ryusu.id
TermsSign in

On this page

  • Who we are
  • Information we collect
  • Google Sign-In and Google user data
  • How we use information
  • Legal bases for processing
  • How information is shared
  • Cookies and local storage
  • How long we keep information
  • Your choices and rights
  • Security
  • International transfers
  • Children's privacy
  • Changes to this policy
  • Contact us

Privacy Policy

This policy explains what information the ryusu.id Portal collects, why we collect it, who we share it with, and the choices you have. It covers the portal at every point you use it — signing in, viewing your projects, and communicating with us.

Who we are

The ryusu.id Portal ("the Portal", "we", "us") is operated by ryusu.id. The Portal is a private, invite-only workspace where our clients follow the progress of the projects we deliver for them: work items and schedules, open actions, risks, and minutes of meeting.

We are the controller of the personal information described in this policy. For the project content that a client organisation stores in the Portal, we act on that organisation's behalf.

Information we collect

We collect only what the Portal needs to function. Specifically:

  • Account information. Your email address, display name, the client organisation you belong to, your role (client user or staff), and — if you sign in with a password — a salted hash of that password. We never store your password in readable form.
  • Google account information, if you choose to sign in with Google. See section 3 for exactly what we receive and keep.
  • Project content. Projects, work items, schedules and assignments, actions, risks, and minutes of meeting — including any files or images uploaded into meeting minutes. This content is created by us and by your project team, and may name you as an assignee or an action owner.
  • Activity records. When a change is made to project data we record who made it, when, what changed, and the before/after values. These audit records exist so a client can always see how a project reached its current state.
  • Technical data. Standard server logs generated when your browser contacts the Portal, such as IP address, request time, and error diagnostics.

We do not run advertising networks, third-party analytics, or tracking pixels on the Portal, and we do not buy personal information from data brokers.

Google Sign-In and Google user data

Signing in with Google is optional — every account can also use an email address and password. If you use it, Google returns a signed identity token to the Portal. We request only the basic profile and email address scopes. We do not request, and cannot access, your Gmail, Drive, Calendar, Contacts, or any other Google service.

From that token we keep exactly two things:

  • Your email address, used solely to match you to an existing Portal account. Accounts are invite-only: if the address does not already belong to an account, sign-in is refused and nothing is stored.
  • Your Google account identifier (the opaque sub value), stored once so that later sign-ins can be recognised as the same Google account.

We discard the rest of the token, including your Google profile picture. We never receive your Google password, and we do not store Google refresh tokens or make API calls to Google on your behalf.

Limited Use. ryusu.id's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to third parties except as necessary to provide or improve the Portal, do not use it for advertising, and do not allow humans to read it except with your consent, for security purposes, to comply with applicable law, or where the data is aggregated and anonymised.

You can disconnect the Portal from your Google account at any time at myaccount.google.com/permissions. Your Portal account and its password sign-in remain unaffected.

How we use information

We use the information described above to:

  • authenticate you and keep your session secure;
  • show you the projects, work items, actions, risks, and minutes that belong to your organisation, and nothing else;
  • assign work and notify the people responsible for it;
  • send transactional email — account invitations, password setup links, and notices about the Portal itself;
  • generate the progress reports you can print or download;
  • keep an audit trail of changes to project data;
  • diagnose faults, prevent abuse, and keep the service available and secure;
  • comply with our legal obligations.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use it to train machine learning models.

Legal bases for processing

Where data protection law requires a legal basis (for example the GDPR), we rely on:

  • Contract — providing the Portal to you and to the organisation that engaged us.
  • Legitimate interests — securing the service, preventing abuse, maintaining audit records, and improving the Portal, balanced against your rights.
  • Consent — where you choose to connect your Google account. You may withdraw it at any time by disconnecting the Portal from your Google account.
  • Legal obligation — where retention or disclosure is required by law.

How information is shared

We share information only with the service providers needed to run the Portal, and only to the extent needed:

  • Hosting and database — the infrastructure provider that runs the Portal's application servers, database, and file storage.
  • Email delivery — our outbound mail provider, used to send invitations and account notices.
  • Google LLC — only if you use Google Sign-In, and only as part of that sign-in exchange.

These providers act on our instructions and are bound to protect the information they handle. We may also disclose information where we are legally required to, or where necessary to protect our rights, the safety of users, or the integrity of the service. If our business is transferred, information may pass to the acquirer subject to this policy.

Within the Portal itself, your name and assigned work are visible to other members of the same project.

Cookies and local storage

The Portal uses cookies strictly to keep you signed in. There are two, both set by us, both expiring after seven days:

  • cp_token — your signed session token.
  • cp_user — your display name, role, and organisation, so the interface can render correctly on first load.

Both are restricted to same-site requests. We set no advertising or analytics cookies. On the sign-in page only, the official Google Identity Services script is loaded from Google in order to display the Google sign-in button; Google may set its own cookies at that point under Google's Privacy Policy. Clearing your cookies signs you out.

How long we keep information

We keep account information for as long as your account is active. When an account is closed, we delete or anonymise its personal information within 90 days, except where we must keep it longer to meet a legal obligation or to resolve a dispute.

Project content and audit records belong to the client organisation and are retained for the life of the engagement and any agreed archival period. Server logs are kept for a short operational window and then discarded.

Your choices and rights

Depending on where you live, you may have the right to access, correct, export, or delete your personal information, to object to or restrict certain processing, and to withdraw consent. To exercise any of these, email jose@ryusu.id from the address on your account. We respond within 30 days.

You can also disconnect Google Sign-In yourself at any time — see section 3. Because accounts are created by invitation and tied to a client engagement, deleting your account may require confirmation from your organisation's project lead. You have the right to complain to your local data protection authority.

Security

Passwords are stored only as salted hashes. Sessions use signed tokens with a limited lifetime. Access to project data is scoped to your organisation and checked on every request, and every administrative change is written to an audit log. Access to production systems is limited to the staff who need it.

No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify you and any relevant regulator as required by law.

International transfers

We operate from Indonesia and our providers may process information in other countries. Where information is transferred across borders, we rely on appropriate safeguards — such as standard contractual clauses — to protect it.

Children's privacy

The Portal is a business tool and is not directed at children. We do not knowingly collect information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

Changes to this policy

We may update this policy as the Portal changes. The effective date at the top of this page always reflects the current version. If a change materially affects how we handle your information, we will notify account holders by email before it takes effect.

Contact us

Questions, requests, or complaints about this policy or your information: jose@ryusu.id.

ryusu.id — Indonesia