This policy applies to the SIR, YES SIR! app ("SYS"), published by Fyro.studio (H. Gene, sole trader, Brunoy, France). SYS does not require account creation — no email, no password, no sign-up form exists anywhere in the app. Your identity within the app is tied only to your device and your own Apple ID, through Apple's own systems (see §3).
Health data (HealthKit) — SYS reads, with your explicit authorization requested by iOS, three passive HealthKit metrics: daily step count, active energy burned, and sleep analysis. This reading is: - Passive only — SYS never records a workout session or writes any data back to Apple Health. - Gated to relevance — the health permission prompt only appears once you have an active "Body & Training" goal selected in the app; if that category isn't part of your active goals, SYS never asks for or reads this data at all. - Used only to power an in-app dashboard display (the health carousel) reacting to your daily activity — for example, the in-app Sergeant character commenting on your step count. - Never transmitted to Fyro.studio or to any third party. This data is read directly from your device's Health data store via Apple's HealthKit framework and stays there. If synced across your own devices, it is synced only through Apple's own Health/iCloud systems under Apple's own privacy terms — never through a Fyro.studio server, because Fyro.studio operates no backend server for this data. - Never used for advertising. This data is never used, by Fyro.studio or anyone else, to target, personalize, measure, or otherwise support advertising of any kind. SYS shows no ads and contains no advertising SDK. - Revocable at any time — you can withdraw this authorization at any time in iOS Settings ▸ Privacy & Security ▸ Health ▸ SIR, YES SIR!. If you do, the affected dashboard elements simply stop displaying (degrade gracefully) rather than the app malfunctioning.
App progress data — your grade, XP, missions, streaks, badges, and program progression are generated and stored on your device, and synced across your own devices only through your own private Apple iCloud (CloudKit private container) — a container only you and Apple can access, never Fyro.studio. This is the same mechanism Apple uses for apps to sync data privately across a user's own devices; it is not a Fyro.studio-operated database.
Purchases — subscription and one-time purchase processing (the "Bataillon" subscription and "Lieutenant à vie" lifetime tier) is handled entirely by Apple through StoreKit. Fyro.studio never receives, stores, or has access to your payment method, card number, or billing details — only Apple does, under Apple's own privacy terms. Fyro.studio does not receive a record of your individual purchases either — only anonymized/aggregated sales figures via App Store Connect, the same reporting every app developer receives from Apple.
Because your data is stored on your own device and, where synced, in your own private Apple iCloud container, it benefits from Apple's own device- and iCloud-level security and encryption standards — the same protection Apple provides for any app using these frameworks. Fyro.studio does not additionally transmit or store this data elsewhere, so there is no separate Fyro.studio server to secure.
Your progression and health-derived dashboard data persist on your device and in your own private iCloud for as long as you use the app. You can reset this data at any time yourself, in-app (Settings ▸ Account): - "Reset All Data" — clears your local progress and restarts onboarding, keeping your device identity intact (useful if you want a clean slate). - "Delete My Account" — permanently erases your local app data and your private iCloud data associated with the app, in full, with no residual copy retained by Fyro.studio (because none exists to begin with). Note: deleting your data does not cancel an active subscription — Apple subscriptions must be cancelled separately via "Manage Subscription" (also available in the same Settings section), since SYS cannot cancel an Apple subscription on your behalf.
Because SYS stores your data on your own device and your own private iCloud rather than on a Fyro.studio server, you already hold direct, immediate control over it via the in-app tools described in §6, without needing to submit a request to us. If you have a question about this policy or about how your data is handled, you can reach out via our Support page.
SYS is not directed at children. [Final age-rating language pending the App Store Connect age questionnaire, a separate open chantier — this section will be finalized once that questionnaire is completed. See open points at the end of this document.]
We may update this policy as the app evolves. The "last updated" date at the top will always reflect the latest version.
The App is distributed worldwide via the Apple App Store (no territorial restriction currently planned), so this policy is written to hold up regardless of where you live, rather than being scoped narrowly to France. The reasoning: - GDPR (EU/UK) — Fyro.studio is a French sole trader, so GDPR applies to Fyro.studio's processing regardless of where an individual user is located, not only to EU residents. Rather than try to segment rights by the user's country (impractical for an app with no accounts or backend to check location against), this policy extends GDPR-style rights (transparency, minimal collection, self-service access/deletion, no data sale) to every user, everywhere — the simplest approach given the app's architecture, and the more protective one, so it should not need weakening later even where GDPR doesn't strictly apply. - CCPA/CPRA (California) — SYS is a solo/indie app; the applicability thresholds for CCPA (broadly: ~$25M+ annual gross revenue, or buying/selling/sharing the personal information of 100,000+ consumers or households per year, or deriving 50%+ of revenue from selling/sharing personal information) are very unlikely to be met, especially at launch. The policy still includes CCPA-style language in substance (no sale/sharing of personal information, clear disclosure of what is/isn't collected) as a matter of good practice, without formally claiming CCPA coverage — a lawyer should confirm whether an explicit "Notice to California Residents" clause is worth adding regardless of the threshold question. - Practical simplification specific to SYS: because almost no personal data is collected by Fyro.studio at all (see §2–§3 — everything stays on-device or in the user's own private iCloud), most of the heavier GDPR/CCPA compliance machinery (data processing registers, international transfer safeguards, sale opt-out mechanisms) has little to act on in practice. The main concrete obligations that remain relevant are the ones already reflected above: clear disclosure (§2–§4), a lawful basis for the one real consent point (HealthKit's iOS-level permission prompt), and accessible self-service rights (§6–§7). This proposal deliberately avoids citing specific article numbers (GDPR articles, CCPA sections) until confirmed by a lawyer, to avoid citing the wrong basis and having to walk it back later.