Privacy Policy
Last updated: August 24, 2026
1. Who We Are
This Privacy Policy describes how Rhyma ("we", "us", "our") collects, uses, and protects your personal data when you use our mobile application available on the Apple App Store and Google Play (the "App") or visit rhyma.app (the "Website").
The data controller is Vitalii Samarskyi, individual entrepreneur, Ukraine. You can contact us at: support@rhyma.app.
Rhyma's backend services are hosted on Google Firebase, which acts as our data processor/service provider for authentication, data storage, messaging, and related infrastructure services.
2. Data We Collect
We collect account and profile data, authentication data, device and technical data, approximate location data, camera and gallery data, purchase and subscription data, and usage or diagnostic data when you use Rhyma.
This may include your name or nickname, email address, profile images, user identifiers, basic settings, device information, Firebase identifiers, approximate city or region, uploaded photos, purchase history and subscription status, in-app events, error and crash information including stack traces and diagnostic breadcrumbs, and performance diagnostics.
If you create or join a Circle, we also collect Circle membership and role information, the Circles you own or moderate, invitations you create or accept, moderation records such as removals and bans, and the details you give a Circle you create, such as its name, description, category, tags, language, and cover image.
If you submit beta feedback through the Website, we collect the feedback category, platform, message, and any app version, device model, email address, or social handle you choose to provide. Contact details are optional. We also process limited request information to prevent automated abuse, but we do not store your raw IP address with the feedback.
Rhyma asks for coarse location only. The App requests foreground location permission, never background access, and asks the device for a balanced-accuracy position rather than a high-precision one. Positions are read when the game needs one, with short-lived caching, rather than by following your movements, and we do not build a location history of you.
Coordinates for the lines you write are stored on our servers so a poem's journey, map, and distance travelled can be calculated. They are not part of what other players can read: poem lines are served to other users without coordinates, and what they see is a place name such as a city or region.
We do not access your photos or camera for any purpose other than allowing you to select or capture images for use inside the App.
3. How We Use Your Data
We use your data to create and manage your account, authenticate you, synchronize your profile and settings, operate collaborative poetry features, operate Circles including their membership, invitations, discovery, and moderation tools, process purchases and subscriptions, provide notifications, protect the App and Website from abuse, improve reliability and user experience, respond to beta feedback when contact details are provided, and comply with applicable legal obligations.
Approximate location is part of how Rhyma works rather than an optional extra. A Rhyma poem travels: its lines are written in different places, and the journey, the map, and the distance travelled of a completed poem are part of the game and of the rewards it grants. We therefore need an approximate position for the lines you write. The same approximate area is used to show you nearby public Circles and region-based content, which needs no additional location data.
4. Data Visible to Other Users and the Public
Rhyma is a collaborative game. Your nickname, avatar, public profile information, and certain activity details (such as contributions, achievements, and reactions) are visible to other users. The poem lines you submit become part of poems that are visible to other contributors and, once a poem is completed, to all of its participants.
When a completed poem is shared, it may become available on a public web page to anyone who has the link, together with the contributors' nicknames. Please keep this in mind when choosing your nickname and profile images and when submitting content.
Rhyma also includes Circles, which are persistent communities you can create or join. A Circle is either private or public, and this type is fixed when the Circle is created.
Inside a private Circle, your nickname, avatar, and the lines you contribute are visible to the other members of that Circle. Completed poems written in a private Circle can be read by the Circle's current members, which means a member who joins later can read poems that were completed before they joined.
Public Circles can be found by any user through Circle discovery, and completed poems written in a public Circle can be read without joining. A public Circle also has a public web page on rhyma.app, so its name, description, cover image, category, tags, language, and general area, together with the poems completed in it and the nicknames of their contributors, can be viewed by anyone with the link and may be indexed by search engines. Joining is required in order to write lines, react, or comment.
If you create an invitation link or QR code for a private Circle, anyone holding that link can see a preview of the Circle until the invitation expires or is revoked. Poems written in the Circle are not shown in that preview. Please treat invitation links as confidential and do not post them publicly.
