Legal
Privacy Policy
This policy describes how Rithma ("we", "us") handles information when you use our website (rithma.ai), mobile apps, and care management platform (the "Service").
Effective date: July 7, 2026
Introduction
At rithma.ai ("us", "we", "our" or the "Company") we value your privacy and the importance of safeguarding your data. This Privacy Policy (the "Policy") describes our privacy practices for the activities set out below. As per your rights, we inform you how we collect, store, access, and otherwise process information relating to individuals. In this Policy, personal data ("Personal Data") refers to any information that on its own, or in combination with other available information, can identify an individual.
Rithma Inc is operated from the United States. Our website is https://www.rithma.ai. Correspondence may be sent to 251 Main St, Los Altos, CA 94022.
We are committed to protecting your privacy in accordance with applicable privacy regulation. As such, we follow obligations under laws that may apply to you, including:
- California's Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA) and California Online Privacy Protection Act (CalOPPA)
- Colorado Privacy Act (CPA)
- Utah Consumer Privacy Act (UCPA)
- Connecticut Data Privacy Act (CTDPA)
- Virginia Consumer Data Protection Act (VCDPA)
- Texas Data Privacy and Security Act (TDPSA)
- Oregon Consumer Privacy Act (OCPA)
- Montana Consumer Data Privacy Act
- Delaware Personal Data Privacy Act
- Nebraska Data Privacy Law
- New Hampshire Data Privacy Act
- New Jersey Data Privacy Act
- Minnesota Consumer Data Privacy Act
- Maryland Online Consumer Protection Act
- Kentucky Consumer Data Protection Act (KCDPA)
- Tennessee Information Protection Act (TIPA)
- The Rhode Island Data Transparency and Privacy Protection Act (RIDTPPA)
- Indiana Consumer Data Protection Act (INCDPA)
- Iowa Consumer Data Protection Act (ICDPA)
- Where applicable: GDPR, UK GDPR, PIPEDA, LGPD, and POPIA (see Your Rights).
- We do not sell your personal information. We do not use care data for third-party advertising or targeted advertising.
In the preceding 12 months, we have not sold or shared personal information, and we have not disclosed sensitive personal information for any purpose other than providing and supporting the Service. We disclose personal information to service providers and contractors (listed below) only to operate the Service, under contracts that prohibit them from using it for their own purposes.
Scope
This Policy applies to rithma.ai, dashboard.rithma.ai, jobs.rithma.ai, our mobile applications, and related websites, domains, applications, services, and products (collectively, the "Service"). It also applies to transactional email, SMS (including two-factor authentication codes), and push notifications we send in connection with the Service.
This Policy does not apply to third-party applications, websites, products, services or platforms that may be accessed through (non-rithma.ai) links that we may provide to you. These sites are owned and operated independently from us, and they have their own separate privacy and data collection practices. Any Personal Data that you provide to these websites will be governed by the third-party's own privacy policy. We cannot accept liability for the actions or policies of these independent sites, and we are not responsible for the content or privacy practices of such sites.
Processing Activities
This Policy applies when you interact with us by doing any of the following:
- Make use of our application and services as an authorized user
- Visit any of our websites that link to this Privacy Policy
- Receive transactional communications from us (account, billing, security, care-related notifications) by email, push notification, or SMS where you have provided a phone number
Personal Data We Collect
Depending on your role (agency, caregiver, family member, senior) and how you use the Service, we may collect:
- Account information — name, email, phone, role, and login credentials (stored as secure hashes, never plain text)
- Care and operations data — schedules, tasks, visit notes, voice snippets and transcripts, messages, documents, incidents, and related metadata you or your organization enter in the Service
- Health and care information — diagnoses, medications, allergies, assessments, and similar information entered for care coordination; for agency customers this may include protected health information (PHI) under HIPAA
- Payment information — billing is processed by Stripe. We receive subscription status, Stripe customer IDs, and receipts; we do not store full credit or debit card numbers. Business and service addresses may be stored for invoicing and scheduling.
