Data & permissions
Effective: June 3, 2026 · Last updated: June 3, 2026
A plain-language, at-a-glance summary of what data Health Codex collects and which device permissions the app may request. This page is a companion to our full Privacy Policy and AI Policy — those documents contain the complete and legally binding details.
The short version
Every device permission Health Codex may request is optional and revocable at any time in your device Settings. The app does not use your microphone or access your location — ever. You are always in control.
1. Device permissions
Health Codex is a mobile app (Expo/React Native). Depending on the features you choose to use, the operating system may ask you to grant certain permissions. The table below lists every permission the app may request, when it is asked for, whether it is required, and why.
| Permission | When it is requested | Required? | Why |
|---|---|---|---|
| Notifications | When you turn on reminders in the app | Optional | Sending you reminders to log meals, workouts, or supplements and to follow your plan |
| Camera & Photo Library | Only if you choose to attach a photo to an entry | Optional | Adding a photo to a meal log or progress entry — the app never accesses your camera or photos otherwise |
| Health & activity data | Only if you choose to connect a health service (e.g., Apple Health or Google Fit) | Optional | Importing activity or body-metric data to enrich your log — only accessed after you explicitly opt in |
| Files / Storage | When you export your data from the app | Optional | Saving a copy of your exported data to your device |
| Microphone | Not requested | Not used | Health Codex does not use your microphone |
| Location | Not requested | Not used | Health Codex does not access your location |
The exact wording of OS permission prompts may vary by device model, operating system version, and platform (Android vs. iOS). You can review and change any permission granted to Health Codex at any time in your device's Settings app.
2. Data the app collects
The following is a brief summary. For the complete description — including legal basis, retention periods, and your rights — please read our Privacy Policy.
Account information
When you create a Codex account we collect your email address and, optionally, your name. If you use multi-factor authentication (MFA), passkeys, or Google sign-in, we store the data needed to support those security features.
Health and wellness inputs
Health Codex stores what you choose to record, which may include food and meals, exercise and workouts, supplements, body metrics, wellness check-ins, mood and sleep notes, habits and streaks, hydration, and the goals and plans you build. Health data is sensitive, and we treat it with a correspondingly high standard of care.
Usage and device information
We may collect limited technical information — such as app version, device type, operating system, and basic diagnostic or crash data — solely to keep the service stable and to fix bugs.
3. On the website
This website (the Health Codex landing page and its legal pages) does not request any device permissions. It does:
- Collect aggregate analytics data through Google Analytics (page views, general location, and similar signals) to help us understand how people find the app. Analytics data is used in aggregate and is not linked to your identity.
- Remember your light or dark theme preference using localStorage under the key
theme. This data never leaves your browser.
4. AI features and your data
Certain Health Codex features use artificial intelligence to parse your natural-language log entries and to generate plans, recipes, insights, and targets. To do this, relevant entry text and related context may be sent to AI service providers for processing. AI outputs are automated and informational only — not professional advice. For full details on what is sent, data-use restrictions, and our training-data stance, see our AI Policy.
5. Your choices and controls
- Permissions: Toggle any permission on or off in your device's Settings app at any time. Revoking a permission only affects that feature — the rest of the app continues to work.
- Export: You can request a portable export of your data from within the app.
- Deletion: You can delete your account and all associated data from within the app or by contacting us.
- Contact: For any data-related request, reach us at privacy@codexcorp.ca.
6. Data location, retention, and your rights
Health Codex is operated by Codex Labs, a Codex Corp company, based in Vancouver, British Columbia, Canada. Your data may be stored or processed by our service providers on servers outside of British Columbia or Canada, including in the United States.
We keep your data for as long as your account is active or as needed to provide the service. Under PIPEDA (federal) and BC PIPA, you have the right to access, correct, and request deletion of your personal information. For the full treatment of these rights and cross-border transfers, see our Privacy Policy.
7. Contact
Questions about data collection or permissions? Reach our privacy team at privacy@codexcorp.ca.