Circle owners and moderators can see the member list of their Circle and can remove or ban members. Reports you submit about a poem, a comment, a user, or a Circle are visible to us for moderation purposes and are not shown to the person you reported.
We do not publish your email address, location data, or other non-public account information to other users.
5. Legal Bases for Processing
Where applicable law (such as the EU/UK GDPR) requires a legal basis, we rely on the following bases:
Performance of a contract: creating and managing your account, authenticating you, operating collaborative poetry features, using your approximate location to place the lines you write and to calculate poem journeys and distances, operating Circles and their membership and invitations, synchronizing your profile and settings, and processing purchases and subscriptions.
Legitimate interests: protecting the App and Website from abuse and fraud, securing our systems, diagnosing errors and crashes, operating reporting, blocking, and Circle moderation tools to keep the Service safe, reviewing beta feedback, responding when requested, and improving reliability and user experience.
Consent: optional rewarded ads, and non-essential analytics or tracking technologies where consent is required by law.
Legal obligations: complying with accounting, tax, and other legal requirements that apply to us.
You may withdraw consent for the consent-based purposes above at any time, without affecting processing that occurred before withdrawal. Your device settings control the App's access to location, camera, and photos at any time; because approximate location is needed for core gameplay, revoking it stops the features that depend on it rather than only narrowing analytics.
6. Camera, Photos, and Location
The App requests camera and photo library access only so you can capture or select images for your avatar, cover image, or other user content.
Rhyma is a location-based game, so the App asks for approximate location during onboarding and you need to grant it to start playing. We ask only for foreground, balanced-accuracy location: we do not request background location access and we do not request high-precision tracking. If you withdraw the permission later in your device settings, the features that depend on it, including poem journeys for new lines and nearby Circle discovery, stop working.
7. Service Providers and Sub-Processors
We use Firebase Authentication, Cloud Firestore, Cloud Storage for Firebase, Cloud Functions for Firebase, Firebase Cloud Messaging, and Firebase App Check as our primary backend infrastructure. Firebase and Google process personal data on our instructions and for the purposes described in this Policy.
We use RevenueCat to manage in-app subscriptions and purchases. RevenueCat processes user identifiers, device identifiers, purchase history, and subscription status on our behalf. Payment card details are handled by the Apple App Store or Google Play and never reach us or RevenueCat.
We use Sentry to collect crash reports and performance diagnostics so we can find and fix defects. Sentry processes a pseudonymous account identifier, device and app information, error and stack trace data, and navigation and network diagnostic breadcrumbs on our behalf. Our Sentry data is hosted in the European Union. We do not enable session replay or screen recording, we do not send application console output to Sentry, and we have disabled IP address storage, so the content of your poems, comments, and messages is not sent to Sentry.
The Website is hosted on Vercel. We use Cloudflare Turnstile to distinguish genuine form submissions from automated abuse, Resend to deliver waitlist and feedback notifications, and privacy-focused Umami analytics to understand aggregate Website usage. These providers process limited technical or submitted information on our instructions as needed to provide those services.
Except for Google AdMob as described in Section 10, we do not share your personal data with independent third-party controllers for their own marketing or advertising purposes.
8. Data Retention, Anonymization, and Deletion
We store account and profile data for as long as your account remains active or as necessary to provide the App's services. Technical and diagnostic logs are retained for up to 3 months unless a longer period is required for security or technical investigations.
Crash reports and performance diagnostics held by Sentry are deleted automatically after 90 days.
Website beta feedback, including optional contact details, is retained for up to 12 months and then automatically deleted. Pseudonymized Website feedback rate-limit records expire after 48 hours. Operational email copies are also retained for up to 12 months unless they are needed longer to resolve an active support request or meet legal obligations.
To preserve the integrity of collaboratively created content, we may anonymize personal data instead of fully deleting all related records. If you request deletion, we will remove or anonymize personal identifiers in active systems while retaining anonymized collaborative content where necessary.
