Privacy Policy
Last updated: September 12, 2026. Applies to Nyxa on iOS and Android, and to this website.
MMZ Development (“we”, “us”) operates Nyxa. This policy explains what we collect, why, who else sees it, how long we keep it, and how you delete it. Using Nyxa or this site means you have read this policy. Questions: support@mmzdevelopment.com.
What Nyxa is
Nyxa is a voice-first assistant. You speak or type a task. We store it and remind you at the time or place you asked. You can start as a guest with no email. An account is optional until you want Sign in with Apple, email login, or Nyxa Pro.
Information we collect
Account and device
- Name, if you give one
- Email and password, if you register. Passwords are stored hashed
- Apple user ID and a refresh token if you use Sign in with Apple. Apple may give us a private relay address instead of your real email
- Passkeys, if you add one (WebAuthn credentials tied to mmzdevelopment.com)
- A device identifier we create or read from the OS (iOS identifierForVendor, Android ID) so guest sessions, attestation, and this device stay linked
- Language, timezone, reminder and haptic preferences, quiet hours, whether overdue tasks auto-complete
- Optional profile photo
- Expo push token for this device, if you allow notifications
Tasks, notes, people, and places
- Task title, comment, notes, due time, remind time, timezone, recurrence, source (voice, chat, or manual)
- Quick notes you save
- People names you attach to tasks
- Places you save: name, address, map coordinates, and radius, used for arrive or leave reminders
- A one-off venue on a task (name, address, coordinates) if you pick a map pin
Voice and chat
- Microphone audio while you talk to the assistant, processed to text and to create or change tasks
- On Apple Watch, speech recognition may run so what you say becomes a task
- Typed chat messages and short recent conversation history sent with a request so the assistant can continue the thread
- Assistant name, voice, and any custom instructions you write
Spoken and typed content is sent to our servers and to Google Gemini so the assistant can understand you and call tools (create, list, update, complete, or delete tasks). That is third-party AI. Do not put secrets in voice or chat that you do not want processed that way.
Location
We ask for location only to save a place or to fire an arrive/leave reminder. If you grant Always, the OS may wake the app near a saved place. If you ask the assistant to save where you are, the current coordinates go to our servers and to Google Gemini so it can create that place. We do not sell a location trail and we do not need location for timed reminders. You can refuse location and still use the rest of Nyxa. You can turn it off in system Settings or in the app permissions screen.
Camera and photos
Used only if you set a profile photo. We do not read your library for anything else.
Notifications
If you allow notifications, we store a push token and send reminders you asked for (due time, or arrive/leave at a place). You can disable reminders in the app or in system Settings.
Security signals
On supported devices we may send an Apple DeviceCheck or Google Play Integrity token with some API calls so we can tell a real app install from abuse. Those tokens go to Apple or Google to be checked, then we store the result of the check, not a profile of you.
Purchases
Nyxa Pro is sold through the App Store or Google Play. We receive subscription status (free or Pro, store, expiry) through RevenueCat. Apple or Google handle the payment. We do not see your full card number.
Analytics and diagnostics
In production builds, PostHog receives events such as screens opened, tasks or notes created, onboarding finished, and purchases restored, plus a Nyxa user id so we can see what people use. This is product analytics, not advertising.
Sentry receives crash reports and logs from the app, the API, and the assistant service. On some iOS and Android sessions Sentry also records a replay of the screen (about one in ten sessions, and every session that errors) so we can see what went wrong. Those reports can include device data and a user identifier. Sentry is off in development builds.
We do not use IDFA or App Tracking Transparency for ads. Nyxa does not show ads.
This website
The site is static. We do not set an account cookie here. The host (Vercel) may log standard request data (IP, user agent) to operate the site.
How we use it
- Run Nyxa: save what you said, remind you, show your list, widget, and Watch
- Keep you signed in on this device, including guest and passkey
- Send the reminder you asked for
- Provide Pro features you paid for
- Stop abuse and keep quotas honest
- Fix crashes and understand whether the product works
- Reply if you email us
We do not sell your personal information. We do not use your tasks or conversations to train a public model of our own. Google’s processing of Gemini requests is governed by Google’s terms and privacy policy.
Who else sees data
We share data with the processors below only to run Nyxa. Each must protect it at least as this policy requires.
- Google (Gemini). Voice and chat text, timezone, and recent turns, so the assistant can act. Google Privacy Policy
- PostHog. Product events and errors, when enabled. PostHog Privacy Policy
- Sentry. Crashes, logs, and sampled screen replays. Sentry Privacy Policy
- RevenueCat. App user id and subscription state. RevenueCat Privacy Policy
- Apple. Sign in with Apple, App Store purchases, push (APNs), DeviceCheck, and Watch/widget delivery. Apple Privacy Policy
- Google Play. Android purchases and Play Integrity. Google Privacy Policy
- Expo. Push delivery. Expo Privacy Policy
- Vercel. This website. Vercel Privacy Policy
Our API and AI services that host Nyxa also store the account and task data described above. Those servers may be outside your country. If you are in the EEA or UK, that is an international transfer for the purpose of providing the service.
How long we keep it
- Account, tasks, notes, people, places, preferences, and photo: until you delete the account
- Chat sessions: deleted after 7 days
- Unfinished email registrations that never verify: removed after about one day
- Push token: until you sign out, disable reminders, or delete the account
- Support email you send us: as long as needed to reply, then ordinary mail retention
Your choices
- Use Nyxa as a guest. Email is not required for the core list and Speak
- Refuse microphone, notifications, location, camera, or photos. Those features then stay off. Timed tasks still work without location
- Turn reminders off in the app
- Delete a task, note, person, or place in the app
- Delete the account in Nyxa under Account. That removes the data we store for that account (tasks, chats, photo, session). An active Pro subscription continues in the App Store or Google Play until you cancel it there
- If you used Sign in with Apple, you can also revoke Nyxa in iOS Settings. Apple may then tell us to delete the account
- Email support@mmzdevelopment.com to ask what we hold or to request deletion if you cannot open the app
Children
Nyxa is not directed at children under 13. We do not knowingly collect personal information from them. If you think we have, write to us and we will delete it.
This website
Public pages (home, privacy, terms, support) do not require a login. Associated Domains files for Apple passkeys are served here so Sign in with a passkey can work.
Changes
We may update this policy. The date at the top will change. If a change is material, we will note it here. Continued use after an update means you accept the new policy.
Contact
MMZ Development
support@mmzdevelopment.com
Also see our Terms of Use and Support.