Effective date: September 15, 2026 Last updated: September 15, 2026
Previous version effective September 7, 2026.
Noxy is operated by Alvino Bernardo, an individual based in Indonesia ("Noxy," "we," "us," or "our"). This Privacy Policy explains how we handle information when you use the Noxy iOS app and related services (the "Service").
Privacy contact: alvino.support@gmail.com
Noxy is a consumer wellness app, not a medical device or health-care provider. Noxy is not covered by HIPAA. This does not reduce the care we apply to wellness-related information.
Summary
- Food logs, calories eaten, attached photos, saved foods, and their meal-derived fox ratings are stored on your device and sync to your signed-in account. Food logs and their photos expire seven days after logging; saved foods and their photos stay until you delete them. Siri food drafts stay on your device. If you enable Apple Health, selected meal and body-measurement data can be saved to Health under your Apple settings.
- When you are signed in, Noxy syncs your profile, body measurements, goals, plan settings, reminder settings, streak totals, and up to 90 recent journal entries so they can be restored or used on another signed-in device.
- With your permission, AI estimates send food text and, if you choose it, a resized meal photo to Noxy's servers and Google Gemini. Nutrition estimates also use Google Search grounding, so the food text you enter is normally part of a grounded request. Noxy does not retain estimate-only photos after the request completes. If you log or save a food with a photo, that photo is backed up with the food as described in Section 6.
- Optional Apple Health reads can update your weight and calorie plan. Imported weight becomes part of your signed-in cloud profile. Disconnecting Health or deleting Noxy does not erase records already saved in Apple Health.
- Optional PostHog analytics and crash reporting help us understand app usage and diagnose problems. They are off until you allow the first-launch prompt or enable them in Settings on this device. When enabled, PostHog receives your account ID and available email/name, usage metadata, and app/device diagnostics. Our custom usage events exclude actual meal text, photos, journal text, exact body measurements, and nutrition values.
- You can turn off analytics in Settings → Your data. Account deletion and privacy requests are described below. AI and Apple Health permissions are separate.
- We do not sell personal information or use wellness, meal, photo, or journal content for third-party advertising.
1. Who may use Noxy
Noxy requires you to be at least 13. Onboarding does not accept a date of birth younger than 13. Noxy is not intended for children under 13, and we do not knowingly collect personal information from anyone under 13.
Users aged 13 to 17 may use the Service only with the consent and supervision of a parent or legal guardian. If we learn that we collected personal information from a person under 13, or from a user aged 13 to 17 without the required consent, we will take appropriate steps to delete it. If you believe this has happened, contact us.
2. Information we handle
2.1 Account information
We handle your email address, display name when provided by Apple or Google, Firebase Authentication identifier, sign-in provider, authentication tokens, and information needed to keep you signed in. Apple or Google also handles information when you choose its sign-in service.
2.2 Profile, wellness, and journal information
You may provide:
- date of birth;
- gender or a preference not to say;
- height, current weight, and desired weight;
- activity level, goal type, and weekly pace preference;
- calorie, protein, carbohydrate, fat, and fiber targets;
- estimate preference, measurement units, and reminder settings; and
- journal dates, mood selections, notes, and save times.
When you are signed in, these fields are stored in your Firebase Firestore profile and sync across signed-in devices. Noxy currently includes up to the 90 most recent journal entries in that profile. Food logs and saved foods are stored in separate account-owned Firestore collections.
Your progress totals are also stored in that Firestore profile so a streak survives a reinstall or appears on another signed-in device. The app currently syncs current and personal-best streak length, available streak freezes, the dates a streak freeze protected, and the date your current streak was last counted. Your device reports these values and a Noxy server merges and stores them. Firestore rules reject any client change to a stored progress value; a client may only create a new profile with those values at zero, and after that only a Noxy Cloud Function updates them.
An unfinished onboarding draft, including body measurements and questionnaire answers, is temporarily stored in the iOS Keychain on that device so you can continue onboarding. Noxy clears the draft after onboarding finishes and when local account data is cleared.
2.3 Content stored on your device
Noxy stores the following locally:
- meal descriptions, nutrition estimates, portions, timestamps, and other meal-log details;
- meal photos you choose to keep;
- your saved-meal library and its photos;
- Siri food descriptions or estimates awaiting confirmation;
- meal health ratings and this device's copy of the streak totals described in Section 2.2; and
- a small App Group snapshot containing today's calorie and macro totals and goals so the Noxy widget can display them.
