Nox
Made it to grad school

Data Protection and Privacy Policy

Last Updated: 28 April 2026

OVERVIEW

Nox ("Platform", "we", "us", "ours") is an AI-powered personal coaching application accessible only via mobile applications on the Apple App Store and Google Play Store. Our website https://www.nox.today provides marketing information about the Platform and download links to these mobile applications, and is not itself a means of accessing the Platform. The Platform is owned and operated by M/s Mowgli Brothers Studios Private Limited ("Company"), a company incorporated under the laws of India.

This Data Protection and Privacy Policy ("Policy") explains what personal data we collect, why we collect it, how we use and protect it, who we share it with, and what rights you have. This Policy applies to all users of the Platform, regardless of location.

We are committed to protecting your privacy in compliance with:

If you do not agree with this Policy, please discontinue use of the Platform immediately.


1. DATA CONTROLLER / DATA FIDUCIARY

Mowgli Brothers Studios Private Limited acts as the Data Fiduciary (under DPDP Act) and Data Controller (under GDPR) for your personal data.

Contact Details:

For EU/UK users, you may also contact your local supervisory authority if you are unsatisfied with our response to a privacy concern.


2. CONSENT

Giving Consent

By registering on the Platform and accepting the Terms of Use and this Policy as part of account creation and onboarding, you confirm that you have read, understood, and consented to the collection, use, and processing of your personal data as described herein.

The Platform is an AI-powered service. Use of any AI feature on the Platform inherently requires the transmission of your inputs (including chat messages, proof submissions, and related context) to our AI service providers (such as OpenAI) so that Nox AI can generate a response. By accepting this Policy and using the Platform, you consent to such transmission. Nox AI cannot function without it, and there is no separate prompt for this transmission; your acceptance of this Policy on registration is the consent.

Training and Fine-Tuning Opt-Out

The only consent that you may withdraw without ceasing to use the Platform is the consent for Nox to use your eligible Content and related usage data to improve, evaluate, fine-tune, or train Nox-controlled AI systems (Section 4.3). This opt-out is available at any time via Settings > Data Controls.

Withdrawing Consent Generally

If you no longer consent to the processing described in this Policy, your remedy is to delete your account (Section 9). Account deletion terminates ongoing processing of your personal data subject to the limited retention obligations described in Section 10. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.


3. WHAT DATA WE COLLECT

3.1 Data You Provide Directly

Data CategorySpecific FieldsPurpose
Account & IdentityEmail address, password (encrypted), full name, username, display name, date of birth, genderAccount creation, authentication, age verification
ProfileProfile photograph (avatar), bio textPersonalisation, social features
Pact ContentPact titles, descriptions, goals, rules, deadlines, frequency settingsPact creation and management
Proof SubmissionsPhotographs, written statements ("bonds"), text descriptionsGoal verification, AI analysis
Chat MessagesNox AI conversation text, Pact Chat messages, voice inputs (converted to text)AI coaching, group communication
Social ConnectionsFriend requests, group memberships, block listsSocial features, safety
Reports & FeedbackReport reasons, feedback textContent moderation, platform improvement
Support CommunicationsEmails to support@nox.todayCustomer support

3.2 Data We Generate or Derive

Data CategoryDescriptionPurpose
Integrity Score (INT / Integrity Points)Numerical score, expressed in Integrity Points (abbreviated INT), reflecting Pact completion history, difficulty, and closure performanceGamification, accountability
AI MemoriesUsage patterns, preferences, goals, habits, and contextual information extracted from your conversationsPersonalised AI coaching
Proof MetadataStructured data extracted from proof submissions by AI (e.g., exercise type, reps, weight)Progress analytics, AI verification
Streaks & RankingsConsecutive completion counts, leaderboard positionsSocial accountability

3.3 Data Collected Automatically

Data CategorySpecific FieldsPurpose
Device InformationDevice model, operating system, app version, platform (iOS/Android)Compatibility, crash reporting
Usage DataScreens viewed, features used, session duration, interaction eventsAnalytics, product improvement
Push Notification TokensDevice identifiers for push deliveryPush notification delivery
IP AddressIP address at time of accessApproximate geolocation, security, fraud prevention
Error & Crash DataError reports, device contextApp stability and debugging
Attribution DataInstall source, campaign identifiersMarketing attribution

3.4 Data We Do NOT Collect

We do not collect:


