Privacy Policy
Last updated: July 20, 2026
This English version is provided for convenience only. The legally binding German version can be found here.
1. Controller
The controller responsible for data processing in connection with this service (Sioly) is:
Noah Sioly UG (haftungsbeschränkt)
Hoheluftchaussee 139
20253 Hamburg, Germany
Managing Director: Ines Kupka
E-mail: support@sioly.app
2. Overview: What This App Does
Sioly is a native app for iOS and Android. Users complete routines, check off tasks, store progress, optionally create journal entries, and optionally use an AI Coach. The app accesses device services for individual features (see Section 3.8). The earlier web application (PWA) is no longer offered; for users who had an account there, this policy continues to apply unchanged.
3. Data Processed
3.1 Account and Profile Data
- Email address (login)
- Name (mandatory)
- Date of birth (mandatory; for age calculation, no official verification)
- Gender (mandatory; option "prefer not to say" available)
- Profile picture (if uploaded)
Registration and sign-in are also possible via Google Sign-In. In that case, we receive from Google the identity data required to create your account (name, email address, Google account ID); Google's privacy terms additionally apply (see Section 10).
3.2 Usage / Content Data (App Data)
- Routine level, day progress, streaks, tasks (title + status), badges/trophies
- Journal and gratitude entries (if created within the app)
- Settings (e.g., language)
3.3 Technical Data
- Device and browser information
- IP address (for security and fraud prevention), timestamp, accessed pages/endpoints, user agent
3.4 Web Push Notification Data
If you activate push notifications, we process push subscription data (endpoint, public key/token components), notification settings (time zone, time, weekly plan, on/off), and the association with your app usage.
3.5 User Responsibility for Entered Content
Users are solely responsible for any content they enter. Please do not enter personal data of third parties, copyrighted content without proper authorization, or sensitive personal information.
3.6 Handling of Sensitive Data (Special Categories under Art. 9 GDPR)
With the exception of the optional, consent-based health and fitness features of the native apps (see Section 3.8), the app is not intended to specifically request or systematically analyze special categories of personal data within the meaning of Art. 9 GDPR (e.g., ethnic origin, religious beliefs, or sexual orientation). The provision of any further sensitive data is neither required nor intended by us.
However, as the journal, gratitude logs, and AI Coach contain free text fields, it cannot be excluded that you voluntarily enter such sensitive information.
If you voluntarily enter health-related or other sensitive data in free text fields, their processing is based on your explicit consent pursuant to Art. 9(2)(a) GDPR. You may withdraw this consent at any time with effect for the future by deleting the respective content.
We do not carry out automated evaluation or profiling based on such sensitive data.
3.7 Obligation to Provide Data
The provision of personal data marked as mandatory is required for the conclusion and performance of the user contract and for the use of the app. Without this information, no user account can be created and no access to the app can be granted.
3.8 Additional Data Processing in the Native Apps (iOS/Android)
The native apps for iOS and Android offer additional features that access device sensors and system services. Each of these accesses only occurs after your explicit approval via the operating system's permission dialog and can be revoked at any time in your device settings.
- Health and fitness data (Apple Health / Google Health Connect): If you enable it, the app reads activity data such as steps, distance covered, and active energy in order to display your daily activity and history. This data is processed solely for display within the app and is not used for advertising, marketing, or data mining, nor shared with third parties for such purposes. The legal basis is your explicit consent (Art. 9(2)(a) GDPR), which you may withdraw at any time with effect for the future by revoking the health permission.
- Location data (GPS): For the running feature, the app processes your precise location during active use — including in the background while an activity is in progress — to calculate and display route, distance, and pace. Legal basis: consent (Art. 6(1)(a) GDPR), which you can withdraw at any time with effect for the future by revoking the location permission in your device settings. No location processing occurs unless you use the running feature.
- Calendar: If you enable it, the app can access your device calendars (e.g., iCloud, Google) to display and edit events. Calendar data generally remains on your device.
- Camera, photos, and microphone: For profile and community photos, the AI Coach photo feature, and the voice feature, the app accesses your camera, photo library, and microphone after your approval. Audio for speech recognition is processed as described in Section 6.
- System push notifications: In addition to web push (Section 7), the native apps use the operating system's push services (Apple Push Notification service or Firebase Cloud Messaging) to deliver reminders.
Where health- or location-related data is synchronized with your account to display your history, it is stored with our processor Supabase (EU, Frankfurt).
3.9 Community Features (User-Generated Content)
When you use the community feature, we process the content you post (posts, comments, photos), your display name and profile picture, and associated metadata (e.g., group/thread association, timestamps). This content is visible to other members of the respective group. The legal basis is contract performance (Art. 6(1)(b) GDPR) or your consent through active participation.
When you report content or users, we process the report (reported content, user ID, reason) and the resulting moderation decisions in order to keep the community safe. The legal basis is our legitimate interest in the security of the platform and compliance with our obligations under the Digital Services Act (Art. 6(1)(f) GDPR).
