In short: no Rutmia account is required. Rutmia does not advertise, sell, rent, or use cross-app tracking of personal data. Cloud assistance is optional; when cloud consent is off, requests remain on-device. Details marked [LEGAL INPUT NEEDED] must be completed before publication.
Version history
1.1 · August 15, 2026 · Revised to reflect local processing, optional cloud assistance, consent, iCloud, and Apple payments. Effective date: [LEGAL INPUT NEEDED: confirm].
1.0 · [LEGAL INPUT NEEDED: prior version date] · Previous text and change scope: [LEGAL INPUT NEEDED: confirm].
Who is responsible for your data
Rutmia is operated by [LEGAL INPUT NEEDED: full legal entity name]. The identity of the controller or responsible party, and any EU/UK representative or data protection contact that is required, are [LEGAL INPUT NEEDED: confirm and provide details].
For privacy questions, rights requests, or complaints, contact [LEGAL INPUT NEEDED: privacy contact email, postal address, and any required local contact].
What this Policy covers
This Policy covers the Rutmia app and the routine, habit, wellness, optional HealthKit, optional Calendar, iCloud sync, purchase, and AI features described in the app. It also covers this public website only to the extent confirmed below.
Rutmia does not require you to create a Rutmia account or provide an email address to use the app. Apple may process information through Apple services that you choose to use, such as your Apple account for iCloud or the App Store. Rutmia does not describe your iCloud identity as being sent to cloud AI unless that flow is separately verified.
Routine data stored and processed on your device
Your habit and routine data is primarily stored and processed on your device. This includes the routine information needed for the features you use, such as active habits, schedules, reminders, goals, and related settings. The complete on-device data inventory is [LEGAL INPUT NEEDED: confirm].
Rutmia does not use personal data for advertising, sell or rent personal data, or use cross-app tracking. Rutmia also does not create a separate Rutmia account profile for you.
Optional HealthKit and Calendar access
HealthKit and Calendar access is optional. When you grant a permission, Rutmia uses the permitted information only for the feature described in the app and you can turn the permission off in your device settings.
Rutmia’s on-device handling of HealthKit and Calendar information is the default description in this Policy. Whether any particular HealthKit value, calendar event title or note, availability signal, or completion history can ever leave the device must be verified before publication: [LEGAL INPUT NEEDED: confirm every cloud payload and exclusion].
Rutmia AI and optional cloud assistance
You can choose in Settings how routine requests are handled. “Automatic · First on device” means Rutmia tries local processing first and uses cloud assistance only when needed and previously allowed. “Cloud only” means routine requests use cloud assistance after the required consent. If cloud consent is disabled, requests remain on-device.
Basic conversational questions may receive a local response and should not consume cloud quota. Free and Pro plans may have different cloud-usage limits and reasonable anti-abuse safeguards; the exact limits, signals, and retention for those safeguards are [LEGAL INPUT NEEDED: confirm].
When cloud assistance is enabled and consented to, cloud AI may receive only the minimum context needed for the request: your request, locale, time zone, and limited active-habit fields such as a title, schedule, reminders, goal configuration, and opaque identifiers. Rutmia must verify that the payload matches this description before publication.
Unless separately verified, this Policy does not say that cloud AI receives HealthKit data, calendar event titles or notes, completion history, purchase data, email, advertising identifiers, or your iCloud identity. The actual exclusions and consent wording are [LEGAL INPUT NEEDED: verify against the production implementation].
Cloud prompts and responses are not described here as deleted after a particular period or as not used for training. Provider agreements must confirm retention, deletion, training use, human access, security, and service-improvement practices before those statements are made: [LEGAL INPUT NEEDED: complete provider terms].
Apple and other service providers
Apple provides services that may support the app, including the App Store payment system, iCloud sync, HealthKit, Calendar, and other Apple device services that you enable. Apple’s own terms and privacy information also apply to those services.
The third-party AI or cloud provider(s) used by Rutmia, their legal names, purposes, processing locations, data protection terms, and subprocessors are [LEGAL INPUT NEEDED: identify and link the providers where legally required]. Do not publish internal class names, model names, API keys, or implementation details in place of this information.
Rutmia does not use advertising networks or cross-app tracking providers. Any analytics, crash reporting, hosting, support, fraud-prevention, or other vendor used by the app or website is [LEGAL INPUT NEEDED: confirm and add to the provider list if applicable].
Purchases and App Store payments
Purchases are handled through Apple’s App Store payment systems. Rutmia does not receive full payment-card details. The information Rutmia receives about purchase status or Pro access is [LEGAL INPUT NEEDED: confirm the exact fields and purposes].
