Nox
Go to graduate school

Data Protection and Privacy Policy

Last Updated: 1 August 2026

OVERVIEW

Nox ("Platform", "we", "us", "ours") is an AI-powered personal coaching application accessible only via mobile applications on the Apple App Store and Google Play Store. Our website https://www.nox.today provides marketing information about the Platform and download links to these mobile applications, and is not itself a means of accessing the Platform. The Platform is owned and operated by M/s Mowgli Brothers Studios Private Limited ("Company"), a company incorporated under the laws of India.

This Data Protection and Privacy Policy ("Policy") explains what personal data we collect, why we collect it, how we use and protect it, who we share it with, and what rights you have. This Policy applies to all users of the Platform, regardless of location.

We are committed to protecting your privacy in compliance with:

If you do not agree with this Policy, please discontinue use of the Platform immediately.


1. DATA CONTROLLER / DATA FIDUCIARY

Mowgli Brothers Studios Private Limited acts as the Data Fiduciary (under DPDP Act) and Data Controller (under GDPR) for your personal data.

Contact Details:

For EU/UK users, you may also contact your local supervisory authority if you are unsatisfied with our response to a privacy concern.


2. CONSENT

Giving Consent

By registering on the Platform and accepting the Terms of Use and this Policy as part of account creation and onboarding, you confirm that you have read, understood, and consented to the collection, use, and processing of your personal data as described herein.

The Platform is an AI-powered service. Use of any AI feature on the Platform inherently requires the transmission of your inputs (including chat messages, proof submissions, and related context) to our AI service providers (such as OpenAI) so that Nox AI can generate a response.

By accepting this Policy and using the Platform, you consent to such transmission. Nox AI cannot function without it, and there is no separate prompt for this transmission; your acceptance of this Policy on registration is the consent.

This includes health and activity information. Where you connect a health service, record a tracked activity, or log a meal or workout plan, derived information about that activity may be transmitted to our AI provider for proof verification, coaching, nudges, and insights, as described in Sections 3.5 and 4.2. This is enabled by default when you use those features. Raw health-provider payloads and raw GPS coordinates are never transmitted. If you do not want health information processed this way, do not connect a health service, and disconnect any service you have already connected.

Training and Fine-Tuning Opt-Out

The only consent that you may withdraw without ceasing to use the Platform is the consent for Nox to use your eligible Content and related usage data to improve, evaluate, fine-tune, or train Nox-controlled AI systems (Section 4.3). This opt-out is available at any time via Settings → Legal → Data controls.

Withdrawing Consent Generally

If you no longer consent to the processing described in this Policy, your remedy is to delete your account (Section 9). Account deletion terminates ongoing processing of your personal data subject to the limited retention obligations described in Section 10. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.


3. WHAT DATA WE COLLECT

3.1 Data You Provide Directly

Data CategorySpecific FieldsPurpose
Account & IdentityEmail address, password (encrypted), full name, username, display name, date of birth, genderAccount creation, authentication, age verification
ProfileProfile photograph (avatar), bio textPersonalisation, social features
Pact ContentPact titles, descriptions, goals, rules, deadlines, frequency settingsPact creation and management
Proof SubmissionsPhotographs, written statements ("bonds"), text descriptionsGoal verification, AI analysis
Chat MessagesNox AI conversation text, Pact Chat messages, voice inputs (converted to text)AI coaching, group communication
Social ConnectionsFriend requests, group memberships, block listsSocial features, safety
Reports & FeedbackReport reasons, feedback textContent moderation, platform improvement
Support CommunicationsEmails to support@nox.todayCustomer support

3.2 Data We Generate or Derive

Data CategoryDescriptionPurpose
Integrity Score (INT / Integrity Points)Numerical score, expressed in Integrity Points (abbreviated INT), reflecting Pact completion history, difficulty, and closure performanceGamification, accountability
AI MemoriesUsage patterns, preferences, goals, habits, and contextual information extracted from your conversationsPersonalised AI coaching
Proof MetadataStructured data extracted from proof submissions by AI (e.g., exercise type, reps, weight)Progress analytics, AI verification
Streaks & RankingsConsecutive completion counts, leaderboard positionsSocial accountability

