Privacy Policy
Last updated: September 26, 2026
Privacy at a glance
- We do not sell your personal or health data.
- All current Nox chat models are Nox models. The Nox 2 generation — Nox Orion 2, Nox Orion Flash 2, and Nox Vela 2 — and Nox 1.3 Astra are Nox's own models, not Fireworks AI or OpenAI products; Fireworks AI provides the inference infrastructure that runs them for us. OpenAI services generate answers to messages that include a photo and power specific supporting features and Nox Voice 1.2 (beta) (see Sections 4 and 6), and ElevenLabs services for Voice Mode speech. Under OpenAI's and Fireworks AI's API terms, your content is not used to train their foundation models. We send ElevenLabs only the voice audio and response text needed to provide Voice Mode speech features; how ElevenLabs may use that content is governed by its terms and the data-use settings of our ElevenLabs account (see “Retention” below).
- We retain your data while your account is active and delete it within 30 days after you delete your account.
- You can export your data, delete individual conversations, delete your whole account, use Incognito mode (no chat is saved), and opt out of having your chats used to improve Nox — all from inside the app.
- Nox is a wellness and education tool. It is not a medical device, is not HIPAA‑regulated, and is not a substitute for a clinician.
1. Who we are
Nox is an AI health and wellness assistant provided by Xhealth, Inc. ("Xhealth", "we", "us", or "our"). This Privacy Policy explains what information we collect when you use Nox (the "Service"), how we use and share it, and the choices and controls you have.
This is the official Privacy Policy for the Service. If Nox describes our privacy practices inside a conversation, that description is informational only — this Policy controls.
2. Information we collect
- Account information: your name and email address, managed through our authentication provider (Clerk).
- Conversation content: the messages, prompts, images, and files you send to Nox, and Nox's responses, stored to maintain your conversation history (except in Incognito mode — see Section 11).
- Voice audio: if you use Voice Mode or the composer's voice dictation, the microphone audio you record is transmitted for transcription (see Section 4). We keep the resulting transcript as conversation content; we do not retain the raw audio recording after it has been transcribed and the response generated.
- Health-related information you choose to share in chat (defined in Section 3).
- Payment information: if you subscribe to a paid plan on the web, billing is handled by Stripe. In the iOS app, subscriptions are purchased through Apple's App Store and verified through RevenueCat. We store a customer/subscription identifier and plan status; we do not store your full card number.
- Connected‑service data: if you choose to connect third‑party apps — your own Google account (Calendar events and Docs created by Nox) or your own Todoist account — we access only the data those permissions cover, and Nox only reads it to answer you or writes to it after you approve a confirmation card in chat. The OAuth access tokens for your connections are stored encrypted; we do not store copies of your calendar, documents, or tasks beyond the conversation itself. You can disconnect an app at any time in Settings → Connected apps, which deletes the stored tokens and revokes our access.
- Usage and device data: features used, session activity, approximate timing, browser type, operating system, and IP address — used for security, reliability, and product improvement.
3. What we mean by "health data"
Because Nox is a health assistant, you may share sensitive information. "Health data" includes, but is not limited to:
- Sleep data, heart rate, heart‑rate variability (HRV), body temperature, respiratory rate, activity/steps, and other wearable or Aurena Ring–style readings you type or upload
- Apple Health (HealthKit) metrics you choose to sync from the Nox iOS app — daily steps, sleep duration, resting/average heart rate, HRV, active energy, walking distance, blood‑oxygen (SpO2), respiratory rate, body weight, and wrist‑temperature deviation
- Symptoms, conditions, diagnoses, and how you're feeling physically or mentally
- Medication and supplement names, dosages, and schedules
- Lab results, vitals, and measurements (e.g., blood pressure, blood glucose)
- Menstrual / cycle and reproductive‑health information
- Mental‑health information you disclose
- Photos or screenshots you upload (e.g., labels, supplements, meals, rashes, wearable readings, lab reports)
- Location information, only if you choose to share it (e.g., to find nearby care)
You decide what to share. Please avoid sharing more identifying detail than you need (for example, full name, address, or government IDs) inside a conversation.