- Demographic data — date of birth, gender or sex, marital status, primary language, and similar fields when entered in intake or profile forms
- Financial and insurance data — payer and insurance information, Medicare/Medicaid or LTC benefit data, and billing rates when entered for claims or client billing (not full payment card numbers)
- Purchase and subscription information — plan tier, license counts, trial status, and payment status
- Mobile and device data — push notification tokens, device platform, app version, and device registration identifiers (we do not collect IMEI)
- Location data — GPS coordinates when caregivers clock in or out of shifts or use travel/mileage features, and service addresses
- Work-related information — employment history, certifications, resumes, schedules, and background screening status when provided for hiring or compliance
- Feedback and support — contact form submissions, support correspondence, and complaints
- Content you provide — messages, documents, audio, photos, and similar user-generated content
- Website and operational logs — IP address, browser type, user-agent, timestamps, authentication records, API paths, and audit log entries (audit logs intentionally exclude clinical text and PHI)
We may also process the following categories of sensitive personal data where relevant to the Service and permitted by law:
- Health information — as described above; agencies that require a Business Associate Agreement (BAA) under HIPAA should contact us before processing PHI in production
- Government identifiers — such as SSN (last four digits where collected), Medicare/Medicaid member IDs, NPI, professional license numbers, and driver's license or insurance document uploads
- Precise geolocation — tied to caregiver shift verification as described above
- Criminal history screening results — when an agency orders background checks through Checkr (summary status and report references; detailed reports remain with Checkr)
- Cultural or spiritual preferences — optional care-coordination fields (e.g., religion or cultural preferences for meal or care planning)
- Work authorization — whether an applicant is authorized to work in the U.S. (we do not collect political opinions, union membership, genetic data, or passport numbers in standard forms)
- Biometric login — if you enable Face ID or Touch ID on our mobile app, biometric templates remain on your device; we do not receive or store your fingerprint or face data on our servers
We do not use your voice as a biometric identifier. We transcribe voice recordings to create care documentation; we do not create voiceprints and do not use your voice to identify or authenticate you. If we ever introduce voice-based identification, we will update this Policy and obtain any consent the law requires first.
How We Collect Your Personal Data
From you. You provide information when you:
- Create an account or subscribe to a paid plan;
- Use the Service (including scheduling, documentation, messaging, and billing features);
- Submit content through the Service;
- Download or use our mobile application;
- Contact us by email, phone, or our website contact form;
- Apply for a position through an agency's recruiting flow hosted on jobs.rithma.ai.
Automated technologies or interactions: When you use our website or app we automatically collect device and usage data such as IP address, user-agent, timestamps, session and authentication events, and API access logs. Our public marketing site may send a first-party analytics beacon (anonymous page paths and button clicks only — no advertising cookies, no user IDs) and, when enabled, Cloudflare Web Analytics (a cookieless third-party performance/traffic beacon operated by Cloudflare), only after Analytics consent — see the Cookies section below.
Third parties. We may receive Personal Data from:
- Your agency, family administrator, or care organization when they invite you or enter information about you;
- Stripe — payment and subscription status (not full card numbers);
- Checkr — background screening status when your agency orders a check;
- Optional integrations your agency connects (e.g., QuickBooks, Xero, EVV or clearinghouse vendors) — only as configured by the customer;
- Service providers that host or process data on our behalf under contract (see Third Party Tools).
If you provide us, or our service providers, with any Personal Data relating to other individuals, you represent that you have the authority to do so and acknowledge that it will be used in accordance with this Policy. If you believe that your Personal Data has been provided to us improperly, please contact us using the information in the Contact Us section below.
Data we collect from third parties.
Agencies and other organizations using Rithma may submit Personal Data about caregivers, clients, and family members. That organization controls much of that data and its own privacy obligations. If your data was provided by an agency, contact them first for access or correction; we will assist as required by law and our agreement with the agency.
Purpose and Legal Basis for the Processing of Personal Data
We collect and use Personal Data to provide, secure, and improve the Service, communicate with you, and comply with law. Legal bases may include performance of a contract, legitimate interests (such as security and fraud prevention), consent where required, and legal obligation.
