← Back to riymo

Privacy Policy

Last updated July 7, 2026

This Policy explains what Riymo collects, how we use and protect it, who we share it with, and the choices you have. We are built to collect only what we need to run the app, to keep your location coarse, and to never sell your personal data.

Information you provide

Account and identity: your email address, and your name. Others only ever see your first name and last initial; your full name is private. If you sign up with email you set a password (stored only as a secure hash by our authentication provider); if you use Apple or Google, we receive the basic profile details they return.

Date of birth: collected to verify you are at least 18 and kept private. It is never shown to other users.

Profile and rhythms: your bio, profile photo, your rhythms and sub-rhythms, the times you are usually active, your “base” spots, and any vibes you add.

Phone number (optional): if you add one, it is used only to help friends find you. It is converted to a one-way hash on your device and stored as that hash; we do not keep your phone number in plain text.

Content and activity: your presence (Sync) and rhythm moments (Drop) and any photos or notes attached to them, your plans, direct and crew messages, reactions, comments, follows, connections, Mutuals, the crews you join, and any blocks or reports you make.

Information collected automatically

Approximate location: if you grant permission, your location is coarsened on your device to a city or district area used for nearby matching. Precise GPS coordinates are not stored against your profile.

Contacts (optional): if you choose to find friends, phone numbers from your address book are normalized and hashed on your device, and only those one-way hashes are sent to check for matches. Your address book itself never leaves your phone, and the process is rate-limited.

Device and diagnostics: a push-notification token (if you enable notifications), your app version, platform, and operating system, and crash and error diagnostics that help us fix problems.

Usage analytics: basic product events (for example completing onboarding) so we can understand and improve the experience. These are stored in our own database, not shared with a third-party analytics company.

How we use your information

To run the core experience: match you with people who share your rhythms nearby, power presence, discovery, and messaging, and deliver the notifications you have opted into.

To keep the community safe: blocking, reporting, moderation, enforcing the 18+ requirement, and preventing abuse.

To maintain and improve the app, diagnose crashes and performance issues, and secure the service.

How we share your information

With other users: your profile and activity are visible to others according to your visibility settings (Incognito, Hide active hours, Pause location sharing). When you join or create a crew, its other members can see your membership and the messages you send to that crew. People you block cannot see or contact you, and people who have not finished onboarding do not appear to others.

With service providers who process data on our behalf under contract: Supabase (database, authentication, file storage, and realtime), Expo (push-notification delivery), Resend (sending account emails), Sentry (crash and error diagnostics), and OpenAI (automated content moderation of the photos you post). If you sign in with Apple or Google, those providers process your sign-in.

For legal and safety reasons when required by law, or to protect users, the public, or the service. We do not sell your personal data, and we do not use it for cross-app tracking or advertising.

Your choices and controls

Visibility: go Incognito, hide your active hours, and pause location sharing in Settings, Privacy and Safety.

Notifications: turn rhythm-match, direct-message, and other notification types on or off in Settings, Notifications, and in your device settings.

Permissions: location and contacts access can be changed or revoked in your device settings at any time. Blocking and your blocked list are managed in the app.

Access and deletion: you can delete your account and its data at any time (see below), and you can email us with any question or request about your data.

How we protect your information

Data is encrypted in transit using HTTPS/TLS. Access is enforced server-side with database Row-Level Security, so each person can reach only the data they are permitted to.

On your device, your session tokens are kept in the platform’s secure storage (Keychain / Keystore), and cached messages and photos are stored in an encrypted local database to make the app fast and work offline; you can wipe them anytime with Settings, Clear app cache.

Photos are stripped of embedded location and camera metadata (EXIF) on upload. We follow least-privilege access and retry-safe writes. No method of transmission or storage is completely secure, but we work to protect your information and to limit what we collect.

How long we keep it, and deletion

We keep your information while your account is active. When you delete your account (Settings, Delete account, which requires typing DELETE to confirm), we permanently delete your personal data, including your profile, rhythms, messages, connections, and your photos in storage, and end your session.

Accounts that never verify their email or never finish onboarding are removed automatically. Residual copies in routine backups age out on our standard cycle.

Children

Riymo is for adults. The service is not directed to anyone under 18, and the 18+ requirement is enforced at sign-up. If you believe someone under 18 has provided us personal data, contact us and we will remove it.

International transfers and changes

Your information may be processed in countries other than your own, with appropriate safeguards. We may update this Policy from time to time; if we make material changes we will announce them in the app or by email.

Contact us

Questions or requests about your data, including access or deletion? Email support@riymoapp.com.

This document reflects Riymo’s current data practices and is provided for transparency. It is not legal advice and is reviewed with counsel before launch.