1. Controller
Leobalo GmbH Schwester-Jovita-Str. 15 64625 Bensheim, Germany Managing Director: Tino Volbracht Email: support [at] ritualio [dot] de
This privacy policy applies to the website ritualio.de (Part 2) and the Ritualio app for iOS and Android (Part 3).
2. Your rights
You have the right at any time to access (Art. 15 GDPR), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), data portability (Art. 20) and to object to processing based on legitimate interests (Art. 21). Please contact the email address above.
You also have the right to lodge a complaint with a data protection supervisory authority. Responsible for us: The Hessian Commissioner for Data Protection and Freedom of Information (Der Hessische Beauftragte für Datenschutz und Informationsfreiheit), Postfach 3163, 65021 Wiesbaden, Germany.
3. Principle
We process as little data as possible. Ritualio is financed through the Premium subscription — not through ads or data. There is no advertising, no profiling and no sale of data — neither on the website nor in the app. The website uses cookieless, self-hosted traffic measurement (section 5); the app contains no analytics SDK (section 13).
Part 2 — Website (ritualio.de)
4. Hosting and server logs
The website is operated on servers in Germany at Hetzner Online GmbH (Industriestr. 25, 91710 Gunzenhausen, Germany). When you visit, technically necessary server logs are processed (IP address, time, requested page, user agent). The legal basis is our legitimate interest in secure operation (Art. 6 (1) (f) GDPR). Logs are deleted after 14 days at the latest.
5. Web analytics (Umami)
We use the self-hosted analytics software Umami on our own server. Umami sets no cookies and stores no personal profiles; IP addresses are not stored. Only anonymous page views and click events are recorded. Legal basis: legitimate interest in reach measurement (Art. 6 (1) (f) GDPR). A cookie banner is therefore not required.
6. Contact form
If you use the contact form, we process your name, email address and message to handle your request (Art. 6 (1) (b) or (f) GDPR). The transmission runs through our self-hosted automation software n8n on servers in Germany. The data is deleted as soon as your request is completed and no statutory retention obligations exist.
7. No cookies, no third parties
The website sets no cookies, loads no external fonts and embeds no content from third-party servers.
Part 3 — Ritualio app (iOS and Android)
8. Account data
A parent account is required to use the app. We process your email address and your password (stored exclusively hashed and salted). Legal basis: performance of contract (Art. 6 (1) (b) GDPR). Verification and password reset emails are sent via our processor ALL-INKL.COM – Neue Medien Münnich (Hauptstraße 68, 02742 Friedersdorf, Germany).
9. Children’s data
Child profiles are created and managed exclusively by parents. Children themselves do not enter into a contract with us. Per child we process: name or nickname, chosen avatar symbol, chosen profile color, the routine, task and reward data created by the parents, the balance of coins, streaks and trophies as well as — if you use these features — the entries in the children’s diary including the chosen mood and stickers, and the parents’ day notes. The text of diary entries and day notes is encrypted on the device before it is synchronized (see section 12). This data serves exclusively the function of the app, is only visible to your own family and is never used for advertising or analytics purposes (cf. Art. 8 GDPR). We recommend using a nickname only.
10. Photos (puzzle feature)
Parents can upload photos as puzzle rewards. The photos are stored on our servers at Hetzner in Germany and are visible exclusively to your own family. If you delete a puzzle or the account, the photo is removed from the server.
11. In-app purchases
The Premium subscription is handled entirely via the Apple App Store or Google Play. We receive no payment data — only a purchase receipt (receipt or purchase token), which we verify to unlock Premium. The privacy policies of Apple and Google apply to the purchase process; data may be transferred to the USA (both providers are certified under the EU-US Data Privacy Framework).
12. Local data and synchronization
The app stores your data locally on the device and synchronizes it with our server at Hetzner in Germany so that all of your family’s devices share the same state. The transmission is encrypted (TLS).
Beyond that, the text of diary entries and day notes is encrypted on the device before it reaches the server. The app generates the necessary key on your device; on our server it exists only in encrypted form, derived from your password. We also keep a sealed copy of that key which can only be opened with a spare key that we store offline and separately from the server. Without that copy, a forgotten password would mean every entry is lost for good. We use the spare key exclusively when you ask us to restore your data.
13. What the app does NOT do
The app contains no advertising, no tracking, no third-party analytics/statistics SDKs and no crash reporting to third parties. We do not sell data and do not pass it on, unless required by law.
14. Retention and account deletion
Your data remains stored as long as your account exists. You can delete your account at any time directly in the app (Settings → Delete account). This permanently removes all account, child, routine and photo data of your family from our servers. Backups are overwritten after 30 days at the latest.
Last updated: June 7, 2026