Privacy Policy
For the Pyron app and for this website. It explains what data we process, why we are allowed to do so and what you can do about it.
Last updated: 23 September 2026
This is an English translation of the German original. If the two versions differ, the German version applies.
In short
The following is a summary. It does not replace the sections below, but it puts the most important points first.
- We read exactly three values — your step count, your active calories and the floors you have climbed. On an iPhone from Apple Health, on an Android phone from Health Connect. Read-only, and we never write anything back.
- Step counts are health data. We process them only with your explicit consent, which you can withdraw at any time.
- Your step counts and everything else in your profile are visible to everyone. Anyone who signs in sees the same figures as you do in the leaderboard, the round and the profile — steps, rank, level, rating and what you have achieved in competition.
- We do not sell any data and we do not show any advertising in the app. We do, however, advertise Pyron on Facebook and Instagram. So that we can see whether this advertising works, the iPhone app reports to Meta that it has been installed and opened. Meta never receives your steps or any other health data. More under Ad measurement with Meta.
- To keep the app running reliably, we send technical diagnostic data to Sentry in Frankfurt — up to and including a screenshot taken at the moment of the error. What exactly this covers is set out under Crash reports.
- All data is stored on servers in Ireland, i.e. in the EU.
- You can delete your account yourself in the app. Then everything is gone.
Who is responsible
The controller within the meaning of Art. 4(7) GDPR is:
Neurolytix GmbH
Hauptstraße 127
68259 Mannheim
Germany
Managing Director: Jonas Reggelin
Email: info@neurolytix.de
We have not appointed a data protection officer. The requirements of Art. 37 GDPR and Section 38 of the German Federal Data Protection Act (BDSG) are not met in our case; for all questions about data protection, you can reach us at the address given above.
Overview of all processing
The table lists every processing activity with its legal basis. The sections below explain each of them in detail.
| What | Purpose | Legal basis |
|---|---|---|
| Email address, password, or Apple or Google identifier | So that you have an account and can be recognised again | Art. 6(1)(b) GDPR (contract) |
| Username, time zone | Display to others, assigning your days | Art. 6(1)(b) GDPR |
| Step counts from Apple Health or Health Connect | Rank, level, XP and competition scoring | Art. 9(2)(a) GDPR (explicit consent), together with Art. 6(1)(a) |
| Floors climbed from Apple Health or Health Connect | Display on your Home screen and our analysis of whether Pyron gets people moving — not part of any competition scoring | Art. 9(2)(a) GDPR (explicit consent), together with Art. 6(1)(a) |
| Rank, level, rating, placings | Competition, leaderboards, profile | Art. 6(1)(b) GDPR |
| Friendships and invitations | Friends list, club and teams, mutual visibility | Art. 6(1)(b) GDPR |
| Device token for notifications | Push notifications to your phone | Art. 6(1)(a) GDPR (consent) |
| Bug reports, crash logs | Finding and fixing bugs | Art. 6(1)(f) GDPR (legitimate interest in an app that works) |
| Reports about other users | Following up on abuse | Art. 6(1)(f) GDPR, also in fulfilment of Art. 16 DSA |
| Pseudonymous usage events | Detecting whether the competition works technically | Art. 6(1)(f) GDPR |
| App installation, app launches and purchases in the App Store, with technical device data (iPhone app only) | Measuring whether our advertising on Facebook and Instagram works | Art. 6(1)(f) GDPR (legitimate interest in effective advertising for the app) |
| Server logs of this website | Operation and security of the website | Art. 6(1)(f) GDPR |
Your account
Pyron does not work without an account: a competition needs someone to compete, and a rank needs someone it belongs to. There are three ways in; which ones you see depends on your phone.
With email address and password
We store your email address and your password. We never store the password in plain text, only as a cryptographic hash (bcrypt) — we can neither read it nor tell it to you. To confirm, we send you an email with a six-digit code.
With “Sign in with Apple”
Apple sends us a user identifier that is unique to Pyron and, if you agree, your email address. If you choose “Hide My Email” at Apple, we only receive a forwarding address from Apple and never your real one. Apple only releases your name the very first time you sign in; we then use it as a suggestion for your username.
