Privacy Policy
Last updated: 28 September 2026.
Ratito ("we", "us") is a collaborative video diary app operated by Barbara Sanchis Server, based in the United Kingdom. This policy explains what personal data we collect, why, where it's processed, and how you can control it.
1. Who this policy covers, and which law applies
We're UK-based, so UK GDPR and the Data Protection Act 2018 are our primary framework, and the Information Commissioner's Office (ICO) is our lead regulator. Because Ratito's users include people located in the EU, EU GDPR applies in parallel — this policy is written to satisfy both.
2. Who we are
Ratito is operated by Barbara Sanchis Server, an individual based in the United Kingdom. For any privacy question, request, or complaint, contact hello@ratitoapp.com.
3. What we collect
Account data. When you sign up (email + password, or native Sign in with Apple/Google), we collect your email address and, for email sign-up, a password (stored as a hash we never see in plain text, via Supabase Auth). Your display name and, if you set one, an avatar image are stored in your profile.
Content you and your collaborators create. The 1-second video clips you record, and their thumbnails, are stored in our video storage (Cloudflare R2). Clip metadata — who recorded it, when, and which stream it belongs to — is stored in our database (Supabase Postgres).
Product analytics. We use PostHog to understand which features are used, where people get stuck, and when something breaks. This runs by default, on the basis described in §7, which also covers exactly what it does and doesn't include and how to opt out.
Push notification data. If you allow notifications, we store a device push token — an opaque identifier for your device, not your identity — so we can notify you when your video export is ready. We also record whether you've granted or denied notification permission, and when, so we don't ask again after you've already answered. You can turn export notifications off separately in Settings, or revoke notification permission entirely in your device's system settings; either way, we stop sending to that device.
What we deliberately don't collect: no payment or billing information (Ratito is currently free — see §11), no phone number, no location data, no contacts-list access, and no facial-recognition or biometric identification of anyone in your clips — we don't analyse video content at all, we just store and play it back.
4. People who appear in clips but never signed up
Ratito's whole purpose is capturing moments with the people around you — which means clips will often show people who are not Ratito account holders themselves: children, friends, family members who never created an account. That footage is still personal data, and we want to be direct about how we think about it.
Capturing and sharing footage of the people in your life, within a private group you chose to invite, is treated as part of your own personal/household use of the app — the same basis that covers taking a photo of your family on your phone. Separately, we (Ratito) have our own legitimate interest in providing the storage and sharing service that makes that possible. Recording contributors are responsible for having an appropriate relationship and context to capture and share footage of people around them within their stream.
This applies in particular to footage of children. We don't have a way to detect or restrict this technically, and restricting it in principle would work against the app's actual purpose — a shared family/friend diary is expected to include children who are never account holders themselves. If you're uncomfortable with footage of you appearing in someone else's stream, contact hello@ratitoapp.com and we'll help you get it removed.
5. Why we process your data, and on what legal basis
- Providing the service (your account, your streams, your clips, exports) — necessary to perform our contract with you.
- Keeping a shared stream intact when a contributor leaves (§8) — our legitimate interest, and that of the stream's other members, in preserving a collaborative work they co-created.
- Product analytics and debugging (§7) — our legitimate interest in understanding how Ratito is used and catching bugs. You can opt out at any time — see §7.
- Security (rate-limiting, fraud/abuse prevention) — our legitimate interest in keeping the service and its users safe.
We don't currently send marketing communications. If that changes, it will be on the basis of your separate, specific consent — never bundled into accepting these terms.
6. Who we share data with
We use a small number of infrastructure providers ("subprocessors") to run Ratito. None of them can use your data for their own purposes — they process it only to provide their service to us.
- Supabase (authentication + database) — hosted in France, EU.
- Cloudflare R2 (video and thumbnail storage) — hosted in the Western Europe (WEUR) region.
- AWS Lambda (video stitching — combining your group's clips into one film) — hosted in London, UK. This process only ever receives a stream identifier and a list of clip file references — never your name, email, or profile data.
- PostHog (product analytics) — hosted on PostHog's EU infrastructure. See §7.
- Expo (push notification delivery) — relays your device's push token and the notification's title and message to Apple's Push Notification service or Google's Firebase Cloud Messaging, depending on your device. An export-ready message may include the name of the relevant stream; it never includes your email address, profile name, or video clips.
We never sell your data, and we don't share it with advertisers.
