RippleRoot Privacy Policy

Last updated: July 24, 2026

This Privacy Policy explains how Coderipple Tech Ltd ("CodeRipple Tech", "we", "us", or "our") handles information when you use the RippleRoot website, hosted cloud service, desktop application, command-line tools, and related services ("RippleRoot").

1. The short version

RippleRoot is designed to keep sensitive workspace data under your control. We do not sell personal data, use it for advertising, or run third-party behavioural analytics. We collect and process only the account, workspace, device, activity, and billing information needed to provide and secure the service.

Environment secret values are encrypted on your device before hosted storage. RippleRoot stores and transfers the resulting ciphertext; it is not designed to expose plaintext secret values through its cloud, dashboard, logs, or audit APIs.

2. Information we process

Depending on the features you use, RippleRoot processes:

3. Google sign-in data

RippleRoot uses Google OpenID Connect to authenticate you. The production sign-in flow requests the openid scope and uses the verified Google subject identifier to create a pseudonymous RippleRoot account identifier. Google access and ID tokens are used only to complete sign-in and are not stored as account profile data.

RippleRoot's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.

4. Information stored on your device

The desktop app and CLI keep local workspace state, configuration, encrypted vault material, and operational history on your machine. The desktop app uses operating-system credential storage for saved cloud access credentials.

The hosted dashboard stores interface preferences and non-secret filters in browser local storage. A hosted session token may be kept in browser session storage so it is removed when the tab session ends. RippleRoot does not use advertising cookies.

5. How we use information

We use information only to:

6. Service providers and disclosure

We share information only where needed to operate RippleRoot or comply with law. Our processors are: Hetzner (Germany) for the servers and PostgreSQL database behind the hosted cloud and application downloads, Cloudflare for this website and DNS, Google for sign-in, Stripe for hosted billing and payment-card handling, and Resend for transactional and support email. Hosted cloud data and its backups are stored on servers located in Germany.

We do not sell personal data. We do not share personal data with advertisers or data brokers.

7. Retention and deletion

We retain service data while your account or organisation is active and as needed to provide the service, maintain security and audit records, resolve disputes, and meet legal obligations. Expired and revoked credentials may be removed under the organisation's configured retention policy. Backup copies may remain for a limited recovery period before being overwritten.

To request access, correction, export, or deletion of your RippleRoot account data, email [email protected]. We may need to verify the request before acting. Organisation owners may control memberships and revoke credentials through RippleRoot's administration tools.

8. Security

We use transport encryption, hashed bearer credentials, role-based access controls, short-lived sessions, audit records, and encrypted secret storage. No system is completely secure, so you should protect your devices and credentials and contact us promptly if you suspect unauthorised access.

9. International processing

Our providers may process information in the United Kingdom, European Economic Area, United States, or other countries where they operate. Where required, we use appropriate safeguards for international transfers.

10. Your rights

Depending on where you live, you may have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data. You may also complain to your local data-protection authority. In the United Kingdom, this is the Information Commissioner's Office.

11. Children's privacy

RippleRoot is a developer and business productivity service and is not directed to children under 16. We do not knowingly collect personal data from children under 16.

12. Changes to this policy

We may update this policy when RippleRoot or applicable requirements change. We will update the date above and provide additional notice when a change materially affects how we handle personal data.

13. Contact

Coderipple Tech Ltd
Email: [email protected]