With “Continue with Google” (Android only)
Google sends us a user identifier that is unique to Pyron, your email address and the name stored in your Google account. We use the name only the very first time you sign in as a suggestion for your username; if you have given yourself a name of your own, it remains untouched. We never get to see your Google password — sign-in works via a signed identity token that we have Google verify.
In all cases
In addition, we store your username and the time zone in which you registered. The time zone is not a location lookup — it is the setting your phone comes with anyway, and we need it to know when a day begins and ends for you. Someone walking in Tokyo should not find their steps in a German calendar day.
Steps from Apple Health and Health Connect
This is the core of the app and the most sensitive part of this policy.
Exactly which data
From Apple HealthKit we read exactly three values: your step count (HKQuantityTypeIdentifierStepCount), your active energy in kilocalories (HKQuantityTypeIdentifierActiveEnergyBurned) — the same figure that Apple shows as “Move” in the Fitness app — and the floors climbed (HKQuantityTypeIdentifierFlightsClimbed). No heart rate, no distance, no sleep, no weight, no workouts, no locations. The permission the app requests from iOS technically covers only these three types, and it is read-only access: Pyron never writes anything back to Apple Health.
On an Android phone, the same three values come from Health Connect, Google's store for health data: steps (StepsRecord), active calories (ActiveCaloriesBurnedRecord) and floors climbed (FloorsClimbedRecord). There too, Pyron requests read permissions only and never writes anything back. Two further permissions are added because Android requires them separately: reading data older than 30 days — so that days filled in later are not lost, and for the comparison over twelve months — and reading in the background, so that your steps arrive even when the app is not open. You can revoke both at any time in Health Connect under “App permissions › Pyron”; the app will then tell you that nothing is arriving any more.
Anything someone enters by hand in Health Connect is not counted by us: Pyron recognises such entries and excludes them. On Android, too, we read which app or device measured the steps, and only count recognised sources — the same rule as on the iPhone.
Active energy was added on 22 August 2026 together with the calories tile on the Home screen. A stricter rule applies to it than to steps: it never leaves your iPhone. The app reads it directly from HealthKit, uses it to draw the tile and the calories detail page, and then forgets it. It is not transmitted to our server, not stored anywhere, and does not feed into any rank, level or competition. Moreover, the tile is not enabled by default: it only appears on your Home screen once you add it there. If you remove it again, the app no longer reads the value from HealthKit at all.
Floors were added on 29 August 2026, and a rule of their own applies to them: they do not count in any competition. They do not feed into any rank, level, rating or achievement. We use them for two things. First, we show them to you — on the Home screen, the steps tile shows how many floors you have climbed today, against a goal that you set yourself in the settings. This figure is read, drawn and forgotten again on your device; it is not sent to our server for this, and nobody but you sees it. Second, we use them for an analysis for our own purposes — whether the people who use Pyron move more than before. For this, we make a one-time read of your steps and floors for the last twelve months, i.e. also from the period before you installed the app, and compare the average before with the average after. These figures are kept separate from everything the app calculates with; they do not appear in any leaderboard or profile. If you do not want this, deny access to “Flights Climbed” in Apple Health — the Home screen will then show “not measured” instead of a number, and everything else in Pyron keeps working.
In addition, we read which source measured the steps — i.e. whether they come from the iPhone, from an Apple Watch or from another app. We need this because exactly one source always counts in the scoring; otherwise the same walk would be counted twice.
How we collect them
If you allow it, iOS notifies us in the background that your step count has changed (“Background Delivery”). The app then asks HealthKit for the totals for certain time windows and sends them to our server. What is transmitted are hourly totals, not individual movements and not the times of individual steps.
On Android, there is no such automatic notification. There, Pyron checks Health Connect at a fixed interval — at most every 15 minutes — to see whether anything has changed, and only then fetches the totals. The same is transmitted: hourly totals.
What for
Exclusively to calculate your rank, your level, your XP and your placing in the competition from them. For no other purpose.
