Privacy Policy

Last updated: July 20, 2026

1. Controller

The controller responsible for data processing in connection with this service (Sioly) is:

Noah Sioly UG (haftungsbeschränkt)

Hoheluftchaussee 139

20253 Hamburg, Germany

Managing Director: Ines Kupka

E-mail: support@sioly.app

2. Overview: What This App Does

Sioly is a native app for iOS and Android. Users complete routines, check off tasks, store progress, optionally create journal entries, and optionally use an AI Coach. The app accesses device services for individual features (see Section 3.8). The earlier web application (PWA) is no longer offered; for users who had an account there, this policy continues to apply unchanged.

3. Data Processed

3.1 Account and Profile Data

Registration and sign-in are also possible via Google Sign-In. In that case, we receive from Google the identity data required to create your account (name, email address, Google account ID); Google's privacy terms additionally apply (see Section 10).

3.2 Usage / Content Data (App Data)

3.3 Technical Data

3.4 Web Push Notification Data

If you activate push notifications, we process push subscription data (endpoint, public key/token components), notification settings (time zone, time, weekly plan, on/off), and the association with your app usage.

3.5 User Responsibility for Entered Content

Users are solely responsible for any content they enter. Please do not enter personal data of third parties, copyrighted content without proper authorization, or sensitive personal information.

3.6 Handling of Sensitive Data (Special Categories under Art. 9 GDPR)

With the exception of the optional, consent-based health and fitness features of the native apps (see Section 3.8), the app is not intended to specifically request or systematically analyze special categories of personal data within the meaning of Art. 9 GDPR (e.g., ethnic origin, religious beliefs, or sexual orientation). The provision of any further sensitive data is neither required nor intended by us.

However, as the journal, gratitude logs, and AI Coach contain free text fields, it cannot be excluded that you voluntarily enter such sensitive information.

If you voluntarily enter health-related or other sensitive data in free text fields, their processing is based on your explicit consent pursuant to Art. 9(2)(a) GDPR. You may withdraw this consent at any time with effect for the future by deleting the respective content.

We do not carry out automated evaluation or profiling based on such sensitive data.

3.7 Obligation to Provide Data

The provision of personal data marked as mandatory is required for the conclusion and performance of the user contract and for the use of the app. Without this information, no user account can be created and no access to the app can be granted.

3.8 Additional Data Processing in the Native Apps (iOS/Android)

The native apps for iOS and Android offer additional features that access device sensors and system services. Each of these accesses only occurs after your explicit approval via the operating system's permission dialog and can be revoked at any time in your device settings.

Where health- or location-related data is synchronized with your account to display your history, it is stored with our processor Supabase (EU, Frankfurt).

3.9 Community Features (User-Generated Content)

When you use the community feature, we process the content you post (posts, comments, photos), your display name and profile picture, and associated metadata (e.g., group/thread association, timestamps). This content is visible to other members of the respective group. The legal basis is contract performance (Art. 6(1)(b) GDPR) or your consent through active participation.

When you report content or users, we process the report (reported content, user ID, reason) and the resulting moderation decisions in order to keep the community safe. The legal basis is our legitimate interest in the security of the platform and compliance with our obligations under the Digital Services Act (Art. 6(1)(f) GDPR).

Community content is stored as long as the respective group or your account exists. After you delete your account, your community content is removed or anonymized; reported content and related moderation records may be retained for a limited period for documentation and to comply with legal obligations.

4. Purposes and Legal Bases (Art. 6 & 9 GDPR)

5. AI-Supported Functions (AI Coach)

The AI Coach is optional. If you use it, data is transmitted to third-party AI services in order to generate responses.

5.1 Data Transmitted to AI Providers

5.2 Data NOT Transmitted to AI Providers

5.3 No Intended Processing of Sensitive Health Data

The AI Coach is not intended to process special categories of personal data within the meaning of Art. 9 GDPR. Users are expressly requested not to enter sensitive health data (e.g., diagnoses, medical histories, medication details, or mental health conditions) into the AI chat. If users nevertheless provide such information, they do so at their own responsibility.

5.4 AI Providers (Currently)

We may change providers. Significant changes will be reflected in this Privacy Policy.

5.5 Legal Basis

Processing takes place on the basis of your consent (Art. 6(1)(a) GDPR), which you give by first using the optional AI Coach. You may withdraw this consent at any time with effect for the future by no longer using the AI Coach; the lawfulness of processing carried out until withdrawal remains unaffected.

5.6 Responsibility for AI-Generated Content

AI-generated content is provided solely for general motivation and informational purposes. Any decisions, actions, or omissions based on AI output are solely the responsibility of the user.

5.7 No Warranty for Content

There is no claim to accuracy, completeness, or timeliness of content provided by the app or the AI Coach.

5.8 International Data Transfers

The AI providers listed in Section 5.4 (Groq, Inc., Cerebras Systems, Inc., Google LLC / Google Gemini, OpenRouter, Inc., OpenAI, L.L.C.) process data in the USA. We base these transfers on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). You may avoid data transfers in connection with the AI Coach by not using this function.