3.3 Data Collected Automatically

Data CategorySpecific FieldsPurpose
Device InformationDevice model, operating system, app version, platform (iOS/Android)Compatibility, crash reporting
Usage DataScreens viewed, features used, session duration, interaction eventsAnalytics, product improvement
Push Notification TokensDevice identifiers for push deliveryPush notification delivery
IP AddressIP address at time of accessApproximate geolocation, security, fraud prevention
Error & Crash DataError reports, device contextApp stability and debugging
Attribution DataInstall source, campaign identifiersMarketing attribution

3.4 Data We Do NOT Collect

We do not collect:

Health, fitness, and activity data is collected only where you connect a health service or use the in-app tracker — see Section 3.5. Location is used only while you are recording a tracked activity, and exact route coordinates stay on your device — see Section 3.6.

3.5 Health, Fitness and Activity Data

You may connect Nox to a health or fitness service so that completed workouts and activity can be attached as proof of a Pact. These connections are optional, are off until you enable them, and can be revoked at any time.

What we read. Only with your permission, and only from services you connect:

SourceData Read
Apple Health (iOS)Workouts and exercise sessions, heart rate, steps, walking/running distance, active energy, and sleep
Health Connect (Android)Exercise sessions, distance, total calories burned, heart rate, and steps. Sleep is not read on Android
FitbitWorkouts and activity records available through your authorised Fitbit account
In-app trackerActivity you record in Nox itself, including duration, distance, pace, splits, sets, reps, and weight

For each record we also read the source app or device that wrote it, and the times the activity started, ended, and was recorded. We use this to show where a record came from and to avoid storing the same workout twice.

We do not write data back. Nox does not write to Apple Health or Health Connect.

Where it goes. Records from connected services are normalised and synced to Nox servers so they can be shown in the app and attached to Pacts. Fitbit connection credentials are encrypted at rest. Device-based connections (Apple Health, Health Connect) hold no credentials at all.

How we use it. To display your activity, let you attach it as proof, verify proof against your Pact requirements, and personalise coaching, nudges, and insights. Relevant information may be processed by our AI provider as described in Section 4.2. Raw payloads from a health provider are not sent to our AI provider — only a short derived summary of the activity is.

What we will never do with it. We do not sell health or fitness data. We do not use it for advertising or marketing, or for use-based data mining beyond improving your health and fitness experience within Nox. We do not share it with advertising, analytics, or attribution providers. Our analytics and attribution providers never receive health metrics, nutrition content, proof content, or location data.

Improving the Service. We may use this information to evaluate and improve the Nox features it belongs to — most importantly the accuracy of proof verification and the quality of coaching. This is limited to improving Nox's own health and fitness features; it is never used to build advertising audiences, and never to train generalised AI models unrelated to those features. See Section 4.3.

Your control. You can disconnect at any time in Nox under Settings, and you can revoke access directly in iOS Settings › Privacy & Security › Health, or in the Health Connect app on Android. Disconnecting Fitbit disables further syncing and deletes the stored credentials. Synced activity records and connection credentials are deleted when you delete your account (Section 9).

3.6 Location Data

Nox uses location only while you are recording a tracked outdoor activity, such as a run or ride. Location is not collected at any other time, and Nox does not track your location in the background outside a recording session.

3.7 Photographs and Voice Input Processed by AI

Some features send content you provide to our AI provider so it can be interpreted:

Health, activity, or nutrition information that you choose to submit as proof becomes visible to the other Participants in that Pact. This only happens as a result of your own action — see Section 16.


3A. APPLE HEALTH AND HEALTHKIT DATA

This section summarises how Nox handles data from Apple Health (HealthKit) in one place. It restates, and does not replace, the fuller description in Section 3.5.

