1. Who provides Ritemark
Ritemark is provided by Productory Services OÜ (hereinafter “Productory”, “we”, or “us”). Productory is the controller of the personal data described in this privacy policy. We respect your privacy and are committed to protecting your personal data. This privacy policy explains how we collect, use, share, and protect data in connection with the Ritemark desktop application and the ritemark.app website.
Productory’s training and consulting services and its other products are covered by the Productory privacy policy.
2. What data we collect
We may collect the following data:
- Anonymous Ritemark product-usage events when analytics is enabled
- Written feedback that a user explicitly submits
- ritemark.app website usage data and cookie choices
- Name and contact details (email, phone)
3. How we use data
We use data for the following purposes:
- Improving Ritemark and monitoring reliability
- Communicating with you and responding to inquiries
4. Data sharing
We do not sell personal data. We share data with service providers only where necessary to provide a service, carry out an AI request initiated by the user, or comply with law. Ritemark AI requests travel from the selected local runtime directly to the external AI provider or service selected by the user, not through a Productory AI proxy.
5. The Ritemark desktop application
Local files
Ritemark is a free, open-source desktop application for macOS and Windows. Ritemark stores and edits user files locally. Productory does not receive or host a copy of the user’s workspace as part of ordinary editing. Users choose and control any separate file synchronization or backup service.
Desktop analytics
When analytics is enabled, Ritemark uses PostHog’s EU service to collect anonymous product-usage events. Analytics is enabled by default and can be disabled in Ritemark settings. Ritemark stores a random anonymous identifier in local application state. Events may include app version and platform, app-session starts, feature use, selected agent use, and reaction choices. They do not include AI prompts or file contents. If a user explicitly submits written feedback, the text entered by the user is transmitted with that feedback event.
AI-provider processing
AI features are optional. When a user invokes AI, the selected local runtime sends the request and relevant context directly to the selected external provider or service. Supported routes include Anthropic through Claude Code, OpenAI through Codex, and Google, OpenAI, Anthropic, or OpenRouter through OpenCode. The runtime uses the user’s provider account or API key.
Depending on the task, transmitted context may include the user’s prompt, active-file paths or content, selected text and surrounding context, explicit attachments, shared browser context, recent cross-runtime conversation context, and tool results. Where the user’s permission settings allow it, an agent may also read or modify other workspace files or use tools.
Each provider processes data under the terms, privacy policy, retention choices, and account settings applicable to the user. Productory does not receive the user’s API key through an AI proxy.
User control
Ritemark can be used without invoking AI. Before an AI turn, users can review visible context chips, remove supported context items, choose the runtime and model, and select a permission mode. Removing an item from one turn does not prevent an authorized agent from later reading a workspace file with an allowed tool.
6. The ritemark.app website
The ritemark.app website uses PostHog’s EU service to understand how visitors use the site. It works in one of two ways, depending on your choice.
If you accept analytics cookies, PostHog stores an identifier in a cookie and in your browser’s local storage, so that visits from the same browser can be connected.
If you have not made a choice, or you reject analytics cookies, the website counts visits in PostHog’s cookieless mode. Nothing is written to or read from your browser for analytics. Instead, PostHog calculates a privacy-preserving identifier on its own servers.
In both cases, events may include the pages you view, the page you came from, clicks on page elements such as download buttons, when you leave a page, and technical information such as browser and device type. The website does not use advertising or marketing cookies.
Your cookie choice is stored in your browser’s local storage for six months. You can change it at any time through Cookie settings in the website footer.
7. Your rights
Subject to applicable law, you have the right to:
- Access your data
- Correct your data
- Delete your data
- Restrict data processing
- Object to data processing
To exercise your rights, email info@productory.eu. We generally respond within one month. You also have the right to complain to the Estonian Data Protection Inspectorate at info@aki.ee or through aki.ee.
8. Changes to this policy
We may update this privacy policy. Changes take effect when published on this page, and the date at the top shows the latest version.
9. Contact
If you have questions about this privacy policy or want to exercise your rights, contact us:
Productory Services OÜ
Email: info@productory.eu
Phone: +372 520 1443