Apple controls the payment flow, price display, billing records, restoration flow, and any refund process that Apple handles. The current plan names, prices, renewal or lifetime terms, and availability are shown in the App Store and app purchase flow and must not be expanded in this Policy without confirmation.
The website and support
If you contact Rutmia, the information you choose to send may be used to respond to you and provide support. The support channel, any ticketing system, access controls, and retention period are [LEGAL INPUT NEEDED: confirm]. Do not send HealthKit data, private habit data, or exported files unless support specifically requires them.
Website hosting logs, cookies, analytics, embedded content, security monitoring, and other website data practices are [LEGAL INPUT NEEDED: confirm]. This Policy does not promise that the website collects no technical or usage data until those practices are verified.
Purposes and legal bases
Rutmia may process information to provide the app features you request, keep routine data working on your device, sync through iCloud when you enable it, provide cloud assistance after the required consent, support Pro access, respond to support requests, and protect the service against abuse where those functions are implemented.
The legal bases, consent requirements, sensitive-data classification, and Mexico-specific purposes or notices for each processing activity are [LEGAL INPUT NEEDED: legal review by launch market]. Rutmia will not rely on this paragraph as a substitute for a jurisdiction-specific legal basis analysis.
Retention, deletion, and consent withdrawal
Routine data stored on your device remains there until you delete it, remove the app, or manage the related iCloud copy. You can turn off HealthKit, Calendar, iCloud sync, and cloud consent from the controls available in the app or on your device. The exact deletion behavior for each setting is [LEGAL INPUT NEEDED: test and confirm].
Rutmia’s retention of cloud prompts, responses, usage records, quota records, abuse-prevention signals, support messages, purchase-status data, website logs, and backups is [LEGAL INPUT NEEDED: confirm each category and retention period]. Rutmia will not promise a fixed retention period until the relevant provider agreements and systems are verified.
If you shared information directly with an external AI provider, you may also need to use that provider’s controls to request deletion or manage retention. Provider-specific instructions are [LEGAL INPUT NEEDED: provide links].
Security
Rutmia is designed to minimize what leaves your device and to request cloud assistance only through the consent choices described above. Device, iCloud, Apple-service, and cloud-provider security controls may also apply.
The specific technical and organizational measures, encryption in transit and at rest, access controls, incident response process, and security contact are [LEGAL INPUT NEEDED: confirm before publication]. No online service can be promised to be completely secure.
International transfers
Apple or a third-party cloud AI provider may process information in a country different from where you live. The countries or regions involved, the provider roles, and the transfer mechanisms or safeguards are [LEGAL INPUT NEEDED: confirm for each provider and launch market].
Do not rely on this Policy as a statement that a transfer is lawful in every jurisdiction until counsel confirms the required notice, consent, contract, adequacy decision, standard contractual clauses, UK transfer addendum, or other safeguard.
Your rights and choices
Depending on where you live and how the law applies, you may have rights to access, correct, delete, restrict, object to, or receive a copy of personal data; withdraw consent; opt out of certain uses; and complain to a regulator. In Mexico, the applicable ARCO process and any other required mechanisms are [LEGAL INPUT NEEDED: confirm and provide procedure]. In the EU, UK, United States, and other markets, the available rights, exemptions, deadlines, and identity checks may differ.
To make a request, contact [LEGAL INPUT NEEDED: privacy request channel]. Rutmia may need enough information to verify the request and may explain when it cannot complete a request because the data is only on your device, controlled by Apple, or held by an external provider. The response process and authorized-agent rules are [LEGAL INPUT NEEDED: confirm].
Children’s privacy
Rutmia’s intended audience, minimum age, parental-consent rules, and treatment of children’s information are [LEGAL INPUT NEEDED: confirm for Mexico, the United States, the EU/UK, and every launch market]. Do not publish an age threshold or a statement that Rutmia knowingly collects no children’s data until counsel and the product team confirm it.
If Rutmia learns that it received children’s information in a way that was not permitted, the escalation, deletion, and parent or guardian contact process is [LEGAL INPUT NEEDED: define].
Policy updates and contact
Privacy Policy updates are separate from acceptance of the Terms of Use. We will keep the current Policy, its version, effective date, and version history visible on this page. For a material privacy change, Rutmia will provide a conspicuous notice and obtain any consent required by applicable law before the change is used.
For privacy questions or requests, contact [LEGAL INPUT NEEDED: privacy contact email and address]. The legal entity, controller details, representative details, and regulator complaint instructions must be completed before publication.