What Nox reads from HealthKit. With your explicit permission, and only the types you approve on the Apple Health permission screen:

Read-only. Nox does not write any data to Apple Health, and does not request permission to do so.

Why. So you can attach completed workouts and activity as proof of a Pact, see your activity inside the app, and receive coaching based on it. Derived summaries of this activity may be processed by our AI provider for verification and coaching (Section 4.2). Raw HealthKit payloads are never sent to our AI provider.

What Nox will never do with HealthKit data. Consistent with Apple's requirements, Nox does not:

Your control. You can review and change exactly which health types Nox may read at any time in iOS Settings › Privacy & Security › Health › Nox, or by disconnecting the integration inside Nox. Revoking access stops further reading immediately. Health records already synced to Nox are deleted when you delete your account (Section 9).


4. HOW WE USE YOUR DATA

4.1 Purposes and Legal Basis

PurposeData UsedLegal Basis (GDPR)Legal Basis (DPDP)
Account creation & authenticationEmail, name, password, DOB, genderContract performanceConsent
Nox AI coachingMessages, pact context, memories, preferencesConsentConsent
Nox AI proof verificationProof images, text, pact requirementsConsentConsent
Nox AI in Pact ChatsPact Chat messages, pact contextConsentConsent
Nox AI memory & personalisationConversation content, usage patternsConsentConsent
Health, fitness & activity featuresConnected-service records, tracked sessions, nutrition and workout-plan inputsExplicit consent (Art. 9(2)(a))Consent
Activity tracking (location)Location while recording; route data stays on your deviceConsentConsent
Pact managementPact data, deadlines, proof submissionsContract performanceConsent
Social featuresProfile info, friend lists, group membershipsContract performanceConsent
Push notificationsDevice tokens, notification preferencesConsentConsent
Analytics & product improvementUsage data, events, aggregated patternsLegitimate interestLegitimate uses (Section 7, DPDP Act)
Marketing attributionInstall source, campaign IDsLegitimate interestLegitimate uses (Section 7, DPDP Act)
Error tracking & debuggingCrash data, device contextLegitimate interestConsent
Security & fraud preventionIP address, usage patterns, rate limitingLegitimate interestConsent
Legal complianceBilling records, deletion audit logsLegal obligationLegal obligation
Email communicationsEmail addressConsentConsent
Nox AI fine-tuning and trainingYour Content (conversations, proof submissions) and usage patternsLegitimate interest (with opt-out)Consent (with opt-out)

4.2 Nox AI: How Your Data is Processed

Nox AI is a single AI system that operates across multiple surfaces within the Platform:

What is not sent to our AI provider. Two categories of data never leave Nox for AI processing:

Nox AI, long-term memory, personalisation, proof verification, and Pact Chat assistance are required for the AI-powered Service to function. The transmission of your inputs to our AI service providers is therefore a necessary part of using the Platform; if you do not consent to such transmission, your remedy is to delete your account (Section 9). The training and fine-tuning of Nox-controlled AI systems is a separate use governed by Section 4.3 and may be opted out of without disabling the Service.

4.3 Nox AI Fine-Tuning and Training

For the purposes of this Section, "Content" means the input you provide to the Services and the output you receive from Nox AI (collectively, your conversations, messages, proof submissions, and related in-app interactions).

Separately from the core Nox AI processing described in Section 4.2, Nox may use eligible Content and related usage patterns to improve, evaluate, fine-tune, or train the AI systems that power Nox.

Fine-tuning and training is enabled by default. You may opt out at any time via Settings → Legal → Data controls or by contacting support@nox.today. Opting out applies to future Content going forward. Content that has already been used to train a model version cannot be retroactively removed from that model. Opt-out does not disable Nox AI, long-term memory, personalisation, proof verification, or Pact Chat assistance, because those uses are required for the Service to function.

