InPhox (formerly named Judexa) is a device diagnostic application for
iPhone and iPad, made by InPhox LLC. On the App Store it may still appear
under its former name, Judexa, or under the developer name Christopher
Luk; this policy applies to the app under any of these names. This policy lists every kind of information the app
reads while running its hardware tests, whether it is saved, whether it
ever leaves your device, who receives it, and how long it is kept.
I.
Information InPhox Reads
The table below covers every category of information the app reads.
“Saved on device” means the item is written into that
session's history on your device (Section IV). “Sent if
paired” means the item is included only if you choose to pair
the session with a business's intake service using an authorized
pairing code (Section V). Nothing is sent anywhere unless you pair,
apart from the map images described in Section III. Most people who
download InPhox will never have a pairing code, and for them nothing
in this table ever leaves the device.
Table 1 — Information read during a diagnostic session
Information
When it is read
Saved on device
Sent if paired
Why
Device model identifier (for example “iPhone16,2”), operating system and version
When the app opens
Yes
Yes
Decides which tests apply to your hardware
Test results: pass, fail, or skipped, time taken, and a short technical note per test
As each test finishes
Yes
Yes
The diagnostic result itself
Precise location: latitude, longitude, altitude, accuracy, speed, and heading
From the start of a diagnostic session until the GPS test records its result
Yes
Yes
Proves the GPS receiver can get a position fix, and lets the intake service check the location was not faked (Section III)
Wi-Fi network name (SSID), router identifier (BSSID), and your device's local IP address
During the Wi-Fi test
Yes
Yes
Proves the Wi-Fi radio is connected. iOS may withhold the network name and router identifier, in which case they are not recorded
Names, identifiers, and signal strength of nearby Bluetooth devices
During the Bluetooth test
No — shown on screen only
No
Proves the Bluetooth radio can see other devices. Only “radio responsive” is recorded
NFC tag: that a tag was detected and how many data records it holds
During the NFC test, if you hold a tag to the device
Yes
Yes
Proves the NFC reader works. The tag's contents are not read into the result
Text of a QR code
During the autofocus test, if you point the camera at a QR code
Yes
Yes
Proves the camera can focus sharply enough to decode it
Camera image and video
During camera, flash, autofocus, LiDAR, and TrueDepth tests, and when scanning a pairing QR code
No — live preview only
No
Lets you see that each camera works. No photo or video is ever taken or stored
Face mesh and depth map from the TrueDepth camera
During the TrueDepth test only
No — memory only
No
Proves the TrueDepth sensor works. See Section II
Depth map from the LiDAR Scanner
During the LiDAR test only
No — memory only
No
Proves the LiDAR Scanner works
Face ID: success or failure only
During the Face ID test
Yes, as pass/fail
Yes, as pass/fail
Proves the biometric sensor works. InPhox never receives face data from Face ID
Microphone audio: short test recordings
During the microphone test. The speaker test listens live and saves no audio
Temporarily — deleted when you leave the test (Section IV)
No
Played back to you so you can judge each microphone. Only pass/fail is recorded
Motion and environment readings: accelerometer, gyroscope, compass, barometer, ambient light, and proximity
From the start of a diagnostic session until it ends
Summary values and pass/fail only
Summary values and pass/fail only
Proves each sensor responds
Ultra Wideband (Nearby Interaction) support and response
During the Ultra Wideband test
Pass/fail only
Pass/fail only
Proves the Ultra Wideband chip responds
Name of a connected wired or USB audio accessory (for example “Headphones”)
During the headphones test
Yes
Yes
Proves the headphone connection works
Other hardware readings: battery level, charging state and charger type, storage capacity, air pressure, light level range, touch pressure range, screen refresh rate, speaker and microphone tone levels, camera lenses and zoom levels checked, and button and vibration checks
During the related tests
Yes
Yes
Part of the hardware check
Cosmetic condition checklist (cracks, scratches, dents, and so on) and any notes you type
On the results screen, only if you fill it in
Yes
Yes
Records the device's physical condition
Serial number and IMEI
Only if you type them into the Device Barcode screen
No
No
Shown as a scannable barcode on screen, then discarded
InPhox does not collect your name, email address, phone number,
contacts, photos, health data, browsing history, advertising
identifier, or any account information. There is no account or
sign-in.
II.
Face Data and the TrueDepth Camera
On devices with a TrueDepth camera, InPhox's TrueDepth test uses Apple's ARKit face-tracking API (and, as a fallback, the camera's raw depth data) to confirm the sensor is working.