These purposes include:
- To deliver and operate the Service (scheduling, care documentation, messaging, billing, EVV, and related features)
- Building a safe and secure environment; verifying or authenticating your identity; investigating and preventing security incidents
- Providing, developing, and improving our products and services (including anonymous marketing-site analytics and in-product reliability)
- Enabling you to access rithma.ai services and set up accounts; providing technical and customer support
- Generating AI-assisted outputs you request (e.g., tidied voice notes, summaries, chat responses) using configured cloud AI services
- Legal and regulatory compliance (HIPAA expectations, EVV, billing rules, audit requirements)
- Payment processing (subscriptions/invoices via Stripe); background screening (when agencies order Checkr checks on caregivers)
Where we rely on consent (for example, optional marketing email or certain sensitive fields), you may withdraw consent as described in Your Rights. Some features may not be available if required data or consents are not provided.
Our AI and Automated Technology
Rithma is an AI-native service. We use artificial intelligence to process voice recordings and text you provide — for example, to transcribe visit notes, tidy spoken notes into care records, draft messages, generate summaries, and answer questions. AI can make mistakes; AI-generated content may be inaccurate or incomplete and should be verified before you rely on it. We do not use your personal information to train generalized AI models. AI requests are processed through Amazon Web Services (including Anthropic models invoked via Amazon Bedrock); we do not send data directly to Anthropic.
We also use automated technology to help organize, prioritize, and route work (for example, suggesting schedules or task assignments). These tools support human decisions — they do not replace them; a person reviews outcomes that affect you, and AI does not make final decisions on its own authority. You may ask how a decision involving you was reached and request human review by contacting us at [email protected]. Where our AI communicates with you, it identifies itself as AI.
If you apply for a caregiving position through an agency's recruiting page hosted on our Service, AI may help organize and summarize applications for that agency. The agency — not Rithma — makes all hiring decisions, and a person reviews any AI-generated summary or recommendation before a decision is made. We do not use AI to score applicants on personality, "culture fit," facial expressions, or voice characteristics. You may ask the agency for information about how a decision about you was reached, and you may request a reasonable accommodation at any point in the application process by contacting the agency or emailing us at [email protected].
De-Identified and Aggregated Data
We may create de-identified or aggregated data from information in the Service — for example, by removing the identifiers that would link the data to you or to an individual. Once data is de-identified, it no longer identifies you and is not personal information or protected health information. We may use and keep de-identified and aggregated data for purposes such as analytics, benchmarking, research, operating and improving the Service, and improving our AI models.
We maintain and use such data only in de-identified form, we do not attempt to re-identify it (except limited testing of our own de-identification, as permitted by law), and we require any recipient of de-identified data to honor the same restrictions. We do not use your identifiable personal information or protected health information to train generalized AI models.
For agency and covered-entity customers, how we may create de-identified data and perform data-aggregation services is governed by our separate agreement with you (including any Business Associate Agreement or Data Processing Addendum); those terms control.
Health Information and HIPAA
When an agency uses Rithma to coordinate care, health-related information about clients is entered and controlled by that agency. For agencies that are covered entities under HIPAA, we act as a "business associate" and handle protected health information only as permitted by our Business Associate Agreement with the agency and as needed to provide the Service. If you are a client or family member and want to access, correct, or delete care records, please contact your agency first; we will assist as our agreement and the law require. Agencies that need a Business Associate Agreement should contact [email protected] before entering protected health information in production.
Third Party Tools
We use service providers to host, process, and deliver the Service. They may access Personal Data only to perform services for us under contractual obligations. Primary providers include:
- Amazon Web Services (hosting, database, object storage, email, push, AI inference, document extraction, logging)
- Amazon SNS (AWS) — transactional SMS (e.g. two-factor authentication codes)
- Stripe
- Checkr (when agencies order background checks)
- Google Cloud Translation (when translation features are enabled)
- Intuit QuickBooks (optional agency connection)
- Xero (optional agency connection)
- Stedi / Waystar and other EVV or clearinghouse partners (optional, per agency configuration)
- Enzuzo (cookie preference storage on marketing pages and hosted privacy-request form at https://www.rithma.ai/privacy/requests)
International Data Transfer and Storage
Rithma is operated from the United States. Personal Data is primarily stored and processed on servers in the U.S. (including AWS regions we configure). If you access the Service from other regions, your information may be transferred to, and maintained in, the United States and other countries where our service providers operate, which may have different data protection laws than your jurisdiction. Where required, we use appropriate safeguards such as Standard Contractual Clauses.
