Risos AI
ID EN
Back to App
PRIVACY POLICY · v1.0

Your privacy. Our responsibility.

Effective May 1, 2026 · Operated by PT Riset Sinergi Sosial
TABLE OF CONTENTS
  1. About This Policy
  2. Data We Collect
  3. Processing Purposes
  4. Legal Basis
  5. Data Sharing
  6. Storage & Security
  7. Your Rights
  8. Cookies & Tracking
  9. AI Processing & Research Data
  10. Minors
  11. Policy Changes
  12. Word Add-in & Token
  13. Contact

1. About This Policy

Risos AI ("we", "the platform") is a product of PT Riset Sinergi Sosial — a research entity registered with the Indonesian Ministry of Law (Kemenkumham RI, AHU-050449.AH.01.30). This document explains how we collect, process, store, and protect your personal data when you use our service via web, WhatsApp, or Telegram.

We commit to data minimisation — we only collect what is genuinely needed to operate the service, and we do not sell your data to third parties.

2. Data We Collect

2.1 Account Identity

2.2 Research Content

2.3 Usage Data

2.4 Payment Data

Risos AI does not store your credit/debit card numbers. Payments are processed by third-party gateways: Tripay (QRIS) and NowPayments (crypto). We only store transaction reference, amount, status, and timestamp.

3. Processing Purposes

Processing of your data is based on:

5. Data Sharing

We do not sell your data. Sharing is limited to:

6. Storage & Security

Data is stored in our PostgreSQL servers located in a Singapore data centre. Storing data outside Indonesia is permitted for Private-Scope Electronic System Operators under Government Regulation No. 71/2019 Article 21, and Singapore has its own personal data protection regime (Personal Data Protection Act 2012) as required by Personal Data Protection Law No. 27/2022 Article 56 on cross-border transfers of personal data. We remain subject to Indonesian law and guarantee data access for supervision and law enforcement purposes by the competent Indonesian authorities.

We implement:

DATA RETENTION

Active data is retained while your account is active. After you delete your account, data is permanently deleted within 7 working days, except those required for legal compliance (payment transactions retained 5 years per tax regulations).

Research transcripts & recordings. Transcripts, audio files, and supporting files live as long as their analysis session lives. Deleting a session deletes its files from storage, not merely from a list. Machine work artefacts — cached results and context excerpts — are removed by a periodic sweeper, and diagnostic traces expire within 48 hours.

7. Your Rights

Per UU PDP No. 27/2022, you have the right to:

To exercise these rights, visit Settings or contact info@risos.id.

8. Cookies & Tracking

We use minimal cookies:

We do not use ad cookies, third-party tracking pixels, or fingerprinting analytics tools.

9. AI Processing & Research Data

9.1 Features that use language models

Risos AI uses large language models for Chat, Methodology Consultation, AI Persona, and qualitative and quantitative analysis of the files you upload (including interview transcripts, field notes, and datasets). Important notes:

9.2 Research data you upload

Interview transcripts, field notes, and recordings you upload consist largely of the personal data of other people — your informants. For that data, the legal roles differ from those covering your own account data:

YOUR INFORMANTS' DATA

Before an analysis session starts we ask about informant consent status and your ethics clearance reference, then store your answer verbatim as an audit record — answering "not yet" does not block your work, but it is recorded and resurfaces when you declare the analysis complete.

If you mark a session as holding sensitive data, anonymisation becomes a required item before raw text may be sent to any provider; if you still choose to send it as-is, that choice is recorded. In ordinary sessions anonymisation is offered once and your answer is recorded. We do not force it — but you never send informant data without knowing that you are sending it.

Obligations that remain yours: obtaining valid consent, honouring an informant's withdrawal of consent, and not uploading data you are not permitted to process. See also the sub-processor list.

10. Minors

This service is intended for users aged 17 and above (undergraduate level upwards). We do not knowingly collect data from users below that age. If you believe a child under 17 is using a Risos AI account, please contact us.

11. Policy Changes

We may update this policy from time to time. Material changes will be communicated via email and/or in-app notification at least 14 days before they take effect. Previous versions are available upon request.

12. Microsoft Word Add-in (Risos Reference)

The "Risos Reference" add-in for Microsoft Word connects to your account via a personal Reference Token that you generate yourself. The token is stored as a SHA-256 hash on our servers and grants the add-in access to your own reference library — to insert citations & bibliographies, and (on your action) to add references or import citation styles. Access is limited to your reference library.

The add-in does not read your Word document content, payment data, or any other user's data. You may revoke the token at any time at risos.ai/references/word-plugin — revocation cuts access immediately. All traffic uses HTTPS/TLS 1.3.

13. Contact

PT Riset Sinergi Sosial
Pekanbaru, Riau, Indonesia
NIB: 1709250119286
Email: info@risos.id

Privacy-related questions, complaints, or requests will be addressed within 14 working days.