Privacy Policy

Effective 10 July 2026 · Last updated 26 August 2026
Beta version. A full postal contact address and a lawyer review will be added before public launch. Ryvelo processes self-reported mood data and personal reflections.

Ryvelo ("Ryvelo", "we", "us") is a personal-development app that helps you set goals, track daily progress, journal, and receive guidance from an AI mentor. This policy explains what we collect, why, who we share it with, and your choices and rights.

The data controller is Tudor Prodan (sole trader), Romania. Contact us at tudorprodan61@gmail.com.

1. The short version

2. What we collect

DataWhy we need it
Email addressTo create and secure your account and sign you in
PasswordStored only as a one-way hash (bcrypt); we never see the plain text
Display name (optional)To address you personally
Goals, milestones, progressThe core of the app — kept in sync across your devices
Daily check-ins (mood, confidence, productivity, 1–5)To show trends and streaks and inform your weekly review
Subscription statusTo unlock paid features and honour your plan
Workouts you record (exercises, sets, weights, reps, cardio, personal records)To keep a training history and recognise a record when you set one
Food you log (items, portions, calories and macros, and any food you save yourself)To total your day against the targets you set
Settings (timezone, region, notification preferences)To schedule reminders and tailor the experience

Training and food entries are ordinary account data here, kept and deleted exactly like your goals — but they say something about your body, so they are worth naming rather than folding into "the core of the app". They are never shown to anybody else, never part of a shared moment, and never sent to Apple Health, Google Fit, or any other service.

Journal entries

We store your journal entries. They are saved to your account so they survive losing or replacing your phone, and they are encrypted at rest on your device as well. This is a change: earlier versions of Ryvelo kept entries on the device only and never sent them to us. That meant reinstalling the app destroyed them permanently, which we decided was the worse outcome for the most personal thing you write here.

What this means in practice: our staff could technically access entries stored on our infrastructure, in the same way we could access your goals or check-ins. We limit that access to what running the service requires, we do not read entries for any other purpose, and we never use them to train AI models. You can delete any entry, or your whole account, from inside the app at any time — deleting removes it from our servers too.

Photos — both the proof photos attached to a goal and the Proud Moments you save — are stored on your device, encrypted at rest, and backed up to your account by default so they survive losing or replacing your phone. The copies live in private object storage (Cloudflare R2), encrypted in transit and at rest, and are reachable only through short-lived links issued to your signed-in account.

You can switch Back up photos off in Settings at any time. Doing so deletes every copy we hold, and nothing further is uploaded — your photos then live only on your device, and losing that device loses them. Deleting your account also erases the stored copies.

Friends, your profile, and what other people can see

Ryvelo has an optional social side. None of it is on unless you use it, and using it changes what other people can see about you — so this section is specific about which parts leave your account.

WhatWho can see it
Username (unique), name, bio, profile pictureAnyone signed in who can find you, and anyone who opens your invite link
Your invite page at api.getryvelo.com/u/<username>Anyone on the internet — it shows your name and username only, so a person you invite can see who invited them. Turning off "Let others find me" unpublishes it.
Friend list, friend requestsOnly you. We do not show your friends to your friends.
Interests you pickOnly you, plus the count of interests you have in common with someone. The group marked "Just for you" is never shown to anyone else, never used to suggest people, and never counted in a shared-interest list.
Moments you share (a kept goal, a photo, a Proud Moment)Only the friends you sent it to. You can take a shared moment back at any time, which stops everyone from opening it.
Messages in a one-to-one conversationOnly the friend you sent them to. Nobody can message you without being your friend first.
Messages in a groupEveryone in that group — up to twenty people. Somebody has to be your friend to add you, but the others in the room need not be friends of yours, and they see everything sent there from the moment you are added. Leaving a group stops you seeing it; it does not withdraw what you already said.
Whether you have read a messageThe sender, if you both have read receipts on. The switch is reciprocal: turning yours off hides theirs from you as well. In a group, two ticks mean everyone has read it.
Thoughts (your one-line note) and music you shareYour friends, and only while they are up — a thought disappears after 24 hours.

Nothing about your days is shared automatically. Friends never see your streak, your goals, your check-ins, your journal or your photos unless you deliberately send a specific moment to them. Your journal and your mentor's reflections are never shareable in any form.

A shared photo stays in our private storage; friends read it through a short-lived link that stops working when you revoke the share, unfriend the person, block them, or delete the moment.

