Privacy Policy
Last updated: October 2, 2026
This policy explains how RYUKSAIDSO ("we", "us") collects, uses and protects your personal information when you use our agent control plane and related services. By using the service you agree to the practices described here. If you do not agree, please do not use the service.
1Information we collect
- Account data — your name, email address, hashed password, workspace membership and role.
- Workspace content — the agents, prompts, evaluations, documents you upload for knowledge sync, chat-widget conversations and other content you create inside a workspace.
- Run data — agent run inputs and outputs, traces, steps, tool calls and timings, which power the platform's tracing, approval and reliability features.
- Integration data — OAuth access and refresh tokens for the third-party accounts you choose to connect, plus the data those connections return while syncing or running tools.
- Support messages — messages you send through the in-app customer support channel, together with your name, email and workspace so we can reply.
- Payment data — plan, subscription status, invoices and payment confirmations processed by our payment provider. Card, UPI and net-banking credentials never touch our servers.
- Technical data — request logs, IP address, browser user agent, timestamps and error traces used for security, rate limiting and debugging.
2How we use your information
- Provide and operate the service: authentication, workspaces, agent runs, traces, approvals and evaluations.
- Secure the service: session validation, CSRF protection, rate limiting, abuse prevention and audit logging.
- Send transactional email — email verification, password resets and billing notices.
- Manage subscriptions, process payments and keep required billing records.
- Answer your support messages and improve the product based on feedback.
We do not sell your personal data, and we do not use your workspace content to train AI models.
3AI model processing
To execute agents, the relevant prompt content — including data pulled from connected integrations or uploaded documents — is sent to the model provider configured for your workspace. That is the default OmniRoute gateway, a local Ollama instance, or a custom model endpoint added by a workspace admin. Those providers process the content under their own privacy policies.
Model responses are stored as part of your run history so traces, evaluations and rollbacks work as designed.
4Integrations and connected accounts
Third-party connections (such as Gmail, Google Drive, Slack, Notion, GitHub and others) use OAuth 2.0 — you approve the requested scopes on the provider's own consent screen and we never see or store your third-party password. We store the resulting tokens encrypted at rest and only use them to sync content and run the tools you enable.
You can disconnect an integration at any time from Integrations, which deletes its stored credentials and stops further syncing.
5Payments
Checkout happens on our payment provider's (Cashfree) hosted page. We receive confirmation of the transaction — reference IDs, amount, status and plan — but never your card number, UPI PIN or banking password.
6Cookies and local storage
- Essential cookies — access, refresh and CSRF cookies that keep you signed in and protect form submissions. The service cannot function without them.
- Local storage — your theme preference (dark / light / system) is stored in your browser only.
We do not use advertising or cross-site tracking cookies.
7Who we share data with
We share data only with the subprocessors needed to run the service:
- Cloud hosting (AWS) — where the application, database and logs live.
- Cashfree — payment processing and webhooks.
- Model providers — the OmniRoute gateway, Ollama, or any custom endpoint your workspace admin configures, solely to execute runs (see section 3).
- Transactional email provider — verification and reset emails.
- Connected app providers — only when you explicitly connect an integration.
We may also disclose information if required by law or to protect the rights, safety and property of our users or the public. We do not sell data to anyone.
8Data retention and deletion
We keep your information for as long as your account is active so the workspace functions — runs, traces and documents stay available to your team. When you delete content or close an account, we remove the corresponding personal data from active systems within a reasonable period, except records (such as invoices) we must retain to comply with legal, tax or accounting obligations.
Request deletion any time by contacting us at the address below — account deletion is honored for every workspace owner.
9Security
Data is encrypted in transit with TLS. Integration credentials and custom model-provider API keys are encrypted at rest with AES-256-GCM, passwords are stored only as salted bcrypt hashes and platform API keys are stored as hashes. Access to production infrastructure is restricted, logged and audited.
No system is perfectly secure — if we learn of a breach affecting your personal data, we will notify you and the relevant authorities as required by law.
10Your rights
Depending on where you live (including under India's Digital Personal Data Protection Act, the GDPR and similar laws), you may have the right to access, correct, export or delete your personal data, withdraw consent, and object to or restrict certain processing.
To exercise any of these rights, contact us at faizanhameed690@gmail.com or through the in-app support channel. We respond to verified requests within the timeframe required by applicable law.
11Children's privacy
The service is built for professional and organizational use and is not directed at children under 16. We do not knowingly collect personal information from children — if you believe a child has provided us data, contact us and we will delete it.
12Changes to this policy
We may update this policy from time to time. The "Last updated" date at the top always reflects the latest revision, and material changes will be announced in the app or by email. Continued use of the service after an update means you accept the revised policy.
13Contact us
Questions about this policy or your data? Reach the founder directly — RYUKSAIDSO is operated by Faizan Hameed.
Email: faizanhameed690@gmail.com · In-app: the support icon in the top bar sends a message straight to the CEO.