Oryn

Privacy Policy

Last updated 14 August 2026

Oryn is a personal health app. It only works if you trust it with sensitive information, so this policy describes what is actually stored, where it goes, and how long it stays — in plain language, matching what the software does.

Oryn is built and operated by an independent developer ("we", "us"). This policy covers the Oryn iPhone app and the Oryn service, which is reachable at oryn.ink.

The short version

What we collect

Account information

Depending on how you sign in, we store some combination of: an email address, a username, a display name, a password verifier (hashed with Argon2 — never the password itself), and an opaque account identifier provided by Apple or Google when you use Sign in with Apple or Google Sign-In. We also store your time zone, so a "day" in the app matches your day. Name and email are optional; Oryn works without them.

If you subscribe to Oryn Plus, we store the subscription's state as Apple reports it: the product, its status and expiry, and Apple's transaction identifier. Never your payment details — your card and billing address are Apple's alone, and no part of them reaches us. The record is included in your data export and deleted with your account.

Health data

Oryn reads a deliberately narrow set of signals — only what the product actually uses:

SignalWhere it can come from
Sleep durationApple Health, Google Health
StepsApple Health, Google Health
Resting heart rateApple Health, Google Health
Heart rate variabilityApple Health, Google Health

Alongside each measurement we keep the context needed to interpret it honestly: which source reported it, the time range it covers, and — when two sources disagree — a record of how the merged value was decided.

These four carry the daily read. From Apple Health, Oryn additionally asks for read-only access to the categories it can show you in detail — activity and energy, heart, recovery, sleep, respiratory, body, mobility, hearing, mindfulness, cycle, nutrition, and symptoms — and receives only the types you allow on Apple's own permission screen. Oryn never requests write access to Apple Health.

What you tell us yourself

Oryn asks one question in the evening: how the day was on you. If you answer, we store the day it refers to, the level you chose on a five-word scale, and up to three optional tags for what shaped it (work, people, sleep, body, money, news, or something else). Nothing else — there is no free-text note.

This is special-category data under the GDPR: it concerns your health, and you supplied it deliberately. We process it on the basis of your explicit consent, given by answering, and you can withdraw it by deleting your account. Answering is never required — Oryn works without it, and a day you skip stays blank rather than being estimated.

It is included in full in your data export, deleted with your account, and never used for advertising or marketing. We keep it apart from what your devices measure and never fold one into the other: what you said is never used to change what the app reports your body did.

Written explanations (off unless you turn them on)

Oryn can put a short written explanation next to your day, produced by Google's Gemini model. This is the only feature that sends anything about you outside our servers, it is off until you explicitly turn it on, and you can turn it off again at any time.

What we send is deliberately not your measurements. It is the shape of a day: the state Oryn read (for example "strained"), how confident that reading is, and which signals sat above or below your own usual range — in words, from a fixed list we wrote. It contains no numbers, no dates, no device names, no account identifier, and no name or email. A typical message is: state: strained; confidence: high; Heart rate variability: below your usual range.

If you have answered the evening question, the word you chose — Heavy, Tense, Steady, Light or Clear — is included as well, marked as your own: the person called the day: Tense. The word only: never the tags you picked for what shaped the day, and never your answer as a number.

With the same permission, Oryn can also describe your week the same way, for the summary at the top of Insights: the run of daily states, any signal that has sat outside your own usual range — in the same fixed words — and, if you answered the evening question, the word you typically chose. Nothing more: no percentages, no counts, no numbers of any kind.

If you use Ask Oryn, the questions you type — and, for a follow-up, the answers carried back with them — are sent as well, together with the sentences the app already shows you: the day's reading, the week's shape, and any pattern or drift sentence on your Insights screen, including the figures those sentences carry. Your questions and the answers are not stored on our servers and never reach a log; the conversation lives on your phone for the session and ends with it. The only record kept is a daily count, so Ask Oryn has a ceiling.

We never send a heart rate, a sleep duration, a step count, or any other measured value. Whatever the model writes is checked before you see it: anything containing a figure we did not supply is discarded rather than shown, so it cannot invent a measurement about you.

Google processes this under their API terms. We use a paid tier configured so that what we send is not used to train their models. If we ever change what leaves our servers, this section changes with it and your permission stops counting until you have read the new description and agreed to it again.

Turning this off stops it immediately. Explanations already written are stored so the same day does not get re-described every time you open the app; they are deleted with your account and are included in your data export.

Notifications

Oryn sends at most one notification a day — counted across everything it can send, not per kind — and only the kinds you turn on; each has its own switch and each is off until you do. There are two: an afternoon nudge on a day that is asking something of you, and a Saturday-morning note that your week is summed up in the app. Turning either on stores an Apple push token for that device, which is the address Apple uses to reach your phone; we also record, for each day, whether a notification was sent, skipped, or failed, and a short reason. That record is what makes "at most one a day" something we can guarantee rather than intend.

The notification itself contains no health information. Each kind is one fixed sentence, the same every time — it never names a measurement, a number, or how your day or week is going. Whatever there is to say is in the app, behind your own passcode, not on your lock screen.

