⚠️ NOT A MEDICAL APP: Ryzo is a self-improvement tool only. It is NOT a therapy service, medical device, or substitute for professional care. If you are in crisis, contact emergency services.

🧠 Ryzo Privacy Policy

Your mental performance journey, handled with full transparency.

Effective: March 5, 2026 Β· Version 1.2

Table of Contents

  1. About Ryzo
  2. Medical Disclaimer
  3. Data We Collect
  4. How We Use Your Data
  5. Third-Party Services
  6. Data Sharing
  7. Data Storage & Security
  8. Data Retention
  9. Your Rights (GDPR)
  10. Children's Privacy
  11. Subscriptions & Billing
  12. Account Deletion
  13. Policy Changes
  14. Contact Us

ℹ️ 1. About Ryzo

Ryzo ("we", "us", "our") is an AI-powered personal performance and mental wellness application developed by an independent developer. The app is available on Google Play (Android) and the Apple App Store (iOS).

Ryzo helps users track mood, energy, sleep, workouts, nutrition, habits, and goals β€” and provides AI-generated coaching, weekly performance scores, and insights to support personal growth.

Developer Contact: privacy@getryzo.app

🚨 2. Medical Disclaimer

⚠️ IMPORTANT β€” Please Read Before Using Ryzo is a self-improvement, habit-tracking, and motivational coaching tool. It is NOT a medical device, clinical mental health service, therapy platform, or substitute for professional psychological or psychiatric care.

Ryzo complies with Google Play's Health & Wellness category guidelines and does not make clinical claims.

πŸ“‹ 3. Data We Collect

3.1 Account Data (Required)

Data TypePurposeRequired?
Email addressAccount creation, login, password resetYes
Display namePersonalised greeting & performance score cardOptional
Password (bcrypt hashed)Authentication β€” never stored in plain textYes
Google Account (if Sign-In used)OAuth authentication only β€” we receive email & nameOptional

3.2 Wellness & Performance Data (User-Entered)

πŸ“Œ All wellness data is self-reported and entered voluntarily. Ryzo does not collect clinical measurements, medical records, or data from health wearables. This data is not used for medical diagnosis or treatment.
Data TypeExamplesPurpose
Daily check-in (mood, energy, stress)1–5 self-reported scalesProgress tracking, AI coaching, Weekly Scoreβ„’
Sleep hours & qualityUser-entered hours per nightPerformance score, AI insights
Water intakeNumber of glasses per dayHealth tracking
Workout logsSession type, exercises, sets, reps, weight (kg)Fitness tracking, PRs, weekly stats
Nutrition logsMeals, calories, macros (protein/carbs/fat)Nutrition tracking
Journal entriesFree-text personal reflectionsPersonal journaling, AI analysis (opt-in)
Micro-journal entriesQuick mood + text snapshotsPattern tracking
Habits & GoalsHabit names, completion dates, goal milestonesHabit tracking, gamification
Mindset assessment scores6-question self-assessmentPersonalised AI recommendations
AI chat messagesText conversations with the AI coachAI response generation & history
Life Timeline eventsUser-created personal milestonesPersonal growth tracking
Weekly Performance Scoreβ„’Computed score (0–100) from check-ins, mood, sleep, workouts, streakProgress visualisation, shareable card
Gamification dataXP, level, streak, badges, daily challengesEngagement & motivation

3.3 Technical Data (Automatic)

Data TypePurpose
Device type & OS versionBug fixing & compatibility
App versionFeature rollout, OTA update management
Push notification tokenSending scheduled reminders (opt-in)
Session timestampsSecurity & rate limiting
IP address (transient)API security, fraud prevention
πŸ“΅ We do NOT collect: Precise GPS location Β· Camera or microphone data Β· Contacts or call logs Β· Biometric data Β· Payment card details Β· Social media credentials Β· Screen content outside the app

βš™οΈ 4. How We Use Your Data

Legal basis (GDPR Art. 6): performance of contract (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)), and explicit consent for sensitive wellness data (Art. 9(2)(a)).