OpenAI processes Content on our behalf to power Nox AI. OpenAI does not use data submitted through its API to train OpenAI's models. Nox's own training and model-improvement use is governed by your Data Controls setting and this Policy.

Scope for health, activity and proof information. Where Content includes health, fitness, activity, nutrition, or proof information, we use it only to evaluate and improve the Nox features it belongs to — principally the accuracy of proof verification and the quality of coaching. We do not use it for advertising or marketing, we do not sell or disclose it to data brokers, and we do not use it to train generalised or non-personalised AI models unrelated to those features. Exact GPS route coordinates are never available for any of this, because they never leave your device.

Your opt-out is absolute for future Content. Once you opt out, we do not use your subsequent Content to improve, evaluate, fine-tune, or train our AI systems — not in identified form, and not in de-identified or aggregated form either. The control we give you is a real control, and we do not work around it.

Where identifiable data is sought for research or external collaboration beyond what is described above, we will request and obtain your express written consent in advance.

4.4 Automated Decision-Making

The Platform uses automated decision-making in the following way:

Your rights regarding automated decisions (GDPR Article 22):

Under the DPDP Act, there is currently no equivalent automated decision-making right; however, we extend the same human review mechanism to all users regardless of jurisdiction.


5. THIRD-PARTY SERVICE PROVIDERS

We share your data with the following categories of third-party service providers, each bound by contractual data protection obligations:

5.1 AI Services

ProviderData SharedPurposeRetention by Provider
OpenAI (USA)Conversation text, proof images, pact contextAI coaching, proof verification, speech-to-textUp to 30 days for safety monitoring; not used for model training

OpenAI's data processing is governed by their Data Usage Policy and Data Processing Addendum. OpenAI does not use data submitted through its API to train OpenAI's models. Separately, Nox may use eligible Content to improve, fine-tune, evaluate, or train Nox-controlled AI systems as described in Section 4.3 and controlled by your Data Controls setting.

5.2 Authentication

ProviderData SharedPurpose
Clerk (USA)Email, name, sign-in credentialsUser authentication and session management

5.3 Payments & Subscriptions

ProviderData SharedPurpose
RevenueCat (USA)Subscription status, plan type, transaction IDsSubscription management, billing via App Store / Play Store
Apple App Store / Google Play StorePayment details (handled directly by Apple/Google)Payment processing

We do not directly collect or store credit card numbers, bank account details, or other payment instruments. All payment processing is handled by Apple, Google, and RevenueCat.

5.4 Cloud Infrastructure & Storage

ProviderData SharedPurpose
Railway (USA)All application dataServer hosting and database
Cloudflare (Global)Proof images, profile pictures, uploaded documentsFile storage and delivery

5.5 Analytics & Attribution

ProviderData SharedPurpose
Mixpanel (USA)Usage events, device info, app versionProduct analytics, feature usage tracking
AppsFlyer (Israel/Global)Install source, conversion events, device identifiersInstall attribution, campaign measurement

Analytics events tracked include actions such as signing up, creating pacts, submitting proof, sending messages, and subscribing. Attribution data is used by Nox to measure the performance of its own marketing campaigns, understand which user cohorts find Nox valuable, exclude existing Users from acquisition campaigns where appropriate, and help Nox reach similar prospective Users through its own acquisition campaigns. These providers act as service providers / data processors and are contractually prohibited from using this data for their own independent purposes, for the benefit of other advertisers, or to advertise their own products or services to you. Nox does not sell personal data. We do not provide your Nox AI conversations, Pact content, proof submissions, profile data, or other content you create on the Platform to advertisers, data brokers, or third parties so they can market their own products or services to you.

Health, fitness, activity, nutrition, and location data is never shared with these providers. It is not sent to analytics, advertising, or attribution partners, is never used for advertising or marketing, is never used for use-based data mining beyond improving your health and fitness experience within Nox (Sections 3.5 and 4.3), and is never used to build advertising audiences. This restriction applies to data obtained from Apple Health, Health Connect, Fitbit, and the in-app tracker alike.