4. HOW WE USE YOUR DATA

4.1 Purposes and Legal Basis

PurposeData UsedLegal Basis (GDPR)Legal Basis (DPDP)
Account creation & authenticationEmail, name, password, DOB, genderContract performanceConsent
Nox AI coachingMessages, pact context, memories, preferencesConsentConsent
Nox AI proof verificationProof images, text, pact requirementsConsentConsent
Nox AI in Pact ChatsPact Chat messages, pact contextConsentConsent
Nox AI memory & personalisationConversation content, usage patternsConsentConsent
Pact managementPact data, deadlines, proof submissionsContract performanceConsent
Social featuresProfile info, friend lists, group membershipsContract performanceConsent
Push notificationsDevice tokens, notification preferencesConsentConsent
Analytics & product improvementUsage data, events, aggregated patternsLegitimate interestLegitimate uses (Section 7, DPDP Act)
Marketing attributionInstall source, campaign IDsLegitimate interestLegitimate uses (Section 7, DPDP Act)
Error tracking & debuggingCrash data, device contextLegitimate interestConsent
Security & fraud preventionIP address, usage patterns, rate limitingLegitimate interestConsent
Legal complianceBilling records, deletion audit logsLegal obligationLegal obligation
Email communicationsEmail addressConsentConsent
Nox AI fine-tuning and trainingYour Content (conversations, proof submissions) and usage patternsLegitimate interest (with opt-out)Consent (with opt-out)

4.2 Nox AI: How Your Data is Processed

Nox AI is a single AI system that operates across multiple surfaces within the Platform:

Nox AI, long-term memory, personalisation, proof verification, and Pact Chat assistance are required for the AI-powered Service to function. The transmission of your inputs to our AI service providers is therefore a necessary part of using the Platform; if you do not consent to such transmission, your remedy is to delete your account (Section 9). The training and fine-tuning of Nox-controlled AI systems is a separate use governed by Section 4.3 and may be opted out of without disabling the Service.

4.3 Nox AI Fine-Tuning and Training

For the purposes of this Section, "Content" means the input you provide to the Services and the output you receive from Nox AI (collectively, your conversations, messages, proof submissions, and related in-app interactions).

Separately from the core Nox AI processing described in Section 4.2, Nox may use eligible Content and related usage patterns to improve, evaluate, fine-tune, or train the AI systems that power Nox.

Fine-tuning and training is enabled by default. You may opt out at any time via Settings → Data Controls or by contacting support@nox.today. Opting out applies to future Content going forward. Content that has already been used to train a model version cannot be retroactively removed from that model. Opt-out does not disable Nox AI, long-term memory, personalisation, proof verification, or Pact Chat assistance, because those uses are required for the Service to function.

OpenAI processes Content on our behalf to power Nox AI. OpenAI does not use data submitted through its API to train OpenAI's models. Nox's own training and model-improvement use is governed by your Data Controls setting and this Policy.

We may continue to use aggregated and de-identified data (including for model improvement, analytics, and research) regardless of your opt-out setting. Aggregated and de-identified data is not personal data and is not subject to this Policy.

Where identifiable data is sought for research or external collaboration beyond what is described above, we will request and obtain your express written consent in advance.

4.4 Automated Decision-Making

The Platform uses automated decision-making in the following way:

Your rights regarding automated decisions (GDPR Article 22):

Under the DPDP Act, there is currently no equivalent automated decision-making right; however, we extend the same human review mechanism to all users regardless of jurisdiction.


5. THIRD-PARTY SERVICE PROVIDERS

We share your data with the following categories of third-party service providers, each bound by contractual data protection obligations:

5.1 AI Services

ProviderData SharedPurposeRetention by Provider
OpenAI (USA)Conversation text, proof images, pact contextAI coaching, proof verification, speech-to-textUp to 30 days for safety monitoring; not used for model training

OpenAI's data processing is governed by their Data Usage Policy and Data Processing Addendum. OpenAI does not use data submitted through its API to train OpenAI's models. Separately, Nox may use eligible Content to improve, fine-tune, evaluate, or train Nox-controlled AI systems as described in Section 4.3 and controlled by your Data Controls setting.

5.2 Authentication

ProviderData SharedPurpose
Clerk (USA)Email, name, sign-in credentialsUser authentication and session management

5.3 Payments & Subscriptions

ProviderData SharedPurpose
RevenueCat (USA)Subscription status, plan type, transaction IDsSubscription management, billing via App Store / Play Store
Apple App Store / Google Play StorePayment details (handled directly by Apple/Google)Payment processing

We do not directly collect or store credit card numbers, bank account details, or other payment instruments. All payment processing is handled by Apple, Google, and RevenueCat.

