ryusu.id Portal
Privacy Policy
Effective 4 August 2026
This policy explains what information the ryusu.id Portal collects, why we collect it, who we share it with, and the choices you have. It covers the portal at every point you use it — signing in, viewing your projects, and communicating with us.
1Who we are
The ryusu.id Portal ("the Portal", "we", "us") is operated by ryusu.id. The Portal is a private, invite-only workspace where our clients follow the progress of the projects we deliver for them: work items and schedules, open actions, risks, and minutes of meeting.
We are the controller of the personal information described in this policy. For the project content that a client organisation stores in the Portal, we act on that organisation's behalf.
2Information we collect
We collect only what the Portal needs to function. Specifically:
- Account information. Your email address, display name, the client organisation you belong to, your role (client user or staff), and — if you sign in with a password — a salted hash of that password. We never store your password in readable form.
- Google account information, if you choose to sign in with Google. See section 3 for exactly what we receive and keep.
- Project content. Projects, work items, schedules and assignments, actions, risks, and minutes of meeting — including any files or images uploaded into meeting minutes. This content is created by us and by your project team, and may name you as an assignee or an action owner.
- Activity records. When a change is made to project data we record who made it, when, what changed, and the before/after values. These audit records exist so a client can always see how a project reached its current state.
- Technical data. Standard server logs generated when your browser contacts the Portal, such as IP address, request time, and error diagnostics.
We do not run advertising networks, third-party analytics, or tracking pixels on the Portal, and we do not buy personal information from data brokers.
3Google Sign-In and Google user data
Signing in with Google is optional — every account can also use an email address and password. If you use it, Google returns a signed identity token to the Portal. We request only the basic profile and email address scopes. We do not request, and cannot access, your Gmail, Drive, Calendar, Contacts, or any other Google service.
From that token we keep exactly two things:
- Your email address, used solely to match you to an existing Portal account. Accounts are invite-only: if the address does not already belong to an account, sign-in is refused and nothing is stored.
- Your Google account identifier (the opaque
subvalue), stored once so that later sign-ins can be recognised as the same Google account.
We discard the rest of the token, including your Google profile picture. We never receive your Google password, and we do not store Google refresh tokens or make API calls to Google on your behalf.
Limited Use. ryusu.id's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide or improve the Portal, do not use it for advertising, and do not allow humans to read it except with your consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.
You can disconnect the Portal from your Google account at any time at myaccount.google.com/permissions. Your Portal account and its password sign-in remain unaffected.
4How we use information
We use the information described above to:
- authenticate you and keep your session secure;
- show you the projects, work items, actions, risks, and minutes that belong to your organisation, and nothing else;
- assign work and notify the people responsible for it;
- send transactional email — account invitations, password setup links, and notices about the Portal itself;
- generate the progress reports you can print or download;
- keep an audit trail of changes to project data;
- diagnose faults, prevent abuse, and keep the service available and secure;
- comply with our legal obligations.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train machine learning models.
5Legal bases for processing
Where data protection law requires a legal basis (for example the GDPR), we rely on:
- Contract — providing the Portal to you and to the organisation that engaged us.
- Legitimate interests — securing the service, preventing abuse, maintaining audit records, and improving the Portal, balanced against your rights.
- Consent — where you choose to connect your Google account. You may withdraw it at any time by disconnecting the Portal from your Google account.
- Legal obligation — where retention or disclosure is required by law.
8How long we keep information
We keep account information for as long as your account is active. When an account is closed, we delete or anonymise its personal information within 90 days, except where we must keep it longer to meet a legal obligation or to resolve a dispute.
Project content and audit records belong to the client organisation and are retained for the life of the engagement and any agreed archival period. Server logs are kept for a short operational window and then discarded.
9Your choices and rights
Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email jose@ryusu.id from the address on your account. We respond within 30 days.
You can also disconnect Google Sign-In yourself at any time — see section 3. Because accounts are created by invitation and tied to a client engagement, deleting your account may require confirmation from your organisation's project lead. You have the right to complain to your local data protection authority.
10Security
Passwords are stored only as salted hashes. Sessions use signed tokens with a limited lifetime. Access to project data is scoped to your organisation and checked on every request, and every administrative change is written to an audit log. Access to production systems is limited to the staff who need it.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any relevant regulator as required by law.
11International transfers
We operate from Indonesia and our providers may process information in other countries. Where information is transferred across borders, we rely on appropriate safeguards — such as standard contractual clauses — to protect it.
12Children's privacy
The Portal is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.
13Changes to this policy
We may update this policy as the Portal changes. The effective date at the top of this page always reflects the current version. If a change materially affects how we handle your information, we will notify account holders by email before it takes effect.
14Contact us
Questions, requests, or complaints about this policy or your information: jose@ryusu.id.
ryusu.id — Indonesia