Privacy
Ritmai helps you notice how your meals, your sleep and your days fit together. Doing that means handling information about your health, which is the most sensitive kind of personal data there is. This page says what Ritmai holds, where it is kept, who else touches it, and how to get a copy of it or get rid of it.
Who to contact
Ritmai is run by Vizuali terapija, MB, a small partnership registered in Lithuania, legal entity code 304245530, at Ežero g. 4A, Kurnėnų k., LT-64233 Alytaus r., Lithuania. That company is the controller of your personal data: it decides what is collected and why, and it is who every right on this page is exercised against.
Ritmai is a small, independent app. For anything on this page — a question, a copy of your data, a deletion, or a complaint — write to [email protected]. There is no data protection officer to route you to; that address reaches the people who decide.
Your account
Ritmai gives you an account only after you explicitly choose to start. That account is anonymous: no email address, no name, no password. It is a credential issued by Firebase Authentication, a Google service, plus an identifier of our own that everything else is filed under.
You can later link a sign-in method — Sign in with Apple, or a Google account — so the same record follows you to another device. Linking gives us whatever that provider passes on, which is an identifier and, depending on the choice you make with Apple, an email address.
Syncing to an account is new. Until the version of Ritmai you are running offers it, your record stays on your device and the sections below about our servers do not yet describe anything we hold about you.
Health data, and why we ask
Meals, body mass, nights of sleep, cycle observations, how you said you felt, the body signals you noticed — under the GDPR this is special-category data, Article 9. We do not process it on our servers because it is useful to us or because you would probably not mind. We process it only with your explicit consent, under Article 9(2)(a), and only after you have given it. Without that consent the server refuses to record an observation at all.
Consent is tied to a version of this page. The version is printed at the bottom, and the record we keep says which version you agreed to and when. If this page is rewritten in a way that changes what you were agreeing to, you will be asked again rather than carried over.
You can withdraw consent at any time from the app. Withdrawing stops further processing. It does not delete what is already stored, and it is not the same as deleting your account — for that, see below. We keep the record of the consent itself, including the withdrawal, because the law asks us to be able to demonstrate what was agreed and when. Erasing your account deletes those records along with everything else.
For the parts of Ritmai that are not health data, the basis is different and simpler: running your account and answering your support messages is us providing the service you asked for, and the waitlist and website analytics run on your consent, which you can take back.
Client error reports, closed product events and experiment exposures are processed under our legitimate interest in keeping Ritmai reliable and understanding whether its own features work. They use our own endpoints and our existing EU database. They contain no meal name or description, note, photo, Apple Health value, observation value, or other health content, and they do not read or write an identifier on your device.
You may object to that processing under Article 21 by writing to [email protected]. We will stop it for your account unless there is a compelling legal reason not to.
Nothing Ritmai does is an automated decision with legal or similarly significant effects. Its estimates and observations are there for you to read, correct and disagree with.
Where your data is kept
Your account and everything filed under it are stored in a PostgreSQL database run by Neon, in Amazon Web Services' eu-central-1 region — Frankfurt, Germany. The database is dedicated to Ritmai and is not shared with anything else we run. The service that talks to it runs on a rented virtual server, which also holds the nightly copies described under retention.
These companies handle data on our behalf:
- Neon — the database above, and therefore every observation you sync.
- Google — Firebase Authentication for accounts, and the Gemini API for meal estimates. On iPhone, also Firebase Analytics and Crashlytics; on this website, Google Analytics. Both are described under analytics below.
- Our server host — the machine the service, and the backups, run on.
- Cloudflare — every request to this website passes through Cloudflare before it reaches us. Cloudflare terminates the secure connection, filters abusive traffic, and sees the address your device connects from. We do not use it to profile anyone.
- RevenueCat — in the iPhone app only. If you subscribe there, it confirms your access and restores purchases.
- Stripe — on this website only, and it has two roles at once rather than one. For the billing it does on our instructions — taking the payment, running the subscription, telling us it is active — it acts on our behalf. For its own fraud checks and its own legal and tax obligations it acts for itself, and we cannot instruct it in that part. Saying only that Stripe processes payments for us would describe the first half and leave out the second. Stripe Payments Europe, based in Dublin, is the company we contract with.
Meals, photos, and what a model is shown
When you ask Ritmai to estimate a meal, it first tries its own food data, and where that does not resolve the meal it asks Google's Gemini model. What is sent is the photo or the description you chose, and nothing that identifies you: no account identifier, no name, no email address. The estimate comes back for you to review and edit before anything is saved.
The photo itself is never stored against your account. There is no meal-photo table, meal photos do not appear on the web, and a copy of your data will not contain one.
Meal photos may be retained temporarily to improve the service.
Where that happens, the file is stripped of its metadata, named after the analysis rather than after you, and written to our server with nothing recorded that could link it back to an account. That de-linking is deliberate and it cuts both ways: because no account key exists, such a file cannot appear in a copy of your data and cannot be found by a deletion request either. These files are deleted automatically, and none is kept longer than 90 days.