On what legal basis
Step counts are health data within the meaning of Art. 4(15) GDPR and therefore a special category of personal data under Art. 9 GDPR. Processing them is prohibited in principle and only permitted if one of the exceptions in Art. 9(2) applies. We rely on Art. 9(2)(a) GDPR — your explicit consent.
You give this consent in two deliberate steps: first on the welcome screen of Pyron, where we tell you that step counts are health data and what we use them for, and then in the iOS dialog in which you grant read access to HealthKit. Without both steps, we do not process any step data.
How to withdraw your consent
At any time and without giving reasons. You have three options, and they differ in how far they go:
- Revoke access: iPhone Settings → Apps → Health → Data Access & Devices → Pyron → set Steps to “Don't Allow”. From then on, no new values arrive. The existing ones remain stored.
- Delete your account: in the app under Profile → Settings → Delete account. This also removes all existing values. See Delete your account.
- Write to us: at info@neurolytix.de.
The withdrawal takes effect for the future. It does not make our processing of the data up to that point unlawful (Art. 7(3) GDPR).
Who sees what about you
Pyron is a competition, so part of you is visible to others. Which part depends on how you are connected to each other. The limits are set on the server and not merely in what the app displays.
| Who | Sees |
|---|---|
| Every signed-in player | Username, rank, level, title, crest and frame, rating, competition record, achievements earned, your position in leaderboards, the gap to you in steps, as well as your club, your role in it and since when you have been in it |
| Your friends, in addition | your step statistics: daily steps, total steps, best day, number of days walked, longest streak, average of the last seven days, time of the last sync |
| Only you | your hourly values, your email address, your reports and your account settings |
| We as the provider | all of the above, to the extent necessary for operation, scoring and preventing abuse |
Choose your username accordingly. It is visible to everyone and can be found via the people search; you do not have to use your real name for it.
Friends and invitations
We store who is friends with whom, pending invitations and — if you state it when registering — who referred you. Friendships are always mutual. You can unfriend someone at any time; the other person is not told.
We do not match any address book and do not read any contacts. You can only find friends via the people search by username.
Notifications
If you allow push notifications, we store the device token that Apple or Google issues for this, and the platform. The token is not a name and not an identifier of your device, but an address to which notifications are delivered; it changes from time to time.
On the iPhone, notifications are sent via Apple's Apple Push Notification service, on Android via Google's Firebase Cloud Messaging. In the process, the content of a notification passes through the servers of Apple or Google respectively. The legal basis is your consent under Art. 6(1)(a) GDPR, which you can withdraw at any time in your phone's settings.
Reporting bugs, reporting people
Bugs and ideas
If you shake your iPhone, a report box opens. Along with your text, we transmit: which screen was open, the app version, the device class (such as “iOS phone”), the iOS version and the app's most recent log lines. If the app crashes, the same report is created automatically and sent at the next launch. These reports are linked to your account.
The legal basis is our legitimate interest in an app that works (Art. 6(1)(f) GDPR). An app whose crashes nobody hears about does not get fixed.
Reporting a person
If you come across a username that is insulting or deceptive, you can report the person via their profile. We then store who made the report, who was reported and why. The reported person does not find out who the report came from. Details of the procedure are set out in the Terms of Use.
Anonymous usage events
We keep count of whether the competition works technically: how many rounds start, are scored or fail. These events are not linked to your player ID but to a pseudonymous identifier derived from it (HMAC-SHA256 with a secret that never leaves the server). The server explicitly removes step counts, player IDs and display names from every event, even if the app sent them. Rating values are only included in bands (“250–399”), never as an exact number.
Before sign-in, we count how far a visit gets: whether the app was opened, which page of the introduction was reached and whether “Sign in with Apple” or email registration was tapped. For this, the app generates a random visit ID at every launch, which exists only in memory and is not stored on your device. Only this ID, the step reached, the build and app version and the iOS version are transmitted — no player ID, no name, no advertising ID. We do not store an IP address with it. The entries are deleted after 180 days.
Apart from the Meta SDK for ad measurement (see Ad measurement with Meta), we use no third-party analytics or advertising service. The app does not read the advertising ID and therefore does not ask for tracking permission.
