Privacy Protection

Privacy Policy

Last Updated: August 1, 2026. Envoyou is committed to safeguarding your personal and workspace data.

1. Identity of the Data Controller

For the purposes of applicable data protection laws, including the Indonesian Law on Personal Data Protection (UU PDP No. 27/2022) and the European Union General Data Protection Regulation (GDPR), the Data Controller is:

Operator
Envoyou is operated by M Husni Kusuma Thohari, an individual business operator based in Indonesia. Envoyou is the trading and product name of the service.
Business Identification Number (NIB)
Registered under the NIB Framework of the Republic of Indonesia
Electronic System Operator (PSE)
Registered with the Ministry of Communication and Informatics (Kominfo), Republic of Indonesia
Registered Address
Cluring, Banyuwangi, Jawa Timur 68482, Indonesia
Contact Email
support@envoyou.com

3. AI Data Processing Safeguards

As an AI-driven Editorial Intelligence system, Envoyou enforces strict data confidentiality parameters to protect your proprietary intellectual assets:

  • Zero LLM Training

    All drafts, source notes, scraped reference URLs, and outlined articles processed through the Envoyou EAI workspace are submitted to Google LLC's Gemini API via secure commercial developer API endpoints. Under our terms, your data is never used to train Google's public large language models (LLMs).

  • Encrypted Credentials (AES-256-GCM)

    Your external CMS access tokens, API keys, and database secrets are encrypted at rest using industry-standard AES-256-GCM. Decryption keys are managed securely and are never sent or exposed to the browser client.

4. Information We Collect

We collect and process specific categories of data necessary to deliver our services, maintain security, and manage subscriptions:

Visitor Data (Consent-Based Analytics)
When you allow optional analytics, Google Analytics may process IP-derived location, browser information, page paths, and non-personal conversion events. The Google Analytics script is not loaded before consent.
Account Information (Clerk Auth Sync)
Workspace name, user email, profile photo, and associated organization roles synchronized via our identity partner, Clerk.
Workspace Inputs (Editorial Content)
Article drafts, outlines, URL references, briefs, and categories uploaded to the EAI Editor.
Payment Metadata (Midtrans & Paddle)
We process transaction identifiers, payment status, subscription plan, billing period, currency, transaction totals, tax information, and limited customer billing details required to activate and manage your subscription. Complete payment card details are never stored. Local Indonesian payments are processed by Midtrans; international payments may be processed by Paddle once global checkout becomes available.

5. Data Retention Schedule

We retain personal and workspace data according to the following retention schedule, after which data is securely deleted or permanently anonymized:

Data CategoryRetention PeriodAction Upon Expiry
Marketing Cookie Logs (GA4)Up to 14 months from visitAutomatic deletion by Google Analytics
Draft Inputs & Refinement LogsDuring active membership subscriptionPermanent database wipe within 30 days of manual deletion by user or account closure
Identity & Auth Metadata (Clerk)Duration of active accountDeleted within 30 days of account termination
Financial Transactions & Taxes7 years after the fiscal year endRetained to comply with Indonesian tax audit and corporate accounting requirements

6. Third-Party Data Processors

We share specific data subsets with third-party service providers (data processors) who assist us in operating our Site and Service under strict data protection agreements:

Clerk Inc. — Identity & Auth
Identity provider managing account logins, security profiles, and multi-tenant organization access.
Google LLC (Gemini API) — AI Model API
Primary Large Language Model API, utilized via commercial endpoints to process and rewrite draft content.
Vercel Inc. — Frontend Edge Hosting
Frontend deployment, global content distribution, and serverless edge hosting infrastructure.
Railway Corp. — Backend Infrastructure
Cloud infrastructure provider hosting the Envoyou EAI & Blog production backend and supporting services.
Supabase & Neon Database — Database Platforms
Cloud database platforms hosting the blog and EAI production databases respectively.
Cloudflare, Inc. — CDN & Security
DNS routing, content delivery network (CDN) caching, SSL encryption, and DDoS security logs.
PT Midtrans — Local Payment Gateway
Licensed Indonesian payment gateway, securely managing local subscription checkouts and billing renewals.
Paddle.com Market Ltd — Global Merchant of Record
Planned payment provider and Merchant of Record for international transactions once global checkout is available.

Payment Gateway Direct Processing Note: Payment providers may collect and process billing information directly through their hosted checkout interfaces. Their processing of payment credentials, fraud-prevention data, tax information, and legally required transaction records is governed by their respective privacy policies and applicable legal obligations.

7. International Data Transfers (Cross-Border)

Because our technical and payment infrastructure is distributed, personal data, workspace content, account information, and transaction metadata may be transferred to, stored, or processed outside the Republic of Indonesia, including in Singapore, the United States, the United Kingdom, and other locations where our service providers operate. These providers may include Railway, Neon, Supabase, Google, Clerk, Cloudflare, Midtrans, and, once international checkout becomes available, Paddle.

Under Indonesian Law No. 27/2022 on Personal Data Protection (UU PDP) and GDPR, we ensure all cross-border transfers are governed by standard data protection clauses and strict encryption protocols to guarantee your data privacy is maintained at all times.

8. Data Security Standards

To prevent unauthorized access, data leaks, or processing errors, we maintain security measures:

  • Enforcing SSL/TLS encryption for all data transit.
  • Enforcing AES-256 cryptographic standards for all database credentials and third-party secrets.
  • Routine vulnerability checks and restriction of internal access to operational logs.

9. Your Rights & Contact Details

Under UU PDP and GDPR, you have the right to access, rectify, port, restrict processing of, or request the deletion of your personal data. You may also lodge a complaint with your local data protection supervisory authority.

To exercise your rights, please submit a request to our data protection team at: support@envoyou.com.