5.4 Cloud Infrastructure & Storage

ProviderData SharedPurpose
Railway (USA)All application dataServer hosting and database
Cloudflare (Global)Proof images, profile pictures, uploaded documentsFile storage and delivery

5.5 Analytics & Attribution

ProviderData SharedPurpose
Mixpanel (USA)Usage events, device info, app versionProduct analytics, feature usage tracking
AppsFlyer (Israel/Global)Install source, conversion events, device identifiersInstall attribution, campaign measurement

Analytics events tracked include actions such as signing up, creating pacts, submitting proof, sending messages, and subscribing. Attribution data is used by Nox to measure the performance of its own marketing campaigns, understand which user cohorts find Nox valuable, exclude existing Users from acquisition campaigns where appropriate, and help Nox reach similar prospective Users through its own acquisition campaigns. These providers act as service providers / data processors and are contractually prohibited from using this data for their own independent purposes, for the benefit of other advertisers, or to advertise their own products or services to you. Nox does not sell personal data. We do not provide your Nox AI conversations, Pact content, proof submissions, profile data, or other content you create on the Platform to advertisers, data brokers, or third parties so they can market their own products or services to you.

5.6 Error Tracking

ProviderData SharedPurpose
Sentry (USA)Error reports, device infoCrash reporting and error monitoring

5.7 Notifications & Email

ProviderData SharedPurpose
OneSignal (USA)Device identifiers, notification contentPush notification delivery
Resend (USA)Email address, email contentTransactional emails (welcome, deletion confirmation)

5.8 Cross-Border Data Transfers

Your data may be transferred to and processed in the United States and other countries where our service providers operate. We ensure appropriate safeguards for such transfers:


6. DATA STORED ON YOUR DEVICE

The following data is stored locally on your mobile device using encrypted on-device storage:

Data StoredPurpose
Authentication session tokensKeeping you signed in
User preferences (theme, notification settings)Remembering your settings
Pending uploadsResuming uploads when connectivity is restored
Cached dataFaster app performance and offline access
Secure credentialsAuthentication with third-party providers

This data remains on your device and is not transmitted to our servers unless required for functionality (e.g., syncing pending uploads when connectivity is restored). Clearing your app data or uninstalling the app removes this local storage.


7. COOKIES

Mobile Application

The Nox mobile application does not use browser cookies. Local data storage is handled via encrypted on-device storage as described in Section 6.

Website (nox.today)

Our website may use the following cookies:

Cookie TypePurposeDuration
Strictly NecessarySession management, security, load balancingSession
AnalyticsUnderstanding website usage patterns (Mixpanel)Up to 12 months
FunctionalRemembering user preferencesUp to 12 months

We do not use advertising or tracking cookies on our website. You may disable cookies through your browser settings, though this may affect website functionality.

For detailed cookie management, see the cookie consent banner displayed on first visit to our website.


8. YOUR RIGHTS

8.1 Rights Under GDPR (EU/UK Users)

If you are located in the European Union or United Kingdom, you have the following rights:

RightDescriptionHow to Exercise
AccessRequest a copy of your personal dataIn-app data export or email support@nox.today
RectificationCorrect inaccurate personal dataEdit profile in-app or email support@nox.today
ErasureRequest deletion of your personal dataIn-app account deletion or email support@nox.today
Data PortabilityReceive your data in a structured, machine-readable formatIn-app data export or email support@nox.today
RestrictionRestrict processing of your dataEmail support@nox.today
ObjectionObject to processing based on legitimate interest, including profilingEmail support@nox.today
Automated Decision-MakingRequest human review of automated decisions (Nox AI proof verification)In-app appeal or email support@nox.today
Withdraw Training ConsentOpt out of use of your Content for Nox AI training and fine-tuningSettings > Data Controls, or email support@nox.today
Withdraw Consent GenerallyWithdraw consent for processing under this Policy by deleting your account (the Platform's AI features cannot operate without transmission of your inputs to AI providers; see Section 2)In-app account deletion, or email support@nox.today
ComplaintLodge a complaint with your supervisory authorityContact your local Data Protection Authority

Response timeline: We will respond to rights requests within 30 days, extendable to 90 days for complex requests with prior notification.