5.6 Error Tracking

ProviderData SharedPurpose
Sentry (USA)Error reports, device infoCrash reporting and error monitoring

5.7 Notifications & Email

ProviderData SharedPurpose
OneSignal (USA)Device identifiers, notification contentPush notification delivery
Resend (USA)Email address, email contentTransactional emails (welcome, deletion confirmation)

5.8 Cross-Border Data Transfers

Your data may be transferred to and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards for such transfers:

5.9 Connected Health, Fitness and Map Services

These services are distinct from the processors listed above: with the exception of maps, Nox receives data from them under your authorisation rather than sending your data to them.

ServiceDirectionNotes
Apple Health (Apple Inc.)Nox reads from your device, only with your permissionOn-device. No Nox account data is sent to Apple Health; Nox does not write to it
Health Connect (Google LLC)Nox reads from your device, only with your permissionOn-device. Nox does not write to it
Fitbit (Google LLC)Nox reads from your Fitbit account after you authorise itConnected by OAuth. Nox stores encrypted access credentials until you disconnect
Google Maps (Google LLC) — Android onlyDisplays a map inside the appRenders your route on your device. Nox does not send your route or location history to the map provider. On iOS the equivalent map is provided by Apple Maps

Your use of these services is also governed by their own terms and privacy policies. You may revoke Nox's access at any time through the relevant service or your device settings.


6. DATA STORED ON YOUR DEVICE

The following data may be stored locally in Nox's app-private storage on your mobile device. Authentication session tokens and certain credentials are stored using platform-provided secure storage. Other local data is protected by your device's operating-system security controls.

Data StoredPurpose
Authentication session tokensKeeping you signed in
User preferences (theme, notification settings)Remembering your settings
Pending uploadsResuming uploads when connectivity is restored
Cached dataFaster app performance and offline access
Secure credentialsAuthentication with third-party providers
GPS route data from tracked activitiesDrawing your route and calculating distance, pace, and splits. Never transmitted to Nox's servers
Tracked session recordsShowing your activity history inside the app

This data remains on your device and is not transmitted to our servers unless required for functionality (e.g., syncing pending uploads when connectivity is restored). Clearing your app data or uninstalling the app removes this local storage.


7. COOKIES

Mobile Application

The Nox mobile application does not use browser cookies. Local data storage is handled using app-private device storage and, for authentication session tokens and certain credentials, platform-provided secure storage, as described in Section 6.

Website (nox.today)

Our website may use the following cookies:

Cookie TypePurposeDuration
Strictly NecessarySession management, security, load balancingSession
AnalyticsUnderstanding website usage patterns (Mixpanel)Up to 12 months
FunctionalRemembering user preferencesUp to 12 months

We do not use advertising or tracking cookies on our website. You may disable cookies through your browser settings, though this may affect website functionality.

For detailed cookie management, see the cookie consent banner displayed on first visit to our website.


8. YOUR RIGHTS

8.1 Rights Under GDPR (EU/UK Users)

If you are located in the European Union or United Kingdom, you have the following rights:

RightDescriptionHow to Exercise
AccessRequest a copy of your personal dataIn-app data export or email support@nox.today
RectificationCorrect inaccurate personal dataEdit profile in-app or email support@nox.today
ErasureRequest deletion of your personal dataIn-app account deletion or email support@nox.today
Data PortabilityReceive your data in a structured, machine-readable formatIn-app data export or email support@nox.today
RestrictionRestrict processing of your dataEmail support@nox.today
ObjectionObject to processing based on legitimate interest, including profilingEmail support@nox.today
Automated Decision-MakingRequest human review of automated decisions (Nox AI proof verification)In-app appeal or email support@nox.today
Withdraw Training ConsentOpt out of use of your Content for Nox AI training and fine-tuningSettings → Legal → Data controls, or email support@nox.today
Withdraw Consent GenerallyWithdraw consent for processing under this Policy by deleting your account (the Platform's AI features cannot operate without transmission of your inputs to AI providers; see Section 2)In-app account deletion, or email support@nox.today
ComplaintLodge a complaint with your supervisory authorityContact your local Data Protection Authority

Response timeline: We will respond to rights requests within 30 days, extendable to 90 days for complex requests with prior notification.

