Nyra

Privacy Notice

Last updated: 30 September 2026 · Translation — the German version governs

This is a translation provided for convenience. The German version is the legally binding one; in the event of any discrepancy, the German text governs.

1. Controller

The controller for the processing of your personal data within the meaning of Art. 4(7) GDPR is:

Bytenium UG (haftungsbeschränkt)
Desenißstraße 30
22083 Hamburg, Germany
Represented by: Dr. Malte Harland, Managing Director
Email: datenschutz@nyra-app.de

Full provider details are in the Impressum. We have not appointed a data protection officer; we are not required to under § 38 BDSG.

2. What Nyra is — and what it is not

Nyra helps parents organise and structure their new everyday life: rhythm, daily planning, and coordinating care between several people.

Nyra is not a health app and not a medical device. We make no diagnoses, give no medical advice, and do not assess your child's health. We treat the sleep and wake times you record as scheduling data about your household, not as health data within the meaning of Art. 4(15) GDPR. We therefore do not ask for special categories of personal data under Art. 9 GDPR and do not derive any such data. As a precaution we treat just one optional feature differently: the titles of your own appointments that you attach to a care request with your explicit consent may, in an individual case, allow such data about you to be inferred (§ 13).

3. What data we process

  • Account data: email address, password (only ever as a cryptographic hash), optionally your name, time zone, language setting, and email confirmation status.
  • Child profile: name and — optionally — date of birth. You may leave both blank; the date of birth only improves the prediction.
  • Routine data: timestamps of the sleep and wake times you record, who recorded them, and any periods you mark as unavailable for sleep.
  • Prediction data: the forecast of the next sleep window computed from those timestamps.
  • Household and care data: invitations and access grants to other caregivers (their email address), care shifts with their time span, and — for open invitation links — the display name a stand-in enters for themselves.
  • Notification data: your device's push token, a device identifier, and a record of notifications sent.
  • Calendar data (only if you connect a calendar): events from your device calendar and/or your Google Calendar, which the app reads to show them next to the daily routine. We additionally cache these events, encrypted, on your own device to speed up loading; see § 7 for how long and when we delete them. If you choose “Create appointment” in the app, the app creates the appointment you enter — title, start and end, or all-day — in the calendar you selected for it. Nyra never edits or deletes existing calendar entries, including those created through Nyra.
  • Classification of calendar entries (shared within your household, on by default): for appointments you or a Guardian in your household classify, and for remembered buffer times: a one-way identifier of the appointment, the classification chosen, for “Stays awake” also the baby it applies to, and the times of last use and last change; details in § 12.
  • Appointment titles in care requests (only with your consent): the titles of your own appointments that the app attaches to a request to a Guardian, together with when you gave your consent and to which version of the consent text; details in § 13.
  • Location data (only if you use the place search): the coordinates searched, and entries other users contribute about changing facilities.
  • Subscription data: product, purchase and expiry dates, and the App Store's pseudonymous transaction identifier. We never see payment details.
  • Error and diagnostic data: error messages and technical context, used to fix faults – including the app version and build number, the platform (iOS or Android), the operating system version, the device model (where provided by your device), and the screen shown when the error occurred.
  • Enquiries to us: if you email us, your email address, the content of your message, and any information you include in it.

4. Purposes and legal bases

PurposeLegal basis
Account, sign-in, recording and displaying the daily routine, prediction, household sharing, care shifts, classifying calendar entries within the household (§ 12), handling the subscriptionArt. 6(1)(b) GDPR — performance of the user contract
Calendar connection, including creating appointments at your request, push notifications, Alexa linkingArt. 6(1)(a) GDPR — your consent, withdrawable at any time with future effect
Transmitting appointment titles with care requests to Guardians (§ 13)Art. 6(1)(a) GDPR and — as a precaution — Art. 9(2)(a) GDPR — your separate, explicit consent, withdrawable at any time with future effect
Operation, security, abuse prevention, error diagnosisArt. 6(1)(f) GDPR — legitimate interest in a stable and secure service
Answering your enquiries by email, including requests about your rights (§ 9)Art. 6(1)(c) GDPR where you exercise your rights under § 9; Art. 6(1)(b) GDPR where your enquiry concerns the user contract; otherwise Art. 6(1)(f) GDPR — legitimate interest in answering your enquiry
Compliance with statutory retention and record-keeping dutiesArt. 6(1)(c) GDPR