What is collected: while the TrueDepth test screen is open, ARKit provides a face mesh (the approximate 3D shape of the face in front of the camera) and a depth map. InPhox draws these on screen as a live preview. The only thing InPhox records is a single pass/fail value indicating whether depth data was received.
How it is used: only to show a live preview and to determine whether the TrueDepth sensor passes the hardware test. Face data is not used to identify or authenticate anyone, and is not used for advertising, marketing, analytics, profiling, or any purpose other than this test.
Storage and retention: face and depth data is processed in memory on your device only, and is discarded as soon as each frame is displayed. It is never written to storage, never saved to the diagnostic history, and never kept after you leave the test screen.
Sharing: face and depth data is never transmitted off the device and is never shared with anyone, including InPhox LLC, the intake service, or any company (Section V). Only the pass/fail result may be shared, and only if you choose to pair the session.
The Face ID test uses Apple's LocalAuthentication framework, which only tells InPhox whether authentication succeeded. InPhox never receives your Face ID face data, which remains in the device's Secure Enclave and is managed solely by iOS.
LiDAR depth data (on devices with a LiDAR Scanner) is handled in the same way: it is shown as a live preview, is never saved or transmitted, and only a pass/fail result is recorded.
III.
Location
Permission: InPhox asks for location access “While Using the App” only. It never asks for or uses location in the background.
When it is read: when you start a diagnostic session, InPhox begins requesting a GPS position so a fix is ready by the time you reach the GPS test (a fix can take tens of seconds). Location is not read outside of a diagnostic session.
What is recorded: the position from the GPS test (latitude and longitude to six decimal places, altitude, and accuracy) is saved in that session's result.
Map display: the GPS test shows your position on a map. The map images are downloaded from OpenStreetMap's tile servers (operated by the OpenStreetMap Foundation). To supply the images, those servers receive your device's IP address and the map area being displayed, which reveals your approximate location. This happens only while the GPS test screen is open. The OpenStreetMap Foundation's privacy policy applies to those requests: osmfoundation.org/wiki/Privacy_Policy.
Sharing: the recorded position leaves your device only if the session is paired with an authorized pairing code (Section V). The intake service keeps it with the session's results so it can confirm the GPS works and check that the location was not faked, for example a phone tested in the United States reporting a location in another country.
IV.
Storage on Your Device
Session history: each completed session, with the items marked “Saved on device” in Table 1, is saved as a file inside InPhox's private storage on your device. It stays there until you delete that session from the History screen, clear all history, or delete the app.
Microphone test recordings: each recording is saved as an audio file in InPhox's temporary folder so you can replay it before choosing pass or fail. These files never leave your device, are not part of the history, and are deleted as soon as you leave the microphone test.
Settings: your app preferences, such as the automatic fail timer, are saved on your device.
InPhox itself does not back anything up to a server. Session history
may be included in your own iCloud or computer backup of the device,
as with any app's data.
V.
Optional Sharing With an Intake Service
The intake service is a business service. InPhox is used by repair
and resale businesses to check devices they are buying, repairing, or
reselling. Diagnostic results are uploaded only when a business pairs
a session using an authorized pairing code. The app
never uploads anything from a person's ordinary personal use of the
app.
Authorized pairing codes only: a pairing code (a QR code, or the six-character code shown with it) can be created only by a business with an active InPhox intake account, and each code is valid for a single session. The intake service must also confirm the code before the app will send anything. Without a code from such a business, the app cannot upload results, and there is no way to turn uploading on from within the app. Most people who download InPhox will never have a pairing code, so for them no diagnostic data ever leaves the device. The app only ever sends a pairing code to InPhox's own intake servers: a QR code that points anywhere else is rejected, and nothing is sent to it.
Who receives it: the InPhox intake service at intake.inphox.net (previously also reachable at intake.chrisccluk.live), operated by InPhox LLC. The service automatically routes each session's results to the business whose pairing code was used. Each business can view only its own sessions.
What is sent and kept: for the paired session only, every item marked “Sent if paired” in Table 1. That includes these values, which the intake service keeps with the session's results:
precise location from the GPS test (latitude, longitude, altitude, accuracy, speed, and heading)
Wi-Fi network name (SSID), router identifier (BSSID), and the device's local IP address
the text of any QR code scanned during the autofocus test
the cosmetic condition checklist and any notes typed
the name of a connected wired or USB audio accessory
the other hardware readings listed in Table 1
Right after pairing, the device's model, platform, and operating system version are also sent so the intake service can confirm that the device being tested is the one the business expects. Also sent and kept: identifiers that tie the session to the business's records (the pairing code, a session ID, the business's lot or batch reference, and the session's start and finish times), and the device's public IP address, which any server receives when the app connects to it. While the session runs, each test's name and pass/fail status is also sent live so the business can follow progress.