4. How health data is handled differently
- Encryption: all data, including health data, is encrypted in transit (HTTPS/TLS) and encrypted at rest by our database and hosting providers.
- Used to answer you: health data you share is used to generate relevant responses for you in that conversation.
- AI processing: like other chat content, your messages, any health information you share, images or files you choose to upload, and relevant conversation context are sent to the service that runs the selected model or feature. Text-only answers are generated by Nox models — the Nox 2 generation (Nox Orion 2, Nox Orion Flash 2, and Nox Vela 2) and Nox 1.3 Astra — which run on Fireworks AI inference infrastructure. The Nox 2 models are Nox's own models, not Fireworks AI models; Fireworks AI provides the computing that runs them. OpenAI generates the answer when your message includes a photo, and processes content for specific supporting features: generated illustrations, automated safety checks, Memory and long-conversation summaries, and daily check-in scoring. The applicable provider can therefore vary by feature, account, or availability. Under the applicable API terms, this content is not used to train third-party foundation models.
- Voice Mode and dictation: in Voice Mode, we send ElevenLabs only the voice audio and the response text needed to produce speech (see Section 6 and “Retention” for how ElevenLabs may use it), while a Nox model running on Fireworks AI infrastructure generates the response. Nox Voice 1.2 (beta, MAX plan) instead runs the spoken conversation through OpenAI's real-time voice service. Composer voice dictation — and Voice Mode when live transcription is unavailable — sends your voice audio to OpenAI for transcription only. Nox itself uses voice audio solely to provide these features and does not keep it after the response is delivered.
- Not sold, not advertised: we never sell health data and never use it for third‑party advertising.
- Improvement use is opt‑outable: see Section 5 — you can turn off use of your chats to improve Nox.
- Aurena Ring: Nox does not currently receive a live data feed from the Aurena Ring. It only knows the values you type into Settings or share in chat.
- Apple Health (optional, off by default): if you enable Apple Health sync in the Nox iOS app, the daily metrics listed in Section 3 are read from HealthKit (only the categories you approve in iOS permission prompts) and stored with your account so Nox can show them to you and use them to personalize its answers. When these metrics are used to generate a response, the relevant values are included in the request to the AI provider serving your selected model, under the same no‑training API terms described above. HealthKit data is never sold, never used for advertising or marketing, and never shared with third parties except the AI provider processing your request. You can turn sync off at any time in the app, revoke access in iOS Settings → Health, and delete synced data by deleting your account (or asking us to remove it). We keep roughly the most recent 90 days of synced metrics.
5. How we use your information & how we improve Nox
We use your information to provide and maintain the Service, keep your conversation history, run safety checks (such as detecting potential medical red flags), personalize responses, keep the platform secure, process payments, and meet legal obligations.
The phrase "improve AI responses" can mean many different things, so we separate them clearly:
- Training third‑party models: your chats are not used to train OpenAI's or Fireworks AI's foundation models, and we never license or sell your content to anyone for model training. Voice audio and necessary response text processed by ElevenLabs for Voice Mode speech features are governed by the data-use settings of our ElevenLabs account, described under “Retention” below.
- Human review: your conversations are not routinely read by people. Limited, authorized personnel may access specific conversations only for support you request, safety, abuse prevention, debugging, or legal compliance (see Section 7).
- Internal improvement & analytics: we may use conversation data to evaluate quality, fix problems, and improve Nox's own prompts and features. Where practical we use aggregated or de‑identified data for this.
- Opt‑out: you can turn off use of your chats for internal improvement at any time in Settings → Privacy & data. This does not affect processing needed to answer you, keep the Service running, or comply with law.
For details on how our medical‑safety checks (red‑flag detection) are built, measured, and governed, see our Trust & Transparency page.