Apple Health
If you connect Apple Health, Ritmai reads four things: the nights you slept, your daylight time, your workouts, and body-mass readings. These become part of your record and are stored with everything else. That is a change from earlier versions of this page, which said Health data stayed on your device. Ritmai reads nothing else from Health, and writes nothing back to it.
What we hold about you
A copy of your data is one file, and this is everything in it. Each heading is a group of records; every one of them is included even when it is empty, so you can see that we hold no cycle observations about you rather than having to guess from an absent line.
- Your account and subscription — the identifier we generated for you, the identifier the sign-in provider issued, whether the account is still anonymous, your time zone, when the account was created and last used, and — if you arrived from a link we posted somewhere — which of a short list of places that was. Never the link itself, and never anything else from the address you arrived on.
If you subscribe, the same record holds which subscription you have, whether it came from this website or the iPhone app, when it expires, and the identifier Stripe gave your customer record. If you subscribed here it also holds the version of the terms you accepted, when you accepted them, and the two things the law asks for before a subscription can start inside the 14-day withdrawal period: that you asked us to start straight away, and that you acknowledged what starting straight away costs you. Those are kept because they are the proof the contract was made properly — yours as much as ours. - Your rhythm setup — the cycle and schedule context you chose during setup, and when you completed it.
- Your meals — the name, when you ate, how it was captured, anything you typed, the components and assumptions behind the estimate, and the calorie, protein, carbohydrate, fat and fibre figures. Not the photo.
- Rhythm context you logged — caffeine, alcohol, stress, workouts, illness, travel, light, sex and the rest, with the time you gave. The file has a note field for these that no version of Ritmai fills; what you type in the app stays on your phone.
- How you said you felt — alertness, hunger, sleep ease, recovery, mood, cravings and symptoms, each recorded as lower, typical or higher than usual for you.
- Body signals you noticed — which signal and how strong it felt, with the time. Not the note you typed with it; that never leaves your phone.
- Body mass readings — the reading, the time, and whether you typed it or Apple Health supplied it.
- Nights you slept — when sleep started and ended, whether typed by hand or read from Apple Health.
- Which days you marked — the days you called work days, free days or shift days.
- Cycle observations — period starts, and the appetite, craving and symptom entries you recorded. These stay descriptive: Ritmai stores no predicted phase, no ovulation estimate and no hormone value.
- What you thought of an insight — which claims you marked helpful or misleading.
- Your consent record — every time you granted or withdrew consent, which version of this page each one named, and when.
- Daylight — the daylight intervals Apple Health reported, and how many minutes each one held.
- Workouts — when each started and ended, what kind it was, and how long you were actually active.
- Client error reports — an allowlisted error category, scrubbed script locations, the release, browser user agent, normalized app path and time. A report made before an account exists has no account identifier and cannot be linked back to this export.
- Product analytics events — a closed event name, closed string properties and the time, for authenticated web product flows. No meal text, note, photo, Health value or observation content is an allowed property.
- Experiment exposures — the experiment key, variant and first time you actually reached the server-side branch. Being assigned without reaching that branch creates no exposure row.
- Meal estimates you used — one line per AI meal estimate we ran for you, holding the time and which allowance paid for it, and nothing about the meal itself: not the photo, not what you typed, not the result. These lines are what a fair-use ceiling counts, so that one runaway request cannot spend the service for everybody, and they are deleted after 30 days. Meals you enter yourself are never counted and never produce a line.
Records you deleted in the app are included too, marked with the date you deleted them. Something we still hold is something we still have to show you, and seeing why it is there is better than wondering.
What never reaches us
- The note you type alongside a body signal. There is no column for it on our servers: it is not sent to the analysis service, not attached to any analytics event, and not read by anything that produces an insight.
- Your meal photos, as above, except for the de-linked samples described there.
- Anything Apple Health holds beyond the four signals named above.
Getting a copy of your data
From the app, you can download everything listed above as a single file. It is not conditional on consent: withdrawing consent must not cost you the right to your own data, so the two are kept separate deliberately. The request is limited to five downloads an hour, which is about abuse rather than about you.
The app is the only route, and that is not us being unhelpful. Your account may have no email address on it, so the credential your app holds is the only thing that can prove which records are yours. An email asking for someone's data is not proof, and treating it as proof would be the more dangerous mistake.
Deleting your data
Also from the app. Deleting your account removes the account row and, with it, every record listed above, and then deletes the sign-in credential held at Firebase. It is immediate and there is no undo.
One warning worth reading twice: an anonymous account has no email address attached to it, so if you delete the app without deleting your account first, we have no honest way to work out which rows were yours. Delete the account from inside the app, then remove the app.
How long things are kept
- Your records — until you delete them, or delete your account. Nothing expires them on its own today.
