-place identifiers, and detailed visit entries through Firebase.
- Location access is optional and limited to use while the app is open. You can search another area without granting it.
- Rex uses Firebase Analytics to measure app use and Google AdMob to show ads. Apple’s tracking permission controls cross-app advertising tracking; it does not turn off Firebase Analytics.
- Purchases are processed by Apple. Rex does not receive your payment card details.
Information Rex processes
Account and profile
Rex uses Firebase Authentication for guest access, Sign in with Apple, Google Sign-In, and email/password accounts. Depending on how you sign in, Firebase may process a user ID, email address, display name, profile-photo URL, authentication provider, and anonymous or signed-in account status. Apple or Google also processes information under the settings and policy for the sign-in method you choose.
Saved places and visit entries
Saved places can include venue names, addresses, categories, coordinates, and place identifiers. Rex keeps complete saved-place details in local app storage. For signed-in accounts, Cloud Firestore stores saved-place identifiers, timestamps, optional provider IDs, and full visit entries. Visit entries can include the venue, date, ratings, dishes, notes, spending or value details, meal type, dining-party details, dietary information, reservations, parking, atmosphere, and other details you choose to enter. Guest saved places remain in local app storage unless they are later migrated to a signed-in account.
Location, search, and venue information
With permission, Rex receives your location while the app is in use to show nearby places and sort by distance. Rex does not request background location. You can deny or revoke location access and search a different area manually.
Search areas, coordinates, venue names, addresses, and place identifiers may be sent to Firebase Functions, Apple MapKit, Google Places, or Geoapify to return and enrich place results. Providers may also process IP addresses and technical request data needed to run, secure, and troubleshoot their services.
Community contributions and reports
When a signed-in user logs a visit, Rex may send basic venue information—such as the place name, category, address, coordinates, and summary activity counts—to maintain shared place listings. If you enable community sharing, Rex also uploads selected visit-derived facts for aggregate community results. Suggested edits and place reports are sent only when you submit them. Visit insights, edits, and reports are stored with your Firebase user ID so Rex can prevent abuse and handle account deletion. Other users receive aggregate results rather than your raw record, and Rex does not publish your display name with them.
When an account is deleted, Rex removes the user link from retained community contributions, public insights, and place reports. The resulting community facts may remain without that account link.
App analytics
Firebase Analytics records app and feature use, such as app opens, screens viewed, feature taps, category choices, result counts, whether a search had text, ratings, item counts, whether an entry has notes, saved-place and visit-count ranges, sign-in method, location permission status, purchase events, and subscription status. Rex does not send venue names, search text, dish names, or the contents of free-form visit notes as analytics event fields.
Analytics also processes device and app information and a pseudonymous app-instance identifier. Rex does not currently provide a separate in-app switch for Firebase Analytics.
Advertising
The free version of Rex uses Google AdMob. AdMob may process device, advertising, interaction, IP-derived region, and ad-performance data under Google’s policies. If you grant Apple’s App Tracking Transparency permission, the advertising identifier may be used for tracking across other companies’ apps and websites. If you decline or revoke permission, Rex does not have permission to access that identifier, but ads and Firebase Analytics may still operate.
Purchases
Apple processes in-app purchases and payment information through the App Store. Rex receives StoreKit transaction and entitlement information needed to unlock purchases. Product ID, price, currency, purchase result, and subscription status may also appear in Firebase Analytics. Rex does not receive or store your payment card number.
Support
If you email support, we receive your email address and anything you include in the message. Rex does not include an in-app chat, SMS, or marketing-newsletter service.
Why we use this information
We use the information described above to:
- authenticate accounts and sync saved-place identifiers and visit entries;
- return nearby, searched, and enriched venue results;
- provide purchases, community features, and customer support;
- measure feature use, diagnose failures, and improve Rex;
- serve and measure ads; and
- protect the service, prevent abuse, and meet legal obligations.