8.2 Rights Under DPDP Act (Indian Users)

If you are located in India, you have the following rights:

RightDescriptionHow to Exercise
InformationKnow what data is processed and who it is shared withThis Policy; or email support@nox.today
CorrectionCorrect inaccurate or incomplete personal dataEdit profile in-app or email support@nox.today
ErasureRequest deletion of your personal dataIn-app account deletion or email support@nox.today
Grievance RedressalFile a complaint about data handlingEmail grievance@nox.today
NominationNominate another individual to exercise your rights upon death or incapacityEmail support@nox.today

Response timeline: We will acknowledge and respond to rights requests within 7 days as prescribed by DPDP Rules, with resolution within 90 days.

If you are unsatisfied with our response, you may escalate your complaint to the Data Protection Board of India.

8.3 Rights Under CCPA / CPRA (California Residents)

If you are a California resident, the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), provides you specific rights regarding your personal information. This Section supplements Sections 3, 4, and 5 above.

Notice at Collection. In the preceding twelve (12) months, we have collected the following categories of personal information defined by the CCPA. We collect all categories from you directly or from your device, and use them for the purposes set out in Section 4.

CCPA CategoryExamples in NoxDisclosed To
IdentifiersEmail, name, username, IP address, device identifiers, account IDService providers in Section 5 (e.g., Clerk, OpenAI, RevenueCat)
Customer records (Cal. Civ. Code § 1798.80(e))Name, email, encrypted password, date of birth, genderService providers in Section 5
Internet or other network activityScreens viewed, features used, interaction events, app versionMixpanel, AppsFlyer, Sentry
Geolocation dataIP-based approximate location. Precise location is accessed on your device only while you record a tracked activity and is not transmitted to Nox; only derived figures such as distance and pace are (Section 3.6)Service providers handling the relevant request
Visual / audiovisualProfile photo, proof images, voice inputs (transcribed in-session; audio not retained)OpenAI (proof verification), Cloudflare R2 (storage)
InferencesGoals, habits, preferences inferred from your conversationsOpenAI (during coaching session); not shared outside Nox otherwise
Sensitive personal informationHealth and fitness information, where you connect a health service or use the in-app tracker (Section 3.5). Nox does not collect government IDs, financial account numbers, racial/ethnic origin, religious beliefs, union membership, genetic data, biometric identifiers used to identify you, or clinical medical records. Precise geolocation is accessed on-device only and is not transmitted to Nox (Section 3.6)OpenAI (derived activity summaries only), Railway and Cloudflare (storage)

No Sale or Sharing. Nox does not sell your personal information for monetary or other valuable consideration, and does not share your personal information for cross-context behavioral advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve (12) months. Because we do not sell or share, no "Do Not Sell or Share My Personal Information" link is required. If this changes, we will update this Policy and provide the required opt-out mechanism.

Your California Rights. In addition to the rights described in Section 8.1, California residents have the following:

RightDescriptionHow to Exercise
Right to KnowRequest the categories and specific pieces of personal information we have collected, used, disclosed, and shared about you in the preceding 12 months, and the sources, purposes, and recipientsIn-app data export or email support@nox.today
Right to DeleteRequest deletion of your personal information, subject to legal exceptions (e.g., billing records retained for tax compliance)In-app account deletion or email support@nox.today
Right to CorrectRequest correction of inaccurate personal informationEdit profile in-app or email support@nox.today
Right to Limit Use of Sensitive PINox uses health and fitness information solely to deliver the Service you asked for — showing your activity, verifying proof, and personalising coaching — which the CCPA exempts from the limit right. We do not use it to infer characteristics about you, and never for advertising. You may stop this use entirely by disconnecting the health service or deleting your accountDisconnect in Settings, or email support@nox.today
Right to Opt-Out of Sale/SharingNot applicable — Nox does not sell or share personal information
Right to Non-DiscriminationExercise CCPA rights without retaliation from Nox in pricing, service quality, or accessAutomatic

