Tarutha Privacy Policy
Version 1.1, 14 September 2026
This policy explains what personal data Tarutha collects, why, and what you can do about it. Tarutha is operated by PT Teman Bisnis Digital, Indonesia, which is the data controller. Contact: [email protected].
1. What we collect
| Data | When | Why |
|---|---|---|
| Google account subject ID and email, and the access granted to the account | When you sign in with Google | To create your session, identify your keys, and decide what you can open |
| Session record (ID, creation time, expiry) | While you are signed in | To keep you signed in for up to 12 hours |
| API key record: prefix, hash, name, your email, and your account ID for keys you create yourself | When a key is issued | To authenticate requests and list your keys. We store a hash, never the key itself |
| Request logs: key ID, method, path, status, time, latency, response size, request ID, client IP | Every API request | Rate limiting, usage metering, abuse prevention, debugging |
| Support emails | When you write to us | To answer you |
We do not collect payment card data. Memberships are paid by bank transfer against an invoice.
2. What we do not do
- We do not sell personal data.
- We do not use your data for advertising.
- We do not read your queries to build a profile of you. Request logs are used in aggregate and for debugging a request you report.
3. Who processes the data for us
| Processor | Role | Location |
|---|---|---|
| Sign-in, and the support mailbox that receives your emails | Google's infrastructure | |
| Cloudflare | Network edge, DNS, access control | Cloudflare's global network |
| Tencent Cloud | The server that runs Tarutha and stores the database | Asia region |
| Cloudflare R2 | Encrypted nightly backups | Cloudflare's network |
Some of these providers store data outside Indonesia. We use them under their standard contractual terms.
4. How long we keep it
| Data | Retention |
|---|---|
| Session | Stops working after 12 hours. The record is deleted 30 days after it expires |
| Account (subject ID, email) | Until you ask us to delete it |
| API key record | Until you delete your account. A revoked key's record is kept so the key keeps being refused |
| Request logs | 12 months |
| Backups | Rolling. A deleted record leaves backups within 30 days |
5. Your rights
Under Indonesian law you can ask us to:
- tell you what personal data we hold about you.
- correct it.
- delete it, which ends your account and revokes your keys.
- give you a copy in a common format.
- stop a specific processing, where the law allows.
Email [email protected]. We answer requests to access or correct your data within 3 x 24 hours, as UU 27/2022 requires, and other requests as soon as the law requires. We may ask you to prove you own the account.
6. Security
Keys are stored as hashes. Sessions are server-side and revocable. The database is on a private network, backed up nightly to encrypted storage. If we confirm that your personal data was accessed without authorisation, we tell you within 3 x 24 hours of confirming it, as the law requires.
7. Children
Tarutha is for professional and adult use. We do not knowingly collect data from anyone under 18.
8. Changes
We post updates at tarutha.co/privacy with a new version number and date, and email account holders about material changes.