Legal · Ryu

Privacy Policy

Ryu keeps your personal and financial data private. This policy explains what we collect, how we use it, and the control you have.

Last updated · September 28, 2026

Overview

Ryu is a personal finance app for tracking transactions, budgets, and spending. This policy explains what data we collect, why we collect it, who we share it with, and the choices you have. We collect only what the app needs to work and never sell your data.

Data we collect

We collect the following categories of data:

  • Account data: your name, email address, and a password hash when you sign up with email, or your name, email, and profile picture when you sign in with Google.
  • Financial data you enter: transactions, amounts, currencies, categories, budgets, notes, and split-bill shares.
  • Receipt images: photos you upload to attach to a transaction, and text extracted from them by optical character recognition (OCR).
  • Workspace data: the ledgers and teams you create or join, and your role and invitations within them.
  • Billing data: your subscription status and plan, handled by our payments provider. We do not store full card numbers.
  • Technical data: diagnostic logs, error reports, device and browser type, and IP address, used to keep the service reliable and secure.
  • Approximate location: the city and country derived from your IP address when you sign in, shown on your active sessions list so you can spot unfamiliar sign-ins. We do not use GPS or precise location.
  • Android app data: when you use the Ryu Android app, crash and performance reports include your device model, operating system version, app version, and memory and network state. The app does not read your contacts, photos, messages, or other apps.

Google account data

When you choose "Continue with Google," Google shares your name, email address, and profile picture with Ryu. We use this only to create and secure your account and to sign you in. We request the minimum scopes needed for authentication and do not access your Gmail, Drive, contacts, or calendar.

Ryu's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, and we do not sell it or transfer it to third parties except as needed to provide the service, comply with the law, or as part of a merger or acquisition.

How we use your data

  • Provide the core service: store your ledger, compute budgets and insights, and sync across your devices.
  • Authenticate you and keep your account and sessions secure.
  • Read receipt images so we can suggest amounts, merchants, and categories.
  • Send necessary emails such as verification, password reset, and workspace invitations.
  • Process subscriptions and handle billing.
  • Detect, prevent, and debug errors, abuse, and security incidents.

Service providers we share data with

We use trusted third-party processors to run Ryu. Each receives only the data needed for its function and is bound to protect it:

  • Google — sign-in and authentication.
  • Neon — managed PostgreSQL database that stores your account and ledger data.
  • Cloudflare — application hosting and R2 object storage for receipt images.
  • Receipt OCR provider — the configured vision model service that reads uploaded receipt images to extract text.
  • Resend — transactional email delivery.
  • Sentry — error monitoring and diagnostics.
  • Polar — subscription checkout and billing.

Cookies and local storage

On the web, Ryu uses a secure, HTTP-only session cookie to keep you signed in. The website and the Android app also keep small preferences on your device, such as your active wallet and update settings. We do not use advertising or cross-site tracking cookies. Cloudflare may collect aggregated, cookie-free page analytics.

Data retention

We keep your data for as long as your account is active. When you delete your account, we delete your personal and financial data and stored receipt images within 30 days, except where we must retain limited records to comply with legal, tax, or security obligations. Backups are purged on a rolling schedule.

Security

Data is encrypted in transit with TLS and stored with encryption at rest by our infrastructure providers. Passwords are hashed, never stored in plain text. Access to production data is restricted. No system is perfectly secure, so we cannot guarantee absolute security, but we work to protect your data and to respond quickly to incidents.

Your rights and choices

  • Access and export: view and export your transactions and statements from within the app.
  • Correction: edit or delete individual entries, budgets, and receipts at any time.
  • Deletion: delete your account to remove your data, subject to the retention terms above.
  • Communication: transactional emails are required for the service; there is no marketing email to opt out of.

To exercise a right or ask a privacy question, contact us at dev@rin.ci.

Children

Ryu is not directed to children under 13 (or the minimum age in your country), and we do not knowingly collect their data. If you believe a child has provided us data, contact us and we will remove it.

Changes to this policy

We may update this policy as the service evolves. When we make material changes, we will update the date above and, where appropriate, notify you in the app or by email. Continued use after an update means you accept the revised policy.

Contact

Questions about this policy or your data? Email dev@rin.ci.

See also: Terms of Service