Crash reports
To keep Pyron running reliably, we send technical diagnostic data to Sentry (Functional Software, Inc. dba Sentry). Without such reports, we only learn about an error when someone reports it — and most errors are never reported by anyone.
We have deliberately configured these diagnostics broadly. The following is transmitted:
- the error message and the place in the program where it occurred
- app version, operating system version, device model, time
- your IP address
- your player ID and your display name, so that a report can be linked to your account
- the last actions before the error: which screens you opened, what you tapped and which server calls the app made
- a screenshot of the moment of the error and the structure of the screen at that instant — not pixelated
The data is stored in Frankfurt am Main (Sentry's EU region) and is not used for advertising purposes, not sold and not combined with data from other services. The legal basis is our legitimate interest in a stable app (Art. 6(1)(f) GDPR). We delete error reports after 90 days, together with the screenshots belonging to them.
You can object to this processing at any time — write to us at info@neurolytix.de. More under Your rights.
Ad measurement with Meta
We promote Pyron with ads on Facebook and Instagram. To find out how many people find their way to the app through such an ad, the software toolkit of Meta Platforms Ireland Limited (Meta SDK) is built into the iPhone app. The Android app does not contain it.
The SDK transmits to Meta:
- that Pyron has been installed and opened on a device,
- purchases and subscriptions made through the App Store (product and price),
- technical device data: device model, version of iOS and of the app, language, time zone and the IP address of your device.
Not transmitted are your steps, floors, calories or other health data, your username, your email address and anything you see or do in the app. We do not ask for app tracking permission, and the SDK is configured so that it does not read your iPhone's advertising ID. Meta therefore only evaluates the reports in aggregated form (“Aggregated Event Measurement”) and attributes them to an ad via Apple's SKAdNetwork.
The legal basis is our legitimate interest in measuring the effectiveness of our advertising and using the advertising budget sensibly (Art. 6(1)(f) GDPR). We and Meta are joint controllers for the measurement (Art. 26 GDPR); any further processing at Meta is governed by Meta's data policy (facebook.com/privacy/policy). Meta may also process the data in the USA; see Transfers outside the EU.
You can object to this processing at any time (Art. 21 GDPR) — a short message to info@neurolytix.de is enough.
Subscription and purchase
Pyron is offered in the App Store and on Google Play. Anyone who takes out the subscription concludes the purchase contract with Apple or Google respectively, not with us. Your payment data — credit card, billing address, Apple ID or Google account — is processed exclusively by the respective store; we never get to see it.
From Apple and Google, we only receive the information whether a valid subscription exists for your account, as well as aggregated, non-personal sales statistics. More about the subscription can be found in the Terms of Use, and about data processing by Apple in Apple's own privacy policy.
This website
pyron.app is a purely informational site. It has no login and no database connection.
- No cookies. We do not store anything on your device and do not read anything from it. Consent under Section 25(1) of the German Telecommunications Digital Services Data Protection Act (TDDDG) is therefore not required, and there is no cookie banner here for you to click away.
- No trackers, no tracking pixels, no embeds from YouTube, Google Maps or social networks.
- Fonts are hosted by us. The fonts are delivered along with the site when it is built. Your browser does not fetch anything from Google for them, and no IP address is transmitted to the USA.
When the site is accessed, server logs are created at our host Vercel for technical reasons: IP address, time, requested address, browser type and referring page. They serve the operation of the site and the defence against attacks (Art. 6(1)(f) GDPR) and are deleted after a short time.
Who else sees the data
We do not sell your data. For ad measurement, Meta receives the information listed under Ad measurement with Meta. In addition, we use service providers who work for us and on our instructions (processors under Art. 28 GDPR). We have a data processing agreement with each of them that obliges them to a level of protection that corresponds to this policy.
