Privacy

Privacy at Pebs

Pebs is part of Nox, so the Nox Privacy Policy at getnox.ai/privacy is the binding document. This page explains the Pebs specifics in plain words: a task keeps its goal, plan, messages, step results and files; secure-card values and live-view frames are never stored; nothing is sold; and everything is deleted within 30 days of deleting your account.

Last updated

Who is responsible

Pebs is provided by Xhealth, Inc., the company behind Nox, and runs inside your Nox account. The Nox Privacy Policy (Section 12 covers Pebs) is the official policy; the Nox Terms apply too. If anything on this page and the Policy ever differ, the Policy controls. The Nox privacy whitepaper is the plain-language companion.

What a Pebs task stores

  • The task itself: your goal, the plan GHI-1 wrote, your messages in the task, each step's result, and the text, Markdown, CSV or JSON files your Peb created, so you can come back to them.
  • Schedules you set, including your device's time zone (for example "America/Los_Angeles") so a scheduled run happens at your local time.
  • Saved preferences you write in Pebs settings. They shape later tasks and never authorise a purchase or a send.
  • Notification settings: whether Pebs may email you when a task finishes, needs an approval or has a question.
  • Usage records: which model ran and what it cost against your plan. These hold no task content.
  • Share-link state: whether a read-only link exists for a task.

What a Peb reads to do the work

  • The text of the pages it opens in the Cloud Browser, read content-first with menus and navigation stripped. Pages can contain personal information, so only ask a Peb to open pages you are comfortable with it reading.
  • A screenshot of a page, only when it needs to understand the page visually.
  • Your Nox Memories, if Memory is on in Nox. Turn Memory off in Settings → Memory and Pebs does not read it.
  • Your Nox check-in and chat history are not read by Pebs. A task sees only what you give it in that task.

What Pebs never keeps

  • Secure-card values. Logins, verification codes and card details are typed by Nox's server straight into the task's browser. They are never written to the database, logs or messages, never shown to the model, scrubbed from everything the model reads, and masked in screenshots and the live view. They exist only in that browser session's memory.
  • Live-view frames. The Cloud Browser streams frames to your task page while it works; they are held in memory and never saved.
  • The browser session. Each task gets its own isolated Chromium session, including anything signed in inside it, and the session is discarded when it ends. Your own browser, cookies and devices are never used.
  • Files a website offers for download. They sit only in the task's temporary sandbox, cleared when the task ends and in any case within 24 hours.
  • Anything behind a share link beyond the task's messages and step titles. Screenshots, files, events and credential cards are never shared.

Who processes Pebs data

Pebs is powered by GHI-1, Nox's own in-house model system, and no outside AI company takes part in a Pebs task. This section mirrors Sections 6 and 12 of the Nox Privacy Policy; each service receives only what its job requires, none may use your content to train models, Nox does not sell your data, and there are no third-party advertising trackers.

Planning and reasoning
GHI-1, developed in-house by Nox, plans and runs your task. Your goal, plan, messages and the text of the pages a Peb reads go only to GHI-1. It is served on inference infrastructure that Nox contracts (Fireworks AI) with zero data retention by default; that infrastructure never trains on your content.
Page understanding
When a Peb needs to understand a page visually, the screenshot goes to a GHI-1 model, never to a third-party vision service.
Web search
Finding pages uses Brave Search, a plain search index, not an AI service. Only the short search query (never your task, messages or page content) is sent to Brave to get result links, as disclosed in Section 12 of the Nox Privacy Policy. Reading and using the pages then happens in the Cloud Browser on Nox's own infrastructure.
Cloud Browser
Isolated Chromium sessions on Nox's own infrastructure, not a third-party browser service.
Task emails
Sent through Resend from noreply@getnox.ai. They carry the task title, the approval or question text (or the error) and a link, never card details, passwords or codes.
Account and billing
Sign-in through Clerk and plan billing through Stripe are handled by Nox. Pebs has no separate account or payment.

