Legal

Privacy Policy

Last updated: [DATE]

This Privacy Policy explains how [COMPANY NAME] (“RitualOS”, “we”, “us”) collects, uses, and protects your personal data when you use our website and mobile applications (the “Service”). We process personal data in accordance with the EU General Data Protection Regulation (GDPR) and applicable national law.

1. Controller

The controller responsible for your data is:

[COMPANY NAME]
[STREET ADDRESS]
[POSTAL CODE, CITY, COUNTRY]
Email: [CONTACT EMAIL]
[Where applicable: Data Protection Officer — [NAME / EMAIL]]

2. Data we collect

  • Account data — name, email address, and password (stored hashed) when you create an account.
  • Ritual & log data — the habits, protocols, mood, energy, and completion entries you record in the app.
  • Usage & device data — IP address, device type, app version, and interaction data collected automatically.
  • Communications — the content of messages you send us (e.g. support requests).

3. How we use your data

  • To provide, maintain, and personalize the Service.
  • To generate AI-assisted recommendations via Aura AI based on the data you provide.
  • To communicate with you about your account and support requests.
  • To secure the Service and prevent abuse.
  • To comply with our legal obligations.

4. Legal bases (Art. 6 GDPR)

  • Contract (Art. 6(1)(b)) — to provide the Service you sign up for.
  • Consent (Art. 6(1)(a)) — for optional analytics, marketing, and health-related data, where required.
  • Legitimate interests (Art. 6(1)(f)) — to secure and improve the Service.
  • Legal obligation (Art. 6(1)(c)).

Note: health and wellbeing data may qualify as a special category under Art. 9 GDPR and is processed only with your explicit consent.

5. Cookies & analytics

We use [strictly necessary / analytics / marketing] cookies and similar technologies. Non-essential cookies are set only with your consent, which you can withdraw at any time via [cookie settings link]. We use [ANALYTICS PROVIDER] to understand usage.

6. Third-party processors

We share data with service providers acting on our behalf under data processing agreements, including:

  • [HOSTING / DATABASE PROVIDER, e.g. Supabase]
  • [AI PROVIDER, e.g. OpenAI] — to generate Aura recommendations.
  • [ANALYTICS PROVIDER]
  • [EMAIL / PAYMENT PROVIDERS]

7. International transfers

Where data is transferred outside the EEA, we rely on appropriate safeguards such as the EU Standard Contractual Clauses. [List relevant transfers and mechanisms.]

8. Data retention

We keep personal data only as long as necessary for the purposes above or as required by law. Account and log data are deleted [within X days] after you close your account. [Specify concrete retention periods.]

9. Your rights

Under the GDPR you have the right to:

  • Access your data and request a copy.
  • Rectify inaccurate data.
  • Erase your data (“right to be forgotten”).
  • Restrict or object to processing.
  • Data portability.
  • Withdraw consent at any time.
  • Lodge a complaint with a supervisory authority ([RELEVANT AUTHORITY]).

To exercise any right, contact us at [CONTACT EMAIL].

10. Children

The Service is not directed to children under [16]. We do not knowingly collect data from children below that age.

11. Changes to this policy

We may update this policy from time to time. Material changes will be announced via [email / in-app notice], and the “last updated” date above will change.

12. Contact

Questions about this policy? Email us at [CONTACT EMAIL] or write to the address in Section 1.