Sharing and Disclosure
We will share your Personal Data with third parties only in the ways set out in this Policy or at the point when the Personal Data is collected.
Within your care circle. Caregivers, agencies, and family members see information according to roles and permissions configured in the Service.
We do not sell Personal Data and do not share it for cross-context behavioral advertising.
Legal Requirement. We may use or disclose your Personal Data in order to comply with a legal obligation, in connection with a request from a public or government authority, or in connection with court or tribunal proceedings, to prevent loss of life or injury, or to protect our rights or property. Where possible and practical to do so, we will tell you in advance of such disclosure.
Service Providers. We share Personal Data with contracted service providers (such as cloud hosting, email delivery, payment processing, AI inference, and background screening) solely to operate and improve the Service — not with marketing agencies for advertising.
Cookies and Similar Technologies
We use strictly necessary cookies for the authenticated application (sign-in, session management, and CSRF protection). On marketing pages, Enzuzo stores your cookie and privacy-preference choices — we treat these as essential for compliance, not for advertising. We do not use advertising cookies or third-party analytics cookies (such as Google Analytics).
Some convenience settings (such as "Remember email on this device") are stored in your browser's local storage or session storage, not in cookies.
Our public marketing pages send first-party analytics events (anonymous page path and CTA clicks via our own /marketing/event endpoint — no advertising cookies, no user IDs) only after you affirmatively allow Analytics in Cookie settings (Enzuzo preference cookie cookies-analytics=true). Separately, when Cloudflare Web Analytics is enabled, we load Cloudflare's cookieless Insights beacon (static.cloudflareinsights.com) under the same Analytics consent to measure aggregate marketing-site traffic and performance; it does not set advertising cookies and is not used for cross-site advertising. Where your browser sends Global Privacy Control (GPC) or Do Not Track, or when Analytics consent is declined or not yet given, we do not send first-party marketing analytics events and we do not load the Cloudflare Insights beacon. GPC does not disable essential session cookies required to use the authenticated application.
Because we do not sell or share personal information, we are not required to offer a "Do Not Sell or Share" option; however, we honor Global Privacy Control (GPC) signals as an opt-out of any non-essential analytics, and you can review your choices at the "Cookie settings" link in our footer.
Retention & Deletion
We will only retain your Personal Data for as long as necessary for the purpose for which that data was collected and to the extent required by applicable law.
We retain account and care data while your subscription or account is active and as needed to provide the Service, comply with law, resolve disputes, and enforce agreements. Agencies may be required to retain certain records under healthcare or employment laws. You may request deletion subject to those requirements.
How long we keep information depends on the category and why we hold it:
- Account information — for the life of the account and up to thirty (30) days after closure (export window before de-identification).
- Voice recordings — deleted thirty (30) days after transcription and quality review; the transcript becomes the record.
- Transcripts, visit logs, and care records — for the term of the agreement; after termination, Subscriber Data is de-identified after a thirty (30) day export window unless the agency or applicable law requires longer retention.
- Consent and compliance records — up to 4 years (and security-incident records longer) as required by law.
- Precise location — kept with the visit-verification record only; never used or kept for any other purpose.
- Backups — encrypted and cycled out within thirty (30) days.
- Compliance audit logs — minimum six (6) years in dedicated audit storage; these records do not contain PHI.
- Executed e-signed documents — minimum six (6) years after completion unless law or agency settings require longer.
- Application operational logs — approximately thirty (30) days.
- Edge security (WAF) logs — approximately ninety (90) days.
- Recruiting and hiring records — applications, screening results, and related automated-decision records: kept a minimum of four (4) years, as employment law requires.
When we no longer need Personal Data for a disclosed purpose and no legal duty requires keeping it, we delete it from our systems or take steps to de-identify it.
Merger or Acquisition
If we are involved in a merger, acquisition or asset sale, your personal information may be transferred. We will provide notice before your personal information is transferred and becomes subject to a different Privacy Policy.