Food logs from the last seven days, saved foods, and their attached photos sync through Noxy when you are signed in. A change must reach Firebase before it can be restored after reinstall. Signing out waits for saving to finish; if saving fails, the app keeps you signed in and keeps the local data. Journal entries are also stored locally, but signed-in journal entries additionally sync as described in Section 2.2.
If you use widgets, Live Activities, Siri, or App Intents, selected nutrition or logging information may appear in Apple system interfaces, including on a Home Screen or Lock Screen, subject to your Apple device settings.
2.4 AI-estimate and restaurant-lookup information
When you request a nutrition estimate and allow AI processing, Noxy processes the food text you enter and, if you choose photo analysis, a resized meal photo. Asking AI to correct a meal sends the existing meal details and your correction as a new estimate request. Estimates can include a meal-quality rating used to calculate the fox companion’s appearance and HP locally; these are game feedback, not measurements of your health. For restaurant or branded-food lookups, the Service may also process the restaurant or brand name and menu query.
With your permission, Noxy also reads recent photo-library thumbnails on your device so it can show a picker inside the app. Only a photo you select is sent for an estimate; the rest of your library stays on your device.
2.5 Optional analytics and crash information
Noxy uses PostHog for optional product analytics and crash reporting. In this version, its SDK starts only after you choose Allow in the first-launch analytics prompt or enable “Share analytics and crash reports” in Settings → Your data. Choosing Not now keeps collection off and does not cause the prompt to repeat on later launches. The choice applies to this installation and stays in effect until you change it in Settings; signing out does not change the choice. Declining does not affect access to Noxy Pro.
When enabled, PostHog handles:
- app lifecycle and supported screen-view events, app/build and operating-system versions, device model, locale, timezone, screen dimensions, network type, session identifiers, and analytics identifiers;
- analytics identifiers before sign-in; when you sign in, your Firebase account identifier and available email address/display name to associate activity with your account. Previously collected activity from this installation may be linked to that account;
- onboarding and permission-choice events, return-visit milestones, meal logging/editing/deletion, saved-food actions, subscription purchases/restoration, and feedback-submission events;
- action metadata such as entry source, whether a photo is attached, meal type, item count, selected subscription plan, and action outcome; and
- crash/exception reports, stack traces, and associated technical context used to diagnose problems. A report can be saved on the device and sent on a later launch while collection is enabled.
Our custom usage events do not contain actual meal descriptions or photos, journal text, exact weight, height, birthday, or calorie/macronutrient values. Account identity properties separately include the contact details described above. Error messages and crash context can contain incidental information; the exclusion for custom usage events is not a guarantee about every diagnostic report.
PostHog receives network IP information and may derive approximate geography. Our current PostHog project does not enable IP anonymization. Noxy does not request GPS location. This app version does not enable session replay or automatic element-interaction recording; supported screen-view events are not videos of your screen.
Noxy does not request App Tracking Transparency permission or intentionally access IDFA. We do not use these analytics for third-party advertising or cross-context behavioral advertising. There is no Firebase Analytics SDK collection in this version; information from older versions is addressed in Section 4.4.
2.6 Support, security, and subscription information
If you send in-app feedback, we handle your message, Firebase account ID, available email and display name, app version, build number, operating-system description, request ID, and submission time.
If you request a password reset, Firebase generates a one-time reset link and Resend delivers the account-service email. Resend receives the recipient email address and message content, including that link, and handles delivery information. The reset handoff page is hosted by Firebase Hosting. These emails are transactional, not marketing.
For security and Service operation, we handle Firebase App Check attestations and tokens, device or app integrity signals, IP address and function-call metadata, request identifiers, and rate-limit counters. Our server diagnostic logs may record your Firebase account ID, request identifiers, provider error excerpts, and food-related search queries when diagnosing failed AI responses. Password-reset protection also uses email-derived rate-limit identifiers. Those logs are held by Google Cloud Logging under its retention settings and are not removed when you delete your account.
Apple and RevenueCat handle App Store purchase, product, receipt, subscription, and entitlement information. Noxy receives the status needed to offer, unlock, and restore Noxy Pro. Noxy's servers send your Firebase account ID to RevenueCat to confirm your subscription status, including each time you request an AI estimate. Noxy does not receive your full payment-card number.
2.7 Sensitive or health-related information
Body measurements, age, calorie goals, food intake, mood, and journal content may be considered sensitive or health-related information under some laws. We do not sell this information or share it with data brokers or third-party advertisers for their own marketing.
