Privacy policy
What ryra stores, what it cannot read, and who else touches any of it. Ryra is run by Erlend Ravn Ryan.
What this site does
Nothing, beyond serving pages. There is no analytics, no tracking script, no advertising, and no cookie of any kind: not a consent banner's worth, because there is nothing to consent to. Reading this page leaves no record naming you.
Our servers keep ordinary web logs for a short period so that an outage or an attack can be investigated. Those are operational records, not a profile, and nothing is built from them.
What an account stores
Creating an account stores the things an account needs and nothing beside them:
- Your email address, which is how you sign in and how we reach you.
- A name, if you give one. It is optional and shown to the people you share an organization with.
- Your public keys, and the wrapped copies of your master key. A wrapped key is unreadable without a secret held on your device or the recovery phrase only you have.
- The devices you have signed in from: a label you chose, the device's public key, and when it was last used, so you can see and remove them.
- Your organizations, who is in them, and what each member reaches. Membership has to be readable by the server, because the server is what enforces it.
What we cannot read
Secrets, keyring names, and your declaration are sealed by your own devices before they are sent. We hold the ciphertext, serve it back, and have no key that opens it. This is a property of how the keys are made rather than a promise about our conduct: a copy of your master key exists only wrapped to a device you hold or to your recovery phrase, and neither has ever been on our servers.
The consequence is the one people are surprised by, so it is worth saying twice: if you lose every device and your recovery phrase, we cannot restore your account. There is no reset we are declining to perform. There is no reset.
Machines
When ryra provisions a machine for you, we store what is needed to find and manage it: the provider, the provider's own identifier for the server, its addresses and its host key. What runs on that machine, and everything your agents do there, is yours. We do not read it and it does not pass through us.
Sign-in codes, invitations, billing and security notices are sent as part of the service. Product announcements are separate and every one of them carries an unsubscribe link; unsubscribing from those does not stop the essential ones, which you receive for as long as you have an account.
The contact form
A message sent from the contact page reaches us as an email with the address and name you typed. We keep a hashed form of the address for a short while to stop the form being used to send floods, which is deliberately not the address itself. Nothing else about the visit is recorded.
Who else is involved
- Hetzner hosts our servers, and is one of the providers machines can be bought from.
- Resend delivers our email, which means it handles the addresses we send to.
- Stripe handles payment when you buy something. Card details go to Stripe and never to us.
That is the whole list. We do not sell anything about you, and we do not share it with anyone not named above except where the law requires it.
Your rights
You can export everything an organization holds, including the ciphertext exactly as we store it, and you can delete your account from inside the app. Deletion removes your account and the organizations only you belonged to. If you would rather ask us, or want a copy of what we hold about you, get in touch and we will answer.
Changes
If this policy changes in a way that affects what we do with your data, we will tell account holders by email rather than quietly moving the date at the bottom.