Privacy
Effective from 9/28/2026
Who processes your data
The controller of your personal data is Mgr. David Zažímal, a self-employed individual, company ID (IČO) 23198231, Czech Republic. RYTAVO is the name of the app he runs, not a separate company. No data protection officer has been appointed. Contact: zazimald@gmail.com.
What data we process
Your e-mail address, display name, language, appearance and sign-in details: the password only as a secure hash, the identifier of a connected Google or Facebook account, passkeys (public key) and, if two-factor authentication is on, the authenticator key and recovery codes. Also the content you enter into RYTAVO yourself – habits, entries, notes, photos, measurements, challenges, rhythms and sharing – and the e-mail of a person you invite to a group, if you fill it in.
Operational and security data
We record when and how your account was created, the time and method of each successful sign-in and, for each day, only the fact that you used RYTAVO – no tracking of pages, clicks or devices. For every request the web server writes the IP address, time, page address (without parameters and without invitation links) and browser identification into a technical log. Application logs contain the internal account ID and a shortened e-mail, never your content. We use no analytics, advertising or third-party tracking tools.
Confirmations and account access
For your account we store the time you confirmed you are at least 15 (no date of birth or other age information), the time and version of the Terms of Use you accepted, the time beta access was granted and, for accounts created with a beta invitation, the founding beta tester mark. For an invitation we record only a hash of the link, times and, once used, the internal ID of the account created – we do not store the tester's e-mail.
Request to join the beta and Lifetime Access
The "Join the beta" form stores the e-mail, the optional name and reason, the chosen language, the confirmation of interest in active testing and the times of submission and handling. Only the operator sees them and uses them only to decide about an invitation, to e-mail it and to send a short notice if we do not include the request; an invitation from a request is valid only for that e-mail (steps at your request, Art. 6(1)(b) GDPR). Against misuse the number of requests is briefly limited in the server's memory; we do not store the IP address with the request. For beta testers we evaluate from counts of active days, records and feedback (without content) whether they met the active tester criteria; Lifetime Access is granted by hand by the administrator, never automatically, and the account records when and by whom.
Feedback
When you send feedback (Profile → Feedback), we store its type, text, time, the app version, the language and the app page you write from (without parameters). We do not store the IP address, browser, device or location with it. Only the operator sees it, in the internal administration, and uses it only to improve RYTAVO (legitimate interest, Art. 6(1)(f) GDPR). It is part of your data export and is deleted together with the account.
Health data
Weight, body measurements, body fat, heart rate, taking medication and similar data are a special category of personal data. We process them only with your explicit consent (Art. 9(2)(a) GDPR), which is voluntary and not a condition of the account; we record its time and wording. Without consent RYTAVO does not offer the body presets of Measurements or the Medication icon, and it does not analyse the content of notes. You withdraw your consent under Profile → Health data: RYTAVO then irreversibly deletes the items that are clearly health data, and you can choose further Measurements to delete. Withdrawal does not affect processing before it.
Signing in with Google and Facebook
When you sign in with Google or Facebook, we only receive your identifier, e-mail and name from the service. We do not store passwords or access tokens of these services and never post anything on your behalf. Google and Meta process data as separate controllers under their own policies.
Why and on what legal basis
We process your account, sign-in, app features, the sharing you set up and account e-mails (confirmation, password reset, welcome, security notices) because they are necessary to provide the service you signed up for (Art. 6(1)(b) GDPR). Security, technical logs, backups, the record of deleted accounts, beta invitations and an internal operations overview during the beta (counts and account metadata, no content) are based on our legitimate interest in running RYTAVO securely and reliably and improving it (Art. 6(1)(f) GDPR); you can object to this. Health data only with your explicit consent (see above). We do not sell your data, use it for advertising or profiling, or make automated decisions about you. An e-mail address is required to create an account; everything else is voluntary.
Who has access to the data
Only the operator has access to the data. The server, database and e-mail delivery run at a hosting provider of the WEDOS group (WEDOS, a.s., Hluboká nad Vltavou) in the Czech Republic, which processes the data only for RYTAVO as a processor under its data processing agreement. We do not transfer data outside the EU/EEA. Content you share is visible only to the people in the group you share it with; copies they take over belong to them.
How long we keep data
- Account, profile and content: until you delete your account; deletion is immediate.
- Age confirmation, acceptance of the Terms of Use, consent to health data and its withdrawal: as long as the account exists.
- Sign-in history: 180 days.
- Record of days of use: 400 days.
- Beta invitations: used, revoked and expired ones 180 days.
- Requests to join the beta: 90 days after the last change (submission, decision, invitation sent); the account is not affected.
- Feedback: until you delete the account.
- Server and application technical logs: at most 15 days.
- Database backups: daily backups 7 days, pre-update backups at most 30 days.
- Record of a deleted account (only internal ID and time, no e-mail or content): 45 days, so the account does not return when a backup is restored.
- E-mails you send us: as long as needed to handle them.
Cookies and browser storage
We only use cookies necessary for signing in and protecting forms, and cookies that remember the language and appearance you chose. Browser storage remembers which "What's new" version you have seen, and the app stores its own files for offline use (no personal data). We use no analytics, advertising or tracking cookies, so we do not ask for cookie consent.
Your rights
You have the right to access, rectify and erase your data, to restrict processing, to data portability and to object to processing based on legitimate interest. You can withdraw your consent to health data at any time under Profile → Health data. You can correct most data directly in the app; you can download a complete copy of all your personal data and content as a ZIP file (machine-readable JSON) under Profile → Privacy and data → Download my data. For other requests, write to zazimald@gmail.com. We reply within one month at the latest. You can lodge a complaint with the Czech Office for Personal Data Protection (uoou.gov.cz).
Deleting your account and data
You can delete your account with all data yourself: Profile → Sign-in and security → Danger zone → Permanently delete account. Before deleting, we confirm your identity again (with your password or a connected Google or Facebook account). Deletion is immediate and irreversible – it also removes your sign-in history, record of days of use and two-factor authentication; copies others previously took over from your shared content stay with them. Database backups are deleted gradually (after 30 days at most) and a deleted account would not come back even after restoring a backup – for 45 days we keep only its internal ID and deletion time. If you cannot access your account, write from its e-mail address to zazimald@gmail.com and we will delete the data within 30 days. You can also revoke RYTAVO's access in your Google or Facebook account settings.
Contact
Data controller: Mgr. David Zažímal. Send questions about data protection to zazimald@gmail.com.