How We Keep Your Data Safe
We have appropriate organizational safeguards and security measures in place to protect your Personal Data from being accidentally lost, used or accessed in an unauthorized way, altered or disclosed.
The communication between your browser and our website uses a secure encrypted connection (TLS) wherever your Personal Data is involved.
Measures include Argon2id password hashing, required two-factor authentication for agency, agency staff, independent caregiver, and employed caregiver accounts (optional for family and senior accounts when enabled), encryption for stored documents, audit logging, and hosting on AWS with secrets managed through AWS Secrets Manager.
We require service providers that process Personal Data on our behalf to implement appropriate security measures.
If a breach of your personal information occurs, we will notify you and the appropriate authorities without undue delay and within the timeframes the law requires — for California residents, within 30 days of discovering the breach, and sooner where another law or our agreement with your agency requires it.
Children's Privacy
The Service is intended for adults. You must be at least 18 years old (or the age of majority where you live) to create an account or subscribe. We do not knowingly allow anyone under 18 to create an account. A parent, guardian, or authorized representative may create and manage an account on behalf of a senior who receives care. Agencies may store care records about a client who is a minor as part of coordinating that client's care; that information is entered and controlled by the adults responsible for the client, not collected by us directly from a child. We do not knowingly collect personal information directly from anyone under 18; if we learn we have, we will delete it. Because we do not knowingly collect information from anyone under 16, we do not sell or share such information.
Your Rights for Your Personal Data
Depending on your location, you may have rights including:
- Right to Access (PIPEDA, GDPR Art. 15, CCPA/CPRA, CPA, VCDPA, CTDPA, UCPA, LGPD, POPIA)
- Right to Rectification (GDPR Art. 16, CPRA, CPA, VCDPA, CTDPA, LGPD, POPIA)
- Right to be Forgotten / erasure (GDPR Art. 17, CCPA/CPRA, CPA, VCDPA, CTDPA, UCPA, LGPD, POPIA)
- Right to Opt Out (CPRA, CPA, VCDPA, CTDPA, UCPA) — we do not sell Personal Data or use it for targeted advertising; you may still exercise opt-out rights where applicable
- Nondiscrimination and nonretaliation (CCPA/CPRA, CPA, VCDPA, CTDPA, UCPA)
- File an Appeal (CPA, VCDPA, CTDPA) — if you disagree with our response, you may appeal to the regulator in your state where that right applies
- Right to limit the use of sensitive personal information (CCPA/CPRA) — You may direct us to use and disclose your sensitive personal information (such as precise geolocation, health-related information, or government identifiers) only as needed to provide the Service you requested and for other purposes the law permits. We do not use sensitive personal information to infer characteristics about you or for advertising.
- Rights regarding automated decisions (CCPA/CPRA) — Where automated decision-making technology is used for a decision that significantly affects you, you may request information about how it works and request human review, as described in "Our AI and Automated Technology" above.
Withdrawing Consent. If you have consented to our processing of your Personal Data, you may withdraw consent at any time, free of charge, such as opting out of non-essential marketing messages. Contact us using the information below.
How to Exercise Your Rights
You may submit a request by emailing [email protected], using our contact form, or through our privacy request form (hosted by Enzuzo, which processes intake on our behalf); much of your information is also viewable and editable in the app. You may designate an authorized agent to make a request on your behalf — we will ask the agent for proof of authorization and may ask you to verify your own identity directly. We will not discriminate or retaliate against you for exercising your rights. We respond within the timeframes the law requires (for California, generally 45 days, extendable once when reasonably necessary). If we deny your request and your state law provides an appeal (for example, Colorado, Virginia, Connecticut), you may appeal by replying to our decision; if you are still unsatisfied, you may contact your state Attorney General or privacy regulator.
Changes
We may modify this Policy at any time. If we make material changes we will post an updated version on this website and update the effective date. We review and update this Policy at least every 12 months. Continued use after changes constitutes acceptance where permitted by law.
Contact Us
Privacy questions: [email protected] or our contact form linked above.
Privacy Contact
Rithma Inc
251 Main St, Los Altos, CA 94022
Agencies requiring a HIPAA Business Associate Agreement: contact [email protected] before processing PHI in production.