Short version: your health data stays on your phone, and we never sell your data — to anyone, for anything. The long version is below, in plain English.
Kozen-X is a supplement tracker. To do its job it handles two very different kinds of data, and it treats them very differently:
| Data | Where it lives | Why | How long |
|---|---|---|---|
| Account | Our servers — email address, hashed sign-in credentials, email-verification status, subscription status | Sign-in, account security, restoring your subscription, service messages | While your account exists; deleted within 30 days of account deletion (backup copies within 90) |
| Health & supplement data | Your device only. Your profile, goals, allergens, medication classes, conditions, supplement shelf and dose logs are stored locally on your iPhone | Interaction flags, timing suggestions, showing label servings next to published reference values | Under your control — delete it in the app or by deleting the app |
| Apple Health (HealthKit) | Your device only. Read with your permission, processed on-device, never uploaded to our servers and never stored by us in iCloud | Bringing training, activity and sleep context into timing suggestions; writing doses you log back to Apple Health | Not retained by us — it stays in Apple Health under Apple's controls and yours |
| Waitlist | Our servers — email address, signup source, country, browser user-agent, and campaign tags if you arrived from a tracked link | One confirmation email and launch news. No newsletter | Until launch communications are complete, then deleted within 90 days — or immediately on request |
Everything below expands on this table. Nothing below contradicts it.
When you create a Kozen-X account we collect your email address directly from you, and generate the minimum records needed to run the account: secure sign-in records (any password is stored only as a salted hash, never in plain text), your email-verification status, and — if you subscribe to Kozen-X Plus — your subscription status as reported by Apple. We use this to sign you in, secure the account, restore purchases across devices, and send service messages (verification emails, security notices, material changes to this policy). We do not use your account email for marketing.
An account is required because Kozen-X's core features are account-based — your shelf, settings and subscription need something to attach to. We ask for nothing beyond what those features need, and the app never requires you to enter health information to function: every health field is optional.
Kozen-X asks for health information for exactly one reason: safety checks. You choose what to provide, every field is optional, and all of it is saved only with your explicit consent, given in the app before anything is stored. It includes:
This data is stored locally on your iPhone. It is not uploaded to Kozen-X servers. The app's interaction and timing logic runs on your device as a deterministic, rules-based engine working from published sources — your health data is not sent to us and is not sent to any third-party AI system. If we ever introduce an optional feature that changes where this data is processed (for example, encrypted sync or backup), we will update this policy first and ask for your explicit consent before any of it leaves your device.
Kozen-X Plus is sold through Apple's in-app purchase system. Apple processes the payment; we never see or store your card details. We receive only the subscription records Apple provides (a transaction identifier that reveals no card or identity details, and the subscription's status) so the app can unlock what you paid for. Apple's handling of your payment data is governed by Apple's own privacy policy.
The app contains no third-party analytics, advertising or tracking SDKs. If your iPhone's "Share With App Developers" setting is on, Apple may share crash reports and basic usage statistics with us through Apple's own developer tools; Apple anonymises these before we see them, and you can turn this off any time in iOS Settings → Privacy & Security → Analytics & Improvements. We do not "track" you as defined by Apple's App Tracking Transparency framework — there is nothing to consent to, because we don't do it.
Connecting Apple Health is optional. If you connect it, Kozen-X requests access to specific categories — each one is listed on the iOS permission screen when you connect, and you can grant or deny each individually:
Health data read from HealthKit is processed on your device. We do not upload it to our servers, we do not store it in iCloud, and we do not disclose it to any third party. We will never use HealthKit data — or any health data — for advertising, marketing or data-mining, and we will never sell it to advertising platforms, data brokers or information resellers. The app only ever writes to Apple Health what you yourself logged; it never writes inferred or false data.
You can revoke Kozen-X's Apple Health access at any time, per category, in iOS Settings → Privacy & Security → Health → Kozen-X. The app keeps working without it.
We keep the list short, and none of them are ad networks, data brokers or analytics firms. Personal data is disclosed only to service providers acting on our instructions ("data intermediaries" under the PDPA), strictly to run Kozen-X:
Every provider with access to your data is bound by contract to protect it to the same or an equal standard as this policy and applicable law, to use it only to provide their service to us, and never for their own purposes. We confirm that any third party with whom data is shared provides the same or equal protection of your data as stated in this policy. Apple is the exception: it acts independently under your own agreement with Apple, not as our data intermediary — the contractual commitments above apply to the service providers acting on our instructions. If we ever add a provider that materially changes this picture, this policy changes first.
Kozen-X operates from Singapore, and some of our service providers store data on servers located outside Singapore. Where personal data is transferred out of Singapore, we do so in accordance with the PDPA's transfer limitation obligation — through contractual safeguards that hold the recipient to a standard of protection comparable to the PDPA. Your on-device health data is not affected: it doesn't leave your phone in the first place.
We stop retaining personal data as soon as the purpose it was collected for is no longer served by keeping it and retention is no longer necessary for legal or business purposes. If law requires us to keep a specific record longer (for example, transaction records for tax), we keep only that record, only for that period, and tell you at the point of deletion.
Send requests to privacy@kozen-x.com. We respond within 30 days; if a request takes longer, we'll say so and tell you when. We don't charge for reasonable requests.
kozen-x.com sets no cookies. None — not for analytics, not for advertising, not for anything. There is no cookie banner because there is nothing to consent to.
If you join the waitlist we collect, with your consent at the point you submit the form: your email address, the signup source, your country (derived from your IP address at submission; the IP itself is not stored in the waitlist record), your browser's user-agent string, and — only if you arrived through a tracked link — the campaign tags in that link. Purpose, as stated at the form: reserving your spot, one confirmation email, and launch news. No newsletter, no drip sequence, and the list is never shared with or sold to anyone, including for advertising or retargeting.
Two honest technical notes: our hosting provider keeps standard, short-lived server logs (IP address, request path, user-agent) for security and abuse prevention, as virtually every website does; and our pages load fonts from Google Fonts, which means Google receives your IP address and user-agent when a page loads, under Google's privacy policy. That is the entire third-party surface your browser touches; the service providers in §5 process waitlist records server-side.
Server-side data (account and waitlist records) is encrypted in transit (TLS) and at rest, with access restricted to what each system needs. On-device data is protected by your iPhone's built-in encryption. No system is perfectly secure, so we also make this commitment: if a data breach occurs that is likely to result in significant harm to you, or affects 500 or more people, we will notify Singapore's Personal Data Protection Commission as soon as practicable — no later than 3 calendar days after assessing it as notifiable — and notify you directly. Security researchers: responsible disclosure via security@kozen-x.com — see security.txt.
Kozen-X is not intended for anyone under 16, and we do not knowingly collect personal data from children under 16. If you believe a child has created an account, tell us at privacy@kozen-x.com and we will delete it.
When this policy changes, the new version is posted here with a new effective date. If a change is material — anything that touches the table in §1 — we notify you in the app before it takes effect and, where the change involves a new purpose for data already collected, we ask for fresh consent rather than assuming it.
Data Protection Officer, KOZEN-X (PRIVATE LIMITED), UEN 202617407W, Singapore · privacy@kozen-x.com. We'd rather hear it first and fix it fast. If you're not satisfied with our response, you may complain to Singapore's Personal Data Protection Commission (pdpc.gov.sg).
Kozen-X provides general wellness information. It is not a medical device and does not diagnose, treat, cure or prevent any disease. Always speak with your doctor or pharmacist before starting, stopping or changing a supplement.