Legal
Privacy notice
What personal data this website and the PlanRhythm product collect, why we hold it, where it is stored, who else can see it, and what you can ask us to do about it.
Last updated 10 August 2026.
What this notice covers, and what it does not
This is our notice for two things: this website, planrhythm.in, and the PlanRhythm product a practice uses with its clients.
One line does most of the work, and every privacy law we work under starts from it. For a practice's own account data we decide what is collected and why, so we are the controller — the Data Fiduciary, in the words of India's DPDP Act. For the client health data a practice puts in, the practice is the controller and we are its processor, holding that data on its instructions and for no purpose of our own.
It is not the notice your dietitian owes you. If you are a client of a practice that uses PlanRhythm, that practice decides what to record about you and why. It stays responsible for its own privacy notice, its own consent and its own retention choices. We hold that data for it and act on its instructions.
This is a plain-language summary of how we handle personal data. It is written to be understood rather than to be exhaustive, and it is not legal advice. If you run a practice, take your own advice on what your own notice and consent must say.
1. Who we are
PlanRhythm is practice software for dietitians and nutritionists. It is built and operated from India, designed for practices in India. In this notice, "we" and "us" mean PlanRhythm. You can reach us at hello@planrhythm.com.
We have written this notice under India's Digital Personal Data Protection Act, 2023 (DPDP Act). Under the DPDP Act, the practice is the Data Fiduciary (the party that decides what is collected and why) and PlanRhythm is the Data Processor (the party that holds it and acts strictly on instructions).
2. The distinction that matters
Practice account data — we decide, so we are responsible
When you sign up, we collect what we need to run your account and bill you. We chose those fields, we decide how long to keep them, and you can hold us to account for them directly. Under the DPDP Act, PlanRhythm acts as its Data Fiduciary.
Client health data — the practice decides, we only hold it
When a dietitian records her client's intake answers, weight, meal plan, check-ins, photographs and consultation notes, that record belongs to the practice. The practice decides what goes in it and why. We store and process it on her instructions and for no purpose of our own. We do not sell it, do not show it to other practices, and do not use it to train machine-learning models.
Under the DPDP Act, the practice is the Data Fiduciary and we are its Data Processor. Our instructions come from the practice, through the agreement it signs with us, and we do not go outside them.
If you are a client and want your record corrected or deleted, ask your dietitian first — the record is hers to change. If she asks us to act on it, we act.
3. What we collect
From this website
Nothing until you type it. There is no analytics on this site, no advertising pixel, no heatmap, no social widget. If you send an enquiry — through the site, by email or on WhatsApp — we receive your name, your practice name, your email address, your phone number and whatever you write. We use it to reply and to arrange a demo, and for nothing else.
The fonts used on these pages are self-hosted on planrhythm.in. Loading the site does not contact Google Fonts, an analytics provider, an advertising network or a social widget. The WhatsApp link is only a link; your browser contacts WhatsApp only if you choose to open it.
From a practice
- Practice name, practitioner names, email addresses and phone numbers.
- Your GSTIN or local tax registration number — if you give it to us for invoicing.
- Your client counts for the month, invoices and payment records.
- Sign-in records and an audit trail of who changed what, and when.
About a client, on behalf of the practice
- Intake questionnaire answers, including health conditions, medication, allergies and dietary restrictions, and any answers flagged for the practitioner's review queue.
- Meal plans and every published version of them.
- Daily check-in entries — followed the plan, adapted it, ate something different, couldn't do it, skipped — and days with nothing recorded at all.
- Photos, voice notes and free text a client chooses to send.
- Water, sleep, stress and Bristol entries, when she logs them.
- Weight and measurements, when they are recorded.
- Messages and attachments between practitioner and client.
- Consultation notes written by the practitioner, with their lock and revision trail.
- The phone number or email address a one-time sign-in code is sent to, and a record of sign-ins.
- Technical records needed to sync a device that was offline and has come back online.
4. Diet, religion and explicit consent
Some diets say something about faith. A Jain or Swaminarayan diet, or a fast a client keeps through Navratri, Ekadashi, Vrat, or Ramadan can reveal a religious belief. Under the DPDP Act, we treat this as sensitive data. We treat it with care rather than as one more dropdown value.
It is recorded only with the client's explicit consent, and only because it changes what a safe plan looks like — a plan that ignores it is not a plan she can follow.
Health information is treated the same way. Consent is recorded in the app with the date and the version of the wording shown, and it can be withdrawn at any time. Withdrawing consent stops further use of that information; it does not erase plans that were already published, though the practice can delete those too.
5. Why we process it
- To give a practice the product it is paying for: building plans, publishing a day at a time, check-ins, messaging, notes, charts and payments.
- To deliver one-time sign-in codes and notifications to a client's phone or email.
- To take your subscription payment and issue an invoice.
- To answer support requests and fix faults.
- To keep the audit trail and the security records that make an account checkable later.
- To meet legal obligations that apply to us, such as keeping tax and accounting records in India, where we are established.
Things we do not do with it: advertising, profiling for advertising, selling, sharing with another practice, or training machine-learning models on client health data.
And one that is a product law before it is a privacy one: we do not compute an adherence score, a grade, a streak or a red-and-green judgement of any client. A day with nothing recorded is treated as not recorded, never as failure.
6. Our lawful basis
Where we are the controller — practice account data — we rely on the contract with your practice to run the account, on legal obligation for tax and accounting records, on consent for enquiries and for any email you ask to receive, and on legitimate interests for security and audit records. Under the DPDP Act the same processing rests on consent or on the legitimate uses the Act allows.
