Zum Inhalt springen
Pyron

Privacy Policy

For the Pyron app and for this website. It explains what data we process, why we are allowed to do so and what you can do about it.

Last updated: 23 September 2026

This is an English translation of the German original. If the two versions differ, the German version applies.

In short

The following is a summary. It does not replace the sections below, but it puts the most important points first.

  • We read exactly three values — your step count, your active calories and the floors you have climbed. On an iPhone from Apple Health, on an Android phone from Health Connect. Read-only, and we never write anything back.
  • Step counts are health data. We process them only with your explicit consent, which you can withdraw at any time.
  • Your step counts and everything else in your profile are visible to everyone. Anyone who signs in sees the same figures as you do in the leaderboard, the round and the profile — steps, rank, level, rating and what you have achieved in competition.
  • We do not sell any data and we do not show any advertising in the app. We do, however, advertise Pyron on Facebook and Instagram. So that we can see whether this advertising works, the iPhone app reports to Meta that it has been installed and opened. Meta never receives your steps or any other health data. More under Ad measurement with Meta.
  • To keep the app running reliably, we send technical diagnostic data to Sentry in Frankfurt — up to and including a screenshot taken at the moment of the error. What exactly this covers is set out under Crash reports.
  • All data is stored on servers in Ireland, i.e. in the EU.
  • You can delete your account yourself in the app. Then everything is gone.

Who is responsible

The controller within the meaning of Art. 4(7) GDPR is:

Neurolytix GmbH
Hauptstraße 127
68259 Mannheim
Germany
Managing Director: Jonas Reggelin
Email: info@neurolytix.de

We have not appointed a data protection officer. The requirements of Art. 37 GDPR and Section 38 of the German Federal Data Protection Act (BDSG) are not met in our case; for all questions about data protection, you can reach us at the address given above.

Overview of all processing

The table lists every processing activity with its legal basis. The sections below explain each of them in detail.

WhatPurposeLegal basis
Email address, password, or Apple or Google identifierSo that you have an account and can be recognised againArt. 6(1)(b) GDPR (contract)
Username, time zoneDisplay to others, assigning your daysArt. 6(1)(b) GDPR
Step counts from Apple Health or Health ConnectRank, level, XP and competition scoringArt. 9(2)(a) GDPR (explicit consent), together with Art. 6(1)(a)
Floors climbed from Apple Health or Health ConnectDisplay on your Home screen and our analysis of whether Pyron gets people moving — not part of any competition scoringArt. 9(2)(a) GDPR (explicit consent), together with Art. 6(1)(a)
Rank, level, rating, placingsCompetition, leaderboards, profileArt. 6(1)(b) GDPR
Friendships and invitationsFriends list, club and teams, mutual visibilityArt. 6(1)(b) GDPR
Device token for notificationsPush notifications to your phoneArt. 6(1)(a) GDPR (consent)
Bug reports, crash logsFinding and fixing bugsArt. 6(1)(f) GDPR (legitimate interest in an app that works)
Reports about other usersFollowing up on abuseArt. 6(1)(f) GDPR, also in fulfilment of Art. 16 DSA
Pseudonymous usage eventsDetecting whether the competition works technicallyArt. 6(1)(f) GDPR
App installation, app launches and purchases in the App Store, with technical device data (iPhone app only)Measuring whether our advertising on Facebook and Instagram worksArt. 6(1)(f) GDPR (legitimate interest in effective advertising for the app)
Server logs of this websiteOperation and security of the websiteArt. 6(1)(f) GDPR

Your account

Pyron does not work without an account: a competition needs someone to compete, and a rank needs someone it belongs to. There are three ways in; which ones you see depends on your phone.

With email address and password

We store your email address and your password. We never store the password in plain text, only as a cryptographic hash (bcrypt) — we can neither read it nor tell it to you. To confirm, we send you an email with a six-digit code.

