Privacy Policy
Last Updated: August 1, 2026. Envoyou is committed to safeguarding your personal and workspace data.
1. Identity of the Data Controller
For the purposes of applicable data protection laws, including the Indonesian Law on Personal Data Protection (UU PDP No. 27/2022) and the European Union General Data Protection Regulation (GDPR), the Data Controller is:
- Operator
- Envoyou is operated by M Husni Kusuma Thohari, an individual business operator based in Indonesia. Envoyou is the trading and product name of the service.
- Business Identification Number (NIB)
- Registered under the NIB Framework of the Republic of Indonesia
- Electronic System Operator (PSE)
- Registered with the Ministry of Communication and Informatics (Kominfo), Republic of Indonesia
- Registered Address
- Cluring, Banyuwangi, Jawa Timur 68482, Indonesia
- Contact Email
- support@envoyou.com
2. Legal Basis for Processing
We process your personal data under the following legal bases established by UU PDP (Chapter V) and GDPR Article 6(1):
To perform the services you register for, including authentication, setting up Clerk organizations, processing subscription transactions, and running editorial polishing cycles.
To maintain site security, analyze and optimize page performance, detect credit card fraud, and prevent spam/abuse of our trial balances.
For optional marketing communications, newsletters, or third-party tracking cookies (which can be withdrawn at any time).
3. AI Data Processing Safeguards
As an AI-driven Editorial Intelligence system, Envoyou enforces strict data confidentiality parameters to protect your proprietary intellectual assets:
- Zero LLM Training
All drafts, source notes, scraped reference URLs, and outlined articles processed through the Envoyou EAI workspace are submitted to Google LLC's Gemini API via secure commercial developer API endpoints. Under our terms, your data is never used to train Google's public large language models (LLMs).
- Encrypted Credentials (AES-256-GCM)
Your external CMS access tokens, API keys, and database secrets are encrypted at rest using industry-standard AES-256-GCM. Decryption keys are managed securely and are never sent or exposed to the browser client.
4. Information We Collect
We collect and process specific categories of data necessary to deliver our services, maintain security, and manage subscriptions:
- Visitor Data (Consent-Based Analytics)
- When you allow optional analytics, Google Analytics may process IP-derived location, browser information, page paths, and non-personal conversion events. The Google Analytics script is not loaded before consent.
- Account Information (Clerk Auth Sync)
- Workspace name, user email, profile photo, and associated organization roles synchronized via our identity partner, Clerk.
- Workspace Inputs (Editorial Content)
- Article drafts, outlines, URL references, briefs, and categories uploaded to the EAI Editor.
- Payment Metadata (Midtrans & Paddle)
- We process transaction identifiers, payment status, subscription plan, billing period, currency, transaction totals, tax information, and limited customer billing details required to activate and manage your subscription. Complete payment card details are never stored. Local Indonesian payments are processed by Midtrans; international payments may be processed by Paddle once global checkout becomes available.
5. Data Retention Schedule
We retain personal and workspace data according to the following retention schedule, after which data is securely deleted or permanently anonymized:
| Data Category | Retention Period | Action Upon Expiry |
|---|---|---|
| Marketing Cookie Logs (GA4) | Up to 14 months from visit | Automatic deletion by Google Analytics |
| Draft Inputs & Refinement Logs | During active membership subscription | Permanent database wipe within 30 days of manual deletion by user or account closure |
| Identity & Auth Metadata (Clerk) | Duration of active account | Deleted within 30 days of account termination |
| Financial Transactions & Taxes | 7 years after the fiscal year end | Retained to comply with Indonesian tax audit and corporate accounting requirements |
6. Third-Party Data Processors
We share specific data subsets with third-party service providers (data processors) who assist us in operating our Site and Service under strict data protection agreements:
- Clerk Inc. — Identity & Auth
- Identity provider managing account logins, security profiles, and multi-tenant organization access.
- Google LLC (Gemini API) — AI Model API
- Primary Large Language Model API, utilized via commercial endpoints to process and rewrite draft content.
- Vercel Inc. — Frontend Edge Hosting
- Frontend deployment, global content distribution, and serverless edge hosting infrastructure.
- Railway Corp. — Backend Infrastructure
- Cloud infrastructure provider hosting the Envoyou EAI & Blog production backend and supporting services.
- Supabase & Neon Database — Database Platforms
- Cloud database platforms hosting the blog and EAI production databases respectively.
- Cloudflare, Inc. — CDN & Security
- DNS routing, content delivery network (CDN) caching, SSL encryption, and DDoS security logs.
- PT Midtrans — Local Payment Gateway
- Licensed Indonesian payment gateway, securely managing local subscription checkouts and billing renewals.
- Paddle.com Market Ltd — Global Merchant of Record
- Planned payment provider and Merchant of Record for international transactions once global checkout is available.
Payment Gateway Direct Processing Note: Payment providers may collect and process billing information directly through their hosted checkout interfaces. Their processing of payment credentials, fraud-prevention data, tax information, and legally required transaction records is governed by their respective privacy policies and applicable legal obligations.
7. International Data Transfers (Cross-Border)
Because our technical and payment infrastructure is distributed, personal data, workspace content, account information, and transaction metadata may be transferred to, stored, or processed outside the Republic of Indonesia, including in Singapore, the United States, the United Kingdom, and other locations where our service providers operate. These providers may include Railway, Neon, Supabase, Google, Clerk, Cloudflare, Midtrans, and, once international checkout becomes available, Paddle.
Under Indonesian Law No. 27/2022 on Personal Data Protection (UU PDP) and GDPR, we ensure all cross-border transfers are governed by standard data protection clauses and strict encryption protocols to guarantee your data privacy is maintained at all times.
8. Data Security Standards
To prevent unauthorized access, data leaks, or processing errors, we maintain security measures:
- Enforcing SSL/TLS encryption for all data transit.
- Enforcing AES-256 cryptographic standards for all database credentials and third-party secrets.
- Routine vulnerability checks and restriction of internal access to operational logs.
9. Your Rights & Contact Details
Under UU PDP and GDPR, you have the right to access, rectify, port, restrict processing of, or request the deletion of your personal data. You may also lodge a complaint with your local data protection supervisory authority.
To exercise your rights, please submit a request to our data protection team at: support@envoyou.com.