5. Recipients

We use service providers that act for us as processors under Art. 28 GDPR — with the exception of Apple, which is its own controller for the payment transaction. Complete list:

RecipientPurposeLocation
Microsoft (Azure, Microsoft 365)Hosting, database, backups, operational monitoring; email mailboxes for contact and data-protection requestsEU/EEA (hosting: Netherlands)
Azure Communication ServicesSending system emailsEU/EEA
Google (Sign-In)Signing in with a Google accountUSA
Google (Calendar)Only if you connect a calendar: reading your events and the list of your calendars. If you choose a Google calendar as the target when creating an appointment (§ 3), the app asks the first time, in Google's consent screen, for an additional permission to create events, and then transmits the new appointment — title, start and end, or all-day — to that calendar. Reading and creating take place directly between your device and Google, without our servers being involved. In addition: if someone presses the “Add to Google Calendar” button on a care shift's public hand-off page and confirms it in Google's own consent screen, their own browser transmits the first name(s) of the child or children plus the shift's start and end time directly to Google — without our servers being involved and without us ever receiving the access token used. Without that confirmation, no transmission takes place. This applies even to people with no Nyra account of their own who hold nothing but the shift link.USA
Google (Places)Place search. The searched coordinates are transmitted, not your IP addressUSA
Expo / EASApp updates, push notification deliveryUSA
AppleSeller of the subscription, push notification deliveryUSA
AmazonAlexa skill, only if you link itUSA
RevenueCatManaging subscription statusUSA

To RevenueCat we transmit only a pseudonymous user identifier and App Store transaction data. No name, no email address, no date of birth, no location data and nothing about your child is transmitted.

We use the events and calendar lists the app receives through Google APIs only for the features described in this notice. Nyra's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Transfers to third countries

The recipients marked USA in § 5 process data outside the EU/EEA. The basis for these transfers is the European Commission's Standard Contractual Clauses (Implementing Decision (EU) 2021/914) under Art. 46(2)(c) GDPR, supplemented by additional safeguards such as encryption and data minimisation. We do not rely on an adequacy decision and specifically claim no certification under the EU-US Data Privacy Framework. Despite these measures an equivalent level of protection cannot be guaranteed in every case; in particular, US authorities may assert access rights under their law. All core data (account, child, routine data), the classification of calendar entries (§ 12), and appointment titles you share under § 13, is stored exclusively in the EU.

7. Retention

  • Account and profile data are kept for as long as your account exists.
  • Routine data is kept for around 21 days in live operation. After that we move it into a pseudonymised archive, where it is carried without a name, without an exact date of birth, and only with a coarsened age, in order to improve the prediction.
  • Care shifts are kept for around 400 days, so that recurring stand-ins can still be suggested.
  • Calendar data is cached only locally, on your own device — AES-256 encrypted, with the key held in your operating system's secure keystore — for at most 24 hours. The appointments themselves — title, time and calendar name — we never transmit to our servers and never sync between your devices. Exceptions are the titles you attach to a care request with your consent (§ 13), and the pseudonymous classification of individual appointments you share within your household by default (§ 12). The cache is erased immediately when you disconnect the calendar connection, when your operating system or Google revokes access, when you sign out, or when you delete your account. Appointments you create through Nyra exist only in your calendar; we keep no separate reference to them.
  • The classification of calendar entries and buffer times shared within your household is deleted automatically once it has gone 12 months without use or change, immediately when the account of the baby profiles' owner is deleted, or when you bulk-delete it for your household in Settings; details in § 12.
  • Shared appointment titles are deleted at the latest by the daily deletion routine once the end of the care shift concerned lies more than 30 days in the past, and in many cases earlier (§ 13).
  • Error and diagnostic data is deleted regularly after a short period. App version (including build number) and platform are the exception: like routine data, we carry these on indefinitely in an archive — as coarse facts that are not personal data in their own right and contain no diagnostic detail — for example to track error rates by app version.
  • Subscription data is deleted with the account; statutory retention duties remain unaffected.
  • Email enquiries are deleted once they have been fully dealt with, unless statutory retention or record-keeping duties require otherwise.
  • Backups of our database are kept for 7 days. Until a backup has expired, it may contain data we have already deleted in live operation.

8. Deleting your account

You can delete your account in the app at any time. We then remove your identifying details, delete your subscription data and the customer record at RevenueCat, and destroy the key that links the pseudonymised archive to you. After that, no archive entry can be attributed to you or your child.