7. Analytics — how it works, and exactly what we track
We're not a brick-and-mortar business, so usage data is genuinely useful to us — it's how we decide what to build next and catch bugs we'd otherwise never see. This is basic, non-invasive product analytics — not advertising or profiling — and it runs on our legitimate interest in understanding and improving the app.
Here's exactly what that covers. What's tracked: actions like signing up, creating or joining a stream, recording and syncing a clip, requesting an export, and sending an invite — each recorded as a named event with a small number of technical properties (e.g. which method you signed in with, an error code if something failed, how many clips a stream has). Two rolling counts (how many streams you own/contribute to) are attached to your profile. We also automatically see basic app-usage signals (when the app opens, which screen you're on) and get notified if the app crashes, so we can fix it.
What's never included: your email address, your display name, or the content of any video — analytics never touches your clips. Events are linked to your account via an internal account identifier, not your email.
PostHog is configured to discard your device's IP address rather than store it. If you'd like to stop sharing usage analytics, or have your analytics history reset, contact hello@ratitoapp.com and we'll turn it off for your account.
8. What happens to your clips when your membership in a stream ends
Your membership in a stream can end in three ways: you leave it yourself, the stream's owner removes you from it, or you delete your account entirely. Whichever way it happens, the same rule applies — a shared stream is never destroyed just because one member is gone, and your clips are never deleted along with your membership. They're reassigned so the shared film your group is building stays intact:
- If you're the only member of a stream, leaving it (or deleting your account) deletes the stream and its clips entirely.
- If you own a shared stream and you leave it (or delete your account), ownership passes to its longest-standing remaining member, along with your own clips in it.
- If you contribute to a shared stream and you leave it, are removed by its owner, or delete your account, your clips stay in the stream, reassigned to the stream's owner — so your departure doesn't destroy a collaborative film other people are still part of.
A stream's owner can remove a contributor at any time — see our Terms of Service §4 for what that means, including that a removed contributor can't rejoin the stream unless the owner allows them back. Being removed carries the same clip-reassignment consequence described above.
We keep a durable, non-public record of who a membership change was done by and to, and what happened to any clips, so we can explain or help undo it if you contact us about it. That record isn't shown anywhere in the app and doesn't disappear if the stream itself is later deleted.
If you'd like a specific clip removed from a stream even while your account, or the stream, stays open — for example after you've left it — contact hello@ratitoapp.com. We handle this case by case; it isn't yet a self-service feature in the app.
When you delete your account, your login credentials, password, and profile data are permanently deleted straight away. Deleted data can persist for a limited time in backups before being fully purged — see §9. We keep a minimal, non-personal record that a deletion happened (so we can demonstrate it took place), which contains no information that could identify you. If you don't have the app installed, or can't sign in, email hello@ratitoapp.com from your account's email address and we'll delete your account and data manually.
9. How long we keep things
- Video clips are kept for as long as your account and the stream they belong to exist — not on a timer. Storing your moments in the cloud, for as long as you want them there, is core to what Ratito does.
- Finished, stitched exports (the film your group requests) are automatically deleted from storage 14 days after being generated — download and save it to your device in that window.
- Database backups: we currently run backups weekly.
- Push notification device tokens are deleted when you log out or delete your account.
10. Security
Only members of a stream can see its clips — enforced at the database level (Row Level Security), not just in the app's UI. Video files are never publicly accessible; every access uses a short-lived, permission-checked link. The credentials that could access raw video storage never reach your device — all uploads and downloads go through a server-side check first.
11. No monetization today
Ratito is currently free to use, with no in-app purchases or subscriptions. We may introduce paid features in the future — if we do, pricing, billing terms, and cancellation terms will be presented at the time of purchase, and this policy will be updated to describe any new data that involves (e.g. payment processor data).
12. Age requirement
You must be 13 or older to create a Ratito account.
13. Your rights
Under UK/EU GDPR, you can ask us to:
- Access a copy of the personal data we hold about you.
- Correct inaccurate data (or just edit your name/avatar directly in the app).
- Delete your data (in-app account deletion does this immediately — see §8 for what that means for shared streams).
- Export your data in a portable format.
- Object to processing based on our legitimate interests, including the retained-clips arrangement in §8.
Contact hello@ratitoapp.com for any of the above. If you're unhappy with how we've handled your data, you can complain to the ICO (UK) or your local EU data protection authority.
14. Changes to this policy
We'll update this page as Ratito changes, and update the "last updated" date at the top. For a change that meaningfully affects how your data is used, we'll let you know in the app rather than relying on you to check back here.
← Back home