§1Who We Are and Scope
Ritsu is a learning platform provided by [TBD — Legal name pending], an individual operating independently (not a company). When this Policy says “we”, “us”, “Ritsu”, or “the Service”, it means that individual and the systems operated by them to deliver the Service to you.
This Policy applies to:
- The website and application at ritsu.ai and its subdomains
- Account registration, authentication, and user dashboards
- All features of the Service including AI-generated content, source uploads, session sharing, and subscription management
- Communications we send you (transactional emails, notices)
This Policy does not apply to:
- Payment processing by Lemon Squeezy Inc., our Merchant of Record (see Lemon Squeezy’s Privacy Policy)
- Third-party websites linked from Ritsu
- Offline interactions unrelated to Ritsu
For the full agreement between you and Ritsu, also see the Terms of Service.
§2Information We Collect
We collect only what the Service needs to work. We group it by category below.
2.1 Account Data
When you sign up, we collect:
- Email address
- Name or display name (if provided)
- A cryptographic hash of your password (we never store your plain password); hashing is handled by Supabase Auth using bcrypt
- OAuth identifiers if you sign in with Google, GitHub, or similar (scope limited to email + name)
- Account creation timestamp
- The IP address at the time of registration (for fraud prevention)
2.2 Profile Data
When you complete onboarding or edit your profile, we collect:
- Subjects you are studying
- Learning goals and experience level
- Preferred language of the interface
- Time zone (for scheduling and reminders)
- Persona or tutor-style preferences (if you select any)
- Answers to optional onboarding questions
2.3 Learning Content
This is the content you bring into Ritsu to study:
- Documents you upload: PDF, DOCX, Markdown, plain text, PowerPoint, images (PNG/JPEG/WebP), and Jupyter notebooks (up to 20 MB per file)
- YouTube URLs you provide, along with the transcript we retrieve from them
- Prompts, questions, and messages you send to Ritsu’s AI features
- AI-generated outputs (study aids, summaries, quizzes, flashcards) produced in response to your input
- Notes you create or save
- Session records, chat history, and study plans
- Tags, labels, or organization metadata you apply
- Content you choose to share publicly via our session-sharing feature
2.4 Usage Data
As you use the Service, we collect:
- Credit transactions (consumption, monthly resets, one-time pack purchases)
- Feature usage counts and timestamps (which commands you invoked, how often)
- Action logs (what you did and when, for debugging and support)
- Time spent in sessions
- Completion events for learning milestones you reach
2.5 Payment Data (collected by Lemon Squeezy, not Ritsu)
We do not receive or store your full payment card details. When you subscribe or buy a credit pack:
- Lemon Squeezy collects your card information, billing address, and tax identifiers as our Merchant of Record
- Lemon Squeezy transmits to Ritsu only: your subscription status, plan tier, customer ID, subscription start/end dates, and renewal events
- For specifics on Lemon Squeezy’s handling of your payment data, see their Privacy Policy
2.6 Device and Connection Data
When you use Ritsu, our servers automatically log:
- IP address
- Browser type and version
- Operating system
- Viewport size and device type (mobile vs desktop)
- Referring URL (how you arrived at Ritsu)
- Timestamps of requests
These logs are retained for 30 days (see Section 10), used for security and debugging, and not tied to a marketing profile.
2.7 Cookies
We use a small number of cookies:
- Strictly necessary (session authentication): required to keep you logged in. Provided by Supabase Auth.
- Preferences: remember interface settings like theme or language.
- Region: a coarse marker (“your region requires opt-in consent” or “it does not”) derived from your IP address at the edge, so we know which consent rules to apply to you. It records no country name, and we do not store it on our servers.
- Advertising (Meta Pixel): “_fbp”, and “_fbc” if you arrived from a Meta ad. Set by Meta's pixel so we can measure whether our advertising works. See Section 2.8 for exactly what it sends.
- Advertising (Google tag): “_ga”, “_ga_” followed by our measurement ID, and “_gcl_au”. Set by Google Analytics and Google Ads so we can measure whether our advertising works. See Section 2.8 for exactly what they send.