There are two limits we cannot cross, and we state them openly:

  • You must cancel your subscription yourself in the App Store. We cannot technically end an Apple subscription. Deleting your Nyra account does not end it.
  • Apple's purchase records are outside our reach and are subject to Apple's own and to statutory retention periods.

9. Your rights

You have the right to access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20), and to object to processing based on legitimate interests (Art. 21). You may withdraw any consent you have given at any time with future effect under Art. 7(3) GDPR.

To do so, contact datenschutz@nyra-app.de.

Independently of this, you may lodge a complaint with a supervisory authority under Art. 77 GDPR. The authority responsible for us is the Hamburg Commissioner for Data Protection and Freedom of Information.

10. Automated processing

Nyra automatically computes a forecast of the next sleep window from the timestamps you record. This forecast is a planning suggestion. It has no legal effect, does not similarly significantly affect you, and in particular is not an assessment of your child. No automated decision-making within the meaning of Art. 22(1) GDPR takes place.

11. Use by adults

Nyra is intended for adults. Only people who have reached the age of 18 may create an account. Information about a child is entered exclusively by those with parental responsibility; the child does not use the service and does not create an account.

12. Your classification of calendar entries (shared within your household)

When you classify a calendar entry in the app — “Sleeps there”, “Stays awake”, “Needs cover” or “Doesn't apply” — or set a buffer time for it, Nyra shares that classification with your household's Guardians by default: the owner of the baby profiles and the people they have invited. Stand-ins without permanent access do not receive it. This way, not every Guardian has to classify the same appointment separately.

  • What data: on our servers we do not store the appointment itself, only a one-way identifier your device derives from the appointment's unique identifier (iCalUID) or — if that is missing — its normalised title (technically: HMAC-SHA256 keyed with a secret that applies only to your household and is held encrypted with us); together with the classification chosen or the remembered buffer time, for “Stays awake” also the baby it applies to, and the times of the last change and last use. The title, time and the calendar's own name never leave your device for this (§ 7) — the exception remains appointment titles you separately share under § 13.
  • Effect on the prediction: if you choose “Stays awake”, the app stores a period server-side during which, by your own classification, no sleep is expected, linked to the identifier of that classification; if you change the classification, the app removes that period again. When reconciling between your devices, the app transiently transmits the start and end times of the classified appointments for this purpose.
  • Recipients: your household's Guardians — not stand-ins without permanent access, and not third parties.
  • Legal basis: Art. 6(1)(b) GDPR — performance of the user contract, since coordinating care between Guardians is part of the contract (§ 4).
  • Default setting and opting out: sharing is on by default. You can turn it off for yourself at any time under Settings → Calendar (“Share answers with household”); after that, your classifications and buffer times stay on your device only (§ 14).
  • Storage location: our servers at Microsoft Azure in the EU (Netherlands), see § 5.
  • Deletion: we delete a classification automatically once it has gone 12 months without change or use. If you, as the owner of the baby profiles, delete your account, we destroy the household-specific key at the same time; after that, no stored identifier can be attributed to an appointment any longer. You can also bulk-delete all classifications and buffer times of your household in Settings.
  • Backups: deleted classifications may still be contained in backups of our database until these expire after 7 days (§ 7).

13. Appointment titles in care requests (only with your consent)

When you ask a Guardian to take on a care shift, the app can attach the titles of your own appointments in that time span to the request. Guardians are the people with permanent access to your household's baby profiles: the profiles' owner and the people the owner has invited. This feature is off by default. Nyra uses it only if you agree to it separately and explicitly — in the prompt shown the first time a request would contain appointment titles, or with the switch under Settings → Guardians. If you decline, the request is sent without titles; you suffer no other disadvantage. The app remembers your refusal on this device and does not ask again; you can agree later at any time with the switch.

