Back

Privacy Policy

Last updated: September 1, 2026

Effective date: September 1, 2026

This Privacy Policy describes how RITU collects, uses, and protects your personal information.

1. About RITU

RITU is a cycle-tracking and wellbeing companion app designed for women, including those with PCOS/PCOD, to:

  • Track their menstrual cycle
  • Log symptoms (bloating, acne, fatigue, etc.)
  • Access cycle-friendly meal plans
  • Track workouts and weight
  • Get personalized insights via the AI companion Maya

RITU is available in 12 countries:

  • India, United States, United Kingdom
  • Australia, Canada, Singapore, New Zealand, Ireland
  • South Africa, Philippines, Malaysia, Jamaica, Trinidad & Tobago, Ghana

This Privacy Policy applies to all users in all countries.

2. Information We Collect

A. Information You Provide Directly

Account information:

  • Email address
  • Password (encrypted, never stored in plain text)
  • First name (optional)
  • Profile picture (optional)

Health information (sensitive data):

  • Cycle start/end dates
  • Period flow (light/medium/heavy)
  • Symptoms (bloating, cramps, acne, mood swings, etc.) and severity
  • Weight (optional)
  • Workout type and duration

Food information:

  • Meal preferences (vegetarian, non-vegetarian, vegan, etc.)
  • Dietary restrictions (gluten-free, dairy-free, etc.)
  • Saved meal plans and grocery lists

Communication:

  • Messages sent to Maya (AI chat)
  • Support emails to contact@getritiu.in

B. Information Collected Automatically

  • Device information: device type, operating system version, app version
  • Usage information: features used, time and frequency of app usage, crash reports and error logs
  • Location information: NOT collected (we do not request location permissions)
  • Analytics: via Google Analytics — page views, session duration, user flow (anonymized)

C. Information From Third Parties

If you sign in with Google, we receive your email address, name, and profile picture. We do not request access to your Google account data beyond this.

We do NOT collect data from: social media accounts, health devices (Apple Watch, Fitbit, Oura Ring), third-party health apps, or your contacts, calendar, or photos.

3. How We Use Your Information

Providing RITU services:

  • Generate personalized cycle insights
  • Suggest cycle-friendly meals
  • Track your health patterns over time
  • Power the Maya AI companion
  • Send cycle reminders and notifications

Improving RITU: analyze usage patterns (anonymized), identify and fix bugs, improve performance, develop new features.

Communication: account notifications (cycle reminders, app updates), support responses, product updates (opt-in).

Legal compliance: comply with data protection laws, enforce our Terms & Conditions, respond to legal requests.

Security & safety: detect and prevent fraud, protect against unauthorized access, maintain app security.

We do NOT:

  • Sell your data to advertisers
  • Share your health information with third parties
  • Use your data for marketing without consent
  • Profile you for targeted advertising
  • Share cycle/symptom data with anyone else

4. Data Security & Protection

We take the security of your personal health information very seriously.

Encryption:

  • All data is encrypted in transit using TLS 1.2+
  • Sensitive health data is encrypted at rest using AES-256
  • Your password is hashed and salted, never stored in plain text

Access control: only authorized RITU team members can access your data; access is logged and monitored; API keys and secrets are rotated regularly.

Storage: data is stored on enterprise-grade PostgreSQL infrastructure with SOC 2-aligned controls, in the South Asia (Mumbai) region. Automatic daily backups are encrypted and retained for 30 days.

Security audits: we conduct periodic security reviews, monitor for vulnerabilities, and welcome responsible disclosure at contact@getritiu.in.

Limitations: while we implement industry-standard security measures, no system is 100% secure. If you suspect a security breach, contact us immediately at contact@getritiu.in.

5. Your Privacy Rights (by Country)

The following rights apply to residents of specific countries. If you are unsure which applies, scroll to your country section. For all requests, contact contact@getritiu.in.

Australia — Privacy Act 1988

  • Right to access: request a copy of your personal data
  • Right to correction: request correction of inaccurate data
  • Right to complaint: lodge a complaint with the Office of the Australian Information Commissioner (OAIC)

If your data is breached, we will notify you as required by the Privacy Act. Data storage location: South Asia (Mumbai).

Canada — PIPEDA

  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to withdraw consent to data processing
  • Right to complain to the Office of the Privacy Commissioner of Canada (OPC)

We collect your health data only with your explicit consent. You may withdraw this consent at any time by deleting your account. Data storage location: South Asia (Mumbai).

Singapore — PDPA

  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to opt out of marketing communications
  • Right to complain to the Personal Data Protection Commission (PDPC)

Your health data is treated as sensitive personal data. We require your explicit consent to collect and process it. Data storage location: South Asia (Mumbai).

New Zealand — Privacy Act 2020

  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to complain to the Office of the Privacy Commissioner

We comply with the 13 Privacy Principles outlined in New Zealand's Privacy Act 2020, including collection, use, disclosure, data quality, and data security. Data storage location: South Asia (Mumbai).