- Partner referrals: “ritsu_aff_code” and “ls_aff_ref”. If you arrived through a link shared by one of our partners, these remember which partner sent you so that they are paid for the referral. The first is ours and holds only the partner's public code; the second is set by Lemon Squeezy, our payment provider, and identifies the click. They last up to a year. We do not set them for visitors in regions that require prior opt-in consent, and they are never used to build a profile of you or to target advertising.
Advertising storage and partner referrals are the only things we ask consent for. Our own product analytics is not advertising and is never used to target you, but it is no longer accurate to call it cookieless: PostHog keeps a random visitor identifier in your browser's local storage so that repeat visits can be counted once rather than as separate people. It is not a cookie, it is never sent to an advertiser, and every control described below switches it off along with everything else.
If you are in the EEA or the UK: we ask first. No advertising tag is loaded — neither Meta's nor Google's — and no advertising cookie is written, until you choose “Accept” on the banner. Choosing “Decline” is one click, presented identically to “Accept”, and we do not ask again. Declining changes nothing about how Ritsu works. If you change your mind either way, the “Do Not Sell or Share My Personal Information” control in our footer switches advertising measurement off or back on in one click, from any page, without an account — withdrawing consent is exactly as easy as giving it.
Everywhere else: the advertising pixel runs unless you switch it off, which you can do at any time in Settings → Account.
In both cases, if your browser sends a Global Privacy Control or Do Not Track signal, we treat it as a refusal automatically: the pixel is never loaded, no cookie is written, nothing is sent, and you are not shown a banner. We check this before requesting the pixel script, not afterwards.
2.8 Analytics Data
What we use: Vercel Web Analytics, a cookieless, aggregated analytics service provided by our hosting provider. It records page views and a small number of product events (for example: a signup was started, an error card was shown, an upgrade prompt was displayed).
How you are identified: you are not. Vercel derives a hash from the incoming request that is reset every 24 hours, stores no cookie, and stores no IP address. Aggregated data cannot be traced back to you.
What we never collect: your study content, your answers, the materials you upload, your email address, your name, or your account identifier. Page URLs are redacted in your browser before they are sent — share links, certificate links, password-reset links, and session identifiers never leave your device.
Your control: analytics is on by default and you can switch it off at any time in Settings → Account. The choice is stored on your account and applies on every device you sign in from. If your browser sends a Global Privacy Control or Do Not Track signal, we treat that as an opt-out automatically and you do not need to do anything.
Advertising measurement (Meta Pixel): we run the Meta Pixel on ritsu.ai so we can tell which advertising actually brings learners to Ritsu. When it runs, it sends Meta the address of the page you are on, the page that referred you, your browser and device type, your IP address, and the advertising cookie identifiers described in Section 2.7.
Advertising measurement (Google tag): we run Google Analytics on ritsu.ai for the same reason, and Google Ads reads those measurements to tell which ads brought learners here. When it runs, it sends Google the address of the page you are on, the page that referred you, your browser and device type, your IP address, and the advertising cookie identifiers described in Section 2.7. Google receives no name, no email address, and no account identifier: we deliberately do not enable “Enhanced Conversions”, which is the Google feature equivalent to the Meta matching described next.
Contact details, hashed: we use Meta’s “Automatic Advanced Matching”. This applies to Meta only — nothing equivalent is enabled for Google. When you type your email address or your name into a form on Ritsu — signing up, for example — Meta’s pixel reads those fields, scrambles them into an irreversible code inside your browser, and sends the code rather than the text. Your email address and name never leave your browser in readable form.
What that is for, plainly: the code lets Meta recognise that the person who saw our ad and the person who signed up are the same person, including across devices. It is a matching key, not anonymisation — if you have a Meta account under the same email address, Meta can connect the two.
What we never send Meta: your account identifier, your study content, your answers, your uploads, or anything you write to Ritsu’s AI. No password. No payment details — we never hold those ourselves.
If you would rather not: the same controls cover it. In the EEA and the UK nothing is sent unless you accept. Everywhere else, the “Do Not Sell or Share My Personal Information” control in our footer, the switch in Settings → Account, or a Global Privacy Control signal each stop the pixel from loading at all — and a pixel that never loads reads no form fields.
Page addresses are filtered before anything is sent: any address containing an identifier or an access token is skipped entirely rather than reported. Share links, certificate links, password-reset links, and study session addresses are never disclosed to Meta.