2.8 Information Noxy does not request
Noxy does not request GPS location, contacts, calendars, direct motion-sensor access, or in-app microphone recordings. Optional Apple Health access is described below. Siri may process speech through Apple's system interfaces when you choose to use Siri.
2.9 Optional Apple Health integration
You can choose to connect Noxy to Apple Health through HealthKit. The integration is optional and subject to your permission for each data type. During onboarding, Noxy requests write access only and does not import old Health records into your questionnaire answers.
With write permission, Noxy can save your confirmed setup weight and height, later weight changes, and logged meal nutrition to Health. Meal records include dietary energy (calories), protein, carbohydrates, total fat, fiber, the meal name, logging time, and a Noxy meal identifier used to match edits and deletions. Meal photos and journal notes are not written to Health. You may also choose to send recent logs still available in Noxy. Although the Health backfill checks a 14-day window, Noxy’s seven-day food-history retention limits which logs remain available.
If you enable reads in Settings, Noxy requests access to body weight, height, and active energy burned. A newer weight can update your Noxy profile and recalculate your plan. Height may be read to check whether Health access is available. Today's active energy is shown on the Health settings screen for context and is not added to your calorie target. Noxy does not request Health access to your date of birth, biological sex, or other apps' dietary records.
An imported weight and the resulting plan are saved locally and, when signed in, synced to your Firebase Firestore profile under Sections 2.2 and 4.2. Height read to check access and active-energy results are not uploaded to that profile. Noxy does not send HealthKit measurements to Gemini, Google Search, or Analytics. Analytics may receive the connection-choice events described in Section 2.5, without the underlying Health measurements. Health data is not used for advertising, marketing, or sale.
Noxy stores connection preferences and the last sync time locally. You can turn sync off in Noxy Settings and manage individual permissions in Apple Health. Revoking permission stops future permitted access; it does not erase data already imported into your Noxy profile or previously saved to Health. Apple controls storage, backup, syncing, and access to records held in Apple Health according to your Apple settings and policies.
3. How we use information
We use information to:
- create and manage accounts;
- calculate and sync personalized calorie and macro plans;
- restore signed-in profile fields, streak totals, recent journals, seven days of food logs, and saved foods across devices;
- estimate nutrition from text or photos and look up official menu information;
- maintain local meal, saved-meal, journal, widget, Siri, streak, fox-rating, and saved-food features;
- provide the optional Apple Health reads and writes described in Section 2.9;
- schedule meal reminders and an optional local trial-ending notification;
- process, verify, and restore subscriptions and deliver requested password-reset emails;
- with your separate analytics choice, understand product usage, purchases, return visits, and crashes;
- answer support requests;
- prevent fraud, abuse, unauthorized access, and service disruption;
- comply with law and enforce our Terms; and
- maintain, debug, and improve the Service.
We do not sell personal information. We do not use meal content, meal photos, body measurements, or journal content to create third-party advertising profiles.
4. Storage, processors, and AI
4.1 On-device storage
Noxy's SwiftData meal database, saved-meal library, saved photos, local journals, and Siri drafts are stored in the app's Application Support directory with iOS file protection. Noxy marks that directory as excluded from iCloud and device backups.
Two smaller items sit outside that directory. The App Group nutrition snapshot described in Section 2.3 and a few app preferences, such as the install date used for retention milestones, are stored in standard iOS preference storage. They use the system default protection level and are included in device and iCloud backups.
The unfinished onboarding draft is stored in the device Keychain using a this-device-only accessibility class. AI permission is stored for the account in iOS preferences. The analytics choice is stored separately for this installation, including when you are signed out. The AI permission choice is cleared on sign-out or account deletion on that device and must be granted again for another account.
4.2 Cloud profile and account services
Signed-in profile fields, streak totals, up to 90 recent journals, seven days of food logs, and saved foods (including attached food photos) are stored in Firebase Firestore. Firestore rules reject any client change to a stored progress-total value. A client may only create a new profile with those values at zero; after that, only a Noxy Cloud Function writes them. Firebase Authentication manages sign-in. Noxy's Firebase Cloud Functions run in the United States. Firebase and other providers may process information in additional countries where they operate.
4.3 AI estimates
Before the first AI request, Noxy asks you to allow the third-party processing described here. You may decline and enter nutrition manually. Permission covers later text, photo, meal-correction, and Siri estimates for that account on that device. Siri requests are blocked until you allow AI processing in Noxy. Signing out clears your saved AI permission on that device. After signing in again, the next AI estimate asks for permission again. To stop AI processing, stop submitting estimate requests and sign out. This cannot recall a request already sent. Contact us for applicable privacy or deletion requests.
