Ritual
Privacy
You can use Ritual without an account, and then your log stays on your phone. If you sign in, your log is also saved to your account, encrypted on your phone before it leaves, so we can’t read it.
This page covers Ritual, the medication log for iPhone and Android, and lists everything that reaches us or anyone else. It is the complete policy.
Who is responsible
Ritual is published by Forever Works SRL, a company registered in Brașov, Romania (trade register J8/2983/2021, CUI RO45079498). We decide what happens to the information described here. For anything about it, email support@ritual.day.
On your phone
The medications you add, the doses you record and when, any notes you write, and your settings. It is kept in an encrypted database file in Ritual’s own storage, which other apps can’t read. Its key is kept in your phone’s secure storage and is never sent anywhere.
What leaves your phone without an account
Nothing you record. Three things are sent:
- Medication search. When you add a medication, the name you type is sent to our server as you type it, with your phone’s region, to find matching products. If you pick one, the product you picked is fetched too. We answer the search and keep none of it.
- Update check. When it starts, Ritual asks Expo, the service that delivers our updates, whether a newer version of its code exists. The request carries the app’s version, the kind of phone, and a random number chosen when the app was installed, which lets Expo tell installations apart. It carries nothing you recorded.
- Data sources. Opening Settings, then Data sources, fetches the list of public catalogues our medication information comes from.
Like any server, ours sees the network address a request comes from. It uses it to answer, and to guess your country when your phone doesn’t say which region it is set to.
What we keep if you create an account
An account is optional. If you create one, we keep:
- Your email address, and your name and profile picture link if you sign in with Google or Apple and they send them. If you use Hide My Email with Apple, we get Apple’s relay address rather than yours.
- Which way you sign in, and the identifier Google or Apple uses for you.
- Your sign-ins. For each phone that is signed in, a session with the network address and the phone and app description it was created from. We keep these to keep your account safe. A session ends 30 days after the app last used it, or when you sign out.
- Your log, encrypted. Every entry is encrypted on your phone with a key that only your devices and your recovery code hold, then sent to us so another phone of yours, or a new one, can get it back. We can’t read medication names, doses, notes or times.
What we can see about the encrypted log is how many entries there are, how much space they take, random identifiers for each of your devices, and when your devices connect to save or fetch entries.
Your recovery code is shown only to you and is never sent to us. If you lose it and every phone that is signed in, nobody can open the saved copy of your log, including us.
If you sign in with email, we send you a six-digit code. It is stored in a form we can’t read back, and expires after 10 minutes. To refuse floods of sign-in attempts, the server also keeps a count of recent requests to its sign-in service for each network address, not linked to any account.
Who else handles it
We use these providers, and each gets only what it needs for its part:
- Cloudflare runs our server and hosts this website. Your account and the encrypted copy of your log are stored in its data centres in the European Union. A request may be answered from the Cloudflare location nearest to you. The website has no analytics and sets no cookies.
- Resend sends the email with your sign-in code, so it gets your email address and the code.
- Google or Apple, only if you choose to sign in with them. They tell us your email address and, if you let them, your name.
- Expo delivers app updates, as described above.
- Google Workspace holds our email, so it has any message you send to support@ritual.day.
Some of these companies are based in the United States. We don’t sell your information, and we don’t share it with anyone else.
The app has no analytics, advertising or crash reporting. We left these out on purpose: a crash report can include whatever was on your screen when the app failed.
Why we are allowed to
- Your account and the encrypted copy of your log exist because you asked for them by signing in. Keeping them is how we provide that (GDPR Article 6(1)(b)). Because the log is about your health, we keep it with your explicit consent (Article 9(2)(a)), which you give by signing in to save it and can withdraw at any time by deleting your account.
- Sessions, and counting requests to the sign-in service by network address, keep your account and our server safe (Article 6(1)(f)).
- Search text is used only to answer the search you are typing.
Your phone’s own backup
Phones back up their apps, and each app says whether it should be included. Ritual asks not to be.
On Android, Ritual tells the system not to include its data in Google Drive backup.
On iPhone, Ritual asks iOS to leave its storage out of iCloud device backups, and we’re still confirming that this works. Until we have, assume the database file may be in your backup if you have iCloud Backup turned on. The file is encrypted, and its key stays in this phone’s secure storage and is not restored to another phone. The backup belongs to you, in your own Apple account, and we can’t access it.
Reminders
Reminders are off until you turn them on. When you do, your phone schedules them and shows them. Ritual has no push server and never sends you anything. The text of a reminder is written on your phone, from your own log.
How long we keep it
- Your account and the encrypted copy of your log: until you delete your account.
- A sign-in session: until it ends, you sign out, or you delete your account.
- A sign-in code: stored only in a form we can’t read back, and useless after 10 minutes.
- Search text: not kept at all.
- Our hosting provider’s point-in-time backups of the database: up to 30 days after something is deleted.
On your phone, your log stays until you delete the app. Signing out or deleting your account leaves it there.
Deleting your account
In the app, open Settings and choose Delete account. That deletes your account, your sign-ins and the encrypted copy of your log from our server at once. If you can’t open the app, you can ask us to do it.
Your rights
Laws such as the GDPR give you the right to ask what we hold about you, to correct it, to get a copy, to have it deleted, to object to how we use it, and to withdraw consent. Most of it you can do yourself: your log is in the app, you can export it from Settings, and you can delete your account there. For anything else, email support@ritual.day. We answer within a month.
You can also complain to a data protection authority. In Romania that is the ANSPDCP, at dataprotection.ro.
Children
Ritual isn’t meant for children. Please don’t create an account if you are under 16.
If this page changes
We change this page before we release a version of Ritual that changes anything it describes, and the date at the bottom changes with it.