Cyon Privacy Policy

Last updated: July 24, 2026

Cyon helps you reflect on your own health signals. It is built around a simple principle: your health data stays on your device. This policy explains what stays on your device, the little our servers touch, and the choices you have.

Data that stays on your device

Your health readings — sleep, heart-rate variability, resting heart rate, and activity — are read from the providers you connect (Apple Health, Google Health, and WHOOP), aggregated into daily values, and stored only on your device. Your check-ins, reflections, voice recordings, and on-device transcripts are likewise stored only on your device. The text of your check-ins can leave your device only when you start a conversation with the in-app coach. Voice audio is never sent — see "Coaching" below.

What our servers process

Cyon's backend does not retain your health data. It is used for:

WHOOP

When you connect WHOOP, you authorize Cyon to read your recovery, sleep, and cycle data (scopes: read:recovery, read:sleep, read:cycles, and offline). Because WHOOP requires its client secret to be used server-side, the authorization code your device receives is exchanged for access tokens by our backend, which returns those tokens to your device without storing them. The tokens are then kept in your device's secure Keychain, and your device fetches WHOOP data directly. We never store your WHOOP data or WHOOP tokens on our servers. You can disconnect WHOOP at any time in Cyon (Settings → Sources), and you can revoke Cyon's access from your WHOOP account.

Third-party providers

Connecting Apple Health, Google Health, or WHOOP is optional and governed by each provider's own terms and privacy policy. Cyon reads only the signals you enable, and only while connected.

Data retention and deletion

Because your health data lives on your device, deleting the app removes it. You can disconnect any provider at any time, which stops syncing while leaving already-synced days on your device. Deleting your account from within Cyon revokes the Apple grant and removes the account record and Apple refresh token from our servers.

Security

Tokens on the device are stored in the iOS Keychain. Traffic to our backend is encrypted in transit (HTTPS). Account records at rest are encrypted by our cloud provider.

Age requirement

Cyon is intended for users 18 and older; account creation requires confirming your age. We do not knowingly collect data from anyone under 18.

Changes

We may update this policy; material changes will be reflected by the date above.

Contact

Questions? Email privacy@enfinyte.com.