Your control: in the EEA and the UK nothing loads until you accept (Section 2.7). Everywhere else it runs until you switch it off. In either case you can change your decision at any time — in Settings → Account, with the “Do Not Sell or Share My Personal Information” control in our footer, or by sending Global Privacy Control.
PostHog: product analytics, hosted in the European Union. It records which pages you open and which features you use — signing up, adding a source, running a command, finishing a unit — so we can see where people get stuck. Page addresses are filtered the same way they are for advertising: any address containing an identifier or an access token is skipped, so share links, certificate links, and study session addresses are never disclosed. Once you sign in your account identifier is attached, which lets us follow one person’s path through the product rather than counting anonymous visits.
What PostHog never receives: your name, your email address, your passwords, your payment details, and the content of anything you upload or write. It records that you ran a command, never what the command said.
Your control over PostHog: the same switch that governs everything else in this section. Turn analytics off in Settings → Account, use the “Do Not Sell or Share My Personal Information” control in our footer, or send Global Privacy Control, and nothing is sent — including your account identifier.
2.9 What we do NOT collect
- Health or medical records (unless you upload them as study material; see Section 14)
- Biometric data (no face, fingerprint, or voice recognition)
- Precise geolocation (we derive only coarse country/region from your IP)
- Government IDs or passports
- Social Security numbers, tax IDs (Lemon Squeezy handles tax identifiers for billing)
§3How We Use Your Information
We use the categories above for the purposes listed here, and no others:
- Provide the Service (host, display, search, sync your content) — Account, Profile, Learning Content, Usage, Device
- Generate AI responses (send prompts to Gemini/OpenRouter) — Learning Content (prompts + relevant context)
- Process subscriptions and grant paid-tier access — Payment Data received from Lemon Squeezy
- Send transactional emails (receipts, security alerts, updates to this Policy) — Account Data
- Secure the Service against fraud, abuse, and unauthorized access — Account, Device, Usage
- Respond to your support requests — Account, Usage, any context you share in the request
- Comply with legal obligations (tax records, subpoenas, DMCA) — Whatever the law requires
- Improve the Service using aggregated, de-identified data — Usage, Device (never raw Learning Content)
§4Legal Bases for Processing (GDPR, if you are in the EEA or UK)
If you are in the European Economic Area, United Kingdom, or Switzerland, we process your personal data under one of the following legal bases from GDPR Article 6:
- Contract (Art. 6(1)(b)): to provide the Service you requested when you signed up. Covers Account, Profile, Learning Content, Usage, and Payment data necessary to deliver the Service.
- Consent (Art. 6(1)(a)): for optional processing you actively agree to, such as product analytics (PostHog) or marketing emails (we do not send these yet). You can withdraw consent at any time.
- Legitimate interests (Art. 6(1)(f)): for security monitoring, fraud prevention, and improving the Service using aggregated, de-identified data. We have weighed our interests against yours and believe you would reasonably expect this processing. You can object under Section 11.
- Legal obligation (Art. 6(1)(c)): for tax record retention, responding to lawful government requests, and responding to valid DMCA notices.
Special categories of personal data (health, biometric, political, religious, etc.) are not processed by Ritsu unless you voluntarily upload them as part of your Learning Content, in which case processing is based on your explicit consent (Art. 9(2)(a)).
§6Sub-Processors (named list)
These are the third parties we currently use to operate Ritsu. We keep this list current. For significant additions, we will update this Policy and give notice where required.
- Supabase Inc. — Database (Postgres), authentication, Row-Level Security. Region: US East (EU available on request for paid plans). Transfer: Standard Contractual Clauses (SCCs) for EU→US.
- Cloudflare R2 (Cloudflare, Inc.) — Storage of uploaded files. Region: global edge (primary: US). Transfer: SCCs.
- Lemon Squeezy Inc. — Payment processing as Merchant of Record. Region: United States (Delaware). Transfer: SCCs; also an independent controller for payment data (see their Policy).
- Google LLC (Gemini API) — AI inference (primary). Region: United States. Transfer: SCCs; see Section 7 for AI-specific retention.
- OpenRouter Inc. — AI inference (fallback). Region: United States. Transfer: SCCs.
- Vercel Inc. — Application hosting, edge delivery. Region: United States. Transfer: SCCs.