Messages, groups, thoughts and music

We store your messages. Conversations — one-to-one and group — are kept on our servers so they survive losing or replacing your phone. They are encrypted in transit and at rest, but they are not end-to-end encrypted: our staff could technically access them, in the same way we could access your goals or your journal. We limit that access to what running the service requires, we do not read messages for any other purpose, and we never use them to train AI models.

Messages are not scanned. We do not run automated checks over private conversations, and that includes pictures and stickers you send to a friend — the same position iMessage, WhatsApp and Signal take for one-to-one messages. A message is only ever read by a person here if somebody in that conversation reports it — and reporting captures a copy at that moment, so deleting a message afterwards does not remove it from the report.

Groups. A group holds up to twenty people and a record of who is in it, when they joined and when they left. Whoever made it, and anyone they make an admin, can add people, remove them and rename it. A member's record is kept after they leave rather than deleted, so the conversation still shows who said what.

Pictures, clips, voice notes and stickers in chat. A voice note is a recording of your voice and a clip is a recording of whatever you pointed the camera at; both are personal data of a kind a typed message is not, so they are worth naming separately. All of it is stored in the same private object storage as your photos and reached only through short-lived links issued to a signed-in member of that conversation. A sticker is referenced by id, so removing one takes it out of every conversation you ever sent it to at once. When an image is taken down — by you or by us after a report — it stops being visible to everyone immediately, but the file itself is kept for a period afterwards so that a report, or a legal request, still has something to examine. Profile pictures and photos you share as moments are still checked automatically before anyone sees them; these are not.

View-once photos and clips are enforced on our servers rather than in the app: the link is never part of the message, and asking for it is the act that spends it. We still hold the file for the retention period described in section 7 — "view once" is a rule about who may open it, not a promise that the bytes disappear the moment they are seen.

The camera and the microphone. The app asks for them only where they are used — the in-app camera, and holding the microphone to record a voice note. Nothing is captured in the background, and nothing is captured before you press.

Deleting a message removes its text for everyone in that conversation. Deleting your account removes your conversations entirely.

Thoughts — the one-line notes you can post — are visible to your friends for 24 hours and then stop being shown. Music you share is a link and its title, artist and artwork; we never host or store audio, and tapping a track opens it in whichever app you already use. Both stop being shown after 24 hours, both can be taken down sooner at any time, and both are checked automatically before other people see them, the same as a profile or a caption.

Notifications from other people

If you turn on notifications from friends, we send the sender's name and a short preview of the message through Expo's push service, which passes it to Apple or Google for delivery to your device. Only that preview travels this way — never a whole conversation. You can switch From your friends off in Settings, and quiet hours apply to it.

Email we send you

Ryvelo sends you email in two situations only: the code that confirms your address when you sign up, and the code that resets your password if you ask for one. There is no newsletter, no marketing, and nothing you have to unsubscribe from. Those messages are delivered by Resend, which necessarily sees your email address and the message itself; it is listed in section 5 with everyone else who handles your data.

Reports and moderation

If someone reports content, we keep a record of the report, who filed it, and a copy of what was reported — including a copy of content that is later edited or deleted, because otherwise the evidence would be gone before we could look at it. We keep these records after a report is resolved so that repeat behaviour can be recognised.

Profile text and pictures, and photos at the moment you share them, are checked automatically by Anthropic's model before other people can see them. Photos you never share are never sent for checking.

Usage counts

To learn which parts of Ryvelo are actually used, the app sends a small, fixed set of anonymous counts — that a goal was created, a promise kept, a workout finished, a food logged, a screen opened. These are processed by PostHog on servers in the European Union, and are tied to your account's internal identifier, never your name or email address.

What is never included: anything you write or record. No journal text, no goal or food names, no notes, no photos, no messages, no search terms. The counts say that something happened and nothing about what it was — there is no field in which your words could travel, and the app contains no analytics SDK that could collect more on its own.

You can switch Help improve Ryvelo off in Settings at any time and nothing further is counted.

Data we do not collect

We do not collect your contacts, precise location, browsing history, or advertising identifiers. We run no advertising, we do not track you across other apps or websites, and we never sell your data.

3. AI mentor features

Some paid features are powered by Anthropic (the maker of Claude):

What travels with a request, besides what you asked about. A mentor that knows nothing about you can only give advice that would suit anybody, so each of the three requests above also carries a short account of who it is speaking to: your first name if you gave one, how long you have used Ryvelo, the focus you picked, your current streak, the titles and stated reasons of your active goals, your check-in scores for the last fortnight, the derived tags described above, and the gist of the last thing the mentor told you.