8.2 Rights Under DPDP Act (Indian Users)

If you are located in India, you have the following rights:

RightDescriptionHow to Exercise
InformationKnow what data is processed and who it is shared withThis Policy; or email support@nox.today
CorrectionCorrect inaccurate or incomplete personal dataEdit profile in-app or email support@nox.today
ErasureRequest deletion of your personal dataIn-app account deletion or email support@nox.today
Grievance RedressalFile a complaint about data handlingEmail grievance@nox.today
NominationNominate another individual to exercise your rights upon death or incapacityEmail support@nox.today

Response timeline: We will acknowledge and respond to rights requests within 7 days as prescribed by DPDP Rules, with resolution within 90 days.

If you are unsatisfied with our response, you may escalate your complaint to the Data Protection Board of India.

8.3 Rights Under CCPA / CPRA (California Residents)

If you are a California resident, the California Consumer Privacy Act ("CCPA"), as amended by the California Privacy Rights Act ("CPRA"), provides you specific rights regarding your personal information. This Section supplements Sections 3, 4, and 5 above.

Notice at Collection. In the preceding twelve (12) months, we have collected the following categories of personal information defined by the CCPA. We collect all categories from you directly or from your device, and use them for the purposes set out in Section 4.

CCPA CategoryExamples in NoxDisclosed To
IdentifiersEmail, name, username, IP address, device identifiers, account IDService providers in Section 5 (e.g., Clerk, OpenAI, RevenueCat)
Customer records (Cal. Civ. Code § 1798.80(e))Name, email, encrypted password, date of birth, genderService providers in Section 5
Internet or other network activityScreens viewed, features used, interaction events, app versionMixpanel, AppsFlyer, Sentry
Geolocation data (approximate only)IP-based approximate locationService providers handling the relevant request
Visual / audiovisualProfile photo, proof images, voice inputs (transcribed in-session; audio not retained)OpenAI (proof verification), Cloudflare R2 (storage)
InferencesGoals, habits, preferences inferred from your conversationsOpenAI (during coaching session); not shared outside Nox otherwise
Sensitive personal informationNone. Nox does not collect government IDs, financial account numbers, precise geolocation, racial/ethnic origin, religious beliefs, union membership, genetic data, biometric identifiers, or health/medical records.

No Sale or Sharing. Nox does not sell your personal information for monetary or other valuable consideration, and does not share your personal information for cross-context behavioral advertising, as those terms are defined by the CCPA. We have not done so in the preceding twelve (12) months. Because we do not sell or share, no "Do Not Sell or Share My Personal Information" link is required. If this changes, we will update this Policy and provide the required opt-out mechanism.

Your California Rights. In addition to the rights described in Section 8.1, California residents have the following:

RightDescriptionHow to Exercise
Right to KnowRequest the categories and specific pieces of personal information we have collected, used, disclosed, and shared about you in the preceding 12 months, and the sources, purposes, and recipientsIn-app data export or email support@nox.today
Right to DeleteRequest deletion of your personal information, subject to legal exceptions (e.g., billing records retained for tax compliance)In-app account deletion or email support@nox.today
Right to CorrectRequest correction of inaccurate personal informationEdit profile in-app or email support@nox.today
Right to Limit Use of Sensitive PINot applicable — Nox does not collect or use sensitive personal information
Right to Opt-Out of Sale/SharingNot applicable — Nox does not sell or share personal information
Right to Non-DiscriminationExercise CCPA rights without retaliation from Nox in pricing, service quality, or accessAutomatic

Authorized Agents. You may designate an authorized agent to submit a CCPA request on your behalf. We will require the agent to provide written authorization signed by you and may require you to verify your identity directly.

Verification. To protect your privacy, we verify your identity before fulfilling a request to know, delete, or correct. For account-holders, signing in to your Nox account satisfies verification.

Response Timeline. We will acknowledge CCPA requests within ten (10) business days and respond substantively within forty-five (45) days, extendable by another forty-five (45) days where reasonably necessary, with prior notice.

Right to Appeal. If we deny your request in whole or in part, you may appeal by emailing support@nox.today with "CCPA Appeal" in the subject line. We will respond to appeals within sixty (60) days.

8.4 Data Export

You may request a complete export of your personal data at any time. The export is provided as a downloadable archive containing:


9. ACCOUNT DELETION

How to Delete Your Account

You may delete your account at any time through:

What Happens When You Delete

Immediate (during deletion request):

  1. Your account is deactivated and all active sessions are revoked
  2. A deletion confirmation email is sent to your registered email address
  3. An audit record is created (non-PII, for compliance; see Section 10)

Within 24 hours:

  1. All personal data is permanently deleted from our systems, including: profile, messages, AI memories, proofs, friendships, groups, notifications, and subscription records
  2. All uploaded files (proof images, profile pictures) are permanently deleted from our storage
  3. Your account is removed from our authentication and notification providers

What is NOT deleted:

Pre-conditions: If you have an active Pro subscription, you must cancel it through your App Store or Play Store account settings before account deletion can proceed.


