Rytho Privacy Policy
Last updated: August 5, 2026 · Türkçe
Rytho ("the App") is a mobile application offering a personal cosmic insight experience. This policy explains, under the Turkish Personal Data Protection Law (KVKK) and the EU General Data Protection Regulation (GDPR), what data we process and why, how long we keep it, and your rights.
1. Data we process and why
a) Account information
- What: Name, e-mail address and, if present, a profile photo (via e-mail, Google or Apple sign-in).
- Why: To create your account, authenticate your session and display your profile.
b) Birth data
- What: Birth date, time (if known), city and an optional gender field.
- Why: Astrology (natal chart), BaZi, I Ching context and daily readings can only be computed from this data. It is processed on our servers solely to produce your readings and stored in your profile. It is never shared with third parties for advertising or profiling.
c) Face reading (physiognomy) measurements
- What: When you explicitly consent to and use the face reading feature, numeric facial proportions measured ON YOUR DEVICE.
- IMPORTANT: Your face photo or camera image never leaves your device; it is not uploaded and not stored anywhere. Measurement happens entirely on your phone; only anonymous numeric ratios are sent to the server to produce the reading. The feature will not run without a separate biometric consent, which you can withdraw at any time.
d) Social data
- What: Your username, friend relationships, reactions chosen from a fixed closed set, and (if you enable it) your daily streak visibility.
- Why: To run the friends list, daily dyad reading and reactions. The App has no free-text posts, comments or direct messages; other users only ever see the limited fields above.
e) Phone number and contact matching (optional)
- What: If you verify your phone, an irreversible digest (SHA-256) of your number; if you ENABLE contact matching, digests of the numbers in your address book computed the same way.
- Why: So you can find your friends. Raw phone numbers are never stored on our servers; contact digests are processed transiently at match time only and are not saved. Names are never read from your address book.
f) Conversations and memory
- What: Your conversations with Rytho and short insights distilled from them.
- Why: So you can pick up where you left off and so readings get to know you. Conversations not opened for 30 days are deleted automatically.
g) Your diary entries
- What: Short free-text notes you choose to write in the "My Diary" feature.
- Why: So readings can connect to your life. Your notes are used only in YOUR chat and reading context, are never shown to other users, and are never used for advertising or profiling. You can delete entries individually in the app; deleting your account deletes them all.
h) Birth data of people you add ("My Circle")
- What: Birth date/time/city and relationship type for people you choose to add (partner, child, parent, etc.). The person's name is never sent to our servers — the name stays on your device only; the server record is kept under a relationship label such as "your partner" or "your child".
- Why: To compute that person's chart and the astrological measurement of your relationship. You enter this data yourself and informing that person is your responsibility; the records never enter any matching or search index, are never visible to other users, and are deleted when you remove the person or your account.
i) Technical data
- What: Crash reports (Firebase Crashlytics), anonymous usage events (Firebase Analytics), a push token (FCM), and purchase status (RevenueCat).
- Why: To improve stability, send notifications and recognise your subscription.
2. AI processing
Readings and chat replies are generated with the Google Gemini model. For that purpose your chart summary and questions are processed on Google Cloud infrastructure. Raw transcripts are not committed to long-term memory; only short distilled insights are kept. All output is for entertainment and personal insight; it is not medical, legal, financial or psychological advice.
3. Sub-processors
- Google Firebase (authentication, database, notifications, analytics, crash reports) — Google LLC
- Google Cloud Platform / Cloud Run (compute and AI service, us-central1 region) — Google LLC
- RevenueCat (subscription and purchase state; your payment card details go to Google Play / the App Store, never to us or RevenueCat) — RevenueCat, Inc.
Google's data processing terms: cloud.google.com/terms/data-processing-addendum
4. Retention
- Account and birth data: until your account is deleted.
- Face imagery: never collected (measurement is on-device; the server keeps only numeric ratios and the text reading).
- Conversations: deleted automatically 30 days after last open; all of them are deleted with your account.
- Social data: until you remove it or delete your account.
- Crash/analytics logs: Firebase's standard retention (raw data at most 90 days).
5. Your rights and data deletion
Under KVKK art. 11 and the GDPR you have the right to access, rectify, erase, object to processing and port your data.
Deletion: You can delete your account instantly in the App (Profile → Account → Delete account); this permanently removes all your data. You may also write from your registered e-mail address to aslan.mh@gmail.com; requests are resolved within 30 days.
6. Children's privacy
Rytho is not directed at users under 13. Accounts found to belong to children under 13 are deleted.
7. Changes
Updates to this policy are announced in the App. Questions: aslan.mh@gmail.com