6. Audio Transcription (Voice → Text)

For speech recognition, the app primarily uses on-device processing by the operating system; in that case, the audio does not leave your device. In certain cases or as a fallback, audio is transmitted to Groq, Inc. (USA) for transcription. We do not permanently store raw audio on our servers. The provider may temporarily store logs.

Processing is carried out solely for the purpose of converting speech into text within the app.

7. Push Notifications (Web Push)

Push notifications are optional and require your consent.

If activated, we store push subscription data (endpoint, keys) to send routine reminders and re-engagement notifications. We also store notification settings (e.g., time zone, time, weekly schedule, on/off). Push delivery uses browser/OS push services.

8. Contact Form

If you use the contact form, we process your name, email address, and message for the purpose of handling your request (Art. 6(1)(b) or (f) GDPR). Emails are sent via Resend. The data is not stored in our database but retained in our support mailbox as long as necessary for processing.

9. Payment Processing (Paddle)

Purchases currently take place exclusively via the Apple App Store or Google Play (see the following paragraph). For any purchases made through the website, payments, invoicing, and refunds are processed by Paddle as Merchant of Record. Paddle processes payment data independently. We only receive purchase-related information required to activate access.

In the native apps for iOS and Android, purchase and payment processing take place via the respective app store operator (Apple App Store or Google Play); their payment and privacy terms apply. To manage entitlements (unlocking premium content), we use the processor RevenueCat. Here too, we only receive the purchase-related information required to activate access; full payment data (e.g., card details) is processed exclusively by Apple or Google.

10. Hosting and Processors

Where required, we have data processing agreements pursuant to Art. 28 GDPR with our processors. Where processing occurs outside the EU/EEA – in particular in the USA – we base the transfer on the European Commission's Standard Contractual Clauses (Art. 46 GDPR).

11. Cookies and Local Storage (§ 25 TDDDG)

The app uses technically necessary storage mechanisms (cookies/local storage) for login sessions and offline functionality. No tracking, marketing cookies, or analytics tools are currently used.

12. Retention and Deletion

13. Your Rights

You have the following rights:

Withdrawal of consent: You may withdraw consent (e.g., for push notifications or sensitive data) at any time with effect for the future (e.g., by deleting entries or adjusting settings). The lawfulness of processing carried out on the basis of consent until withdrawal remains unaffected (Art. 7(3) sentence 2 GDPR).

The exercise of your rights may be restricted in individual cases within the limits of statutory provisions, particularly where necessary to protect overriding legitimate interests, system security, or abuse prevention.

Automated decision-making within the meaning of Art. 22 GDPR does not take place.

Contact: support@sioly.app

14. Right to Lodge a Complaint / Supervisory Authority

Under Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates data protection law.

Competent authority:

The Hamburg Commissioner for Data Protection and Freedom of Information

Ludwig-Erhard-Str. 22, 7th floor

20459 Hamburg, Germany

This Privacy Policy primarily addresses users within the European Union and is based on the General Data Protection Regulation (GDPR). For users outside the EU, personal data is processed in accordance with GDPR standards. Where additional national data protection laws apply, these apply additionally without excluding the applicability of the GDPR.

15. This Website (sioly.app)

The sections above cover the app. This one covers the website sioly.app itself — what happens when you open a page here.

Hosting and server logs. The website is operated by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) as our processor and served from the European location Frankfurt am Main. When a page is requested, Vercel processes the technically necessary connection data: IP address, time of the request, the address requested, the amount of data transferred, and the browser and operating system identifier. This data is required to deliver the page and keep it secure; the legal basis is Art. 6 (1) (f) GDPR. A data processing agreement is in place; for transfers to the USA the European Commission's standard contractual clauses apply.

No tracking, no analytics, no advertising cookies. This website sets no analytics or advertising cookies, embeds no analytics services and loads nothing from third-party servers. Fonts, images and icons are all served from this domain, so opening a page does not cause your browser to contact anyone else.

Contact form. If you use the form at sioly.app/contact, we process what you enter: your name, your email address and your message. We need all three to answer you. Delivery to our mailbox is handled by Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as our processor; a data processing agreement is in place and the standard contractual clauses apply to the transfer to the USA. Your IP address is processed while sending, solely to limit how many messages can be sent per hour — without that the form would be an open relay for spam. The legal basis is Art. 6 (1) (b) GDPR where your message concerns an existing or intended contract, otherwise Art. 6 (1) (f) GDPR. Your message stays in our mailbox for as long as it takes to answer it and handle any follow-up; ask us and we delete it immediately.

One technical cookie. A cookie is set only after you submit the form, and it contains nothing but the time of your last message. It stops the same form being submitted repeatedly within a minute, expires after 60 seconds, and is not used to recognise you. Under § 25 (2) TDDDG it is strictly necessary and needs no consent.

Your rights from the sections above — access, rectification, erasure, restriction, portability, objection and complaint to a supervisory authority — apply to this processing in exactly the same way.

This Privacy Policy is effective as of July 20, 2026; section 15 as of 24 August 2026.

Privacy Policy — Sioly