Nyra
Privacy Notice
Last updated: 30 September 2026 · Translation — the German version governs
1. Controller
The controller for the processing of your personal data within the meaning of Art. 4(7) GDPR is:
Bytenium UG (haftungsbeschränkt)Desenißstraße 30
22083 Hamburg, Germany
Represented by: Dr. Malte Harland, Managing Director
Email: datenschutz@nyra-app.de
Full provider details are in the Impressum. We have not appointed a data protection officer; we are not required to under § 38 BDSG.
2. What Nyra is — and what it is not
Nyra helps parents organise and structure their new everyday life: rhythm, daily planning, and coordinating care between several people.
Nyra is not a health app and not a medical device. We make no diagnoses, give no medical advice, and do not assess your child's health. We treat the sleep and wake times you record as scheduling data about your household, not as health data within the meaning of Art. 4(15) GDPR. We therefore do not ask for special categories of personal data under Art. 9 GDPR and do not derive any such data. As a precaution we treat just one optional feature differently: the titles of your own appointments that you attach to a care request with your explicit consent may, in an individual case, allow such data about you to be inferred (§ 13).
3. What data we process
- Account data: email address, password (only ever as a cryptographic hash), optionally your name, time zone, language setting, and email confirmation status.
- Child profile: name and — optionally — date of birth. You may leave both blank; the date of birth only improves the prediction.
- Routine data: timestamps of the sleep and wake times you record, who recorded them, and any periods you mark as unavailable for sleep.
- Prediction data: the forecast of the next sleep window computed from those timestamps.
- Household and care data: invitations and access grants to other caregivers (their email address), care shifts with their time span, and — for open invitation links — the display name a stand-in enters for themselves.
- Notification data: your device's push token, a device identifier, and a record of notifications sent.
- Calendar data (only if you connect a calendar): events from your device calendar and/or your Google Calendar, which the app reads to show them next to the daily routine. We additionally cache these events, encrypted, on your own device to speed up loading; see § 7 for how long and when we delete them. If you choose “Create appointment” in the app, the app creates the appointment you enter — title, start and end, or all-day — in the calendar you selected for it. Nyra never edits or deletes existing calendar entries, including those created through Nyra.
- Classification of calendar entries (shared within your household, on by default): for appointments you or a Guardian in your household classify, and for remembered buffer times: a one-way identifier of the appointment, the classification chosen, for “Stays awake” also the baby it applies to, and the times of last use and last change; details in § 12.
- Appointment titles in care requests (only with your consent): the titles of your own appointments that the app attaches to a request to a Guardian, together with when you gave your consent and to which version of the consent text; details in § 13.
- Location data (only if you use the place search): the coordinates searched, and entries other users contribute about changing facilities.
- Subscription data: product, purchase and expiry dates, and the App Store's pseudonymous transaction identifier. We never see payment details.
- Error and diagnostic data: error messages and technical context, used to fix faults – including the app version and build number, the platform (iOS or Android), the operating system version, the device model (where provided by your device), and the screen shown when the error occurred.
- Enquiries to us: if you email us, your email address, the content of your message, and any information you include in it.
4. Purposes and legal bases
| Purpose | Legal basis |
|---|---|
| Account, sign-in, recording and displaying the daily routine, prediction, household sharing, care shifts, classifying calendar entries within the household (§ 12), handling the subscription | Art. 6(1)(b) GDPR — performance of the user contract |
| Calendar connection, including creating appointments at your request, push notifications, Alexa linking | Art. 6(1)(a) GDPR — your consent, withdrawable at any time with future effect |
| Transmitting appointment titles with care requests to Guardians (§ 13) | Art. 6(1)(a) GDPR and — as a precaution — Art. 9(2)(a) GDPR — your separate, explicit consent, withdrawable at any time with future effect |
| Operation, security, abuse prevention, error diagnosis | Art. 6(1)(f) GDPR — legitimate interest in a stable and secure service |
| Answering your enquiries by email, including requests about your rights (§ 9) | Art. 6(1)(c) GDPR where you exercise your rights under § 9; Art. 6(1)(b) GDPR where your enquiry concerns the user contract; otherwise Art. 6(1)(f) GDPR — legitimate interest in answering your enquiry |
| Compliance with statutory retention and record-keeping duties | Art. 6(1)(c) GDPR |
5. Recipients
We use service providers that act for us as processors under Art. 28 GDPR — with the exception of Apple, which is its own controller for the payment transaction. Complete list:
| Recipient | Purpose | Location |
|---|---|---|
| Microsoft (Azure, Microsoft 365) | Hosting, database, backups, operational monitoring; email mailboxes for contact and data-protection requests | EU/EEA (hosting: Netherlands) |
| Azure Communication Services | Sending system emails | EU/EEA |
| Google (Sign-In) | Signing in with a Google account | USA |
| Google (Calendar) | Only if you connect a calendar: reading your events and the list of your calendars. If you choose a Google calendar as the target when creating an appointment (§ 3), the app asks the first time, in Google's consent screen, for an additional permission to create events, and then transmits the new appointment — title, start and end, or all-day — to that calendar. Reading and creating take place directly between your device and Google, without our servers being involved. In addition: if someone presses the “Add to Google Calendar” button on a care shift's public hand-off page and confirms it in Google's own consent screen, their own browser transmits the first name(s) of the child or children plus the shift's start and end time directly to Google — without our servers being involved and without us ever receiving the access token used. Without that confirmation, no transmission takes place. This applies even to people with no Nyra account of their own who hold nothing but the shift link. | USA |
| Google (Places) | Place search. The searched coordinates are transmitted, not your IP address | USA |
| Expo / EAS | App updates, push notification delivery | USA |
| Apple | Seller of the subscription, push notification delivery | USA |
| Amazon | Alexa skill, only if you link it | USA |
| RevenueCat | Managing subscription status | USA |
To RevenueCat we transmit only a pseudonymous user identifier and App Store transaction data. No name, no email address, no date of birth, no location data and nothing about your child is transmitted.
