Tarutha Privacy Policy

Version 1.1, 14 September 2026

This policy explains what personal data Tarutha collects, why, and what you can do about it. Tarutha is operated by PT Teman Bisnis Digital, Indonesia, which is the data controller. Contact: [email protected].

1. What we collect

Data When Why
Google account subject ID and email, and the access granted to the account When you sign in with Google To create your session, identify your keys, and decide what you can open
Session record (ID, creation time, expiry) While you are signed in To keep you signed in for up to 12 hours
API key record: prefix, hash, name, your email, and your account ID for keys you create yourself When a key is issued To authenticate requests and list your keys. We store a hash, never the key itself
Request logs: key ID, method, path, status, time, latency, response size, request ID, client IP Every API request Rate limiting, usage metering, abuse prevention, debugging
Support emails When you write to us To answer you

We do not collect payment card data. Memberships are paid by bank transfer against an invoice.

2. What we do not do

  1. We do not sell personal data.
  2. We do not use your data for advertising.
  3. We do not read your queries to build a profile of you. Request logs are used in aggregate and for debugging a request you report.

3. Who processes the data for us

Processor Role Location
Google Sign-in, and the support mailbox that receives your emails Google's infrastructure
Cloudflare Network edge, DNS, access control Cloudflare's global network
Tencent Cloud The server that runs Tarutha and stores the database Asia region
Cloudflare R2 Encrypted nightly backups Cloudflare's network

Some of these providers store data outside Indonesia. We use them under their standard contractual terms.

4. How long we keep it

Data Retention
Session Stops working after 12 hours. The record is deleted 30 days after it expires
Account (subject ID, email) Until you ask us to delete it
API key record Until you delete your account. A revoked key's record is kept so the key keeps being refused
Request logs 12 months
Backups Rolling. A deleted record leaves backups within 30 days

5. Your rights

Under Indonesian law you can ask us to:

  1. tell you what personal data we hold about you.
  2. correct it.
  3. delete it, which ends your account and revokes your keys.
  4. give you a copy in a common format.
  5. stop a specific processing, where the law allows.

Email [email protected]. We answer requests to access or correct your data within 3 x 24 hours, as UU 27/2022 requires, and other requests as soon as the law requires. We may ask you to prove you own the account.

6. Security

Keys are stored as hashes. Sessions are server-side and revocable. The database is on a private network, backed up nightly to encrypted storage. If we confirm that your personal data was accessed without authorisation, we tell you within 3 x 24 hours of confirming it, as the law requires.

7. Children

Tarutha is for professional and adult use. We do not knowingly collect data from anyone under 18.

8. Changes

We post updates at tarutha.co/privacy with a new version number and date, and email account holders about material changes.