Community content is stored as long as the respective group or your account exists. After you delete your account, your community content is removed or anonymized; reported content and related moderation records may be retained for a limited period for documentation and to comply with legal obligations.
4. Purposes and Legal Bases (Art. 6 & 9 GDPR)
- Contract performance (Art. 6(1)(b) GDPR): Provision of app functions, synchronization, progress tracking, and account management.
- Legitimate interest (Art. 6(1)(f) GDPR): Security, fraud and abuse prevention, error analysis.
- Consent (Art. 6(1)(a) GDPR): Push notifications (revocable at any time).
- Explicit consent (Art. 9(2)(a) GDPR): If you voluntarily enter health-related or other sensitive data in free text fields (journal/AI).
5. AI-Supported Functions (AI Coach)
The AI Coach is optional. If you use it, data is transmitted to third-party AI services in order to generate responses.
5.1 Data Transmitted to AI Providers
- The text of your AI chat messages
- Your name (for personalization)
- Routine context (current day, streak, level, language, time of day)
- Today's tasks (titles only; completion status is not transmitted)
5.2 Data NOT Transmitted to AI Providers
- Journal entries (unless you share them in the chat)
- Gratitude logs (unless you share them in the chat)
- Personal notes
- Email address and full account data
- Payment information
5.3 No Intended Processing of Sensitive Health Data
The AI Coach is not intended to process special categories of personal data within the meaning of Art. 9 GDPR. Users are expressly requested not to enter sensitive health data (e.g., diagnoses, medical histories, medication details, or mental health conditions) into the AI chat. If users nevertheless provide such information, they do so at their own responsibility.
5.4 AI Providers (Currently)
- Groq – AI inference and audio transcription
- Cerebras – AI inference
- Google Gemini – AI language model
- OpenRouter – AI routing (including models such as DeepSeek)
- OpenAI – AI inference and speech/audio processing
We may change providers. Significant changes will be reflected in this Privacy Policy.
5.5 Legal Basis
Processing takes place on the basis of your consent (Art. 6(1)(a) GDPR), which you give by first using the optional AI Coach. You may withdraw this consent at any time with effect for the future by no longer using the AI Coach; the lawfulness of processing carried out until withdrawal remains unaffected.
5.6 Responsibility for AI-Generated Content
AI-generated content is provided solely for general motivation and informational purposes. Any decisions, actions, or omissions based on AI output are solely the responsibility of the user.
5.7 No Warranty for Content
There is no claim to accuracy, completeness, or timeliness of content provided by the app or the AI Coach.
5.8 International Data Transfers
The AI providers listed in Section 5.4 (Groq, Inc., Cerebras Systems, Inc., Google LLC / Google Gemini, OpenRouter, Inc., OpenAI, L.L.C.) process data in the USA. We base these transfers on the European Commission's Standard Contractual Clauses (Art. 46(2)(c) GDPR). You may avoid data transfers in connection with the AI Coach by not using this function.
6. Audio Transcription (Voice → Text)
For speech recognition, the app primarily uses on-device processing by the operating system; in that case, the audio does not leave your device. In certain cases or as a fallback, audio is transmitted to Groq, Inc. (USA) for transcription. We do not permanently store raw audio on our servers. The provider may temporarily store logs.
Processing is carried out solely for the purpose of converting speech into text within the app.
7. Push Notifications (Web Push)
Push notifications are optional and require your consent.
If activated, we store push subscription data (endpoint, keys) to send routine reminders and re-engagement notifications. We also store notification settings (e.g., time zone, time, weekly schedule, on/off). Push delivery uses browser/OS push services.
- Legal basis: Consent (Art. 6(1)(a) GDPR)
- Withdrawal: You may disable push notifications at any time in your browser/device settings
8. Contact Form
If you use the contact form, we process your name, email address, and message for the purpose of handling your request (Art. 6(1)(b) or (f) GDPR). Emails are sent via Resend. The data is not stored in our database but retained in our support mailbox as long as necessary for processing.
9. Payment Processing (Paddle)
Purchases currently take place exclusively via the Apple App Store or Google Play (see the following paragraph). For any purchases made through the website, payments, invoicing, and refunds are processed by Paddle as Merchant of Record. Paddle processes payment data independently. We only receive purchase-related information required to activate access.
In the native apps for iOS and Android, purchase and payment processing take place via the respective app store operator (Apple App Store or Google Play); their payment and privacy terms apply. To manage entitlements (unlocking premium content), we use the processor RevenueCat. Here too, we only receive the purchase-related information required to activate access; full payment data (e.g., card details) is processed exclusively by Apple or Google.