With “Sign in with Apple”

Apple sends us a user identifier that is unique to Pyron and, if you agree, your email address. If you choose “Hide My Email” at Apple, we only receive a forwarding address from Apple and never your real one. Apple only releases your name the very first time you sign in; we then use it as a suggestion for your username.

With “Continue with Google” (Android only)

Google sends us a user identifier that is unique to Pyron, your email address and the name stored in your Google account. We use the name only the very first time you sign in as a suggestion for your username; if you have given yourself a name of your own, it remains untouched. We never get to see your Google password — sign-in works via a signed identity token that we have Google verify.

In all cases

In addition, we store your username and the time zone in which you registered. The time zone is not a location lookup — it is the setting your phone comes with anyway, and we need it to know when a day begins and ends for you. Someone walking in Tokyo should not find their steps in a German calendar day.

Steps from Apple Health and Health Connect

This is the core of the app and the most sensitive part of this policy.

Exactly which data

From Apple HealthKit we read exactly three values: your step count (HKQuantityTypeIdentifierStepCount), your active energy in kilocalories (HKQuantityTypeIdentifierActiveEnergyBurned) — the same figure that Apple shows as “Move” in the Fitness app — and the floors climbed (HKQuantityTypeIdentifierFlightsClimbed). No heart rate, no distance, no sleep, no weight, no workouts, no locations. The permission the app requests from iOS technically covers only these three types, and it is read-only access: Pyron never writes anything back to Apple Health.

On an Android phone, the same three values come from Health Connect, Google's store for health data: steps (StepsRecord), active calories (ActiveCaloriesBurnedRecord) and floors climbed (FloorsClimbedRecord). There too, Pyron requests read permissions only and never writes anything back. Two further permissions are added because Android requires them separately: reading data older than 30 days — so that days filled in later are not lost, and for the comparison over twelve months — and reading in the background, so that your steps arrive even when the app is not open. You can revoke both at any time in Health Connect under “App permissions › Pyron”; the app will then tell you that nothing is arriving any more.

Anything someone enters by hand in Health Connect is not counted by us: Pyron recognises such entries and excludes them. On Android, too, we read which app or device measured the steps, and only count recognised sources — the same rule as on the iPhone.

Active energy was added on 22 August 2026 together with the calories tile on the Home screen. A stricter rule applies to it than to steps: it never leaves your iPhone. The app reads it directly from HealthKit, uses it to draw the tile and the calories detail page, and then forgets it. It is not transmitted to our server, not stored anywhere, and does not feed into any rank, level or competition. Moreover, the tile is not enabled by default: it only appears on your Home screen once you add it there. If you remove it again, the app no longer reads the value from HealthKit at all.

Floors were added on 29 August 2026, and a rule of their own applies to them: they do not count in any competition. They do not feed into any rank, level, rating or achievement. We use them for two things. First, we show them to you — on the Home screen, the steps tile shows how many floors you have climbed today, against a goal that you set yourself in the settings. This figure is read, drawn and forgotten again on your device; it is not sent to our server for this, and nobody but you sees it. Second, we use them for an analysis for our own purposes — whether the people who use Pyron move more than before. For this, we make a one-time read of your steps and floors for the last twelve months, i.e. also from the period before you installed the app, and compare the average before with the average after. These figures are kept separate from everything the app calculates with; they do not appear in any leaderboard or profile. If you do not want this, deny access to “Flights Climbed” in Apple Health — the Home screen will then show “not measured” instead of a number, and everything else in Pyron keeps working.

In addition, we read which source measured the steps — i.e. whether they come from the iPhone, from an Apple Watch or from another app. We need this because exactly one source always counts in the scoring; otherwise the same walk would be counted twice.

How we collect them

If you allow it, iOS notifies us in the background that your step count has changed (“Background Delivery”). The app then asks HealthKit for the totals for certain time windows and sends them to our server. What is transmitted are hourly totals, not individual movements and not the times of individual steps.