Ireland & EU — GDPR

Your rights under GDPR Articles 12–22:

  • Right of access (Art. 15): request a copy of your data
  • Right to rectification (Art. 16): correct inaccurate data
  • Right to erasure (Art. 17): request permanent deletion ("Right to be Forgotten")
  • Right to restrict processing (Art. 18)
  • Right to data portability (Art. 20): get your data in a portable format
  • Right to object (Art. 21)
  • Rights related to automated decision making (Art. 22)

Legal basis for processing: we process your personal health data based on your explicit consent (GDPR Art. 6(1)(a) and Art. 9(2)(a)). You may withdraw consent at any time.

International data transfers: your data is transferred outside the EU to South Asia (Mumbai) under Standard Contractual Clauses (SCCs) to ensure adequate protection.

Complaints: you have the right to lodge a complaint with your national Data Protection Authority. Data Protection Officer contact: contact@getritiu.in.

South Africa — POPIA

  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to erasure of your data
  • Right to complain to the Information Regulator

We implement appropriate, reasonable technical and organizational security measures to protect your data. Data storage location: South Asia (Mumbai).

Philippines — Data Privacy Act (DPA) of 2012

  • Right to be informed about data collection
  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to dispute the processing of your data
  • Right to erasure of your data
  • Right to complain to the National Privacy Commission (NPC)

Your health data is treated as sensitive personal information under the DPA. We require your explicit consent to collect it. Data storage location: South Asia (Mumbai).

Malaysia — PDPA 2010

  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to erasure of your data
  • Right to complain to the Personal Data Protection Commissioner

We collect your health data with your explicit consent. You may withdraw consent by deleting your account. Data storage location: South Asia (Mumbai).

Jamaica — Commonwealth Privacy Principles

  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to erasure of your data
  • Right to lodge a privacy complaint

RITU commits to international data protection best practices and Commonwealth privacy principles. Data storage location: South Asia (Mumbai).

Trinidad & Tobago — Commonwealth Privacy Principles

  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to erasure of your data
  • Right to lodge a privacy complaint

RITU commits to protecting your privacy in accordance with Commonwealth privacy best practices and international data protection standards. Data storage location: South Asia (Mumbai).

Ghana — ECOWAS Data Protection Framework

  • Right to access your personal data
  • Right to correction of inaccurate data
  • Right to erasure of your data
  • Right to lodge a complaint

RITU complies with the ECOWAS Supplementary Act A/SA.1/01/10 on Data Protection and Privacy (2010). Data storage location: South Asia (Mumbai).

India, United Kingdom & United States

  • Right to access, correct, and delete your personal data at any time
  • Right to export your data in a portable format
  • Right to withdraw consent by deleting your account
  • India: rights under the DPDP Act 2023, including grievance redressal via contact@getritiu.in
  • UK: rights under UK GDPR, including complaint to the ICO

6. Data Retention & Deletion

Active accounts: while your account is active, we retain your personal data (cycle logs, symptom data, meal plans, profile info) so the app works.

Deleted accounts: when you delete your account, your personal data is permanently deleted within 30 days. We keep only a hashed audit record for legal compliance.

Backups: we maintain encrypted daily backups for disaster recovery, retained for a maximum of 30 days. Deleted data is also purged from backups within 30 days.

How to delete your data:

  1. In-app: go to Settings → Privacy & Data → Delete Account, confirm your email.
  2. Email: send "Delete My Account" to contact@getritiu.in. We will delete your account and data within 30 days and confirm by email.

Legal retention: in some cases we may retain anonymized or hashed data for legal compliance (audit trails, transaction records) and fraud prevention, as required by law.

7. Third-Party Sharing

We do NOT share your personal health data with: advertisers, marketing partners, social media companies, data brokers, insurance companies, or employers.

We DO share limited data with:

  • Service providers (under data processing agreements): cloud database & storage, Google Analytics (anonymized usage analytics), AI providers powering Maya, and email service providers. These providers are contractually bound to protect your data.
  • Legal compliance: law enforcement (only with court order) or government agencies (only with legal authority), as required by law.
  • Data breach disclosure: if your data is breached, we will notify you and disclose only what's necessary.

By using RITU, you consent to data storage on our cloud infrastructure, anonymized analytics via Google Analytics, and email confirmations and support communications. You do NOT consent to any other third-party sharing.

8. Children's Privacy

RITU is designed for women aged 18 and above. We do not knowingly collect data from anyone under 18.

  • At sign-up, users must confirm they are at least 18 years old.
  • If you are under 18, you cannot create a RITU account. If you have created one, please delete it immediately.
  • If we discover we have collected data from someone under 18, we will delete that account and all associated data immediately.
  • If you believe your child has created a RITU account, contact us immediately: contact@getritiu.in.

9. Changes to This Policy

We may update this Privacy Policy to reflect changes in our data practices, new legal requirements, or improvements to privacy protections.

  • We will update the "Last Updated" date at the top.
  • For material changes, we will notify users via email or in-app notice.
  • Continued use of RITU after changes constitutes acceptance.

You can always view the current version at getritiu.in/privacy.

10. Contact Us

If you have questions about this Privacy Policy or want to request access to your data, request deletion, file a privacy complaint, or report a security issue:

We will respond to your request within 15 business days.

For GDPR complaints (Ireland/EU residents): you may contact your national Data Protection Authority (e.g. the Data Protection Commission, dataprotection.ie).