Back to homeNoxy — Privacy Policy
Effective date: August 4, 2026
Last updated: August 4, 2026
Noxy is operated by Alvino Bernardo, an individual based in Indonesia ("Noxy", "we", "us", or "our"). This policy explains how we handle information when you use the Noxy iOS app.
Privacy contact: alvino.support@gmail.com
Noxy is a consumer wellness app, not a medical device or health-care provider. It is not covered by HIPAA. This does not reduce the care we apply to wellness-related information.
1. Who may use Noxy
Noxy is not intended for children under 13. We do not knowingly collect personal information from anyone under 13.
Users aged 13 to 17 may use the Service only with the consent and supervision of a parent or legal guardian. If we learn that we have collected personal information from a person under 13, or from a user aged 13 to 17 without the required consent, we will take appropriate steps to delete that information. If you believe this has happened, please contact us.
2. Information we handle
We may handle:
• Account data: email address, display name provided by Apple or Google, Firebase authentication identifiers, and sign-in provider.
• Profile and wellness inputs: date of birth, gender or preference not to say, height, weight, desired weight, activity level, goal type, pace preference, calorie and macro targets, estimate preference, and reminder settings.
• On-device content: meal descriptions, estimates, meal photos you choose to save, journal notes, mood entries, streaks, XP, and saved meals. These are stored locally on your device, not in Noxy’s cloud meal database.
• AI-estimate inputs: food text and, if you choose it, a resized meal photo.
• Support feedback: your message, account identifier, available email/display name, app version, build number, and operating-system description.
• Security and subscription data: Firebase App Check material and tokens, rate-limit counters, App Store purchase information, and RevenueCat entitlement status.
Wellness inputs, food intake, meal photos, journal content, and mood entries may be sensitive or health-related information under some laws.
We do not collect HealthKit/Apple Health data, location, microphone audio, contacts, calendars, motion/fitness data, advertising identifiers, or payment-card numbers. We do not use advertising analytics, crash-reporting, or advertising SDKs.
3. How we use information
We use information to provide accounts, personalize plans, estimate nutrition, maintain local meal records, synchronize your signed-in profile, process and restore subscriptions, answer support requests, protect the Service, comply with law, and enforce our Terms. We do not sell personal information or use wellness, meal, or journal data for third-party advertising.
4. Storage, processors, and AI
Meals, saved meal photos, journals, streaks, and preferences are stored locally in the app’s Application Support storage. The app excludes this storage from iCloud and device backups.
Signed-in profile data is stored in Firebase Firestore. Firebase Authentication manages authentication. Noxy’s Firebase Functions run in the United States. RevenueCat manages subscription entitlements; Apple processes App Store billing; Apple and Google may process sign-in data if you choose those sign-in methods.
For an AI estimate, the app sends food text and/or a resized JPEG to Firebase Functions over HTTPS. The image is re-encoded before upload, which removes embedded EXIF metadata. The function sends the request to Google Gemini and returns the estimate to your device. Noxy does not store uploaded estimate photos in its cloud after the request completes. Google’s handling is governed by its applicable Gemini API terms and privacy disclosures.
For named restaurant or branded-food queries, Noxy may use Google Search grounding. Google states that it retains the prompt, relevant context, and output for 30 days for grounding-related purposes. Do not put personal information into food-estimate text.
Noxy stores a hash-keyed text-estimate cache without an account ID. Cache entries are treated as expired after about 30 days, but account deletion does not remove them and the current implementation does not guarantee physical deletion at that time. We do not describe a query hash as anonymous or irreversible.
Security counters record request frequency to protect against abuse. Their active windows are about one minute or one hour. They are not used for advertising or profiling.
5. Sharing
We share information only as needed to run the Service:
• Google Firebase: authentication, Firestore, Cloud Functions, and App Check;
• Google Gemini: food-text and optional meal-photo estimates;
• RevenueCat and Apple: subscription entitlement and App Store billing;
• Apple and Google: sign-in and system features you choose to use;
• legal authorities or others where required by law, to protect rights and safety, or in a business transfer.
We do not share health or meal information with data brokers or third-party advertisers.
6. Retention and deletion
Local content remains on your device until you delete it, delete the account on that device, clear app data, or uninstall Noxy. It is not included in iCloud/device backups by Noxy’s storage configuration.
Profile and authentication data are kept while your account is active. Settings → Delete account deletes the Firebase Authentication user, cloud profile, associated support feedback, and related per-user live records; it also clears local content on the device completing deletion. Support feedback is otherwise retained until account deletion. Firebase may retain residual encrypted backup or recovery copies for up to 180 days under its deletion practices.
Account deletion does not cancel your App Store subscription. Manage it through Apple subscription settings. It does not remove the hash-keyed nutrition cache because that cache is not connected to an account.
7. Your rights and choices
Depending on where you live, you may be entitled to request access, correction, deletion, restriction or objection to processing, portability, or withdrawal of consent. Email alvino.support@gmail.com. We may verify requests before acting. We can provide cloud profile information we hold; we cannot remotely export local-only meal or journal data from your device.
California privacy notice
If you are in California, you may have rights to know, correct, delete, and opt out of sale or sharing. Noxy does not sell or share personal information for cross-context behavioral advertising and will not discriminate against you for exercising applicable rights.
EEA, UK, and GDPR notice
If you are in the European Economic Area ("EEA") or the United Kingdom, the General Data Protection Regulation ("GDPR") or UK data-protection law may give you additional rights. Alvino Bernardo is the controller of the personal data described in this policy.
We process account and subscription data to perform our contract with you; security data for our legitimate interest in protecting the Service; and information where required for legal obligations or consent. You may request access, correction, deletion, restriction, objection, portability, or withdrawal of consent by emailing alvino.support@gmail.com. You may also complain to your local data-protection authority.
Information may be processed in Indonesia, the United States, and other countries where our providers operate. Where required, we use appropriate transfer safeguards.
You can turn local reminders on or off, revoke camera/photo access in iOS Settings, sign out, and delete your account. Noxy sends local reminder notifications only; it does not send marketing email.
8. Security and breach response
We use HTTPS/TLS, Firebase Authentication, App Check, server-side validation, rate limiting, access controls, and server-held API secrets. No security system is perfect; protect your device and password.
If a breach of unsecured identifiable health information triggers the FTC Health Breach Notification Rule, we will notify affected users, the FTC, and others as the rule requires.
9. Changes and contact
We may update this policy. We will post a revised version with a new Last updated date and provide additional notice for material changes where appropriate.
For privacy questions or requests, contact alvino.support@gmail.com.