- Vercel Inc. (Vercel Web Analytics) — Cookieless, aggregated product analytics. Collects page views and a small set of product events; no cookies, no IP address stored, visitor hash reset every 24 hours. Region: United States. Transfer: SCCs. You can opt out in Settings → Account, or via Global Privacy Control.
- Meta Platforms, Inc. / Meta Platforms Ireland Ltd. — Advertising measurement (Meta Pixel). Receives page addresses, referring page, browser and device type, IP address, advertising cookie identifiers, and — via Automatic Advanced Matching — an irreversible hash of your email address and name when you type them into a form. Receives no account identifier, no profile data, and no learning content. Region: United States and Ireland. Transfer: EU–US Data Privacy Framework and SCCs. Meta is an independent controller for this data (see their Privacy Policy). In the EEA and the UK nothing is sent unless you accept; everywhere else you can opt out in Settings → Account, with the footer control, or via Global Privacy Control.
- Google LLC / Google Ireland Ltd. (Google Analytics 4 and Google Ads) — Advertising measurement. Receives page addresses (filtered as described in Section 2.8), referring page, browser and device type, IP address, and advertising cookie identifiers. Receives no name, no email address, no account identifier, no payment details, and no learning content — we do not enable Enhanced Conversions, so no hashed email or phone number is sent. Region: United States and Ireland. Transfer: EU–US Data Privacy Framework and SCCs. Google is an independent controller for this data (see their Privacy Policy). In the EEA and the UK nothing is sent unless you accept; everywhere else you can opt out in Settings → Account, with the footer control, or via Global Privacy Control. This is a separate purpose from the Gemini API entry above, which processes learning content and never advertising data.
- Resend — Transactional email (receipts, security alerts). Region: United States. Transfer: SCCs — deployed when we turn email on.
- PostHog, Inc. — Product analytics. Deployed. Receives page addresses (filtered as described in Section 2.8), referring page, browser and device type, IP address, the feature-usage events listed in Section 2.8, and your account identifier once you sign in. Receives no name, no email address, no payment details, and no learning content. Region: European Union (Frankfurt). Transfer: none for EEA and UK users — the data does not leave the EU. PostHog processes this only on our instructions, as our processor.
When we add or change a sub-processor, we update this list within 30 days. For material additions affecting how your data is processed, we give notice through in-app banner or email.
§7AI Processing — Important Disclosures
Ritsu’s AI features are the core of the Service, so we want to be especially clear about how AI processing works.
7.1 What happens when you use AI features
When you ask Ritsu to generate study aids, summaries, quizzes, or answer questions:
- We prepare a prompt that includes your input and relevant context from your Learning Content (for example, portions of a document you asked us to summarize).
- We send the prompt to our AI sub-processor: Google Gemini API (primary), or OpenRouter (if Gemini is unavailable or fails).
- The AI sub-processor processes the prompt and returns a response.
- We return the response to you and store it as part of your session history.
7.2 Retention at AI sub-processors
- Google Gemini API: per Google’s Gemini API Terms, prompts and responses from the paid API tier are not used to improve Google’s models and are retained only for a short operational window (up to 24 hours for abuse detection) before deletion. We use the paid tier exclusively.
- OpenRouter: retention depends on the upstream model. Where OpenRouter and the underlying model provider offer a no-logging or zero-retention option, we configure Ritsu to use it.
7.3 We do not train AI on your content
7.4 AI output quality
AI outputs may be inaccurate or hallucinated. Ritsu disclaims warranties about AI output quality in the Terms of Service §11. Do not rely on AI outputs for medical, legal, financial, or other professional decisions.
7.5 Art. 22 (automated decision-making, EEA/UK users)
Ritsu does not use automated processing to make decisions with legal or similarly significant effects about you. AI-generated study aids are not used to determine your access, pricing, or eligibility for any service, benefit, or credential.
§8International Transfers
Ritsu is operated by an individual who may be located in or travel through multiple jurisdictions, and most of our sub-processors are in the United States. Your data will therefore be transferred across borders, including to the United States.
We use Standard Contractual Clauses (SCCs) approved by the European Commission (and the equivalent UK IDTA) with each US-based sub-processor as the primary transfer mechanism. We also apply the supplementary measures described in Section 12 (encryption in transit and at rest, access controls) to protect data during transfer.