  • What data: the titles of those of your appointments from your connected device calendar or Google Calendar for which you chose “Needs cover” and which fall within the requested care shift — at most five titles of at most 200 characters each. We transmit no other information from your calendar.
  • When not: we transmit no titles for requests made through an open invitation link, for requests to people who are not Guardians, or when you take on a care shift yourself.
  • Purpose: to let the person you ask see what you need care for, so that they can decide on your request.
  • Recipients: the titles are shown to the Guardian you ask. We transmit them only to that Guardian and to your own app. The other Guardians of your household, stand-ins without permanent access — including anyone who takes on a care shift through an open invitation link — and third parties never receive the titles. The titles are part of neither push notifications nor a care shift's public hand-off page.
  • Storage location: our servers at Microsoft Azure in the EU (Netherlands), see § 5.
  • Deletion: we delete a care shift's titles as soon as the person asked declines the request, the care shift is released or cancelled, you ask someone else (only the newly attached titles then apply), the person asked loses access to your household, you or the person asked delete the account, or you withdraw your consent. Independently of this, a daily deletion routine removes the titles of every care shift whose end lies more than 30 days in the past.
  • Backups: titles that have already been deleted may still be contained in backups of our database until these expire after 7 days (§ 7).
  • On the recipients' devices: the app caches the content it last loaded, including titles received, AES-256 encrypted on the device concerned, for at most 24 hours (§ 14). After a deletion on our servers, the next refresh replaces this copy; until then it may still contain the titles.
  • Legal basis: your consent under Art. 6(1)(a) GDPR. Because the title of one of your own appointments may, in an individual case, allow special categories of personal data about you to be inferred — a doctor's appointment, for instance, about your health — we obtain the consent, as a precaution, also as explicit consent under Art. 9(2)(a) GDPR. Nyra does not analyse the content of appointment titles and draws no conclusions from them.
  • Record of consent: for as long as your consent stands, we store when you gave it and to which version of the consent text; we delete this record when you withdraw your consent or delete your account.
  • Withdrawal: you can withdraw your consent at any time with future effect by turning off the switch under Settings → Guardians. We then at the same time delete every appointment title you have already attached to requests; new requests contain no titles until you agree again. The lawfulness of processing carried out before the withdrawal remains unaffected.

14. Cookies and storage on your device

Our website sets no cookies. This applies to the home page, these legal pages, and the public pages for taking over a care shift. We embed no analytics or advertising services and no content from other providers there; fonts are served from our own server. Only if you press the “Add to Google Calendar” button on a care shift's hand-off page does your browser load Google's sign-in and consent service from Google's servers (see § 5). What Google stores on your device in doing so is governed by Google's own privacy information.

The app stores information on your device and reads it back where this is technically required for the features you use:

  • Sign-in: your sign-in token, in your operating system's secure keystore, so that you stay signed in; a one-way checksum of the last signed-in account, so that the previous account's information is removed from the device when a different account signs in; and, while linking Alexa, short-lived security values that are deleted immediately after use.
  • App settings: language, calendar view, the calendars you selected, the calendar in which appointments created through Nyra are saved, whether you have declined to share appointment titles (§ 13), whether you have turned off sharing your classifications within the household (§ 12) — if turned off, additionally how you have classified appointments and the associated buffer times, stored as one-way checksums using a random value held only on your device — the person you last chose for a shift offer, and whether you have already seen a notice or dismissed an update recommendation.
  • Local copy of your data: the content the app last loaded — such as the daily routine, prediction, child profile, care shifts (including appointment titles transmitted to you under § 13), your household's classifications and buffer times (§ 12), and, if you have connected a calendar, your appointments — AES-256 encrypted with a key held in the secure keystore, so that the app starts quickly and can show content without a connection. Entries are discarded after at most 24 hours.
  • Notifications: your device's push token, a randomly generated identifier for this app installation, and the times of scheduled reminders, so that they appear even when the app is closed.
  • Pending error reports: error messages with the technical details listed in § 3 that could not yet be transmitted to our servers. They are deleted from the device once transmitted successfully.
  • Embedded components: the components for signing in with Google and for managing the subscription (RevenueCat) also store the information they need to function, such as sign-in or subscription status, on your device. App updates (Expo) are stored on your device before they are installed.

The legal basis for storing and reading this information is § 25(2) no. 2 TDDDG (German Telecommunications Digital Services Data Protection Act): it is strictly necessary for us to provide the service you have expressly requested. No consent is required for it, which is why we show no cookie banner. The processing of any personal data involved is based on the legal bases listed in § 4. We use no analytics, advertising or tracking tools, either on the website or in the app.

When you sign out or delete your account, the app removes the local copy of your data, together with the settings, scheduled reminders and push token associated with your account, from this device. General settings such as language and calendar view remain, as does the random identifier for the app installation.

15. Changes to this notice

We update this privacy notice when the service or the legal situation changes. The version published on this page is the applicable one; the date shown above indicates its current status.