10. Hosting and Processors
- Supabase (EU, Frankfurt) – Database and authentication
- Vercel, Inc. (USA) – Web hosting and CDN
- Resend, Inc. (USA) – Email delivery (contact form, see Section 8)
- Google Ireland Ltd. / Google LLC (EU/USA) – Sign-in via Google Sign-In and push notifications on Android via Firebase Cloud Messaging
- Apple Inc. (USA) – Push notifications on iOS via the Apple Push Notification service
- RevenueCat, Inc. (USA) – Management of in-app purchase entitlements (see Section 9)
- AI providers (USA) – see Sections 5.4 and 5.8
- Paddle.com Market Limited – Payment processing for any website purchases (see Section 9)
Where required, we have data processing agreements pursuant to Art. 28 GDPR with our processors. Where processing occurs outside the EU/EEA – in particular in the USA – we base the transfer on the European Commission's Standard Contractual Clauses (Art. 46 GDPR).
11. Cookies and Local Storage (§ 25 TDDDG)
The app uses technically necessary storage mechanisms (cookies/local storage) for login sessions and offline functionality. No tracking, marketing cookies, or analytics tools are currently used.
12. Retention and Deletion
- Data retention duration: App data (profile, routines, journal) is stored as long as your account exists.
- Deletion upon account termination: If you delete your account, we remove your data from active systems without undue delay.
- Technical logs and backups: Data may temporarily remain in backups or log files for system security and abuse prevention. These are overwritten or deleted in regular cycles.
- Statutory retention obligations: Regardless of account deletion, we are legally required to retain certain data (particularly invoice and payment data processed via Paddle) for up to 10 years in accordance with tax and commercial law.
- Self-deletion: Content entered by you (e.g., journal entries or tasks) can be deleted by you at any time within the app.
13. Your Rights
You have the following rights:
- Access (Art. 15 GDPR)
- Rectification (Art. 16 GDPR)
- Erasure (Art. 17 GDPR)
- Data portability (Art. 20 GDPR)
- Restriction of processing (Art. 18 GDPR)
- Objection (Art. 21 GDPR)
Withdrawal of consent: You may withdraw consent (e.g., for push notifications or sensitive data) at any time with effect for the future (e.g., by deleting entries or adjusting settings). The lawfulness of processing carried out on the basis of consent until withdrawal remains unaffected (Art. 7(3) sentence 2 GDPR).
The exercise of your rights may be restricted in individual cases within the limits of statutory provisions, particularly where necessary to protect overriding legitimate interests, system security, or abuse prevention.
Automated decision-making within the meaning of Art. 22 GDPR does not take place.
Contact: support@sioly.app
14. Right to Lodge a Complaint / Supervisory Authority
Under Art. 77 GDPR, you have the right to lodge a complaint with a supervisory authority if you believe that the processing of your personal data violates data protection law.
Competent authority:
The Hamburg Commissioner for Data Protection and Freedom of Information
Ludwig-Erhard-Str. 22, 7th floor
20459 Hamburg, Germany
This Privacy Policy primarily addresses users within the European Union and is based on the General Data Protection Regulation (GDPR). For users outside the EU, personal data is processed in accordance with GDPR standards. Where additional national data protection laws apply, these apply additionally without excluding the applicability of the GDPR.
15. This Website (sioly.app)
The sections above cover the app. This one covers the website sioly.app itself — what happens when you open a page here.
Hosting and server logs. The website is operated by Vercel Inc. (340 S Lemon Ave #4133, Walnut, CA 91789, USA) as our processor and served from the European location Frankfurt am Main. When a page is requested, Vercel processes the technically necessary connection data: IP address, time of the request, the address requested, the amount of data transferred, and the browser and operating system identifier. This data is required to deliver the page and keep it secure; the legal basis is Art. 6 (1) (f) GDPR. A data processing agreement is in place; for transfers to the USA the European Commission's standard contractual clauses apply.
No tracking, no analytics, no advertising cookies. This website sets no analytics or advertising cookies, embeds no analytics services and loads nothing from third-party servers. Fonts, images and icons are all served from this domain, so opening a page does not cause your browser to contact anyone else.
Contact form. If you use the form at sioly.app/contact, we process what you enter: your name, your email address and your message. We need all three to answer you. Delivery to our mailbox is handled by Resend (Plus Five Five, Inc., 2261 Market Street #5039, San Francisco, CA 94114, USA) as our processor; a data processing agreement is in place and the standard contractual clauses apply to the transfer to the USA. Your IP address is processed while sending, solely to limit how many messages can be sent per hour — without that the form would be an open relay for spam. The legal basis is Art. 6 (1) (b) GDPR where your message concerns an existing or intended contract, otherwise Art. 6 (1) (f) GDPR. Your message stays in our mailbox for as long as it takes to answer it and handle any follow-up; ask us and we delete it immediately.
One technical cookie. A cookie is set only after you submit the form, and it contains nothing but the time of your last message. It stops the same form being submitted repeatedly within a minute, expires after 60 seconds, and is not used to recognise you. Under § 25 (2) TDDDG it is strictly necessary and needs no consent.
Your rights from the sections above — access, rectification, erasure, restriction, portability, objection and complaint to a supervisory authority — apply to this processing in exactly the same way.
This Privacy Policy is effective as of July 20, 2026; section 15 as of 24 August 2026.