If Supabase (our database provider) offers EU hosting on a plan tier we adopt, we will host EU-resident users’ data in the EU and update this Policy accordingly.
§10Data Retention
We keep personal data only as long as we have a legitimate need to. The schedule below sets out our periods.
- Active account data (Account, Profile, Learning Content) — retained while your account is open.
- Learning Content after account deletion — soft-deleted for 30 days, then hard-deleted (irrecoverable).
- Billing records (subscription history, invoices) — 7 years after account closure (tax law).
- Server logs (IP, request metadata) — 30 days.
- Database backups — 90 days rolling; older backups are permanently destroyed.
- Inactive account — flagged at 12 months of inactivity, email notice sent; account and data deleted at 24 months if no reactivation.
- AI prompts at Google Gemini — ≤ 24 hours (operational window), then deleted by Google.
- AI prompts at OpenRouter — configured for non-retention where available; otherwise per upstream model’s policy.
- Session auth cookies — session + up to 30 days.
- Support email threads — 2 years after resolution.
After the retention period, data is deleted from primary storage. Residual copies may persist briefly in system backups during their natural expiration window (see the 90-day backup line above).
§11Your Rights and Choices
You have rights over your personal data. Which specific rights you have depends on where you live, but Ritsu applies the broader set globally where practical.
11.1 Rights under GDPR (EEA, UK, Switzerland)
- Access: get a copy of the personal data we hold about you
- Rectification: correct inaccurate data
- Erasure (“right to be forgotten”): ask us to delete your data (subject to legal retention requirements like tax records)
- Portability: receive your data in a machine-readable format (JSON)
- Restriction: ask us to pause processing while we investigate a dispute
- Objection: object to processing based on legitimate interests
- Withdrawal of consent: for any processing based on consent, you may withdraw at any time
- Complaint: lodge a complaint with your local supervisory authority
11.2 Rights under California CCPA/CPRA
California residents additionally have:
- The right to know what categories of personal information we collect, use, and share
- The right to delete personal information (with exceptions for legal retention)
- The right to correct inaccurate information
- The right to opt out of sale or sharing. We do not sell your data. We do share data with Meta for advertising measurement, and you can opt out at any time in Settings → Account, with the “Do Not Sell or Share My Personal Information” link in our footer, or by sending Global Privacy Control, which we honor automatically.
- The right to limit use of sensitive personal information (we do not collect sensitive PI)
- The right to non-discrimination for exercising privacy rights
11.3 Rights under other US state laws (Virginia VCDPA, Colorado CPA, Connecticut CTDPA, Utah UCPA, Texas TDPSA, and similar)
Residents of states with comparable privacy laws have rights analogous to those above, including access, correction, deletion, portability, opt-out of targeted advertising or sale, and appeal if we deny a request. We do not sell personal data; for advertising measurement and how to opt out, see Section 2.8 and Section 11.2 above.
11.4 How to exercise your rights
11.5 Authorized agents
You may designate an authorized agent to exercise rights on your behalf (e.g., CCPA §1798.135(c)). We will verify the agent’s authority, usually by requesting written authorization from you.
11.6 Self-serve dashboard (roadmap)
Transparent disclosure: at launch, Ritsu does not have a one-click “Download my data” or “Delete my account” dashboard built into the app. We handle these requests manually via email. A self-serve privacy dashboard is planned for P1 after launch.
11.7 Data Privacy Framework (DPF)
Ritsu is not currently certified under the EU-US Data Privacy Framework or the UK/Swiss Extensions. We rely on Standard Contractual Clauses for EU→US transfers (see Section 8).
§12Security
We apply commercially reasonable administrative, technical, and physical safeguards. For the full public-facing description, see the Security Policy. In summary:
- Encryption at rest: AES-256 for database (Supabase) and file storage (Cloudflare R2).
- Encryption in transit: TLS 1.2+ with HSTS preload.
- Row-Level Security (RLS): all user tables in Supabase enforce RLS. A user cannot query another user’s data even if our application code has a bug — the database layer refuses.
- Password hashing: bcrypt (via Supabase Auth).
- Access control: production access limited to the operator. Service role keys are scoped to server-side contexts and never exposed to the browser.
