Legal
Privacy Policy
Last updated: August 2, 2026
Ritual is built local-first. The short version: your tasks, habits, and notes live on your device. Using Ritual needs no account, and it runs no advertising or cross-app tracking. There is exactly one way your content reaches a server of ours, and it can’t happen by accident: Ritual Cloud, an optional subscription you have to buy and then sign into. It has its own section below.
What we collect
Nothing personal. Ritual does not ask you to sign in to use it, and unless you subscribe to Ritual Cloud, none of your content is sent to us. Your data is created and kept on your iPhone.
iCloud sync
If you turn on sync, your data is stored in your own private iCloud account and synced across your devices by Apple’s CloudKit. It is governed by Apple’s privacy policy. We never see it, and sync requires no separate Ritual account or login.
Ritual Cloud
Ritual Cloud is an optional subscription that connects your tasks and habits over MCP, so an assistant can answer from your real day. It is the one part of Ritual where your content leaves your device for a server we run, and it applies only if you both subscribe and sign in. If you never do, nothing in this section happens to you.
What is stored. A mirror of your Ritual data on our server at api.ritual.from81.app: tasks, projects, habits, tags, lists, checklist items and habit check-ins, as they are on your device — including the titles and notes you write. There is no way to answer “what’s on today?” without it. The mirror is kept up to date as you change things, and it is stored in plain form in our database, which means we could read it if we went looking. We don’t: it is not sold, not mined, not used to train anything, and not shared with anyone but the MCP clients you sign in yourself.
Your account. Signing in uses Sign in with Apple, so we get the account identifier Apple issues and the email address you let Apple share — which can be Apple’s private relay address, if that’s what you choose. There is no password. We also keep a record of your subscription: the App Store transaction identifier and when it expires, so the server knows whether access is still paid for.
Where it lives. On servers we rent, not our own hardware: the service runs on Vercel and stores data in a hosted Postgres database (Neon). They process it on our behalf and for no purpose of their own.
Deleting it. Settings → Ritual Cloud → Delete Account permanently deletes your account and every copy of your data on our server — the mirror, your subscription record, and the account itself. Your data on your device and in your own iCloud is not affected. One thing survives on purpose: if Apple has told us a subscription was refunded or revoked, we keep that App Store transaction identifier and the date, so the same purchase can’t be reused. It carries no link to you or your data. Note that deleting your account does not cancel the subscription — the App Store bills that, and only you can cancel it.
Ritual Cloud does not change how iCloud sync works, and it is not a backup service. Keeping your devices in step is still Apple’s CloudKit, still your own iCloud, and it works whether or not you subscribe.
Analytics & tracking
No advertising SDKs, no tracking identifiers, and nothing that follows you into other apps. We do not build a profile of you and have nothing to sell. Two services do receive limited technical data, and neither of them ever receives your content.
Crash and error reports (Sentry). When Ritual crashes or hits an error it recovers from, a diagnostic report is sent so it can be fixed: the error, where in the code it happened, and the device model and OS version.
Error counts (PostHog). When Ritual recovers from an error, PostHog is also told that one happened — the kind of error and where in the app, as a code, never a message. That is so a problem can be matched to the session it interrupted.
Anonymous usage analytics (PostHog). Counts of what happens in the app — a task completed, a habit checked in, the paywall shown, a purchase finished — so we can tell which parts of Ritual are worth building on. Events carry no text you have written. A small share of sessions also records a replay of how the interface was used, with every piece of your content masked out: titles, notes, habit names and amounts render as blank blocks, never as words.
How it is identified. By a random identifier generated on your device — not your name, your email, your Apple ID, or your device’s push token. Signing in to Ritual Cloud does not change that: analytics is never linked to your account, which is why your own devices count separately rather than as one person. Ritual has no way to tell analytics who you are.
What neither of them gets: the text of your tasks, notes, habits, projects or tags. That stays on your device and in your own iCloud.
You can switch usage analytics off at any time in Ritual under Settings → Share anonymous usage data. Turning it off stops collection immediately, including session replay.
This website
This site is a simple informational page. It sets no advertising or tracking cookies and does not collect personal information from visitors. The one exception is the public roadmap: voting there sets a single anonymous cookie containing a random ID, used only to prevent duplicate votes on the same item. It isn’t tied to your identity and isn’t used anywhere else on the site.
Children
Ritual is not directed at children under 13 and does not knowingly collect their data.
Changes
If this policy changes, we’ll update the date above and post the new version here.
Contact
Questions about privacy? Email hello@ritual.from81.app.