Privacy Policy

// effective 2026-05-26 · version 4
NOX is built around a no-PII principle. We do not collect email addresses, phone numbers, real names, or any cross-app advertising identifiers. The only thing we ask for at sign-up is a username, display name, and password.

1. Who runs NOX

NOX is operated by an individual maintainer ("we", "us", "operator") on hardware they control. There is no parent corporation. By using a NOX instance you are interacting with that operator. If you are using a third-party-run instance, that operator — not us — is your data controller for any data you submit there.

2. What we collect

When you create an account, NOX stores:

Anonymous, self-hosted analytics. To understand how the site and app are used — page views, referrers, rough country, device type, and which features get used — we run our own instance of Umami (open-source analytics) on infrastructure we control. It is cookieless, sets no persistent identifier or cross-site tracker, and records no personal data and no message content. The data never leaves our servers — nothing goes to Google, Meta, or any third party, and nothing is sold. This is the only usage measurement on NOX; there are no behavioural-ad SDKs, tracking pixels, or fingerprinting.

3. What we do NOT collect

4. Voice, video, and screen sharing

NOX voice / video / screen-share uses WebRTC. When you join a voice channel or DM call:

4a. End-to-end encryption (direct messages)

Direct messages are end-to-end encrypted when the feature flag is enabled for your account. The implementation is the Signal Protocol (X3DH key exchange + Double Ratchet), the same protocol used by Signal and WhatsApp.

5. Cookies, local storage, and push

6. Third-party services we touch

NOX itself does not embed advertising or social SDKs. We do rely on a small set of operational vendors:

7. Where data lives and how long

8. Who can see your data

9. Security

10. Account recovery

Because we do not store an email or phone, there is exactly one way to recover a lost password: the 6-word recovery phrase shown to you once at registration. If you lose both your password and your recovery phrase, your account cannot be recovered. This is intentional: no recovery channel = no recovery vulnerability.

11. Account deletion

You can delete your account from Settings → My Account → Delete Account. Deletion permanently removes your user record, sent messages, DMs, owned servers, friendships, and read state. See Section 7 for retention nuance.

12. Children

NOX is not directed at children under 13. If we learn that a user under 13 has created an account, we will delete it. In the EU/UK and other jurisdictions where the digital age of consent is 16, NOX is not directed at users under 16 without verifiable parental consent. The instance operator is responsible for community moderation.

13. Your rights (GDPR / UK GDPR)

If you are in the EU, EEA, UK, or another jurisdiction with similar rights, you may:

To exercise these rights, contact the operator via the channels listed in Section 16. We will respond within 30 days.

14. California rights (CCPA / CPRA)

If you are a California resident: you have the right to know what personal information we collect, to request deletion, to correct inaccurate information, and to not be discriminated against for exercising these rights. We do not sell or share personal information for cross-context behavioral advertising (and never have). Submit requests via the contact channel in Section 16.

15. International users

NOX servers are physically located with the operator. Using NOX from outside that country means your data is transferred to and processed there. Where required (e.g. EU users), we rely on appropriate safeguards for cross-border transfer.

16. Contact

Privacy questions, data-subject access / deletion requests, CCPA and GDPR correspondence, and any other communication about this policy can be sent to:

[email protected]

In-app DMs are also available as an alternative channel. We aim to respond to verifiable requests within 30 days.

17. Changes to this policy

We may update this policy as NOX evolves. The "effective" date and version number above will move forward on every change. Material changes (anything that meaningfully changes what we collect, who sees it, or what you can do about it) will trigger an in-app notice and a re-prompt to accept the new version. Continued use after the effective date constitutes acceptance.

END_OF_DOCUMENT — this policy is a plain-language statement of how NOX handles user data. It does not waive any rights you have under applicable law.