All of it is data you have already given us for the app to work, it goes only to Anthropic, only for the length of that one request, and only when you ask for a reflection, a review or advice. It never carries the text of another journal entry — the derived tags are labels, which is the entire reason they exist.

Anthropic processes this data as our sub-processor and, under its commercial terms, does not use it to train its models. If you never use AI features, none of this is ever transmitted.

4. How we use your data

To provide, maintain and secure the app; sync your goals, progress and check-ins; calculate streaks and trends; generate AI guidance when you request it; schedule reminders you turn on; manage your trial and subscription; respond to support; and comply with legal obligations.

Legal bases (GDPR Art. 6): performance of our contract with you, your consent (optional AI features and notifications), and our legitimate interests (security). Where mood or reflection data is treated as special-category data, we rely on your explicit consent (Art. 9). We do not make solely-automated decisions with legal or similarly significant effects.

5. Who we share it with

ProviderPurpose
Railway (application hosting, EU)Runs the Ryvelo server itself — every request passes through it
Neon (database hosting, EU)Stores your account, goals, check-ins, journal entries, subscription status
Anthropic (Claude API)Generates AI reflections/reviews when you use those features
RevenueCatManages subscriptions and receipts
Apple App Store / Google PlayProcess your payment under their own policies
Sentry (EU)Error monitoring so we can fix crashes
Cloudflare R2 (EU)Private storage for your photos and profile picture
Anthropic (Claude API)Also checks profile text, profile pictures and shared photos before other people see them
PostHog (EU)Counts which features are used — see "Usage counts" above. Never your words.
Expo (push delivery)Passes a notification to Apple or Google for delivery to your phone
Resend (email delivery)Delivers the few emails we send you — your confirmation code and your password reset code. It sees your email address and the message.

We may also disclose data if required by law or as part of a business transfer (with notice). We never sell your personal data.

6. International transfers

Our providers may process data outside your country. Where required, transfers are covered by appropriate safeguards such as the EU Standard Contractual Clauses. Our database is hosted in the EU.

7. How long we keep it

Account and growth data are kept while your account is active. When you delete your account, we permanently erase this data (a cascading delete), except anything we must retain for legal reasons. Journal entries are erased with your account in the same cascading delete, and you can delete any single entry at any time. Photos are backed up to your account unless you switched that off, and those stored copies are erased with your account too; a photo you delete in the app is removed from the backup as well.

What you said in a group stays in the group. Leaving one does not withdraw your messages, and deleting your account removes the conversation from your side without erasing what the other members were already shown — in the same way a letter you have sent is not yours to take back. You can delete any single message you sent, which removes it for everyone.

Moderation records are the exception. When content is reported, the report and the copy of what was reported are kept after the matter is resolved, so that repeated behaviour can be recognised and so we can show what we did if we are asked. A username you release is also held for 90 days before anyone else can take it, so that nobody can take over a name people knew you by.

8. Your rights

You have the right to access, correct, export, delete, restrict, or object to the processing of your data, and to withdraw consent. You can export your data and delete your account instantly in Settings. For anything else, email tudorprodan61@gmail.com; we respond within 30 days. EEA/UK users may complain to their local data-protection authority.

9. Security

Traffic is encrypted in transit (HTTPS/TLS). Passwords are stored only as salted one-way hashes. Journal entries and proof photos are encrypted at rest on your device using a key held in your device's secure keychain, and journal entries stored on our servers sit in an encrypted database. Unless you switch photo backup off, the stored copies sit in private object storage, encrypted at rest, reachable only through short-lived links issued to your signed-in account; pictures, clips and voice notes sent in a conversation sit in the same storage under the same rules. We limit access to production data, but no system is perfectly secure.

10. Children

Ryvelo is not directed to children. You must be at least 16 (or the age of digital consent in your country) to use it. We do not knowingly collect data from children below that age; if we learn we have, we delete it.

The social features — friends, profiles and sharing — are additionally limited to people aged 13 or over everywhere, and to 16 or over wherever that is the age of digital consent. They also sit behind a paid subscription, which means an adult payment method, and that is deliberate: it is the strongest practical barrier we have against throwaway accounts.

11. Changes

We may update this policy as the app evolves. If we make a material change, we will notify you in the app or by email before it takes effect.

12. Contact

Tudor Prodan (sole trader), Romania · tudorprodan61@gmail.com