- The database's own recovery history — roughly six hours.
- Nightly copies of the database — taken at 02:41 UTC onto our server and deleted once they are more than fourteen days old. The last copy that still contains your data is the one taken the night before you deleted your account, so it is gone within sixteen days of your deletion at the outside.
- Retained meal photo samples — no longer than 90 days, and unlinkable to you throughout.
- Feedback you send — twelve months, then deleted automatically.
- Client error reports — 30 days. Signed-out reports have no account identifier; signed-in reports are also removed immediately if you erase the account.
- Product analytics events and experiment exposures — 180 days, or immediately when you erase the account.
- A waitlist email address — until you ask us to remove it, or we stop running the waitlist.
Authentication storage and security
When you sign in on this website, the session is kept by your own browser, in IndexedDB or in local storage where IndexedDB is unavailable. Ritmai sets no session cookie and no login cookie. Clearing this site's stored data signs you out.
Firebase App Check uses Google's reCAPTCHA Enterprise to protect the authentication service from automated abuse. When reCAPTCHA runs, Google may set the necessary _GRECAPTCHAcookie for its risk analysis. This is a security cookie, not a Ritmai session or login cookie, and it is not controlled by the optional analytics choice below.
Analytics
On the public marketing pages, Ritmai uses Google Analytics. The tag does not load inside the authenticated /app area. On the marketing layout, until you choose “Allow analytics” it is instructed to store nothing on your device, and no analytics cookies are set. Google still receives the request that loads it, including your IP address, because that is what loading a script from another server means. If you do allow analytics, Google Analytics then sets its own cookies. Your answer is remembered in your browser's local storage — not in a cookie — so clearing this site's stored data brings the question back.
Inside the authenticated web app, product events go only to Ritmai. The browser batches closed names and closed string properties to our own endpoint, one database row per event. Error reports and experiment exposures use the same first-party boundary. There is no Sentry, PostHog, Firebase Analytics, or other third-party product telemetry SDK in the web app.
In the iPhone app, Ritmai uses Firebase Analytics and Firebase Crashlytics to see which parts of the app are used and what crashed. That can include technical identifiers, the app version, and device and operating-system information. It never includes your meal photos, meal descriptions, Health data, your notes, or the contents of feedback. When you add rhythm context, the only thing recorded is that you added some — not which kind, not the note, not the time.
Ritmai does not sell personal information and does not use it for advertising, on this site or in the app.
Subscriptions
Ritmai Plus can be bought in two places, and they are two different contracts. In the iPhone app, Apple is the seller: RevenueCat processes what is needed to confirm your access and restore purchases, your card details are handled by the App Store, which does not pass them to us, and what reaches us is that a subscription exists and when it expires.
On this website, we are the seller and Stripe takes the payment. Your card details go to Stripe and not to us. What reaches us is what a subscription needs in order to work — the identifier Stripe gives your customer record, whether the subscription is active, when it expires, and the country the purchase was made from, which is what decides the VAT. That is billing information rather than payment information, and the difference is worth spelling out instead of glossing: the second never reaches us, the first does, and a page saying only that payment details never reach us would be describing one while you read it as both.
Subscribing here also records that you accepted the terms, which version you accepted, and the two acknowledgements the law asks for before a subscription can begin inside the 14-day withdrawal period. That is a record of a contract and not a consent: withdrawing your health-data consent does not repudiate it, and it does not stop your subscription either. The terms page explains the mechanism, and the account bullet above says what is stored.
Neither RevenueCat nor Stripe is told anything about your meals, your sleep, your cycle, or any other observation. A subscription decides what Ritmai will compute for you; it is not a description of you. What a subscription costs, how it renews and how to cancel it are on the terms page, and so is your right to change your mind about one.
Feedback and support
When you send a feature request or a bug report, we store the message, the type you chose, the app version, the build number, the operating-system version and your locale. You may add an email address if you want a reply. Feedback is deleted automatically after twelve months.
Please do not put meal photos, health details or passwords in feedback. Feedback sent without a reply address cannot normally be traced back to anyone, which also means we may not be able to find it if you later ask us to delete it.
Website and beta waitlist
If you join the beta waitlist we store your email address and the date, so we can send occasional updates about Ritmai. Write to us and we will remove it.
Your rights
You have the right to see the data we hold about you, to get a portable copy of it, to correct it, to have it erased, to restrict or object to processing, and to withdraw consent at any time. The first two and the fourth are built into the app, as described above; you can correct your own records by editing them. For anything else, write to [email protected].
You can also complain to a data protection authority. In Lithuania that is the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija); if you live elsewhere in the EU, it is the authority for the country you live in.
Children
Ritmai is not designed for, or directed at, children under 16.
When this page changes
The version below is the date this page was last written. If it changes in a way that affects what you agreed to, you will be asked to agree again rather than moved across quietly, and the record we keep will show both versions and both dates.