6. Service providers & subprocessors
We share data only with the providers needed to run the Service, and each provider receives only the data needed for its function. We do not sell your data. Every provider processes data under its published API terms and data-processing terms; the specific commitments that matter for your data (training use, retention, encryption) are stated per provider below and under “Retention”, based on each provider’s published terms as of the date of this Policy. Where a provider’s terms give weaker protection than this Policy (for example, ElevenLabs’ model-improvement setting), we say so rather than represent otherwise. Our current subprocessors are:
- Nox/Xhealth — Nox's own models and AI features, including the Nox 2 generation (Nox Orion 2, Nox Orion Flash 2, and Nox Vela 2) and Nox 1.3 Astra. We may process your messages, images, files, and related context to provide the response or feature you request.
- OpenAI, L.L.C. — processing for specific supporting features: answering messages that include a photo you upload, generated illustrations, automated safety checks, Memory and long-conversation summaries, daily check-in scoring, transcription of dictated voice audio (and Voice Mode audio when live transcription is unavailable), and Nox Voice 1.2 (beta) spoken conversations. Nox Light 1.1 was retired from Nox chat on September 23, 2026 and remains available only in NOX WORK and the Nox developer API. Under OpenAI’s API data policies, API content is not used to train OpenAI models by default, may be retained for up to 30 days for abuse monitoring, and is encrypted in transit and at rest. The specific OpenAI-backed features may change over time.
- Fireworks AI, Inc. — inference infrastructure that runs Nox's models: the Nox 2 generation (Nox Orion 2, Nox Orion Flash 2, and Nox Vela 2) and Nox 1.3 Astra, including the Nox model that answers in Voice Mode. These are Nox models, not Fireworks AI models; Fireworks AI runs them on our behalf. Receives your text, shared health information, uploaded file text, and conversation context for those models. Per Fireworks AI’s published data-handling terms, inference requests are handled with zero data retention by default (prompts and responses are not logged or stored) and are not used to train Fireworks models.
- ElevenLabs, Inc. — receives Voice Mode audio and the necessary response text to produce speech. Does not receive your account identity, conversation history, or files. ElevenLabs states that data is encrypted in transit and at rest; its model-improvement data use is described under “Retention”.
- Topaz Labs LLC — only when you explicitly ask Nox to enhance or upscale a photo you attached, or to sharpen an illustration Nox generated for you; that image is sent to Topaz Labs for processing under its API terms.
- Kaleido AI GmbH (remove.bg) — only when you explicitly ask for a transparent background on an illustration Nox generated for you (and, in Nox Work, for photos you attach); the image is sent to remove.bg for processing under its API terms.
- RevenueCat, Inc. — verifies and manages in-app subscriptions purchased through Apple's App Store in the Nox iOS app (receives your account identifier and purchase receipt; never your conversation or health data).
- Apple Inc. — processes in-app purchases in the Nox iOS app under Apple's own terms and privacy policy.
- Clerk, Inc. — authentication and account management (name, email, sign‑in).
- Stripe, Inc. — payment and subscription processing for paid plans.
- Google LLC — only if you (or your deployment) connect Google services; we access only the scopes you authorize (calendar events and Nox‑created documents for personal connections).
- Doist Inc. (Todoist) — only if you connect Todoist; we access your tasks solely to perform the actions you request and confirm.
- Our cloud infrastructure provider — application hosting and the managed, encrypted PostgreSQL database where your data is stored.
Nox's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements: Google user data is used only to provide the features you request, is never sold, never used for advertising, and never used to train AI models.
We may also disclose information when required by law, to enforce our terms, to protect rights and safety, or in connection with a merger, acquisition, or sale of assets (with notice where required). For an up‑to‑date subprocessor list, contact us at Info@Xhealthus.com.
7. Human access to your conversations
Your conversations are not browsed by our team. Human access is restricted to authorized personnel and only for specific purposes:
- Providing support you have requested
- Investigating safety issues, abuse, or security incidents
- Debugging a specific reported problem
- Complying with a valid legal obligation
We limit access to health data, train personnel on handling it responsibly, and require contractors to sign confidentiality obligations.
8. HIPAA & medical‑device status
- Nox is not a medical device and is not intended to diagnose, treat, cure, or prevent any disease.
- Nox is not a replacement for a clinician or for professional medical advice.