- Webhook integrity: HMAC signature verification on incoming webhooks (Lemon Squeezy).
- Dependency security: automated scanning (Dependabot or equivalent) for known vulnerabilities.
- No SOC 2 or ISO 27001 certification yet: we implement industry-standard practices but are not currently third-party audited. Planned when enterprise customer demand justifies the investment.
12.1 Breach notification
If a personal data breach affects you, we will notify you within 72 hours of discovery where feasible, per GDPR Art. 33 and US state-law requirements. The notice will describe what happened, what data was affected, what we are doing about it, and what you should do.
12.2 Responsible disclosure
If you discover a security vulnerability, please report it to security@ritsu.ai. We do not currently run a paid bug bounty program but we acknowledge responsible disclosures in good faith.
§13Children’s Privacy
Ritsu is intended only for users who are at least 16 years old. When you create an account you must confirm you meet this minimum age. This confirmation is a self-attestation — not identity or age verification — and we do not collect a date of birth. Alongside this age confirmation we rely on the rules below and a notice-and-takedown process, applied globally and adjusted for local law:
- Under 16: Ritsu is not available to you. We do not knowingly collect personal data from anyone under 16. If we learn that an account belongs to someone under 16, we delete the account and its data.
- Under 13 (COPPA, United States): we do not knowingly collect personal data from children under 13. If we learn we have collected data from a child under 13, we delete it promptly.
- Why a flat 16, not a lower age with parental consent: 16 is the highest age of digital consent under GDPR Art. 8. By setting a single global minimum of 16, we avoid operating a verifiable-parental-consent process for younger children — we simply do not offer accounts below 16.
AI training on minors’ data: consistent with US FTC’s April 2025 updates to the COPPA Rule, Ritsu does not use any minor’s data for AI training, and we do not authorize our AI sub-processors to do so. This commitment applies to all users, but is especially important for minors.
A parent or guardian who believes a child under 16 has created an account or provided personal data to Ritsu should contact privacy@ritsu.ai. We will delete the account and its data promptly.
§14Your Learning Content — an Important Reminder
You control what you upload or input into Ritsu. For your safety:
- Do not upload content that identifies you or others in ways you don’t intend to share (medical records, financial statements, government-issued IDs, tax documents) unless you have a specific study reason.
- Do not paste passwords, API keys, or other secrets into the chat.
- Be thoughtful with public shares: if you use Ritsu’s session-sharing feature, anyone with the link can see the shared content. Do not share anything you would not post on a public forum.
Ritsu’s security is commercially reasonable but not perfect. You are in the best position to decide what belongs in a study tool versus what belongs somewhere more guarded.
§15Third-Party Links and Services
Ritsu may link to or embed content from third-party services (for example, YouTube videos you import for transcription). We are not responsible for the privacy practices of those third parties. Review their policies before providing them with your data.
§16Data from Other Sources
We generally collect data from you directly. In limited cases we may receive data from:
- Your authentication provider if you sign in with Google or GitHub (email and basic profile only, scoped to what you authorize)
- Lemon Squeezy, regarding your subscription status (see Section 2.5)
We do not purchase personal data from data brokers.
§17Changes to This Policy
We may update this Policy to reflect changes in the Service, our sub-processors, or applicable law. When we make changes:
- We update the “Last Updated” date at the top
- We notify you by email for changes that materially affect how we process your data
- We post an in-app banner for at least 14 days before material changes take effect
- We publish a summary of significant changes in the Legal Hub
If you disagree with a change, you may delete your account before the change takes effect. Continued use after the effective date indicates your acceptance.
§18Contact Us
If you have questions about this Policy, want to exercise your rights, or have a concern:
- Privacy: privacy@ritsu.ai
- Data Protection Officer / EU representative: privacy@ritsu.ai (we do not yet have a designated DPO; privacy@ritsu.ai is the contact until we do)
- Security / vulnerability reports: security@ritsu.ai
- General / legal: legal@ritsu.ai
Legal notice address: [TBD — Contact address pending]
You also have the right to lodge a complaint with a supervisory authority in your country (for EEA/UK residents) or your State Attorney General (for US residents).
Thank you for trusting Ritsu with your study. We take that trust seriously.