Privacy
This notice covers the website at rindo.io and the Rindo product at app.rindo.io. It is written to be read, not to be skimmed past; if anything here is unclear, write to privacy@rindo.io.
Who is responsible
Rindo is built and operated by the Rindo team, which is not yet incorporated. The company that takes over this notice will be named here when it exists. Until then the team is the party responsible for the data described below, and privacy@rindo.io reaches it.
The website (rindo.io)
The site sets no cookies and runs no analytics or tracking scripts. It is served by Cloudflare, which keeps short-lived request logs (IP address, user agent, requested URL) to operate and protect the service. Rindo does not use those logs to identify visitors.
The product (app.rindo.io)
Rindo is currently a closed preview: accounts are created by the administrator for invited people, and there is no public sign-up.
What Rindo collects
- Account data. A username, a display name, an interface language, your preferences, and timestamps such as when the account was created and last used. If the administrator creates your account for you, they enter these.
- Sign-in data. For password accounts, a salted hash of the password — never the password itself. For Google sign-in, see the next section.
- Content you create. Projects, tasks, documents, comments, files you upload, reviews, and the revision history of each. This is the point of the product, and it is visible to the other members of the projects you belong to, according to their roles.
- Activity records. An audit trail of administrative and content actions (who changed what, when), and server logs holding IP addresses and user agents for security and rate limiting.
- Connections you set up. If you or your administrator connect a git provider, an AI assistant, or an agent runner to Rindo, the tokens that make those connections work are stored encrypted.
Signing in with Google
If you sign in with Google, Rindo asks Google for the openid, email and
profile scopes. Google then shares your Google account identifier, your email
address (with whether it is verified), and your basic profile such as your name
and picture, as permitted by your Google settings.
Rindo uses this data for one purpose: to sign you in and link the Google account to your Rindo account. Concretely, Rindo:
- stores your Google account identifier and your email address, so that the same Google account reaches the same Rindo account next time;
- checks that the email address is verified and, where the administrator has configured it, that it belongs to an allowed domain;
- does not store your profile picture, and does not store any Google access or refresh token — the sign-in exchange is completed and discarded;
- does not use Google user data for advertising, does not sell it, and does not use it to train machine-learning or AI models.
Rindo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
You can see and remove the link between your Google account and your Rindo account under Account → Linked sign-ins; the administrator can remove it as well. Removing the link deletes the stored Google identifier.
How Rindo uses data
To provide the product: showing you your projects, notifying you of mentions and assignments, keeping the history of your content, and searching it. To keep the service secure: rate limiting, detecting abuse, and auditing changes. To support you when you write to us. Nothing else — there is no advertising, no profiling, and no sale of data.
Who else sees data
Rindo runs on infrastructure operated by third parties that process data on the team’s behalf:
- Cloudflare — edge network and TLS termination in front of app.rindo.io and rindo.io.
- The hosting provider — the server in Vietnam on which the product, its database and uploaded files run.
- An embedding provider — if the administrator enables semantic search, the text of documents and tasks is sent to the configured provider to compute search vectors. Which provider is used is shown in the administrator settings.
- Services you connect yourself — a git provider, an AI assistant such as Claude, or an agent runner receives exactly the data the connection is for, under that service’s own terms, and only after you or your administrator set it up.
Beyond these, data leaves Rindo only when the law requires it.
How data is protected
All traffic is encrypted in transit (TLS). Passwords are stored as salted hashes. Tokens and secrets held on your behalf are encrypted at rest with a key that is kept outside the database. Access to data follows the roles of each project; the administrator can see instance-wide administrative information but not your password.
How long data is kept, and how to delete it
Account and content data are kept for as long as the account exists. When an account is deleted by the administrator, its personal data is removed; content you contributed to shared projects may remain attributed to a deactivated account so that the project’s history stays intact. Server logs and rate-limit counters are short-lived. Because Rindo is in closed preview, the instance may also be reset when the preview ends; participants will be told in advance.
To access, correct, or delete your data, or to unlink your Google account, use the Account page or write to privacy@rindo.io. Requests are answered within 30 days.
Children
Rindo is a workplace tool and is not directed at children under 16.
Changes
This page carries the date it was last updated. Material changes will be noted here and, for account holders, announced in the product.