Privacy Policy for the Rhythm of Life Mobile App ("the App")
Last updated: August 2026
This Privacy Policy explains how Rhythm of Life Ltd ("Rhythm of Life", "we", "us", or "our") collects, uses, shares, and protects your personal information when you use our App (app.myrhythmoflife.net), visit our website, or otherwise engage with us.
RHYTHM OF LIFE LTD is a company registered in England and Wales. Our registered office is at 14 Lancaster Gardens, Wimbledon, London, England, SW19 5DG.
This Privacy Policy is governed by data protection regulation applicable to your region. In the UK this is under UK GDPR, the Data Protection Act 2018 and the Data Use and Access Act 2025.
We are registered as a data controller with the UK Information Commissioner's Office (ICO): our registration number is ZC221597.
We may update this policy from time to time. The most recent version will always be available at app.myrhythmoflife.net.
1. What This Notice Covers
This notice explains:
- What personal information we collect and how we get it
- How we use your information
- Who we may share it with
- How we keep it secure
- Your rights under UK data protection law
- How we will handle any complaint that you make
- How to contact us
2. What Personal Information We Collect
"Personal information" means any information from which we can identify you.
We may collect and process the following types of information:
a. Information you provide to us
This includes information you share when:
- Registering for an account on the App or signing up for our updates
- Contacting us directly by email, support forms, or in-app feedback
- Completing optional profile fields or surveys
Typical data includes:
- Account Data: Name, email address, and optional profile photo.
- Optional Profile Data: Gender, date of birth, and basic location (country, region, city, or postcode area).
- Activity & Routine Data: Daily check-ins, routine logs, general activity levels, and voluntary mobility notes.
- Communications: personal information contained in correspondence sent by you to hello@myrhythmoflife.net.
- Financial Data: Payment handling is processed directly by third-party payment gateways (e.g. Apple App Store, Google Play Store, or Stripe). We do not store full credit card details on our systems.
b. Information collected automatically
When you use our App or website, our infrastructure (including Cloudflare and Supabase) automatically collects technical telemetry:
- Device type, operating system version, browser type, and IP address.
- Application diagnostic logs, performance metrics, and crash reports.
- Email open rates or link clicks from transactional communications.
- Analytics events and Meta Pixel conversion data (collected only where you have given explicit prior consent via our cookie/privacy controls).
c. Information from third parties
We do not currently purchase or routinely receive background personal data about you from external third-party data brokers or marketing partners. We receive download, purchase and subscription information from the Apple App and Google Play Stores.
3. How We Use Your Information
We use your personal information to:
- Deliver our services, including running your account, enable you to track your activity habits, and personalising your movement and routine plans.
- Respond to enquiries, feedback, and customer support requests.
- Maintain, secure, and improve the performance of the App and platform.
- Compile aggregated, fully anonymised statistical reports (e.g., regional user numbers) to build local coaching networks and community meetups. This data never identifies you individually.
- Send direct marketing and product updates (only where you have ticked the box to opt in).
- Prevent fraudulent activity, ensure network security, and comply with legal or regulatory obligations.
We do not use your personal data for automated decision-making or profiling that produces legal or similarly significant effects.
4. Legal Bases for Processing
Under UK GDPR, we rely on the following legal bases to process your personal data:
- Contract: To establish your account, provide core App services, and fulfil our service agreement with you.
- Consent: For marketing emails, analytics cookies, Meta Pixel tracking, and processing any optional health-related notes (e.g. voluntary mobility logs). You can withdraw consent at any time via your in-app profile settings. Any health data (special category personal data) will be collected with your explicit consent.
- Legitimate Interests: To maintain App security, prevent fraud, measure technical reliability, and improve our services, balanced against your privacy rights.
- Legal Obligation: Where required by law to retain operational or accounting records.
5. Sharing Your Information
We will never sell your personal data.
We share your personal information only with trusted service providers who process data on our strict instructions under written Data Processing Agreements:
- Hosting & Platform Infrastructure: Lovable (app platform development), Cloudflare (hosting, security, CDN), and Supabase (database, file storage, and authentication).
- Communications Providers: Transactional email service providers (e.g. Resend) for account administration and password resets.
- Marketing & Analytics: Meta Platforms (Meta Pixel) — only where you have explicitly opted in.
- Professional Advisors & Authorities: Legal, tax, or regulatory bodies if strictly required by law or in connection with legal claims.
- Third Party Service Providers: we may provide third party services through our application in connection with our core functions and may be required to provide information related to your interests and intended purchases.
International Transfers
Where our service providers host or access data outside the UK or European Economic Area (EEA) — such as in the United States — we ensure appropriate legal safeguards are in place. These include the UK International Data Transfer Agreement (IDTA), EU Standard Contractual Clauses (SCCs) with the UK Addendum, or vendor certifications under the UK Extension to the EU-U.S. Data Privacy Framework.
International transfers are made as specified in the below table:
| Recipient | Destination | Safeguards |
|---|---|---|
| Cloudflare | Global | US DPF; EU SCCs + UK Addendum |
| Supabase Inc. | USA | EU SCCs + UK Addendum |
| Resend Inc. | USA | US DPF |
| Meta Platforms Inc. | USA | UK IDTA |
| Google LLC | USA | EU SCCs + UK Addendum |
| Lovable Labs | EU, USA | EU SCCs + UK Addendum |
6. Data Security and Retention
We apply robust technical and organisational security measures to protect your data, including Transport Layer Security (TLS) encryption in transit, AES-256 database encryption at rest, and strict database Row-Level Security (RLS).
Data Retention Limits:
- Active Accounts: Profile and log data are retained for as long as your account remains active.
- Account Erasure: When you delete your account via the App, your personal data is purged from live production databases within 30 days.
- Encrypted Backups: Residual encrypted backup files are automatically overwritten within 90 days.
- Anonymised Data: Fully anonymised statistics that cannot identify an individual may be retained indefinitely for analytical purposes.
- Payment records: may be required to be retained for up to six (6) years post account closure.
7. Your Rights and How to Contact Us
Under UK data protection law (and EU GDPR where applicable), you have the following rights:
- Access: Request a copy of the personal data we hold about you (available via the in-app "Download My Data" feature).
- Rectification: Request correction of inaccurate or incomplete data.
- Erasure: Request deletion of your account and personal data (available via "Delete My Account" in your profile).
- Restriction & Objection: Ask us to restrict or stop processing your data in certain circumstances.
- Data Portability: Receive your personal data in a structured, machine-readable format (JSON export).
- Withdrawal of Consent: Withdraw consent for marketing, pixels, or optional data processing at any time via your profile settings.
To exercise any of these rights, or if you have questions, please contact us at hello@myrhythmoflife.net.
8. Cookies and Tracking
We use cookies, local storage, and tracking pixels to:
- Essential Storage (Strictly Necessary): Keep you signed in securely and save core preferences. Always active.
- Analytics Storage: Measure aggregated, anonymous app metrics to improve performance. Active only with your consent.
- Marketing Pixels: Measure advertising conversions (Meta Pixel). Disabled by default; active only if you grant explicit consent.
You can update your cookie preferences at any time in the App under Profile > Your Data.
9. How We Will Handle Any Complaint That You Make
If you have a complaint about how we handle your personal data, please email us directly at hello@myrhythmoflife.net so we can resolve the issue.
We very much hope that you would contact us first so that we can sort out any concerns, but you also have the legal right to lodge a complaint at any time with the UK supervisory authority:
Information Commissioner's Office (ICO)
Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
Website: ico.org.uk | Telephone: 0303 123 1113
Last updated: August 2026