Purchases and approvals

Before anything is sent, submitted, bought or changed on an outside site, a Peb pauses and asks you to approve that exact action. For a purchase it can fill the checkout, but only you provide the card details, and placing the order is a separate approval. Nox is not the seller and does not process the payment: your card details go only to the merchant's own checkout, under the merchant's and its payment processor's terms. Fields inside a payment provider's embedded frame cannot be filled by Pebs; you take over the browser and type them yourself, and what you type then passes through Nox's servers to the browser in real time and is not stored.

Share links

You can create a read-only link to a task. Anyone with the link can read the task's messages and plan step titles and nothing else. Turning sharing off, or deleting the task, stops the link from working.

Your controls

  • Pause, take over, stop or delete any task.
  • Pause or delete any schedule.
  • Turn off task emails and clear your saved preferences in Pebs settings.
  • Turn off a share link at any time.
  • Turn Memory off in Nox so Pebs cannot read it.
  • Export your Nox data, delete individual conversations, or delete your whole account from inside Nox (Settings → Privacy & data). You can also email Info@Xhealthus.com.
  • Depending on where you live, you may also have rights to access, correct, restrict or object to certain processing, and to data portability.

Retention and deletion

  • Tasks are kept until you delete them or your account is deleted.
  • Deleting a task removes its messages, step history and files immediately, and its share link stops working. Usage records without task content are kept for billing until your account is deleted.
  • Deleting your Nox account removes every Pebs task and its contents, schedules, saved preferences, usage records and share links, together with the rest of your Nox data.
  • Residual copies in encrypted backups are purged on a rolling cycle, within 30 days. Security and diagnostic logs are kept for a limited period and then deleted.
  • In short: your personal data is deleted within 30 days after account deletion, except where limited information must be kept to comply with law.

Security

Encrypted transmission (HTTPS/TLS), encryption at rest, secure authentication and access controls, isolated browser sessions per task, and secure cards that keep secrets out of the model. There is no routine human review of tasks; access to production data is limited to operating the service, debugging a problem you report, or meeting a legal obligation. Nox has not yet completed an independent third-party audit such as SOC 2 and says so plainly. Details are on the Security page.

Health, children and location

  • Pebs is a wellness and productivity tool, not a medical device, and is not HIPAA-regulated. Pebs can handle health-adjacent errands such as comparing clinic hours or gathering research summaries. It is not a doctor and does not give medical advice or diagnoses.
  • Nox and Pebs are for adults 18 and older. If you believe a child has provided information, contact Nox and it will be deleted.
  • The service is operated from the United States and your information is processed there. The Nox Privacy Policy is governed by the laws of the State of California.

Changes and contact

This page carries a visible "Last updated" date and is revised whenever Pebs' handling changes; significant changes to the binding Policy are announced inside Nox or by email. Privacy questions and requests: Xhealth, Inc., 7098 Miratech Dr., Ste 110, San Diego, CA 92121, USA, Info@Xhealthus.com.

Questions

Which privacy policy applies to Pebs?

The Nox Privacy Policy at getnox.ai/privacy, Section 12 in particular. Pebs is part of Nox and has no separate account.

Does Pebs store my passwords or card details?

No. Secure-card values are typed straight into the task's browser session, never saved to the database, logs or messages, and never shown to the model.

Are Cloud Browser screenshots saved?

Live-view frames are streamed to you while the task runs and held in memory only. A screenshot is sent to a Nox model only when a Peb needs to understand a page visually.

Is my data used to train AI models?

No. GHI-1 is Nox's own model system, served on infrastructure with zero data retention by default, and Brave Search receives only the short search query. Nobody may train on your content.

What does a share link reveal?

Only the task's messages and step titles. Never screenshots, files, events or credential cards. You can turn a link off at any time.

How do I delete everything?

Delete a task to remove its messages, steps and files. Delete your Nox account to remove every task, schedule, preference, usage record and share link; residual backups are purged within 30 days.

Pebs by Nox

Give it something to do.

Coming to Nox on all platforms November 1, 2026. Sign up for Nox to join the waitlist.