Effective date:
Who handles your data
Ritmelio is a service for professionals who work by appointment. For questions about your data or requests to access, correct or delete information, contact support@ritmelio.com.
This policy applies to the public website, early-access form, Telegram bot and Mini App, and Ritmelio’s Google Calendar integration.
Data we receive
We process only the data needed to provide the features you choose.
- Account and profile data: Telegram identifier, display name, username, language, time zone and preferences.
- Work data entered in Ritmelio: client details, schedules, sessions, notes, packages and payment records.
- Website request data: email, optional profession, form language, submission time, consent version and a separate broadcast preference.
- Technical data: error and security logs. A coded network identifier is retained for one hour to protect the website form from spam.
Google data Ritmelio receives
Connecting Google Calendar is optional. Ritmelio receives the connected Google Account email, OAuth tokens and granted permissions. We also retain the identifier and name of the separate calendar Ritmelio creates, identifiers of events created in it, and technical synchronization status.
Ritmelio requests openid, email and https://www.googleapis.com/auth/calendar.app.created. The last permission only allows access to calendars created by this application. Ritmelio does not read or change your personal calendar or any other existing calendars and events.
How we use Google data
Ritmelio uses access only for the user-facing feature you choose: it creates a separate calendar and performs one-way creation, updating or deletion of events when matching Ritmelio sessions change. Your email identifies the connected Google Account.
Data received through Google APIs is not used for advertising, credit decisions, data sales, advertising profiles, or training generalized AI or ML models.
Google API Services User Data Policy and Limited Use
Ritmelio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
We do not transfer Google data to third parties except infrastructure providers processing it on our behalf solely to provide synchronization, with the user’s separate consent, when legally required, or to investigate security abuse. Human access is permitted only with the user’s permission for support, when legally required, or when necessary for security and service operations.
Other purposes
- Providing Ritmelio features, authentication, support and responses to requests.
- Protecting accounts, preventing abuse, diagnosing errors and keeping the service reliable.
- Reviewing an early-access request. Broadcasts require separate consent.
- Complying with law and protecting the legitimate rights of users and the service.
Storage and security
Data is stored with access-controlled cloud infrastructure providers. In production, Google OAuth tokens are protected with application-level encryption; connections use HTTPS. Short-lived access tokens are refreshed using the refresh token.
We use organizational and technical safeguards, but no storage or transmission method can guarantee absolute security.
Retention and deletion
Google data and technical event links are retained while synchronization is enabled and needed. On disconnect, Ritmelio revokes the refresh token and removes stored credentials. The created calendar identifier and account email may remain to reuse the calendar after reconnection; you can ask us to remove them.
When disconnecting, you can also delete the calendar Ritmelio created. Otherwise, its events remain in your Google Account under your control. Early-access request data is retained for up to 12 months. Other data is retained while your account is active and as needed for the service, law, security or dispute resolution.
Your choices and rights
Disconnect Google Calendar in Ritmelio under Profile and settings → Synchronization. You can also revoke access on your Google Account permissions page. To request a copy, correction or deletion of Ritmelio data and residual integration metadata, contact us; we may need to verify your identity.
Delete a website request using the personal link shown after submission. Revoking Google access stops future synchronization but does not by itself delete data entered directly into Ritmelio.
International processing and policy changes
Infrastructure providers may process data in other countries with safeguards required by applicable law. We do not sell personal data.
For material changes, we will update the date and, when required, notify users or request renewed consent.