Push tokens are deleted when you sign out, when you delete your account, and when Apple tells us a token is no longer valid. Turning notifications off stops them immediately. You can also revoke them entirely in iOS Settings, which we cannot override.

Connection and operational records

To keep syncing reliable we store records of your connected devices and integrations, the status and timing of sync runs, and de-duplication receipts that stop the same upload being counted twice. We keep a privacy audit log of sensitive actions such as export and deletion requests; entries in that log identify you only by a one-way hash, never by your name, email, or account identifier.

We also record what goes wrong: failed syncs, records a source sent that we could not interpret, and background work that gave up. These records hold identifiers and error codes so we can find the problem — never a measurement. Separately, and unlike the privacy audit log above, we keep an operations log of everything our own staff do in the support tools, which does name the account that was looked at. That is the deliberate trade described under Who else sees your data.

What we do not collect

We do not collect advertising identifiers, location history, contacts, or browsing behaviour, and we ask for no health category beyond those listed above. This website sets no cookies and loads no external fonts, scripts, or trackers.

How your sources are connected

Apple Health

Apple Health data never leaves your iPhone without your explicit permission, granted per data type through Apple's own permission screen. You choose which signals Oryn may read, and you can change or revoke that at any time in the iOS Health app. Data obtained through Apple HealthKit is used solely to provide the features described here. It is never used for advertising or marketing, never sold, and never shared with third parties. It is not used for any purpose other than your own health insights.

Google Health

Connecting Google Health is optional; Oryn works with Apple Health alone. If you do connect it, Oryn requests read-only access to exactly three scopes, each tied to a specific feature:

ScopePurpose
googlehealth.sleep.readonlyRead sleep duration for your daily view and sleep baseline.
googlehealth.activity_and_fitness.readonlyRead daily step counts, and de-duplicate movement counted by more than one device.
googlehealth.health_metrics_and_measurements.readonlyRead resting heart rate and heart rate variability for your recovery baseline.

We never request write access, and Oryn cannot modify anything in your Google account. Access tokens are encrypted before they are stored, and you can disconnect at any time — from inside Oryn, or from your Google Account permissions page. Disconnecting stops future syncing; data already synced is removed when you delete your account or the integration.

Limited Use. Oryn's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. Specifically, data obtained through these scopes is used only to provide and improve the features described in this policy; it is never transferred to others except as required to operate the Service, to comply with applicable law, or as part of a data export you request; it is never used for advertising; and no human reads it except with your explicit consent, for security purposes, or where required by law.

How we use it

Your data is used to operate the product you asked for and nothing else: to merge signals across sources, build your daily view and personal baselines, explain how a merged value was reached, keep syncing working, and secure your account. We do not profile you for advertising, and we do not use your health data to train machine learning models.

How it is protected

No system is perfectly secure, and we will not pretend otherwise. We design to limit what an incident could expose.

How long it is kept

DataRetention
Account and health dataUntil you delete your account
Data export archives24 hours, then automatically revoked and erased
Push token for a deviceUntil you sign out, delete your account, or Apple reports it invalid
Record of notifications sent or skippedDeleted with your account
Privacy audit log (hashed)90 days
Operations log of staff access1 year; the account identifier is removed as soon as the account is deleted
Error recordsDeleted with your account; resolved ones are cleared after 90 days
Live data after a deletion requestRemoved within 24 hours
Encrypted backups after deletionExpire on their own schedule within 30 days

Your choices

Who else sees your data

We do not sell, rent, or trade your data, and we do not share health data with advertisers, data brokers, or analytics providers. Your data is processed by us and by the infrastructure providers that host the servers and the database on our behalf, under their standard confidentiality obligations. Apple and Google act as the sources you choose to connect and receive only what is needed to authenticate you and read the signals you approved. We may disclose information if we are legally compelled to, and we will not do so silently unless the law forbids telling you.

Our own staff

Oryn has internal support tools, and through them our staff can see your account, your connected sources, the errors your account has hit, and your health measurements themselves — the same values the app shows you, and the original records your phone or Google uploaded.

We would rather not have that access, and we thought about withholding it. But when someone writes to say "my sleep has been missing since Tuesday", the honest answer requires looking at what actually arrived and what the app did with it. A support tool that could not see the data could not answer the question.

So the access exists, and we constrain it instead of pretending it does not:

What the tools cannot do is quietly change your measurements. Merged results and personal baselines are protected against modification by the database itself; the only way to correct a wrong value is to run the calculation again over the original records, and the original records are what your source sent us.

Staff can also block an account, which stops it being used but deletes nothing and can be undone, and can start the same deletion you can start yourself — which cannot be undone. If we block your account, we will tell you why.

Children

Oryn is not intended for anyone under 16, and we do not knowingly collect data from children. If you believe a child has created an account, write to privacy@oryn.ink and we will delete it.

Changes

If this policy changes in a way that materially affects you, we will update the date at the top and notify you in the app before the change takes effect. Continuing to use Oryn after that means the updated policy applies.

Contact

Questions, requests, or concerns about privacy: privacy@oryn.ink