- Xhealth, Inc. is not a HIPAA "covered entity", and the Service is not HIPAA‑regulated. Your conversations are protected under this Privacy Policy and applicable consumer‑privacy law, not under HIPAA.
9. Your choices & controls
- AI processing consent (mobile app): the Nox iOS app requires an account and asks for your explicit consent right after you sign in or create an account — you read these Terms, this Privacy Policy and the AI data disclosure in full and tap "I agree" before any message can be sent; nothing is sent to an AI provider before that. You can review or withdraw this consent at any time in Settings → Data controls → AI data & privacy; withdrawing shows the agreement again before your next AI message.
- Incognito mode: start a private chat that is not saved to your history (see Section 11).
- Improvement opt‑out: stop your chats from being used to improve Nox.
- Export your data: download a copy of your account and conversations as a file.
- Delete individual conversations: remove a single chat at any time.
- Connected apps: connect or disconnect your own Google or Todoist account at any time in Settings → Connected apps. Disconnecting deletes the encrypted access tokens and revokes Nox's access; Nox never changes anything in a connected app without an explicit in‑chat confirmation from you.
- Delete your account: permanently remove your account and associated data.
- Access & correction: depending on your location, you may also have rights to access, correct, restrict, or object to certain processing, and to data portability.
Privacy controls live in Settings → Privacy & data and in the chat itself. You can also email Info@Xhealthus.com.
10. Data retention & deletion
We keep your account information and conversation history for as long as your account is active. When you delete a conversation or your account, here is what happens:
- Chat history: deleted conversations are removed from our active database immediately.
- Account deletion: deleting your account removes your conversations, plan/usage records, connected‑app tokens, and account profile from our active systems, and deletes your sign‑in record with Clerk.
- Backups: residual copies in encrypted backups are purged on a rolling cycle, within 30 days.
- Operational logs: security and diagnostic logs are kept for a limited period and then deleted.
- Nox/Xhealth: content processed by Nox-operated systems is handled under this Privacy Policy and our internal retention and security controls.
- OpenAI: content sent to OpenAI services may be retained by OpenAI for a limited period for abuse monitoring and then deleted, per OpenAI's API data policies.
- Fireworks AI: content sent to Fireworks AI services is processed to generate the response and handled per Fireworks AI's API data policies; it is not used to train their models.
- ElevenLabs: voice audio and necessary response text processed by ElevenLabs for Voice Mode speech features are handled per ElevenLabs' API terms and the data-use settings of our ElevenLabs account. ElevenLabs' terms allow it to use content to improve its services unless the account has opted out; we do not represent that this content is excluded from ElevenLabs model improvement unless and until we have confirmed that opt-out. Voice audio is not stored by Nox after your Voice Mode response is delivered.
In short: your personal data is deleted within 30 days after account deletion, except where we must retain limited information to comply with law.
11. Incognito mode
When you use Incognito mode, your messages and Nox's responses for that session are not saved to your conversation history and are not stored in our database after the response is delivered. Your messages are still sent to the service operating your selected model (a Nox model running on Fireworks AI infrastructure, or OpenAI for messages that include a photo and for automated safety checks) to generate a response and run applicable safety checks. Incognito chats still count toward your plan's usage limits. Closing or leaving the Incognito session clears it.
12. Security
We use industry‑standard safeguards including encrypted transmission (HTTPS/TLS), encryption at rest, secure authentication, and access controls. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
13. Children
The Service is intended for adults 18 and older. We do not knowingly collect personal information from children under 18. If you believe a child has provided us information, contact us and we will delete it.
14. International users & governing law
The Service is operated from the United States and your information is processed there. This Policy is governed by the laws of the State of California, United States, without regard to its conflict‑of‑laws rules.
15. Changes to this Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date and, for significant changes, provide a prominent notice in the Service or by email. Continued use after changes take effect constitutes acceptance of the updated Policy.
16. Contact us
For privacy questions or requests, contact:
Xhealth, Inc.7098 Miratech Dr., Ste 110, San Diego, CA 92121, USA
Info@Xhealthus.com