Privacy Policy
Last updated: 27 August 2026
RYQO is operated by SPARSIM, which is the data controller for the data described here. This page says what we hold, why we hold it, and who else touches it.
What we collect
- Account — your email address and display name.
- Workspace content — projects, issues, comments, documents, and the code and files your agents work on.
- Session records — what an agent did: its plan, tool calls, diffs and output. This is the product's main feature and cannot be turned off while a session runs.
- Usage — token counts and cost attributed to a workspace, so you can see what was spent.
- Registrant details — if you register a domain through us: name, email, postal address and phone. Registries require these and verify them.
What we do not collect
We never see your card. Payment details are entered at Paddle and stay there; we receive only the outcome of a payment and the last four digits of the card, if that.
We do not read your AI provider credentials: they stay on the machine that runs your agent, and we hold only the fact that an account exists and what it is allowed to do.
Why we hold it
To provide the service you asked for (performance of a contract), to bill correctly and meet tax obligations (legal obligation), and to keep the platform secure and abuse-free (legitimate interest).
Who else processes it
- Paddle — payments, invoicing and tax, as merchant of record.
-
Google Cloud — building and running the applications we host, in the
europe-west1region. - Cloudflare — DNS, TLS and serving traffic at the edge.
- Neon — the database of each hosted application, in the EU.
- name.com — domain registration. Registrant details are passed to the registrar and to the relevant registry, which is what a registration requires.
- GitHub — repositories holding the code of hosted applications.
Registrant details are encrypted before storage and are shown back to nobody, including us, after they are submitted.
Where it lives
Application data and databases are hosted in the European Union. Some processors above operate globally and may process data outside the EU under standard contractual clauses.
How long we keep it
Workspace content and session records are kept while your account is open, and for 30 days after it closes so you can export them. Billing records are kept as long as tax law requires — this is usually longer, and we cannot delete them earlier.
Your rights
You can ask for a copy of your data, ask us to correct it, or ask us to delete it. Write to hello@ryqo.io and we will answer within 30 days. If you are in the EU or UK you may also complain to your local data protection authority.
Cookies
This site sets no analytics or advertising cookies. The application at
app.ryqo.io sets a session cookie, which is required to keep you signed in.
Changes
If we change this policy materially we will say so by email or in the product before the change takes effect.
Contact
Privacy questions: hello@ryqo.io.