Effective: 18 August 2026 · Last updated: 18 August 2026
Ritmo helps you plan and reflect on your time. To make that work across your devices — and across iPhone and Android — the things you create in Ritmo (your schedule, captures, notes, reflections, goals, persona answers, and household setup) are stored on your device and synced to Ritmo's own backend, run on Cloudflare, tied to your account. On iPhone they also sync through your private iCloud.
Some things stay on your device only: anything you read from Apple Health, your calendar and reminder contents, voice-capture audio (transcribed on-device, then discarded), and photos you attach to captures.
The one time your Ritmo content is sent to another company for processing is when you use the AI assistant — then the conversation and the relevant schedule context go to Anthropic to generate a reply. We don't sell your data, run ads, or track you across other apps. We use no analytics or advertising SDKs. You can delete everything we hold, from inside the app, at any time.
Ritmo ("Ritmo", "we", "us") is an independent app operated from Ghana. You can reach us at support@app-ritmo.com. For the purposes of the GDPR / UK GDPR, Ritmo is the data controller for the information described here.
| What | Why | Where it lives |
|---|---|---|
| Email address | Sign-in by one-time code, and to recognize your account | Stored on our Cloudflare backend as your account identifier (email sign-in) and used to deliver the code. No marketing — there is none. |
| Apple / Google sign-in identifier | To recognize you across devices without a password | An opaque, per-app identifier — not your real Apple or Google account. Stored on our backend as your account key. |
| Your name (optional) | So the app can greet you | Kept on your device only. If you use Sign in with Apple, Apple offers it once at first sign-in; we don't re-request it. |
| Your Ritmo content — schedule blocks, captures, notes, reflections, goals, tasks, weekly reviews, observances, persona/calibration answers, and household setup | This is the app's whole function, and it must be available on all your devices | On your device, synced to our Cloudflare backend under your account, and (on iPhone) through your private iCloud. |
| Voice-capture audio | To turn a spoken note into text | Transcribed on-device; the audio is discarded and only the text is kept (and then synced as content, above). |
| Photos attached to captures | So a snapshot can become a schedulable item | Stored with that capture. Synced as your content; never shared beyond your account. |
| Calendar events (Apple, Google, Outlook) & Apple Reminders | To show alongside your Ritmo schedule and let you plan around them | Read with your permission and shown in the app. Connecting Google or Outlook uses their OAuth sign-in. On Android, Ritmo can also adjust or remove calendar events it manages. |
| Apple Health signals (e.g. sleep, activity), if you connect Health | To shape gentle scheduling and recovery suggestions | Read from HealthKit on your device and used there. Not sent to our backend. |
| Subscription status | To unlock paid features and honor your plan | Your purchase is verified with Apple or Google; we store the resulting entitlement (plan + expiry) on our backend, not your card details. |
| What | Why | Where it lives |
|---|---|---|
| A per-install device identifier | To attribute which device wrote which record, and to secure the app with App Attest | On your device and on our backend, tied to your account. |
| Sign-in & rate-limit counters | To deliver one-time codes and prevent abuse of the service | Cloudflare KV, keyed by email and a hashed IP, expiring on a short window. |
| Crash, hang & performance reports | To find and fix bugs | Prepared by Apple's MetricKit on your device and forwarded to our backend, stored ~30 days keyed by a hashed IP — not your account, and with no schedule content, names, emails, or conversations. On by default; you can turn it off in the app's Diagnostics settings. |
Beyond your device, your information travels only along these paths, each for a specific purpose:
When you share within a household, the household-shareable records (members, coverage, and household-linked blocks) become readable by the other members of that household. Your private records stay private.
We do not share your data with marketers, data brokers, advertisers, analytics platforms, or any third-party SDK not listed here.
If you are in the EU or UK, you also have the right to lodge a complaint with your local data protection authority.
Ritmo is operated from Ghana, and the providers above (Apple, Cloudflare, Anthropic, Google, Microsoft, Resend) process data on infrastructure that may be located in the United States, the European Union, or elsewhere. By using Ritmo you understand your information may be processed in countries other than your own, under those providers' safeguards.
Ritmo is intended for people aged 16 and over (or the age of digital consent in your country, if higher). We do not knowingly collect data from children below that age. If you believe a child has provided us data, contact support@app-ritmo.com and we will delete it.
No software is perfectly secure, and we don't claim otherwise — but we design conservatively, review our boundaries, and act quickly on anything we find.
If we change this policy we'll update the date above, and for material changes we'll notify you in the app and give you notice before the change takes effect.
Questions, concerns, or requests: support@app-ritmo.com. We aim to respond within 5 business days; complex requests may take up to 30.