We use the events and calendar lists the app receives through Google APIs only for the features described in this notice. Nyra's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Transfers to third countries
The recipients marked USA in § 5 process data outside the EU/EEA. The basis for these transfers is the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) under Art. 46(2)(c) GDPR, supplemented by additional safeguards such as encryption and data minimisation. We do not rely on an adequacy decision and specifically claim no certification under the EU-US Data Privacy Framework. Despite these measures an equivalent level of protection cannot be guaranteed in every case; in particular, US authorities may assert access rights under their law. All core data (account, child, routine data), the classification of calendar entries (§ 12), and appointment titles you share under § 13, is stored exclusively in the EU.
7. Retention
- Account and profile data are kept for as long as your account exists.
- Routine data is kept for around 21 days in live operation. After that we move it into a pseudonymised archive, where it is carried without a name, without an exact date of birth, and only with a coarsened age, in order to improve the prediction.
- Care shifts are kept for around 400 days, so that recurring stand-ins can still be suggested.
- Calendar data is cached only locally, on your own device — AES-256 encrypted, with the key held in your operating system's secure keystore — for at most 24 hours. The appointments themselves — title, time and calendar name — we never transmit to our servers and never sync between your devices. Exceptions are the titles you attach to a care request with your consent (§ 13), and the pseudonymous classification of individual appointments you share within your household by default (§ 12). The cache is erased immediately when you disconnect the calendar connection, when your operating system or Google revokes access, when you sign out, or when you delete your account. Appointments you create through Nyra exist only in your calendar; we keep no separate reference to them.
- The classification of calendar entries and buffer times shared within your household is deleted automatically once it has gone 12 months without use or change, immediately when the account of the baby profiles' owner is deleted, or when you bulk-delete it for your household in Settings; details in § 12.
- Shared appointment titles are deleted at the latest by the daily deletion routine once the end of the care shift concerned lies more than 30 days in the past, and in many cases earlier (§ 13).
- Error and diagnostic data is deleted regularly after a short period. App version (including build number) and platform are the exception: like routine data, we carry these on indefinitely in an archive — as coarse facts that are not personal data in their own right and contain no diagnostic detail — for example to track error rates by app version.
- Subscription data is deleted with the account; statutory retention duties remain unaffected.
- Email enquiries are deleted once they have been fully dealt with, unless statutory retention or record-keeping duties require otherwise.
- Backups of our database are kept for 7 days. Until a backup has expired, it may contain data we have already deleted in live operation.
8. Deleting your account
You can delete your account in the app at any time. We then remove your identifying details, delete your subscription data and the customer record at RevenueCat, and destroy the key that links the pseudonymised archive to you. After that, no archive entry can be attributed to you or your child.
There are two limits we cannot cross, and we state them openly:
- You must cancel your subscription yourself in the App Store. We cannot technically end an Apple subscription. Deleting your Nyra account does not end it.
- Apple's purchase records are outside our reach and are subject to Apple's own and to statutory retention periods.
9. Your rights
You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). You may withdraw any consent you have given at any time with future effect under Art. 7(3) GDPR.
To do so, contact datenschutz@nyra-app.de.
Independently of this, you may lodge a complaint with a supervisory authority under Art. 77 GDPR. The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information.
10. Automated processing
Nyra automatically computes a forecast of the next sleep window from the timestamps you record. This forecast is a planning suggestion. It has no legal effect, does not similarly significantly affect you, and in particular is not an assessment of your child. No automated decision-making within the meaning of Art. 22(1) GDPR takes place.
11. Use by adults
Nyra is intended for adults. Only people who have reached the age of 18 may create an account. Information about a child is entered exclusively by those with parental responsibility; the child does not use the service and does not create an account.