Where we are the processor — client health data — the lawful basis is your practice's to establish, not ours. A client consents in the app, to her practice, and we keep the record of it. The diet and health information in section 4 is recorded on explicit consent.
Where the law obliges us to keep something — a tax invoice, for instance — we keep it on that basis rather than on consent, and withdrawing consent does not remove it.
7. Where the data is stored
PlanRhythm runs on Microsoft Azure Central India (Pune/Mumbai). Your practice's data lives in Central India, encrypted in transit and at rest, and does not leave India. Backups stay in the same region as the data they protect.
8. How long we keep it
- While the account is open: for as long as the practice keeps it, because the record is the point of the product.
- After a practice closes its account: 60 days so the data can be exported, then deletion within a further 30 days.
- When a practice deletes a client's record: it goes from the live system straight away. Backups are overwritten on a rolling cycle, so a copy can survive in a backup for a short period before it is gone for good.
- Invoices and tax records: as long as the tax law that applies to us requires us to keep them. That is Indian tax law today.
- Audit records: for the life of the account. Their whole purpose is to be checkable later.
9. Who else sees it
A short list, and it stays short.
- Microsoft Azure, which provides the servers and storage the data sits on, in the region named in section 7.
- A payment processor, for collecting our own subscription fees. It gets what it needs to take the payment. It does not get client health data.
- A messaging provider, to deliver one-time sign-in codes and notifications by SMS, WhatsApp or email. It gets the phone number or email address and the message itself.
- Authorities or professional advisers, where the law requires it. We will tell the practice unless we are legally barred from doing so.
A current list of these providers, and the country each one operates from, is available on request before you sign. Ask for it.
We do not sell personal data. Not to advertisers, not to data brokers, not to pharmaceutical or supplement companies, not to anyone. There is no version of PlanRhythm in which that becomes a line of revenue.
10. Your rights
Under India's Digital Personal Data Protection (DPDP) Act, 2023, you hold specific rights as a Data Principal. You can ask us for:
- Access — a summary of the personal data we hold about you and what we do with it.
- Correction and completion — anything wrong, out of date or missing.
- Erasure — deletion, unless the law requires us to keep it.
- Withdrawal of consent — as easily as you gave it.
- Nomination — naming someone to exercise these rights if you die or cannot act for yourself.
- Grievance redressal — a complaint to our Grievance Officer before you go anywhere else.
If you are a practice, write to us and we will act. If you are a client of a practice, start with your dietitian: her record, her decision. Write to us as well if she does not respond, and we will help her act on it.
You can also complain to the regulator: the Data Protection Board of India.
We aim to answer any request within 30 days, and to tell you if it will take longer and why. Where a regime gives us a month, we do not use the extra days.
11. Cookies
This website sets no cookies. None for analytics, none for advertising, none at all. Two scripts run here: one opens the mobile menu, handles the contact form and stamps the year in the footer; the other runs the calculator on the pricing page. Neither stores anything on your device — no cookie, no local storage, nothing. The calculator works entirely in your browser: the client numbers you type stay on the page, are not sent to us or to anyone else, and are gone when you close the tab. So there is no cookie banner here, because there is nothing to ask you about.
The product is different, and only in the way it has to be. When you sign in, it stores a session token so you stay signed in, and a client's app keeps her plan and her recent entries on her own device so it works on a train, in a basement or on one bar of signal, and syncs when the network returns. That is what makes offline work; it is not tracking, and it cannot be switched off without breaking sign-in.
12. How we protect it
- Data is encrypted in transit and at rest, in the Azure region named in section 7.
- Access is by role. An owner sees the practice; staff see only the clients assigned to them.
- Consultation notes carry a lock and a revision trail, so an old note still says what it said and an amendment is visible as an amendment.
- An audit trail records who read or changed what.
- Clients sign in with a one-time code rather than a password, so there is no password to reuse, leak or forget.
No system is perfectly secure and we will not claim otherwise.
If a breach occurs, we will tell the practices affected without undue delay. That is not a courtesy: a practice is the controller of its clients' data and has its own reporting clock to meet under India's DPDP Act 2023. We will notify the Data Protection Board of India, and any other regulator or affected person the law requires, and we will tell you what we know and when we knew it.
13. Children
PlanRhythm is intended for use with adult clients. Under the DPDP Act, individuals under 18 require verifiable consent from a parent or lawful guardian. If a practice works with anyone under 18, obtaining and recording that consent is the practice's responsibility. Nothing in PlanRhythm profiles or advertises to anyone, of any age.
14. Changes to this notice
When this notice changes we update the date at the top of the page. If a change materially affects what we do with personal data, we will tell the practices using PlanRhythm directly rather than relying on you to re-read the page.
15. How to reach us, wherever you are
Every question about data, and every complaint, reaches a person. Different regimes expect different routes, so there are two — and both are read by the same people. You do not need a particular form of words.
Privacy contact, PlanRhythm
For anyone, anywhere: a question, a request about your data, or a complaint.
Email grievance@planrhythm.com
General enquiries hello@planrhythm.com
Message us on WhatsApp (+91 86904 05060)
We reply within one working day. Tell us what you want done and we will tell you what we can do and by when.
Grievance Officer, PlanRhythm
Grievance Officer: PlanRhythm Privacy Team
Email: grievance@planrhythm.com
Phone / WhatsApp: +91 86904 05060
The route the DPDP Act requires for a Data Principal in India. Raise it with us first. If we do not resolve it, you can take it to the Data Protection Board of India.
Last updated 10 August 2026.
Something here unclear?
Ask. If a line in this notice does not answer your question, that is a fault in the notice and we would like to fix it.