πŸ”— 5. Third-Party Services

ServicePurposeData SharedPrivacy Policy
Supabase
(EU – Frankfurt)
Database & authentication Email, hashed password, all wellness data supabase.com/privacy
OpenAI
(USA – Data Processor)
AI coaching response generation Chat text only β€” no email, no name, no user ID. Transfer via SCCs (GDPR Art. 46) openai.com/privacy
Google Sign-In
(OAuth – coming soon)
Optional authentication method (planned feature – not yet active) Will collect email & display name only (OAuth token) β€” no data collected currently policies.google.com
Vercel
(Edge Network)
API hosting / serverless backend Server-side request logs (IP, timestamps) vercel.com/legal
Google Play Billing Subscription payments (Android) Purchase token, subscription status policies.google.com
Apple App Store
(planned)
Subscription payments (iOS) Purchase receipt apple.com/legal/privacy
RevenueCat
(USA – IAP SDK)
In-app purchase & subscription management (Android & iOS) Purchase token, subscription status, app user ID (anonymous) β€” no personal data shared revenuecat.com/privacy
Expo / EAS App build & OTA update delivery No personal user data β€” build/update metadata only expo.dev/privacy
πŸ‡ͺπŸ‡Ί OpenAI Data Processor Compliance: OpenAI acts as our data processor (GDPR Art. 28). Chat messages contain no personal identifiers. Cross-border transfer is lawful under Standard Contractual Clauses. API data is not used to train OpenAI models.

🀝 6. Data Sharing

We never sell your personal data to any third party.

πŸ”’ 7. Data Storage & Security

⚠️ No system is 100% secure. In the event of a breach, we will notify affected users within 72 hours per GDPR Art. 33.

πŸ“… 8. Data Retention

Data TypeRetention Period
Account data (email, name)Until account deletion
Wellness & performance dataUntil account deletion
AI chat logs90 days (then anonymised)
Push notification tokensUntil revoked or account deleted
Server / access logs30 days
Billing records7 years (legal requirement)
Anonymised analyticsIndefinitely (no personal data)

βš–οΈ 9. Your Rights (GDPR)

As a user in the European Economic Area, you have the following rights:

πŸ‘οΈ

Access

Request a copy of all data we hold about you.

✏️

Rectification

Correct inaccurate or incomplete data.

πŸ—‘οΈ

Erasure

Request deletion of your account and all data.

⏸️

Restriction

Limit how we process your data.

πŸ“¦

Portability

Receive your data in JSON/CSV format.

🚫

Object

Object to processing based on legitimate interests.

↩️

Withdraw Consent

Revoke consent at any time.

πŸ“£

Lodge Complaint

Contact your national Data Protection Authority.

To exercise any right: privacy@getryzo.app β€” we respond within 30 days.

πŸ‘Ά 10. Children's Privacy

Ryzo is intended for users aged 13 and older.

πŸ’³ 11. Subscriptions & Billing

PlanFeaturesPrice
Free3 AI conversations/day, daily check-in, 7-day history, basic habits & goals€0
Premium MonthlyUnlimited AI coaching, full 30-day history, Weekly Performance Scoreβ„’, advanced analytics, AI Trainer, AI Nutritionist, priority support€9.99/month
Premium AnnualAll Premium features β€” best value€89/year (~€7.42/month Β· save ~26%)

πŸ—‘οΈ 12. Account Deletion

You can delete your account and all data at any time:

Upon deletion we permanently erase: email, name, all wellness data, chat logs, performance scores, habits, journal entries, and assessment history. Anonymised aggregated stats may be retained. Billing records retained 7 years (legal requirement).

πŸ”— Direct deletion link (accessible without the app, as required by Google Play):
https://getryzo.app/delete-account
Works even after uninstalling. Requests processed within 30 days.

πŸ“ 13. Policy Changes

When we update this policy:

Version history: v1.0 (Feb 24, 2026) β€” initial release. v1.1 (Mar 4, 2026) β€” added Google Sign-In (planned), Weekly Performance Scoreβ„’, local AsyncStorage data, Expo/EAS, nutrition & workout tracking details. v1.2 (Mar 5, 2026) β€” added RevenueCat, annual subscription plan, clarified Google Sign-In as coming soon, updated third-party table.

πŸ“¬ 14. Contact Us

ChannelDetails
Privacy & GDPRprivacy@getryzo.app
General supportsupport@getryzo.app
Response time30 days for GDPR requests Β· 2 business days for support