Authorized Agents. You may designate an authorized agent to submit a CCPA request on your behalf. We will require the agent to provide written authorization signed by you and may require you to verify your identity directly.

Verification. To protect your privacy, we verify your identity before fulfilling a request to know, delete, or correct. For account-holders, signing in to your Nox account satisfies verification.

Response Timeline. We will acknowledge CCPA requests within ten (10) business days and respond substantively within forty-five (45) days, extendable by another forty-five (45) days where reasonably necessary, with prior notice.

Right to Appeal. If we deny your request in whole or in part, you may appeal by emailing support@nox.today with "CCPA Appeal" in the subject line. We will respond to appeals within sixty (60) days.

8.4 Data Export

You may request an export of your personal data at any time. The export is provided as a downloadable archive containing:

Records held through connected services — including activity and health records synced from Apple Health, Health Connect, or Fitbit — are not currently included in the self-serve archive. You may request a copy of that data at any time by emailing support@nox.today, and we will provide it within the response timelines set out in Sections 8.1 to 8.3.


9. ACCOUNT DELETION

How to Delete Your Account

You may delete your account at any time through:

What Happens When You Delete

Immediate (during deletion request):

  1. Your account is deactivated and all active sessions are revoked
  2. A deletion confirmation email is sent to your registered email address
  3. An audit record is created (non-PII, for compliance; see Section 10)

Within 48 hours:

  1. All personal data is permanently deleted from our systems, including: profile, messages, AI memories, proofs, friendships, groups, notifications, subscription records, synced activity and health records, and credentials for any connected health or fitness service
  2. All uploaded files (proof images, profile pictures, meal photographs, workout-plan screenshots) are permanently deleted from our storage
  3. Your account is removed from our authentication and notification providers

Data held only on your device — including GPS routes and tracked sessions — is removed when you delete the app or clear its data, since it was never on our servers to begin with.

What is NOT deleted:

Subscriptions and deletion: In the in-app deletion flow, you may delete your Nox account immediately while an Apple-billed subscription is active. Deleting your Nox account does not cancel or refund that App Store subscription; Apple may continue billing you until you cancel it in Apple subscription settings, and the deleted Nox account will no longer receive Pro access. For eligible Google Play subscriptions, the in-app flow can request cancellation before deleting the account. The out-of-app web and email deletion flows may require you to cancel an active subscription first.


10. DATA RETENTION

Data CategoryRetention PeriodBasis
Active user dataFor the duration of your accountService provision
Deleted user dataPurged within 48 hours of deletion requestUser right to erasure
Notifications90 days from creation, then hard deletedData minimisation
AI memoriesPer retention policy (some expire; all deleted with account)AI coaching quality
Billing audit records15 years after account deletionTax compliance (Indian tax law)
Deletion audit logs15 years after account deletionRegulatory compliance
Synced activity and health recordsFor the duration of your account; deleted with itService provision
Connected-service credentialsUntil you disconnect the service, or account deletionMaintaining the connection
Meal photographs and workout-plan screenshotsFor the duration of your account; deleted with itService provision
Locally stored route and tracker dataHeld on your device until you delete the session, clear app data, or uninstall NoxStays on your device
Data held by AI provider (OpenAI)Up to 30 daysSafety monitoring
Analytics dataPer vendor retention policiesAnalytics purposes
Error dataPer vendor retention settingsDebugging

11. CHILDREN'S DATA

Age Restrictions

The Platform is intended for users aged 18 years and older. We do not knowingly collect personal data from anyone under 18 years of age.