For an AI estimate, the app sends food text and/or a resized JPEG to Firebase Cloud Functions over HTTPS. The app re-encodes the image before upload, removing embedded EXIF metadata. The function sends the request to Google Gemini and returns the estimate to your device. Noxy does not retain estimate-only photos after the request completes. Photos attached to logged or saved foods are backed up with those foods.
Noxy is configured to use the paid, billed tier of the Google Gemini API. As of the effective date of this Policy, and under Google's current terms for that tier, Google does not use the prompts Noxy sends or the responses it returns to train or improve Google's models, and does not review them for that purpose. Google may process them briefly to deliver the service, detect abuse, and meet legal requirements. We will update this Policy if those terms change.
Noxy uses Google Search grounding on nutrition estimates generally, not only on named restaurant or branded-food queries. The food text you enter is therefore normally part of a grounded request. Google’s Grounding with Google Search terms provide for storage of prompts, relevant context, and output for 30 days to generate grounded results and suggestions and to debug and test the grounding systems. Meal photos are not included in grounded requests.
For some named restaurant or branded-food queries, Noxy's servers also fetch published menu nutrition data directly from official restaurant websites. No personal information is sent to those websites.
Do not put personal information into food-estimate text.
For some official restaurant-menu results, Noxy may store a shared cache entry keyed by a hash of the normalized query. The cache does not include your account ID. A cache result is treated as expired after about 30 days, but expiry does not guarantee immediate physical deletion. Account deletion does not remove a shared cache entry because it is not connected to your account.
4.4 Analytics storage, choices, and older versions
PostHog processes the information described in Section 2.5 using our US-hosted project. Analytics and crash reporting are off by default in this version. You can allow or decline the one-time first-launch prompt, and enable or disable collection later in Settings → Your data. Turning this off stops new usage events and crash reports from that device. Information already collected, or a transmission in progress, is handled separately from withdrawal.
Previously queued diagnostics or events may remain in device storage until the SDK removes them or the app is uninstalled.
We retain account-linked analytics while your account remains active for usage analysis and diagnosis, subject to earlier provider expiry or a valid deletion request. Account deletion initiates the provider-deletion process in Section 6.2. Information not associated with an account follows the provider's retention process; contact us with available account/device details so we can assess an access or deletion request. PostHog's event retention depends on the plan and whether retention enforcement is active. We do not treat its 30-day session-recording setting as an event-retention guarantee or promise automatic erasure after that period. Aggregate reports that no longer identify you can remain longer.
Older app versions used Google Analytics for Firebase or PostHog without the controls in this version. Updating does not erase information already collected. Our previously recorded Google settings were two months for event-level data and fourteen months for user-level data, resetting on new activity; aggregated reports may remain longer. These historical settings do not describe PostHog. You can request deletion of identifiable historical analytics through the privacy contact. Controls introduced in this version do not remotely change an older installation; update each device to use them.
4.5 Password-reset email
Resend processes requested password-reset messages and delivery information. Its published standard Free, Pro, and Scale plans retain email and log data for 30 days; enterprise arrangements may differ. Deleting your Noxy account does not itself delete a message from your inbox or instantly erase Resend delivery records. We handle applicable deletion requests with the provider, subject to justified security and legal retention. Resend data handling
4.6 Website services
Our website is hosted by Vercel. Hosting processes network requests, IP addresses, user-agent/browser information, and operational logs to deliver and secure pages. If you enable optional website measurement through the footer's Privacy choices control, Vercel Web Analytics and Speed Insights process page visits and performance information. Calculator inputs stay in your browser and are not sent as custom measurement events. The website choice is separate from Noxy's in-app analytics setting. Essential hosting continues when optional measurement is off.