On Android, there is no such automatic notification. There, Pyron checks Health Connect at a fixed interval — at most every 15 minutes — to see whether anything has changed, and only then fetches the totals. The same is transmitted: hourly totals.

What for

Exclusively to calculate your rank, your level, your XP and your placing in the competition from them. For no other purpose.

On what legal basis

Step counts are health data within the meaning of Art. 4(15) GDPR and therefore a special category of personal data under Art. 9 GDPR. Processing them is prohibited in principle and only permitted if one of the exceptions in Art. 9(2) applies. We rely on Art. 9(2)(a) GDPR — your explicit consent.

You give this consent in two deliberate steps: first on the welcome screen of Pyron, where we tell you that step counts are health data and what we use them for, and then in the iOS dialog in which you grant read access to HealthKit. Without both steps, we do not process any step data.

How to withdraw your consent

At any time and without giving reasons. You have three options, and they differ in how far they go:

  • Revoke access: iPhone Settings → Apps → Health → Data Access & Devices → Pyron → set Steps to “Don't Allow”. From then on, no new values arrive. The existing ones remain stored.
  • Delete your account: in the app under Profile → Settings → Delete account. This also removes all existing values. See Delete your account.
  • Write to us: at info@neurolytix.de.

The withdrawal takes effect for the future. It does not make our processing of the data up to that point unlawful (Art. 7(3) GDPR).

Who sees what about you

Pyron is a competition, so part of you is visible to others. Which part depends on how you are connected to each other. The limits are set on the server and not merely in what the app displays.

WhoSees
Every signed-in playerUsername, rank, level, title, crest and frame, rating, competition record, achievements earned, your position in leaderboards, the gap to you in steps, as well as your club, your role in it and since when you have been in it
Your friends, in additionyour step statistics: daily steps, total steps, best day, number of days walked, longest streak, average of the last seven days, time of the last sync
Only youyour hourly values, your email address, your reports and your account settings
We as the providerall of the above, to the extent necessary for operation, scoring and preventing abuse

Choose your username accordingly. It is visible to everyone and can be found via the people search; you do not have to use your real name for it.

Friends and invitations

We store who is friends with whom, pending invitations and — if you state it when registering — who referred you. Friendships are always mutual. You can unfriend someone at any time; the other person is not told.

We do not match any address book and do not read any contacts. You can only find friends via the people search by username.

Notifications

If you allow push notifications, we store the device token that Apple or Google issues for this, and the platform. The token is not a name and not an identifier of your device, but an address to which notifications are delivered; it changes from time to time.

On the iPhone, notifications are sent via Apple's Apple Push Notification service, on Android via Google's Firebase Cloud Messaging. In the process, the content of a notification passes through the servers of Apple or Google respectively. The legal basis is your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time in your phone's settings.

Reporting bugs, reporting people

Bugs and ideas

If you shake your iPhone, a report box opens. Along with your text, we transmit: which screen was open, the app version, the device class (such as “iOS phone”), the iOS version and the app's most recent log lines. If the app crashes, the same report is created automatically and sent at the next launch. These reports are linked to your account.

The legal basis is our legitimate interest in an app that works (Art. 6(1)(f) GDPR). An app whose crashes nobody hears about does not get fixed.

Reporting a person

If you come across a username that is insulting or deceptive, you can report the person via their profile. We then store who made the report, who was reported and why. The reported person does not find out who the report came from. Details of the procedure are set out in the Terms of Use.

Anonymous usage events

We keep count of whether the competition works technically: how many rounds start, are scored or fail. These events are not linked to your player ID but to a pseudonymous identifier derived from it (HMAC-SHA256 with a secret that never leaves the server). The server explicitly removes step counts, player IDs and display names from every event, even if the app sent them. Rating values are only included in bands (“250–399”), never as an exact number.

Before sign-in, we count how far a visit gets: whether the app was opened, which page of the introduction was reached and whether “Sign in with Apple” or email registration was tapped. For this, the app generates a random visit ID at every launch, which exists only in memory and is not stored on your device. Only this ID, the step reached, the build and app version and the iOS version are transmitted — no player ID, no name, no advertising ID. We do not store an IP address with it. The entries are deleted after 180 days.