If We Discover a Child's Data

If we become aware that we have collected personal data from a person under 18 without appropriate parental consent, we will:

  1. Immediately cease processing that data
  2. Delete all personal data associated with the account within 48 hours
  3. Notify the parent or guardian if contact information is available

If you believe a child under 18 has created an account on our Platform, please contact us immediately at support@nox.today.


12. PROOF SUBMISSIONS: SPECIAL CONSIDERATIONS

What Proof Data Includes

Proof submissions may contain photographs of yourself, your environment, or activities. These images may incidentally capture:

Proof may also consist of, or include, health and activity information rather than a photograph — for example a workout synced from Apple Health, Health Connect, or Fitbit, or a session you recorded with the in-app tracker. Where you submit such a proof, the associated figures (for example activity type, duration, distance, pace, or heart rate) are shown to the other Participants in that Pact. Exact GPS route coordinates are never included, because they never leave your device.

How Proof Data is Processed

  1. Upload: Proof images are uploaded from your device to our secure cloud storage. Images are compressed on your device before upload.
  2. Nox AI Verification: Proof images are transmitted to OpenAI for automated analysis by Nox AI. OpenAI retains this data for up to 30 days for safety monitoring.
  3. Storage: Proof files are securely stored for the lifetime of your account.
  4. Visibility: Proof submissions are visible to other Participants in the same Pact, and to Nox administrators for moderation purposes.
  5. Deletion: All proof files are permanently deleted upon account deletion.

Your Responsibilities


13. DATA SECURITY

We implement appropriate technical and organisational measures to protect your personal data, including:

No data transmission or storage system is completely secure. While we strive to protect your information using industry-standard practices, we cannot guarantee absolute security against all threats.


14. DATA BREACH NOTIFICATION

In the event of a personal data breach:


15. INVITATIONS

How You Can Invite Others

You may invite non-users to join Nox and participate in Pacts by sharing an invite link. When someone joins via your invite:

Your Responsibility

By inviting someone to Nox, you confirm that the invitation is genuine and welcome. Do not use the invitation feature to spam or harass individuals.


16. SHARING AND VISIBILITY

Within the Platform

ContextWhat is VisibleTo Whom
ProfileUsername, display name, avatar, bio, Integrity Score (INT)Other users (per privacy settings)
Pact participationPact membership, proof submissions, streaks, leaderboard rankingPact members
Pact ChatMessages you send in group chatsOther Pact members
FriendsActivity status, pact participationAccepted friends
GroupsMembership, pact activity within groupGroup members

Public vs Private Pacts

You may manage visibility preferences through your account settings. Participation in multiplayer Pacts requires a minimum level of information disclosure to ensure fair play and accountability.

What We Do NOT Share


17. DISCLOSING YOUR DATA

We may disclose your personal data in the following circumstances:

We do not sell or rent your personal data. Where we share aggregated, anonymised data with partners for analytical purposes, no personally identifiable information is included.


18. THIRD-PARTY LINKS

The Platform may contain links to external websites or services. We do not control and are not responsible for the content, privacy policies, or practices of third-party websites. We encourage you to review the privacy policies of any third-party sites before providing personal data.


19. CHANGES TO THIS POLICY

We reserve the right to update this Policy at any time. Changes will be communicated through:

Where material changes require renewed consent under applicable law, we will obtain such consent before the changes take effect.

Continued use of the Platform after notification constitutes acceptance of the updated Policy. If you do not agree with the changes, you should discontinue use of the Platform and may request account deletion.


20. MISCELLANEOUS


21. CONTACT US

For any questions, concerns, or requests regarding this Policy or your personal data:

We will acknowledge receipt of your query within 7 days and provide a substantive response within 30 days (or 90 days for complex requests, with prior notification).


By using Nox, you acknowledge that you have read and understood this Data Protection and Privacy Policy and consent to the collection, use, and processing of your personal data as described herein.