What is never sent: camera images or video, audio recordings, face or depth data, Face ID data, NFC tag contents, nearby Bluetooth devices, serial number, or IMEI.
How it is sent: over an encrypted HTTPS connection.
Why: to grade the device's condition for the business, and to check that the results are genuine, for example by spotting a faked location or signs of tampering.
Retention: results and the values above are kept for as long as the business keeps the session in its records, and are deleted when the business deletes it. Pass/fail results that have been added to a device history report are kept as described in Section VI. You can ask for any of this to be deleted at any time (Section IX).
Use: the business uses the results to assess the device. InPhox LLC uses the raw values listed above only to operate the service and to check that results are genuine. Raw values are never published, sold, shared with anyone other than the business that paired the session, included in a device history report, or used for advertising, except where required by law. The only information that may be made available beyond that business is the pass/fail summary described in Section VI.
Pairing applies to one session at a time. Any use of the results by
the business beyond the intake service is governed by that
business's own privacy policy.
VI.
Device History Reports
Devices tested through the intake service may have a device
history report, similar to a vehicle history report, that
lets a future buyer or owner see how the device tested in the past.
Reports may be made available to the public, and may be offered for a
fee.
How a report is identified: by the device's serial number or IMEI. The InPhox app never sends these. The business that tested the device may record them in its own intake records, and the report is linked to them there.
What a report contains: only the device model, the test date, whether each component passed, failed, or was skipped, and the cosmetic condition grade.
What a report never contains: location, Wi-Fi or network details, IP addresses, QR code text, typed notes, audio accessory names, any other raw test values, or the name of any person. The name of the business that performed the test is also never included.
Retention: report entries are kept as part of the device's history, and are not removed when a business deletes its own session records.
Removal and correction: the owner of a device can ask for its report to be corrected or removed (Section IX).
Aggregated statistics: InPhox LLC may also publish or sell statistics combined across many devices (for example, failure rates by model). These contain no serial numbers, IMEIs, or other information that could identify a device, person, or business.
VII.
Permissions Requested
To avoid interrupting tests with pop-ups, InPhox asks for Camera,
Microphone, Location (While Using the App), Bluetooth, and Motion
& Fitness access when the app first opens. NFC, Face ID, and
Nearby Interaction are requested when their tests run. Each
permission is used only for the tests listed:
Camera — camera, autofocus, flash, LiDAR, and TrueDepth tests, and scanning a pairing QR code
Microphone — speaker and microphone tests
Location (While Using the App) — GPS test and compass (Section III)
Bluetooth — Bluetooth test
Motion & Fitness — accelerometer, gyroscope, and barometer tests
Near Field Communication — NFC test
Face ID — biometric sensor test
Nearby Interaction — Ultra Wideband test
Declining a permission causes only the matching test to fail or be
skipped. You can change any permission at any time in the iOS
Settings app under InPhox.
VIII.
What InPhox Does Not Do
InPhox does not require or offer any account or sign-in.
InPhox contains no advertising, and no third-party analytics, tracking, or crash-reporting software.
InPhox does not track you across other companies' apps or websites.
Nothing that identifies a person, such as a name, location, network details, or typed notes, is ever sold or rented. The only information that may be sold is the pass/fail device history reports and aggregated statistics described in Section VI.
InPhox does not read sensors or location in the background or outside of an active diagnostic session.
IX.
Your Choices and Deletion
Delete any session from the History screen, or delete the app to remove everything stored on your device.
To ask for a device history report to be corrected or removed, email the address below with the device's serial number or IMEI and proof that you own the device.
To have results deleted from the intake service, email the address below with the approximate date and time of the session, or ask the business you paired with. We will delete them within 30 days.
X.
Children's Privacy
InPhox is a technical diagnostic tool not directed at children and is
not knowingly used to collect information from any person under the
age of 13.
XI.
Changes to This Policy
Should the information collected by InPhox change, this policy will
be revised accordingly and the effective date above will be updated
to reflect the most recent revision.
XII.
Contact
Questions, or requests to delete data or correct a device history report, may be sent to InPhox LLC at the address below.