Here's a plain-language summary of how Rituala handles your data — what we collect, why, who we share it with, and your rights.
What we collect
To build your routine, we collect:
Hair information you provide: answers to the quiz, including hair type, condition, history, lifestyle, and goals
Account info: email, password (hashed and secured by Clerk), and any preferences you set
Payment info: handled entirely by Stripe — we never see or store your full card number
Usage data: page views and feature usage, collected via PostHog analytics to help us improve the product
Photos (Journey only): if you choose to upload progress photos, they are stored securely and only accessible to you
How we use it
To generate and adapt your personalized hair routine
To power Ask Rituala (AI chat) — your hair profile is sent to the AI to generate relevant, personalized answers
To send you relevant emails (account, billing, and optional product education)
To improve recommendations using aggregated, anonymized usage patterns
What we don't do
We don't sell your data. Not to brands, not to data brokers, not to anyone.
We don't share your hair profile with brands in any identifiable way.
We don't use your photos for marketing without your explicit consent.
Your rights
Access: request a copy of all data we have on you
Correction: update incorrect information at any time from your account settings
Deletion: delete your account and associated data — see How to delete your account
Portability: email [email protected] to request a copy of your data
Opt out of marketing emails: use the unsubscribe link in any marketing email
Where your data is stored
Your data is stored on secure cloud infrastructure. We use industry-standard encryption in transit (HTTPS) and at rest.
Third parties we share data with
Stripe — processes all payments. No card data is stored on our servers.
Clerk — manages account authentication and session security.
Anthropic — powers Ask Rituala. Your hair profile context is sent to Claude (Anthropic's AI) to generate personalized answers. Anthropic does not use your data to train their models by default.
PostHog — collects anonymized usage analytics to help us improve the product.
Rewardful — only involved if you arrived via an affiliate or referral link.
If you're in the EU, UK, or California
You have additional rights under GDPR, UK GDPR, and CCPA. To make a data subject access request or learn more about our data processing, email [email protected].
Full privacy policy
For the complete legal privacy policy, visit tryrituala.com/privacy.
Privacy questions? Email [email protected] — we take this seriously and respond directly.