Gyrus, Privacy Policy
Last updated: 28 August 2026
Gyrus is a cognitive training app. It is built so that the data it produces stays on your device, and nothing leaves it without your explicit consent. This page describes exactly what is stored, what leaves the device, and what we never collect.
Publisher: Mounir LAKHFIF
Contact: [email protected]
No account, no identity
Gyrus does not ask you to create an account. We do not collect your name, email address, phone number, contacts, photos, or precise location. We do not sell or share data with data brokers.
There is no advertising inside the app. You will never see an ad, a banner, or sponsored content in Gyrus. That does not mean we run none anywhere: Gyrus is advertised on other platforms, and the "Advertising attribution" section below describes exactly what that involves, and what you can refuse.
What stays on your device
Everything you produce while using Gyrus is written to a database on your device. None of it leaves, apart from the cases described below, each of which needs its own consent and is refused on its own:
- your self-declared goal (focus, working memory, or mental speed);
- the results of your diagnostic and of every training session: scores, accuracy, response times;
- your cognitive pillar scores and their history;
- your difficulty level for each mini-game;
- the dates on which you completed a session, which is how your streak is computed;
- your preferences: sound, haptics, language.
Deleting the app removes all of it. There is no backup and no recovery: we cannot restore your history, because we never had a copy of it.
What leaves your device
Usage analytics: only with your consent
If you agree, Gyrus sends anonymous usage events to PostHog, which we use to understand where people abandon the onboarding and whether the program is worth subscribing to. We send only the fact that a step happened, for example "diagnostic started", "baseline shown", "paywall shown", "session completed", together with a randomly generated identifier that is not linked to your identity, your app version, and your device model and operating system version.
We do not send your scores' content, your answers, your goal, any text, or any screen recording.
You can refuse at the first launch and change your mind at any time in the app's settings. Refusing changes nothing about how the app works.
Comparing yourself to others: only with your consent
One day we would like to tell you where you stand next to other people who train. That number only means something with a measured population, and we have none: inventing it would be fabricating it.
So if you agree, at the end of a session Gyrus sends exactly this and nothing else:
- an identifier drawn at random the moment you agree, never derived from your device, whose only purpose is to avoid counting you twice;
- the date, with no time of day;
- your cognitive index for that day;
- your pillar scores for that day.
We do not send your answers, your response times, your difficulty levels, your streak, your goal, or anything else.
This consent is separate from the usage analytics one. Agreeing that we count which screens you visit is not agreeing that we send cognitive scores, and refusing one does not imply refusing the other.
Until you agree, the identifier does not exist and nothing is prepared. If you withdraw your consent, the app asks the server to erase everything that was sent, then forgets the identifier once that request has gone. If you are offline, the request waits and leaves on its own.
This data is hosted by Cloudflare in the European Union.
Subscription status
If you subscribe, purchases are processed by Apple or Google, never by us. We never see or store your payment details. RevenueCat manages the subscription on our behalf and receives a random app identifier, the country inferred from your store account, and your purchase and renewal history, which is what allows the app to know whether your subscription is active, including when you are offline.
Advertising attribution: only with your consent
Gyrus is advertised on Meta (Instagram, Facebook), TikTok, and the App Store. Paying to be seen means knowing which ad actually brings subscribers; without that measurement, the budget is spent blind.
If you agree — and this is a separate consent, refused on its own without touching the others — RevenueCat passes to those networks the bare fact that a trial or a subscription started, together with the identifier your operating system assigns to the app. That is what allows a subscription to be matched to the ad that preceded it, and nothing else does.
We do not send those networks your scores, your answers, your goal, your response times, or any training data whatsoever. Only the purchase event and the identifier that matches it.
On iOS, the advertising identifier is read only if you allow it in addition, in the prompt Apple presents. That prompt appears only after you have ticked this box: we never ask the system for something you have not already agreed to. Refusing either one changes nothing about how the app works. Apple also provides, for ads shown in the App Store, an attribution token designed not to identify you: it names a campaign, never a person.
This sharing has its own switch in the settings. Turning it off stops it immediately, and leaves usage analytics exactly as you set them.
Third parties
| Service | Purpose | Privacy policy |
|---|---|---|
| PostHog | Anonymous usage analytics, with consent | https://posthog.com/privacy |
| Cloudflare | Hosting for cohort measurements, with consent | https://www.cloudflare.com/privacypolicy/ |
| RevenueCat | Subscription management and advertising attribution | https://www.revenuecat.com/privacy |
| Meta Platforms | Attribution for Instagram and Facebook campaigns, with consent | https://www.facebook.com/privacy/policy |
| TikTok | Attribution for TikTok campaigns, with consent | https://www.tiktok.com/legal/privacy-policy |
| Apple / Google | Payment processing, distribution, and advertising on their stores | Their respective policies |
Legal basis and your rights (GDPR)
Usage analytics, advertising attribution, and the comparison to other people each rest on your consent. All three are asked separately, refused separately, and withdrawable at any time: agreeing to one grants none of the others. Subscription management rests on the performance of the contract between you and us.
No identifier is read from your device for advertising purposes before you have agreed. That is what Article 5(3) of the ePrivacy Directive requires, and the app holds it in its code, not merely on this page.
You have the right to access, rectify, erase, and port your data, and to object to its processing. Because the app holds no account, most of your data is already in your hands: uninstalling the app erases it.
For cohort measurements, erasure is requested from the settings by withdrawing your consent: the app handles it, you have nothing to write to us. One caveat: if you uninstall the app without withdrawing your consent first, the identifier goes with it, and we then have no way to link those measurements to you, and so no way to erase them on request.
For anything held by our processors, write to [email protected] and we will answer within one month. You may also lodge a complaint with your national data protection authority: in France, the CNIL.
Retention
Data on your device is kept until you delete the app. Analytics events are retained by PostHog for a maximum of twelve months. Cohort measurements are kept for twenty-four months, the time it takes for a population to build up, then erased. Attribution events passed to advertising networks follow those networks' own retention periods, stated in their respective policies. Subscription records are kept for the legal accounting period.
Children
Gyrus is not designed for children under 13 and we do not knowingly collect their data.
Changes
If this policy changes, the date at the top of this page changes with it, and any material change will be announced in the app before it takes effect.