5. How we share information
We disclose information only as needed to operate, secure, and support the Service:
- Google Firebase: authentication, Firestore profile, streak, journal, food-log, saved-food, and attached-photo sync, Cloud Functions, App Check, function metadata, and security;
- PostHog: optional account-linked product analytics and crash diagnostics, including available account contact details, interaction metadata, and technical information;
- Resend: requested password-reset messages, recipient email addresses, and delivery information;
- Vercel: website hosting, security, and optional website analytics/performance measurement;
- Google Analytics for Firebase: historical analytics from earlier app versions, as described in Section 4.4;
- Google Gemini and Google Search grounding: food text and optional meal-photo estimates and restaurant or branded-food queries;
- official restaurant websites: Noxy's servers fetch published menu nutrition data from them for some branded-food lookups, and send no personal information to them;
- RevenueCat and Apple: subscription entitlements, product offerings, App Store purchases, billing, refunds, and restoration. Noxy's servers send your Firebase account ID to RevenueCat to check your entitlement, including when you request an AI estimate;
- Apple Health: meal nutrition, names, times, identifiers, and body measurements you permit Noxy to save to Health, as described in Section 2.9;
- Apple and Google: sign-in and system features you choose to use; and
- legal authorities, advisers, acquirers, or others when required by law, needed to protect rights and safety, or involved in a business transfer.
We do not sell personal information. We do not share wellness, meal, photo, or journal content with data brokers or third-party advertisers for their own marketing.
6. Retention and deletion
6.1 Local information
Food logs and their photos expire seven days after logging and are removed locally while Noxy is running or the next time it opens. Saved foods and their photos, journals, profile settings, streak totals, widget data, and Siri drafts remain until you delete the relevant content, clear account data on that device, or uninstall Noxy. A pending Siri draft is treated as expired and deleted the next time Noxy reads it, about 24 hours after it was created. If Noxy never reads it, the draft can remain on the device for longer. An unfinished onboarding Keychain draft is cleared after completion, sign-out, account deletion, or Noxy's next-install cleanup where that cleanup succeeds.
6.2 Account and cloud information
Food logs and attached photos are excluded from recovery after seven days. Firestore automatically deletes expired food documents using its time-to-live policy; physical deletion is asynchronous and typically occurs within 24 hours after expiry. Saved foods and their photos have no automatic expiry and remain until you delete them or your account. Expiry or deletion of a food log does not delete a separate saved-food copy. Deleting a saved food does not delete a previously logged copy, which keeps its own seven-day expiry. Food edits and deletions made offline reach the cloud when syncing succeeds. Profile, journal, streak, and authentication data are kept while your account is active. Support feedback is kept until account deletion unless we need to retain it for security, legal, or dispute purposes.
Settings → Delete account removes your Firestore profile and its food collections before deleting your Firebase Authentication user. If this content cannot be removed, deletion fails so you can retry. Support-feedback cleanup must also succeed before authentication-account deletion. Per-user rate-limit cleanup remains best-effort. If required cleanup fails, you can retry.
Account deletion attempts to remove rate-limit records keyed to your account, including estimate, photo, cache, progress-sync, and account-deletion limits. This cleanup is best-effort, so records can remain if it fails. IP-based and email-derived password-reset rate-limit records are not removed by UID-based account deletion. New or refreshed rate-limit records in the updated backend are assigned expiry at least 24 hours after their last accepted request, and no earlier than the end of their counting window; physical TTL deletion is asynchronous. Older records without an expiry can remain until separate cleanup. These records hold a request count and window timestamps. Counting windows vary by endpoint: common IP request limits use one minute, password-reset IP limits use fifteen minutes, and many account/email limits use one hour. A counting-window reset is separate from record deletion. Server diagnostic logs that recorded your Firebase account ID also remain, subject to Google Cloud Logging retention.
We retain a limited account-deletion marker containing your account identifier and timestamps to prevent stale sessions from recreating deleted information. It expires after seven days and is physically removed asynchronously.
Account deletion also queues a request to delete your account-linked PostHog profile and events. The queue stores the account identifier and request time until successful submission. We wait at least 24 hours and confirm account deletion before submitting the request to PostHog. Failed submissions remain queued for retry. PostHog then processes deletion asynchronously; this is not a promise of complete erasure within 24 hours. Unlinked information or events delivered after a provider request may require additional handling.
Deletion also clears local account content on the device completing deletion. Firebase states that deleted Authentication information is removed from its live and backup systems within 180 days. Other provider backups and security records follow the applicable service’s retention and deletion processes; this is separate from food-log expiry in the app.
Account deletion does not:
- cancel an App Store subscription;
- clear local Noxy data from another device that is offline or not completing the deletion;
- instantly erase already-collected analytics; PostHog erasure is queued as described above, and historical Google data is handled separately;
- delete Apple or RevenueCat records they retain under their own legal and operational requirements;
- remove shared restaurant-menu cache entries that are not connected to an account;
- guarantee removal of every rate-limit record or remove server diagnostic logs, as described above; or
- erase records previously saved to Apple Health. Disconnecting or uninstalling also leaves those records in Health. Review or delete them in Apple Health. Individual meal edits or deletions in Noxy attempt to update Noxy-written Health records while connected, subject to Health permissions and successful processing.