| Who | Purpose | Where the data is stored |
|---|---|---|
| Supabase, Inc. 970 Toa Payoh North, #07-04, Singapore 318992 | Database, accounts, server operation of the app | Ireland (AWS eu-west-1) |
| Functional Software, Inc. dba Sentry 45 Fremont Street, 8th Floor, San Francisco, CA 94105, USA | Crash and error reports of the app | Frankfurt am Main (Sentry's EU region) |
| Apple Distribution International Ltd. Hollyhill Industrial Estate, Hollyhill, Cork, Ireland | App Store, Sign in with Apple, push notifications, subscription | Ireland and other Apple locations |
| Google Ireland Limited Gordon House, Barrow Street, Dublin 4, Ireland | Google Play, “Continue with Google”, push notifications on Android (Firebase Cloud Messaging), subscription on Android | Ireland and other Google locations |
| Vercel Inc. 440 N Barranca Ave #4133, Covina, CA 91723, USA | Operation of this website (not the app) | European data centres, logs also in the USA |
| Meta Platforms Ireland Limited Merrion Road, Dublin 4, D04 X2K5, Ireland | Ad measurement for the iPhone app (joint controller, not a processor) | Ireland, also USA (Meta Platforms, Inc.) |
Beyond that, we only disclose data if we are legally obliged to do so — for example to law enforcement authorities on the basis of a valid order.
Transfers outside the EU
The app's data is stored in Ireland and therefore within the EU. However, some of the companies we use are based outside the EU, so access from a third country — in particular the USA — cannot be ruled out.
For these cases, we base the transfer on the European Commission's standard contractual clauses under Art. 46(2)(c) GDPR, which form part of the contracts with the providers named — in the case of Meta, additionally on the European Commission's adequacy decision on the EU-US Data Privacy Framework (Art. 45 GDPR), which Meta Platforms, Inc. has joined — supplemented by technical measures such as encryption in transit and at rest. A third country outside the EU may not offer a level of protection comparable to that of the EU; in particular, authorities there may be able to access data under less stringent conditions, and legal remedies against this may be limited.
How long we store data
| What | How long |
|---|---|
| Account, profile, friendships, club and teams | until you delete the account |
| Step values, rank, rating, achievements | until you delete the account |
| Device token for notifications | until you withdraw permission, the token becomes invalid or you delete the account |
| Bug and crash reports | until the case is closed, for a maximum of 12 months; the link to your account is removed when the account is deleted |
| Reports about people | until the matter is resolved, then for a maximum of 12 months |
| Pseudonymous usage events | permanently; after the account is deleted, they can no longer be attributed to anyone |
| Server logs of this website | a few days |
| Records relevant for tax purposes | statutory retention periods under Section 147 of the German Fiscal Code (AO) and Section 257 of the German Commercial Code (HGB) (6 or 8 years respectively); this data is not accessible for anything else |
What disappears when you delete your account, and what remains and for what reason, is explained in detail under Delete your account.
Age
We do not collect a date of birth and therefore cannot verify age. If we become aware that an account belongs to a child under 16 without parental consent, we will delete it.
Your rights
You have the following rights with respect to us:
- Access (Art. 15 GDPR) — which data we process about you
- Rectification (Art. 16 GDPR) — having incorrect data corrected
- Erasure (Art. 17 GDPR) — the “right to be forgotten”
- Restriction of processing (Art. 18 GDPR)
- Data portability (Art. 20 GDPR) — receiving your data in a machine-readable format
- Objection (Art. 21 GDPR) — to processing that we base on a legitimate interest
- Withdrawal of consent (Art. 7(3) GDPR) — at any time and with effect for the future
For all of this, an email to info@neurolytix.de is enough. We reply within one month (Art. 12(3) GDPR). There is no charge to you.
Complaint to the supervisory authority
Independently of this, you can lodge a complaint with a data protection supervisory authority at any time (Art. 77 GDPR), in particular in the EU member state of your place of residence or your place of work. The authority responsible for us is:
State Commissioner for Data Protection and Freedom of Information Baden-Württemberg (Der Landesbeauftragte für den Datenschutz und die Informationsfreiheit Baden-Württemberg)
Lautenschlagerstraße 20, 70173 Stuttgart
www.baden-wuerttemberg.datenschutz.de
Changes
If what the app does changes, this policy changes with it. The date at the top tells you which version applies. For changes that affect you significantly — such as a new type of data or a new recipient — we will point them out to you in the app before they take effect. If the purpose for which we process your health data changes, we will obtain new consent beforehand.