Depending on where you live, the legal basis may be performance of the service you request, your consent, our legitimate interest in operating and improving Rex, or compliance with law. You can withdraw a permission or consent through the controls described below.
Service providers and disclosure
Rex relies on the following providers:
- Google and Firebase for authentication, database sync, cloud functions, App Check, Remote Config, analytics, Google Sign-In, Google Places, and AdMob. See Firebase privacy and security and the Google Privacy Policy.
- Apple for Sign in with Apple, MapKit, StoreKit, App Store payments, device permissions, and related platform services. See Apple’s Privacy Policy.
- Geoapify for place search and venue enrichment. See Geoapify’s Privacy Policy.
We do not sell personal information for money. Advertising through AdMob, when tracking permission is granted, may be considered “sharing,” targeted advertising, or cross-context behavioral advertising under some privacy laws. We may also disclose information when required by law or necessary to protect users, the public, or the service.
Retention
- Account profiles, synced saved-place identifiers, and visit entries are kept while the account is active and removed from the primary database when account deletion completes.
- Community records may remain after their account link is removed so aggregated place facts are not lost.
- Security and rate-limit records, support email, logs, analytics, advertising data, and provider-held data are kept only as needed for their purpose or under the provider’s settings and policy.
- Limited residual copies may remain temporarily in Firestore backups and provider backup systems after deletion. They are not restored to active use except for recovery or security needs.
Retention periods vary by category and provider. Contact us for current retention information about a specific category.
Your choices and controls
- Location: deny or revoke access in iOS Settings and search another area manually.
- Tracking:decline the App Tracking Transparency request or change Rex’s tracking permission in iOS Settings. This limits advertising tracking but does not disable all analytics.
- Community sharing: leave community sharing off to keep selected visit-derived facts out of aggregate community results. Basic venue information may be processed separately to maintain shared place listings. Suggested edits and place reports are sent only when you choose to submit them.
- Ads: an eligible in-app purchase removes ads from Rex; it does not delete analytics collected before the purchase.
Export and account deletion
The in-app export creates a JSON file containing the visits and saved places currently available to the app, along with the account’s user ID. It is not an export of provider logs, advertising records, or every record held by a service provider.
In Rex, open Settings and choose Delete Account to delete the Firebase Authentication account, profile, synced saved-place identifiers, and synced visits. Community contributions, public insights, and place reports may be kept after their link to the account is removed. Limited records may also remain in backups, logs, security systems, support email, analytics, advertising systems, or provider systems as described above.
You can also email support@rex.likelilab.com to request access, correction, deletion, or help with a privacy choice. We may need to verify the request. Some analytics or ad records use identifiers we cannot reliably connect back to a person.
Your privacy rights
Depending on where you live, you may have rights to know, access, correct, delete, or receive a portable copy of personal information; to restrict or object to certain processing; to withdraw consent; and to appeal a decision or complain to a data-protection authority. We will respond to verified requests as required by applicable law and will not discriminate against you for exercising a privacy right.
Website analytics
The public Rex website uses Google Analytics 4 to measure page visits and actions such as support contacts and App Store clicks. Website analytics may include a random browser identifier, approximate region, device and browser details, and the pages or links used. Analytics is disabled on shared Rex place links so the place name and coordinates in those URLs are not sent to Google Analytics by this website.
Security and international processing
Rex uses encrypted network connections, Firebase access rules, App Check, and account-based access controls. No system can guarantee absolute security. Providers may process information in the United States and other countries under their own legal safeguards and policies.
Children
Rex is not directed to children under 13 or the minimum age required in their country, and we do not knowingly collect personal information from them. Contact us if you believe a child has provided personal information through Rex.
Changes to this policy
We will update this page and the date above when the policy changes. We will provide additional notice in the app when a material change requires it.
Contact
The data controller is The Likeli Lab LLC, 701 South St. Ste 100, Mountain Home, AR 72653, United States. Email support@rex.likelilab.com with privacy questions or requests.