10. DATA RETENTION

Data CategoryRetention PeriodBasis
Active user dataFor the duration of your accountService provision
Deleted user dataPurged within 24 hours of deletion requestUser right to erasure
Notifications90 days from creation, then hard deletedData minimisation
AI memoriesPer retention policy (some expire; all deleted with account)AI coaching quality
Billing audit records15 years after account deletionTax compliance (Indian tax law)
Deletion audit logs15 years after account deletionRegulatory compliance
Data held by AI provider (OpenAI)Up to 30 daysSafety monitoring
Analytics dataPer vendor retention policiesAnalytics purposes
Error dataPer vendor retention settingsDebugging

11. CHILDREN'S DATA

Age Restrictions

The Platform is intended for users aged 18 years and older. We do not knowingly collect personal data from anyone under 18 years of age.

If We Discover a Child's Data

If we become aware that we have collected personal data from a person under 18 without appropriate parental consent, we will:

  1. Immediately cease processing that data
  2. Delete all personal data associated with the account within 24 hours
  3. Notify the parent or guardian if contact information is available

If you believe a child under 18 has created an account on our Platform, please contact us immediately at support@nox.today.


12. PROOF SUBMISSIONS: SPECIAL CONSIDERATIONS

What Proof Data Includes

Proof submissions may contain photographs of yourself, your environment, or activities. These images may incidentally capture:

How Proof Data is Processed

  1. Upload: Proof images are uploaded from your device to our secure cloud storage. Images are compressed on your device before upload.
  2. Nox AI Verification: Proof images are transmitted to OpenAI for automated analysis by Nox AI. OpenAI retains this data for up to 30 days for safety monitoring.
  3. Storage: Proof files are securely stored for the lifetime of your account.
  4. Visibility: Proof submissions are visible to other Participants in the same Pact, and to Nox administrators for moderation purposes.
  5. Deletion: All proof files are permanently deleted upon account deletion.

Your Responsibilities


13. DATA SECURITY

We implement appropriate technical and organisational measures to protect your personal data, including:

No data transmission or storage system is completely secure. While we strive to protect your information using industry-standard practices, we cannot guarantee absolute security against all threats.


14. DATA BREACH NOTIFICATION

In the event of a personal data breach:


15. INVITATIONS

How You Can Invite Others

You may invite non-users to join Nox and participate in Pacts by sharing an invite link. When someone joins via your invite:

Your Responsibility

By inviting someone to Nox, you confirm that the invitation is genuine and welcome. Do not use the invitation feature to spam or harass individuals.


16. SHARING AND VISIBILITY

Within the Platform

ContextWhat is VisibleTo Whom
ProfileUsername, display name, avatar, bio, Integrity Score (INT)Other users (per privacy settings)
Pact participationPact membership, proof submissions, streaks, leaderboard rankingPact members
Pact ChatMessages you send in group chatsOther Pact members
FriendsActivity status, pact participationAccepted friends
GroupsMembership, pact activity within groupGroup members

Public vs Private Pacts

You may manage visibility preferences through your account settings. Participation in multiplayer Pacts requires a minimum level of information disclosure to ensure fair play and accountability.

What We Do NOT Share


17. DISCLOSING YOUR DATA

We may disclose your personal data in the following circumstances:

We do not sell or rent your personal data. Where we share aggregated, anonymised data with partners for analytical purposes, no personally identifiable information is included.


18. THIRD-PARTY LINKS

The Platform may contain links to external websites or services. We do not control and are not responsible for the content, privacy policies, or practices of third-party websites. We encourage you to review the privacy policies of any third-party sites before providing personal data.


19. CHANGES TO THIS POLICY

We reserve the right to update this Policy at any time. Changes will be communicated through:

Where material changes require renewed consent under applicable law, we will obtain such consent before the changes take effect.

Continued use of the Platform after notification constitutes acceptance of the updated Policy. If you do not agree with the changes, you should discontinue use of the Platform and may request account deletion.


20. MISCELLANEOUS


21. CONTACT US

For any questions, concerns, or requests regarding this Policy or your personal data:

We will acknowledge receipt of your query within 7 days and provide a substantive response within 30 days (or 90 days for complex requests, with prior notification).


By using Nox, you acknowledge that you have read and understood this Data Protection and Privacy Policy and consent to the collection, use, and processing of your personal data as described herein.