RippleRoot Privacy Policy
Last updated: July 24, 2026
This Privacy Policy explains how Coderipple Tech Ltd ("CodeRipple Tech", "we", "us", or "our") handles information when you use the RippleRoot website, hosted cloud service, desktop application, command-line tools, and related services ("RippleRoot").
1. The short version
RippleRoot is designed to keep sensitive workspace data under your control. We do not sell personal data, use it for advertising, or run third-party behavioural analytics. We collect and process only the account, workspace, device, activity, and billing information needed to provide and secure the service.
Environment secret values are encrypted on your device before hosted storage. RippleRoot stores and transfers the resulting ciphertext; it is not designed to expose plaintext secret values through its cloud, dashboard, logs, or audit APIs.
2. Information we process
Depending on the features you use, RippleRoot processes:
- Sign-in and account data — a stable, opaque identifier derived from your Google OpenID Connect account, RippleRoot account and organisation identifiers, membership role, and session metadata. RippleRoot does not persist your Google name or email address for self-serve sign-in.
- Workspace and project data — workspace identifiers, project metadata, setup and environment contracts, sync manifests, file metadata, and content you explicitly choose to sync.
- Device data — device identifiers, optional display names, platform metadata, enrolment state, and public encryption-key metadata.
- Encrypted secret data — ciphertext, public recipient metadata, approval state, and short-lived lease metadata. Plaintext secret values are processed locally when you ask RippleRoot to use them.
- Operational and security data — metadata-only activity and audit events, job status, credential prefixes and hashes, IP and HTTP security logs retained by our infrastructure, and aggregate reliability counters.
- Billing data — plan, seat count, organisation identifier, and subscription status. Payment-card details are entered directly into Stripe Checkout and are not handled by RippleRoot.
- Support data — information you choose to send when contacting support.
3. Google sign-in data
RippleRoot uses Google OpenID Connect to authenticate you. The production sign-in flow requests the openid scope and uses the verified Google subject identifier to create a pseudonymous RippleRoot account identifier. Google access and ID tokens are used only to complete sign-in and are not stored as account profile data.
RippleRoot's use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements.
4. Information stored on your device
The desktop app and CLI keep local workspace state, configuration, encrypted vault material, and operational history on your machine. The desktop app uses operating-system credential storage for saved cloud access credentials.
The hosted dashboard stores interface preferences and non-secret filters in browser local storage. A hosted session token may be kept in browser session storage so it is removed when the tab session ends. RippleRoot does not use advertising cookies.
5. How we use information
We use information only to:
- authenticate users and enforce organisation roles and seat limits;
- sync the workspace data and encrypted material you request;
- operate devices, approvals, releases, and agent workflows;
- process subscriptions and provide support;
- prevent abuse, investigate faults, and secure the service; and
- meet legal and accounting obligations.
6. Service providers and disclosure
We share information only where needed to operate RippleRoot or comply with law. Our processors are: Hetzner (Germany) for the servers and PostgreSQL database behind the hosted cloud and application downloads, Cloudflare for this website and DNS, Google for sign-in, Stripe for hosted billing and payment-card handling, and Resend for transactional and support email. Hosted cloud data and its backups are stored on servers located in Germany.
We do not sell personal data. We do not share personal data with advertisers or data brokers.
7. Retention and deletion
We retain service data while your account or organisation is active and as needed to provide the service, maintain security and audit records, resolve disputes, and meet legal obligations. Expired and revoked credentials may be removed under the organisation's configured retention policy. Backup copies may remain for a limited recovery period before being overwritten.
To request access, correction, export, or deletion of your RippleRoot account data, email [email protected]. We may need to verify the request before acting. Organisation owners may control memberships and revoke credentials through RippleRoot's administration tools.
8. Security
We use transport encryption, hashed bearer credentials, role-based access controls, short-lived sessions, audit records, and encrypted secret storage. No system is completely secure, so you should protect your devices and credentials and contact us promptly if you suspect unauthorised access.
9. International processing
Our providers may process information in the United Kingdom, European Economic Area, United States, or other countries where they operate. Where required, we use appropriate safeguards for international transfers.
10. Your rights
Depending on where you live, you may have rights to access, correct, erase, restrict, object to, or receive a portable copy of personal data. You may also complain to your local data-protection authority. In the United Kingdom, this is the Information Commissioner's Office.
11. Children's privacy
RippleRoot is a developer and business productivity service and is not directed to children under 16. We do not knowingly collect personal data from children under 16.
12. Changes to this policy
We may update this policy when RippleRoot or applicable requirements change. We will update the date above and provide additional notice when a change materially affects how we handle personal data.
13. Contact
Coderipple Tech Ltd
Email: [email protected]