12. Your classification of calendar entries (shared within your household)
When you classify a calendar entry in the app — “Sleeps there”, “Stays awake”, “Needs cover” or “Doesn't apply” — or set a buffer time for it, Nyra shares that classification with your household's Guardians by default: the owner of the baby profiles and the people they have invited. Stand-ins without permanent access do not receive it. This way, not every Guardian has to classify the same appointment separately.
- What data: on our servers we do not store the appointment itself, only a one-way identifier your device derives from the appointment's unique identifier (iCalUID) or — if that is missing — its normalised title (technically: HMAC-SHA256 keyed with a secret that applies only to your household and is held encrypted with us); together with the classification chosen or the remembered buffer time, for “Stays awake” also the baby it applies to, and the times of the last change and last use. The title, time and the calendar's own name never leave your device for this (§ 7) — the exception remains appointment titles you separately share under § 13.
- Effect on the prediction: if you choose “Stays awake”, the app stores a period server-side during which, by your own classification, no sleep is expected, linked to the identifier of that classification; if you change the classification, the app removes that period again. When reconciling between your devices, the app transiently transmits the start and end times of the classified appointments for this purpose.
- Recipients: your household's Guardians — not stand-ins without permanent access, and not third parties.
- Legal basis: Art. 6(1)(b) GDPR — performance of the user contract, since coordinating care between Guardians is part of the contract (§ 4).
- Default setting and opting out: sharing is on by default. You can turn it off for yourself at any time under Settings → Calendar (“Share answers with household”); after that, your classifications and buffer times stay on your device only (§ 14).
- Storage location: our servers at Microsoft Azure in the EU (Netherlands), see § 5.
- Deletion: we delete a classification automatically once it has gone 12 months without change or use. If you, as the owner of the baby profiles, delete your account, we destroy the household-specific key at the same time; after that, no stored identifier can be attributed to an appointment any longer. You can also bulk-delete all classifications and buffer times of your household in Settings.
- Backups: deleted classifications may still be contained in backups of our database until these expire after 7 days (§ 7).
13. Appointment titles in care requests (only with your consent)
When you ask a Guardian to take on a care shift, the app can attach the titles of your own appointments in that time span to the request. Guardians are the people with permanent access to your household's baby profiles: the profiles' owner and the people the owner has invited. This feature is off by default. Nyra uses it only if you agree to it separately and explicitly — in the prompt shown the first time a request would contain appointment titles, or with the switch under Settings → Guardians. If you decline, the request is sent without titles; you suffer no other disadvantage. The app remembers your refusal on this device and does not ask again; you can agree later at any time with the switch.
- What data: the titles of those of your appointments from your connected device calendar or Google Calendar for which you chose “Needs cover” and which fall within the requested care shift — at most five titles of at most 200 characters each. We transmit no other information from your calendar.
- When not: we transmit no titles for requests made through an open invitation link, for requests to people who are not Guardians, or when you take on a care shift yourself.
- Purpose: to let the person you ask see what you need care for, so that they can decide on your request.
- Recipients: the titles are shown to the Guardian you ask. We transmit them only to that Guardian and to your own app. The other Guardians of your household, stand-ins without permanent access — including anyone who takes on a care shift through an open invitation link — and third parties never receive the titles. The titles are part of neither push notifications nor a care shift's public hand-off page.
- Storage location: our servers at Microsoft Azure in the EU (Netherlands), see § 5.
- Deletion: we delete a care shift's titles as soon as the person asked declines the request, the care shift is released or cancelled, you ask someone else (only the newly attached titles then apply), the person asked loses access to your household, you or the person asked delete the account, or you withdraw your consent. Independently of this, a daily deletion routine removes the titles of every care shift whose end lies more than 30 days in the past.
- Backups: titles that have already been deleted may still be contained in backups of our database until these expire after 7 days (§ 7).
- On the recipients' devices: the app caches the content it last loaded, including titles received, AES-256 encrypted on the device concerned, for at most 24 hours (§ 14). After a deletion on our servers, the next refresh replaces this copy; until then it may still contain the titles.
- Legal basis: your consent under Art. 6(1)(a) GDPR. Because the title of one of your own appointments may, in an individual case, allow special categories of personal data about you to be inferred — a doctor's appointment, for instance, about your health — we obtain the consent, as a precaution, also as explicit consent under Art. 9(2)(a) GDPR. Nyra does not analyse the content of appointment titles and draws no conclusions from them.
- Record of consent: for as long as your consent stands, we store when you gave it and to which version of the consent text; we delete this record when you withdraw your consent or delete your account.
- Withdrawal: you can withdraw your consent at any time with future effect by turning off the switch under Settings → Guardians. We then at the same time delete every appointment title you have already attached to requests; new requests contain no titles until you agree again. The lawfulness of processing carried out before the withdrawal remains unaffected.
15. Changes to this notice
We update this privacy notice when the service or the legal situation changes. The version published on this page is the applicable one; the date shown above indicates its current status.