Privacy Policy
Effective September 15, 2026
The data controller and owner of Rytmi is its developer, Dmitrii Kurbakov. You can contact the controller through the support form. Rytmi is intended for adults; children do not create separate accounts.
Data we process
- email address, account identifier, and consent date;
- the child's nickname, date of birth, time zone, and selected diary event types;
- feeding, sleep, diaper, measurement, and milestone records, including their time, duration, and notes;
- family roles, invitations, and the author of each entry;
- technical synchronization identifiers, record versions, and the device token used for notifications;
- the platform, app version, build number, and operating system version of the device you signed in from. We keep this to know when a released version may stop being supported and to offer you an update. What you do inside the app - which screens you open, what you tap - is not recorded;
- the email address and message voluntarily submitted through support.
Why we process data
We use this data only to sign adults in, maintain and synchronize the shared diary, provide personalized forecasts and analytics, deliver selected notifications, export or delete data, and answer support requests. Rytmi does not sell data, display advertising, or use cross-app tracking.
Storage and security
The primary server database is hosted in Russia. Data in transit is protected by HTTPS, the local iPhone database is encrypted, and session tokens are stored in Keychain. Only invited adults can access a diary; the server verifies ownership and the adult's role for each operation.
Apple receives only the credentials or device token needed for sign-in and push notifications, subject to Apple's terms. Transactional sign-in emails are delivered by Unisender Go; diary contents are not shared with that provider.
Retention and deletion
Active data is kept while the account or shared diary exists. Deleting a child profile immediately removes access and sends a deletion marker to connected devices. Deleting an account deactivates it and removes local diary data, sessions, device registrations, and invitations. If Apple sign-in was used, its grant is revoked before deletion.
After deletion, the account email is anonymized within 30 days. Deleted entries and profiles remain inaccessible for up to 90 days only so that a long-offline device cannot recreate them during synchronization; their contents are then irreversibly erased, leaving only a technical deletion marker. Daily server backups rotate within 7 days and are used only for disaster recovery. Deleted data is not restored to an active account from a backup.
Your choices
In the app settings, an adult can export a child's data, delete a child profile, and delete their account. An owner must first delete any child profiles they own so that a family is not left without an owner. For access, correction, export, or deletion questions, use support.
Changes
An updated policy will be published at this address with a new effective date. Material changes to processing purposes or data categories will be communicated and, where required, will request new consent.