Apart from the Meta SDK for ad measurement (see Ad measurement with Meta), we use no third-party analytics or advertising service. The app does not read the advertising ID and therefore does not ask for tracking permission.

Crash reports

To keep Pyron running reliably, we send technical diagnostic data to Sentry (Functional Software, Inc. dba Sentry). Without such reports, we only learn about an error when someone reports it — and most errors are never reported by anyone.

We have deliberately configured these diagnostics broadly. The following is transmitted:

  • the error message and the place in the program where it occurred
  • app version, operating system version, device model, time
  • your IP address
  • your player ID and your display name, so that a report can be linked to your account
  • the last actions before the error: which screens you opened, what you tapped and which server calls the app made
  • a screenshot of the moment of the error and the structure of the screen at that instant — not pixelated

The data is stored in Frankfurt am Main (Sentry's EU region) and is not used for advertising purposes, not sold and not combined with data from other services. The legal basis is our legitimate interest in a stable app (Art. 6(1)(f) GDPR). We delete error reports after 90 days, together with the screenshots belonging to them.

You can object to this processing at any time — write to us at info@neurolytix.de. More under Your rights.

Ad measurement with Meta

We promote Pyron with ads on Facebook and Instagram. To find out how many people find their way to the app through such an ad, the software toolkit of Meta Platforms Ireland Limited (Meta SDK) is built into the iPhone app. The Android app does not contain it.

The SDK transmits to Meta:

  • that Pyron has been installed and opened on a device,
  • purchases and subscriptions made through the App Store (product and price),
  • technical device data: device model, version of iOS and of the app, language, time zone and the IP address of your device.

Not transmitted are your steps, floors, calories or other health data, your username, your email address and anything you see or do in the app. We do not ask for app tracking permission, and the SDK is configured so that it does not read your iPhone's advertising ID. Meta therefore only evaluates the reports in aggregated form (“Aggregated Event Measurement”) and attributes them to an ad via Apple's SKAdNetwork.

The legal basis is our legitimate interest in measuring the effectiveness of our advertising and using the advertising budget sensibly (Art. 6(1)(f) GDPR). We and Meta are joint controllers for the measurement (Art. 26 GDPR); any further processing at Meta is governed by Meta's data policy (facebook.com/privacy/policy). Meta may also process the data in the USA; see Transfers outside the EU.

You can object to this processing at any time (Art. 21 GDPR) — a short message to info@neurolytix.de is enough.

Subscription and purchase

Pyron is offered in the App Store and on Google Play. Anyone who takes out the subscription concludes the purchase contract with Apple or Google respectively, not with us. Your payment data — credit card, billing address, Apple ID or Google account — is processed exclusively by the respective store; we never get to see it.

From Apple and Google, we only receive the information whether a valid subscription exists for your account, as well as aggregated, non-personal sales statistics. More about the subscription can be found in the Terms of Use, and about data processing by Apple in Apple's own privacy policy.

This website

pyron.app is a purely informational site. It has no login and no database connection.

  • No cookies. We do not store anything on your device and do not read anything from it. Consent under Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) is therefore not required, and there is no cookie banner here for you to click away.
  • No trackers, no tracking pixels, no embeds from YouTube, Google Maps or social networks.
  • Fonts are hosted by us. The fonts are delivered along with the site when it is built. Your browser does not fetch anything from Google for them, and no IP address is transmitted to the USA.

When the site is accessed, server logs are created at our host Vercel for technical reasons: IP address, time, requested address, browser type and referring page. They serve the operation of the site and the defence against attacks (Art. 6(1)(f) GDPR) and are deleted after a short time.

Who else sees the data

We do not sell your data. For ad measurement, Meta receives the information listed under Ad measurement with Meta. In addition, we use service providers who work for us and on our instructions (processors under Art. 28 GDPR). We have a data processing agreement with each of them that obliges them to a level of protection that corresponds to this policy.

