Privacy policy

Last updated 24 September 2026

This policy explains what personal data Hyperio collects, why, and what rights you have over it. Hyperio is currently run by an individual developer rather than a registered company – for any privacy question, request, or complaint, contact hyperio.app@yahoo.com. We aim to respond within 30 days, as required under UK GDPR.

What we collect

When you create an account, we collect:

  • Your email address and password (your password is stored in hashed form by our authentication provider – we never see or store it as plain text).
  • Basic profile details you choose to provide: sex, timezone, and an optional display username.

As you use the app, we collect what you log across Hyperio’s five domains – Metabolism, Cognition, Testosterone, Cortisol, and Circadian rhythm. Depending on which features you use, this can include: energy, mood, stress, libido, and sleep ratings; weight, calorie, nap, and exercise entries; wake and bed times; cognitive game results; and the daily and weekly scores Hyperio calculates from all of the above. We also store whether you’ve indicated photosensitive epilepsy, so the app can skip flashing visual effects for you.

If you enable notifications, we store your device’s push subscription details so we know where to send them. If you subscribe to Hyperio Premium, our payment processor (see below) shares back a customer and subscription reference so we know your account is active – we never receive or store your card details ourselves. If something goes wrong, we may log technical error details (which can include your account ID) to help us fix it.

A note on health-related information

Some of what Hyperio asks you to log – sleep, stress, libido, weight, and similar wellness markers – can count as health data under UK GDPR, which normally needs an extra legal basis to process. We rely on your explicit consent for this: by creating an account and choosing to log this information, you’re consenting to Hyperio processing it for the purpose of generating your personal wellness scores and trends. Every one of these inputs is optional – if you’d rather not log a particular marker, you can simply leave it out, and Hyperio will just have less data to work with for that domain. You can withdraw this consent at any time by deleting your account (see “Your rights” below), which permanently deletes this data along with everything else tied to your account.

Why we use your data

  • To provide the app itself – calculating your scores and showing you your own history (necessary to perform our contract with you, i.e. providing the service you signed up for).
  • To process Premium subscription payments (also necessary to perform our contract with you, for Premium users).
  • To send check-in reminders and other notifications you’ve opted into.
  • To process health-related inputs you choose to log, as described above (your explicit consent).
  • To diagnose bugs and keep the app secure and working correctly (our legitimate interest in running a functioning service).

We don’t use your data for advertising, we don’t sell it to anyone, and Hyperio doesn’t run any analytics or tracking scripts – there’s nothing here profiling you for marketing purposes.

Who we share it with

We use a small number of service providers to run Hyperio, each only for what they need to do their job:

  • Supabase stores our database and handles account sign-in, hosted in the UK (London).
  • Vercel hosts and serves the app itself.
  • Stripe handles Premium subscription payments – they receive your email and payment details directly; we only ever see a customer reference, never your card details.
  • Your browser’s own push notification service (run by Google, Apple, or Mozilla depending on your browser) delivers notifications you’ve opted into.
  • The Cognition domain’s word-recall game sends a single word to the Datamuse public word API to find rhymes – no account or personal information is included in that request.

We don’t share your data with anyone else, and we don’t sell it.

How long we keep it

We keep your data for as long as your account is active. If you delete your account, everything tied to it is permanently deleted straight away – there’s no retention period or backup copy we keep it in afterwards.

Your rights

Under UK GDPR, you have the right to:

  • Access a copy of your data – use “Export my data” in Settings for an instant, complete download.
  • Correct inaccurate data – most of your profile and logged data can be edited directly in the app.
  • Delete your data – use “Delete my account” in Settings, or email us.
  • Object to or restrict certain processing, and request your data in a portable format.
  • Withdraw consent for the health-related inputs described above, at any time.

If you’re unhappy with how we’ve handled your data, you also have the right to complain to the UK’s data protection regulator, the Information Commissioner’s Office (ICO).

Cookies

Hyperio only uses the cookies needed to keep you signed in. We don’t use any advertising, tracking, or analytics cookies.

Security

Your data is protected by row-level security in our database, meaning every request is restricted to your own account’s data at the database level, not just in the app’s own code. All traffic to Hyperio is encrypted in transit (HTTPS).

Children

Hyperio is intended for adults aged 18 and over, and isn’t directed at children.

Changes to this policy

If we make a meaningful change to this policy, we’ll update the date at the top of this page. Continuing to use Hyperio after a change means you accept the updated policy.