Privacy Policy

Effective Date: November 28, 2025 | Last Updated: December 13, 2025

Introduction

Welcome to Rhythmicly ("we," "our," or "us"). We are committed to protecting your privacy and ensuring you have a positive experience when using our sleep tracking and circadian rhythm optimization app ("Service").

This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application. Please read this privacy policy carefully. If you do not agree with the terms of this privacy policy, please do not access the application.

Information We Collect

Personal Information You Provide

Health Data

Usage Data

Automatically Collected Information

How We Use Your Information

Primary Services

Service Improvement

Legal and Security

How Remi Uses AI

We use OpenAI's services to power Remi, your AI sleep companion. Here's exactly how different types of data are handled:

Your Health Data (Always Anonymized)

Your sleep data from Apple Health is never sent in raw form to any third party. Before any AI processing:

We never share: Your exact bedtimes, precise wake times, or raw HealthKit data with OpenAI or any third party.

Your Conversations with Remi (Processed by OpenAI)

When you talk to Remi via voice or text, your conversation is processed by OpenAI's AI services:

Voice mode:

Text chat:

Why we do this: Sending your full conversational context allows Remi to understand your unique situation—your family, work schedule, stress factors—and give you genuinely helpful, personalized sleep guidance. A scrubbed, sanitized conversation would make Remi generic and unhelpful.

Your Protection

Your data is never used to train AI. OpenAI does not use your conversations or voice recordings to train their models. Your data is processed and then deleted under their Zero Data Retention policy.

What Stays Private

Data Sent to OpenAI

Data NOT Sent to OpenAI

OpenAI Data Handling

Your Control

Other Integrated Services

Third-Party Privacy Policies

We recommend reviewing these third-party privacy policies:

Information Sharing and Disclosure

We DO NOT Sell Your Data

We do not sell, rent, or trade your personal information to third parties for marketing purposes.

Limited Sharing

We may share your information only in these specific circumstances:

Service Providers: With trusted third-party providers who help us operate our service:

Legal Requirements: When required by law, regulation, or legal process, or to protect the rights, property, or safety of Rhythmicly, our users, or others.

Business Transfers: In connection with a merger, acquisition, or sale of assets (users will be notified of any changes).

With Your Consent: Any other sharing will only occur with your explicit consent.

Data Security

Security Measures

We implement industry-standard security measures to protect your information:

Your Health Data

Your Privacy Rights

Access and Control

You have the right to:

How to Exercise Your Rights

Contact us at colton@rhythmicly.com to exercise any of these rights. We will respond within 30 days.

AI and Chat Data Controls

You can:

Data Retention

Retention Periods

Voice Check-Ins

When you use voice features with Remi:

Account Deletion

When you delete your account:

Children's Privacy

Our service is not intended for children under 13 years old. We do not knowingly collect personal information from children under 13. If we learn we have collected information from a child under 13, we will delete it immediately.

International Data Transfers

Your information may be processed in countries other than your own, including:

We ensure appropriate safeguards are in place to protect your data during international transfers.

Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will:

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us:

Regulatory Compliance

CCPA (California)

California residents have additional rights under the California Consumer Privacy Act (CCPA). Contact us for details about exercising these rights.

GDPR (European Union)

EU residents have rights under the General Data Protection Regulation (GDPR). We are committed to compliance with GDPR requirements.

HIPAA

While we handle health-related data, we are not a covered entity under HIPAA. However, we apply similar security and privacy standards to protect your health information.