If you delete your account, your Circle membership, invitation, and moderation records are deleted, including the records held inside Circles you had already left. Circles you owned are archived rather than deleted, so their members keep access to the poems they wrote, and the archived Circle is no longer linked to your account. Where you had banned another member, the ban remains in force but no longer identifies you.
You can delete your account directly in the App under Settings → Delete Account, or follow the instructions at https://rhyma.app/account-deletion.
9. Your Rights
Depending on your location and applicable law, you may have rights of access, rectification, erasure, restriction, portability, objection, and withdrawal of consent.
To exercise these rights, contact us using the details below. We may need to verify your identity before processing your request.
If you are located in the European Economic Area, the United Kingdom, or another jurisdiction with a data protection supervisory authority, you also have the right to lodge a complaint with your local supervisory authority.
10. Cookies, Analytics, Ads, and Tracking Technologies
The App and its backend infrastructure may use mobile SDKs and identifiers to provide core functionality, maintain authenticated sessions, perform analytics, measure usage, improve reliability, and diagnose errors or crashes. The Website uses privacy-focused Umami analytics and Vercel performance measurement; feedback field values and contact details are not sent to analytics. Our crash reporting SDK does not record your screen and does not capture the content of poems, comments, or messages.
Where required by law, we will obtain consent before using non-essential analytics or tracking technologies.
Optional rewarded ads are provided through Google AdMob. If you choose to watch an ad, Google may process advertising identifiers, consent signals, device information, ad interaction data, and related diagnostics to serve and verify the rewarded ad. For these purposes Google may act as an independent controller of that data under Google's own privacy policy.
Where consent is required, ads are served in accordance with your consent choices; depending on your choices and region, ads may be served in a non-personalized mode. You can avoid AdMob processing entirely by not watching rewarded ads, and you can limit ad tracking in your device settings.
11. International Data Transfers
Because we use Firebase, Google Cloud, RevenueCat, Sentry, Vercel, Cloudflare, Resend, and Umami services, your personal data may be stored or processed outside your country, including in the European Union, the United States, and other jurisdictions where these providers maintain data centers.
Crash and performance diagnostics are stored in the European Union. Some of our providers are established outside the European Economic Area and may access data from there in order to support their services.
Where required, we rely on appropriate safeguards such as standard contractual clauses and technical and organizational measures.
12. Data Security
We implement technical and organizational measures to protect your personal data against accidental or unlawful destruction, loss, alteration, unauthorized disclosure, or access.
These measures include encryption in transit and at rest, access controls, authentication mechanisms, Firebase security rules, Firebase App Check, Cloudflare Turnstile, rate limiting, and monitoring for unusual activity or potential security incidents.
13. Children's Privacy
Rhyma is not directed to children below the minimum age required by applicable law for independent consent to data processing (for example, 13 in the United States and between 13 and 16 in the European Union, depending on the member state). We do not knowingly collect personal data from such children.
If we become aware that we collected personal data from a child contrary to this Policy, we will delete or anonymize it as soon as reasonably possible.
14. Notice for U.S. and California Residents
We do not sell personal information for monetary consideration. If you choose to watch optional rewarded ads, Google AdMob's processing of advertising identifiers may constitute "sharing" for cross-context behavioral advertising as defined under the California Consumer Privacy Act, as amended by the California Privacy Rights Act, depending on your consent choices and ad personalization settings.
You can opt out of any such sharing by not watching rewarded ads and by limiting ad tracking in your device settings. California residents may also exercise rights of access, deletion, and correction by contacting us using the details below. We do not discriminate against you for exercising these rights.
If you are a U.S. or California resident and have questions about how your rights may apply to Rhyma now or in the future, contact us using the details below.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or operational needs.
When we make material changes, we will update the "Last updated" date and, where appropriate, provide notice within the App or by other reasonable means.
16. Contact
If you have questions about this Privacy Policy, our data practices, or wish to exercise privacy rights, please contact: Vitalii Samarskyi, individual entrepreneur, Ukraine.
Contact email: support@rhyma.app