WhoPurposeWhere the data is stored
Supabase, Inc.
970 Toa Payoh North, #07-04, Singapore 318992
Database, accounts, server operation of the appIreland (AWS eu-west-1)
Functional Software, Inc. dba Sentry
45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA
Crash and error reports of the appFrankfurt am Main (Sentry's EU region)
Apple Distribution International Ltd.
Hollyhill Industrial Estate, Hollyhill, Cork, Ireland
App Store, Sign in with Apple, push notifications, subscriptionIreland and other Apple locations
Google Ireland Limited
Gordon House, Barrow Street, Dublin 4, Ireland
Google Play, “Continue with Google”, push notifications on Android (Firebase Cloud Messaging), subscription on AndroidIreland and other Google locations
Vercel Inc.
440 N Barranca Ave #4133, Covina, CA 91723, USA
Operation of this website (not the app)European data centres, logs also in the USA
Meta Platforms Ireland Limited
Merrion Road, Dublin 4, D04 X2K5, Ireland
Ad measurement for the iPhone app (joint controller, not a processor)Ireland, also USA (Meta Platforms, Inc.)

Beyond that, we only disclose data if we are legally obliged to do so — for example to law enforcement authorities on the basis of a valid order.

Transfers outside the EU

The app's data is stored in Ireland and therefore within the EU. However, some of the companies we use are based outside the EU, so access from a third country — in particular the USA — cannot be ruled out.

For these cases, we base the transfer on the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR, which form part of the contracts with the providers named — in the case of Meta, additionally on the European Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), which Meta Platforms, Inc. has joined — supplemented by technical measures such as encryption in transit and at rest. A third country outside the EU may not offer a level of protection comparable to that of the EU; in particular, authorities there may be able to access data under less stringent conditions, and legal remedies against this may be limited.

How long we store data

WhatHow long
Account, profile, friendships, club and teamsuntil you delete the account
Step values, rank, rating, achievementsuntil you delete the account
Device token for notificationsuntil you withdraw permission, the token becomes invalid or you delete the account
Bug and crash reportsuntil the case is closed, for a maximum of 12 months; the link to your account is removed when the account is deleted
Reports about peopleuntil the matter is resolved, then for a maximum of 12 months
Pseudonymous usage eventspermanently; after the account is deleted, they can no longer be attributed to anyone
Server logs of this websitea few days
Records relevant for tax purposesstatutory retention periods under Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB) (6 or 8 years respectively); this data is not accessible for anything else

What disappears when you delete your account, and what remains and for what reason, is explained in detail under Delete your account.

Age

We do not collect a date of birth and therefore cannot verify age. If we become aware that an account belongs to a child under 16 without parental consent, we will delete it.

Your rights

You have the following rights with respect to us:

  • Access (Art. 15 GDPR) — which data we process about you
  • Rectification (Art. 16 GDPR) — having incorrect data corrected
  • Erasure (Art. 17 GDPR) — the “right to be forgotten”
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR) — receiving your data in a machine-readable format
  • Objection (Art. 21 GDPR) — to processing that we base on a legitimate interest
  • Withdrawal of consent (Art. 7(3) GDPR) — at any time and with effect for the future

For all of this, an email to info@neurolytix.de is enough. We reply within one month (Art. 12(3) GDPR). There is no charge to you.

Complaint to the supervisory authority

Independently of this, you can lodge a complaint with a data protection supervisory authority at any time (Art. 77 GDPR), in particular in the EU member state of your place of residence or your place of work. The authority responsible for us is:

State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg)
Lautenschlagerstraße 20, 70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de

Changes

If what the app does changes, this policy changes with it. The date at the top tells you which version applies. For changes that affect you significantly — such as a new type of data or a new recipient — we will point them out to you in the app before they take effect. If the purpose for which we process your health data changes, we will obtain new consent beforehand.