Last updated: July 24, 2026
Cyon helps you reflect on your own health signals. It is built around a simple principle: your health data stays on your device. This policy explains what stays on your device, the little our servers touch, and the choices you have.
Your health readings — sleep, heart-rate variability, resting heart rate, and activity — are read from the providers you connect (Apple Health, Google Health, and WHOOP), aggregated into daily values, and stored only on your device. Your check-ins, reflections, voice recordings, and on-device transcripts are likewise stored only on your device. The text of your check-ins can leave your device only when you start a conversation with the in-app coach. Voice audio is never sent — see "Coaching" below.
Cyon's backend does not retain your health data. It is used for:
When you connect WHOOP, you authorize Cyon to read your recovery, sleep, and cycle data
(scopes: read:recovery, read:sleep, read:cycles, and
offline). Because WHOOP requires its client secret to be used server-side, the
authorization code your device receives is exchanged for access tokens by our backend, which
returns those tokens to your device without storing them. The tokens are then
kept in your device's secure Keychain, and your device fetches WHOOP data directly. We never
store your WHOOP data or WHOOP tokens on our servers. You can disconnect WHOOP at any time in
Cyon (Settings → Sources), and you can revoke Cyon's access from your WHOOP account.
Connecting Apple Health, Google Health, or WHOOP is optional and governed by each provider's own terms and privacy policy. Cyon reads only the signals you enable, and only while connected.
Because your health data lives on your device, deleting the app removes it. You can disconnect any provider at any time, which stops syncing while leaving already-synced days on your device. Deleting your account from within Cyon revokes the Apple grant and removes the account record and Apple refresh token from our servers.
Tokens on the device are stored in the iOS Keychain. Traffic to our backend is encrypted in transit (HTTPS). Account records at rest are encrypted by our cloud provider.
Cyon is intended for users 18 and older; account creation requires confirming your age. We do not knowingly collect data from anyone under 18.
We may update this policy; material changes will be reflected by the date above.
Questions? Email privacy@enfinyte.com.