Privacy Policy

NoxBlanc AG (“we”, “us”, “our”) operates the NoxBlanc mobile application (“the App”).

This Privacy Policy explains what personal data we collect, why we collect it, how we use and protect it, and your rights regarding your data.

Effective date: 20.02.2026

Last updated: 26.02.2026

Data Controller

NoxBlanc AG

c/o Switzerland Innovation Park Ost AG

Lerchenfeldstrasse 3

9014 St. Gallen

Contact: privacy@noxblanc.com

Data We Collect

Account Information

AttributeDetail
WhatEmail address, display name. Provided during registration
PurposeAuthentication, communication, pilot enrollment
Legal basisContract performance (FADP Art. 31.2.a)
RetentionUntil account deletion
StorageNoxBlanc servers (Infomaniak, Switzerland)

Demographic Data

AttributeDetail
WhatDate of birth, gender, height, weight, temperature sleeping preference, temperature-related conditions — provided during onboarding. Age and BMI are computed from these.
PurposeConfigure your mattress settings and personalise your sleep profile
Legal basisContract performance (FADP Art. 31.2.a)
RetentionUntil account deletion
StorageNoxBlanc servers (Infomaniak, Switzerland)

Sleep Data from Apple Health / Health Connect

AttributeDetail
WhatSleep duration, stages (deep, light, REM, awake), bed/wake times, data source name
PurposeDisplay sleep metrics in-app for personal tracking
ImportantThis data is read on your device only. It is NEVER transmitted to NoxBlanc servers.
Legal basisExplicit consent (you grant HealthKit/Health Connect permission)
RetentionNot stored by NoxBlanc — exists only in your device’s Health app
StorageYour device only

Fitbit Data (optional)

AttributeDetail
WhatSleep logs (duration, stages, efficiency), heart rate (resting, zones)
PurposeDisplay sleep and health metrics, pilot participation
Legal basisExplicit consent (you connect your Fitbit account)
RetentionUntil Fitbit disconnected or account deleted
StorageNoxBlanc servers (encrypted tokens, raw data logs)
SharingWe access your Fitbit data via Fitbit’s API. We do not share it with third parties.

Pilot Participation Data

AttributeDetail
WhatQuestionnaire responses, timing data, consent records, enrollment status, demographic metadata (sport, athletic level, years of elite competition — entered by NoxBlanc team)
PurposeSleep optimisation pilots and product development with partner organisations
Legal basisExplicit consent (you provide informed consent before enrollment)
RetentionPilot duration + 10 years (Swiss data protection standards). Consent audit records retained for 10 years.
StorageNoxBlanc servers

Device Information

AttributeDetail
WhatDevice model, operating system version, app version, platform
PurposeConsent audit trail (legally required record of the conditions under which consent was given)
Legal basisLegitimate interest (audit compliance)
RetentionSame as consent records (10 years)
StorageNoxBlanc servers

Journal Entries

AttributeDetail
WhatDaily behavioral notes and answers
PurposePersonal habit tracking
ImportantJournal entries are stored ONLY on your device. They are never sent to NoxBlanc servers.
RetentionUntil you uninstall the app or clear app data
StorageYour device only

Website (noxblanc.com)

AttributeDetail
WhatIP address, browser type, operating system, timestamp, pages visited — collected automatically by the web server
PurposeAnonymous statistical analysis to improve our website
Legal basisLegitimate interest (FADP Art. 31.1)
Retention90 days (server logs are rotated)
StorageIONOS, Germany
ImportantWe do not use cookies, analytics services, or tracking pixels on our website.

Data We Do NOT Collect

  • Location data
  • Contacts, photos, videos, audio, files
  • Financial or payment information
  • Browsing or search history
  • Advertising identifiers (no ads, no tracking)
  • We do not use any analytics, crash reporting, or attribution SDKs

Third-Party Services

ServiceProviderWhat they processPrivacy policy
Auth0Okta, Inc.Email and password for authenticationhttps://auth0.com/privacy
FitbitGoogle LLCOAuth authorization. We retrieve sleep and heart rate data from Fitbit’s API — we do not send user data to Fitbit.https://www.fitbit.com/legal/privacy-policy

No other third-party services receive your data.

Data Sharing

  • We do not sell your personal data.
  • We do not share your data with advertisers.
  • Anonymised pilot data may be shared with publication partners in anonymized form only, and only if you consent to pilot participation.
  • We may disclose data if required by law or court order.

Data Security

  • All data transmitted between the App and our servers is encrypted using TLS 1.3.
  • Authentication tokens are stored in your device’s secure enclave (iOS Keychain / Android Keystore).
  • Fitbit OAuth tokens are encrypted at rest on our servers (AES-256).
  • Our API enforces rate limiting and input validation.
  • Access to our servers is restricted and authenticated.

Your Rights

Under the Swiss Federal Act on Data Protection (FADP) and, where applicable, the EU General Data Protection Regulation (GDPR), you have the right to:

  • Access your personal data (request via the App or email privacy@noxblanc.com)
  • Rectify inaccurate data (update your profile in the App)
  • Delete your account and personal data (On app: Settings > Account > Delete Account, or visit https://noxblanc.com/delete-account)
  • Withdraw consent for pilot participation (in-app, at any time)
  • Data portability (request an export via privacy@noxblanc.com)
  • Lodge a complaint with the Swiss Federal Data Protection and Information Commissioner (FDPIC) or your local supervisory authority

Account Deletion

  • You can delete your account at any time from Settings > Account > Delete Account.
  • You can also delete your account without the App at https://noxblanc.com/delete-account.
  • What happens when you delete your account:
    • Your personal information (email, name) is removed
    • Your demographic data (date of birth, gender, height, weight, preferences) is deleted
    • Your Fitbit data is deleted and Fitbit access is revoked
    • Your pilot responses are anonymized (disassociated from your identity) to preserve data integrity
    • Consent audit records are retained for 10 years as legally required
  • Deletion is processed immediately. Some background cleanup may take up to 30 days.

Children’s Privacy

  • NoxBlanc is not intended for children under 16.
  • We do not knowingly collect data from children under 16.
  • If you believe a child has provided us data, contact privacy@noxblanc.com.

Changes to This Policy

  • We may update this Privacy Policy from time to time.
  • We will notify you of material changes via the App or email.
  • Continued use after changes constitutes acceptance.

Contact Us

NoxBlanc AG

Email: privacy@noxblanc.com

General support: support@noxblanc.com