To cancel Noxy Pro, use Apple subscription settings.
6.3 Analytics and security information
Analytics data is retained as described in Section 4.4. Rate-limit counting windows and record expiry are separate and are described in Section 6.2. Providers may keep security logs, transaction records, and backups for longer periods under their policies or where required by law.
7. Your rights and choices
Depending on where you live, you may be entitled to request access, correction, deletion, restriction or objection to processing, portability, or withdrawal of consent. Email alvino.support@gmail.com. We may verify a request before acting.
You can request a copy of account-linked information we still hold, including your profile, streaks, journals, unexpired synced food logs, saved foods, and attached photos. We cannot recover expired or deleted food history or retrieve unsynced content and local-only drafts from your device. Noxy currently has no one-tap data-export control. In this version, optional analytics is off until allowed through the first-launch prompt or Settings, and can be turned off in Settings → Your data, in every region. You may contact us to object to or request deletion of account-linked Analytics information where applicable. Uninstalling Noxy stops future collection from that installation.
You can turn local reminders on or off, disconnect Apple Health or revoke its permissions in Health, revoke camera/photo access in iOS Settings, remove the widget or Live Activity, sign out, and delete your account.
Noxy uses local reminder notifications and does not send marketing email. If you opt in, it schedules a local reminder approximately one day before an eligible free trial is expected to convert to a paid subscription. It uses your subscription status, expected expiry, available price, and reminder preference; this does not introduce a separate push-notification provider. You may decline the reminder or disable Noxy notifications in iOS Settings. Delivery depends on device settings, notification permission, and current subscription information. A reminder does not cancel or change your subscription.
California privacy notice
If you are in California, you may have rights to know, correct, delete, and opt out of sale or sharing. Noxy does not sell personal information or share it for cross-context behavioral advertising. We will not discriminate against you for exercising applicable rights.
EEA, UK, and GDPR notice
Noxy is currently unavailable in the EU storefronts identified in our distribution settings. It is available in Norway and Iceland, which are in the EEA, and in the United Kingdom. EU storefront availability does not determine whether data-protection law applies. Alvino Bernardo is the controller of the information described here.
For ordinary personal data, our legal bases are performance of our agreement for requested account, sync, estimate, subscription, and support services; legitimate interests in proportionate fraud prevention, security, and service reliability; compliance with legal obligations; and consent for optional analytics and other processing where required.
Some wellness information may qualify as sensitive or special-category health data under applicable law. Where processing is based on consent, you may withdraw it through the relevant feature controls or by contacting us. AI and Apple Health have separate permission flows. General acceptance of these Terms does not replace explicit consent where the law requires it. Withdrawal does not affect processing that was lawful beforehand; limited retention may remain necessary for legal obligations or claims.
You can request access, rectification, erasure, portability, restriction, or objection where applicable and withdraw consent. We normally respond to EEA/UK requests within one month; if law permits an extension, we will explain it within that period. You may complain to your local supervisory authority, including the UK Information Commissioner's Office, Norway's Datatilsynet, or Iceland's Persónuvernd. Contact alvino.support@gmail.com for requests.
Information is processed in Indonesia, the United States, and other countries where our providers operate. International transfers must use an applicable adequacy decision or appropriate safeguards, such as relevant standard contractual clauses and the UK Addendum or International Data Transfer Agreement where required. You may request information about the safeguards applicable to your data and a copy, subject to necessary redactions, through the privacy contact. We do not claim that US hosting alone provides those safeguards.
US consumer health-data notice
Our separate Consumer Health Data Privacy Policy explains health-data categories, sources, purposes, recipients, withdrawal, deletion, and appeals under applicable US consumer health-data laws. It supplements this Policy and is separately linked from our website homepage.
8. Security and breach response
We use HTTPS/TLS, Firebase Authentication, App Check, recent-authentication checks for account deletion, server-side validation, rate limiting, Firestore access controls, iOS file protection, backup exclusion for the main local data directory, and server-held API secrets.
No security system is perfect. Protect your device passcode and account credentials.
If a breach of unsecured identifiable health information triggers the FTC Health Breach Notification Rule, we will notify affected users, the FTC, and others as the rule requires.
9. Changes and contact
We may update this Privacy Policy. We will post a revised version with a new Last updated date and provide additional notice for material changes where appropriate.
For privacy questions or requests, contact alvino.support@gmail.com.
