Privacy Policy

Last Revised: October 8, 2026

This Privacy Policy describes how rafylabs, developed and operated by Muhammad Rafly Mubarak ("Developer", "I", "me", or "my"), collects, uses, and safeguards information when you use software, applications, and bots published under rafylabs, including Scripio and Planoptic.

I respect your privacy and am committed to protecting your personal information. This policy explains what information is collected, how it is used, and how your rights are protected when using these services.

1. Scope and Covered Applications

This policy applies to all personal utilities, bots, and software published by Muhammad Rafly Mubarak on the domain rafylabs.com and associated subdomains, web applications, and messaging platforms (such as Telegram).

Dedicated policies for specific applications with third-party integrations (such as Google Sheets or Google Calendar) are accessible via their respective project paths: /privacy/scripio and /privacy/planoptic.

2. Scripio — Google Sheets & Financial Data

Scripio automates recording financial transactions into the user's private Google Spreadsheet.

Zero-Storage of Financial Records Architecture: Scripio DOES NOT store transaction details, receipt images, or line-item expense contents in its database. All confirmed transactions are written directly to your private Google Spreadsheet. The application database solely retains technical account metadata (Telegram user ID, connected Google Sheet identifier, and configuration preferences).

Temporary Image Processing: Receipt images uploaded are processed temporarily in volatile memory by a Vision AI model solely to extract transaction text, and are discarded immediately after extraction.

No AI Model Training: Your Google user data, financial records, and uploaded receipts are NEVER used to train, retrain, or fine-tune artificial intelligence or machine learning models.

Google API Limited Use Disclosure

Scripio's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

3. Planoptic — Google Calendar Integration

Planoptic helps users schedule events into their Google Calendar from natural language text or event posters.

Google Data Accessed: Planoptic accesses the Google Calendar API solely to create calendar events and reminders explicitly requested by the user. OAuth tokens are encrypted at rest and in transit.

No Model Training: Event descriptions and calendar data are never used to train or fine-tune general AI models.

Google API Limited Use Disclosure

Planoptic's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. Information Sharing and Disclosure

Zero Commercial Sale: I do not sell, rent, trade, or monetize your personal information or Google user data under any circumstances.

Third-Party Service Providers: Data is transmitted securely only to essential infrastructure providers necessary to operate the service (Google Cloud APIs for spreadsheets/calendars, Telegram API for messaging, Cloudflare for edge execution/database, and secure AI inference APIs for transient vision extraction).

Legal Requirements: Your information will only be disclosed if required by law, subpoena, or valid legal process.

5. Data Retention, Security, and Storage

Security: All network communications use industry-standard HTTPS encryption (TLS 1.3). Database records (such as user settings) are stored on Cloudflare D1 with strict access control and environment isolation.

Retention: User settings are retained only as long as you maintain an active account with the service. Transient receipt images are purged immediately upon transaction extraction.

6. User Rights, Revocation, and Data Deletion

Revoking Google Access: You can revoke the application's access to your Google account at any time via your Google Account Permissions page at https://myaccount.google.com/permissions.

Disconnecting: In Scripio or Planoptic, you can disconnect your account or clear configurations directly through application commands (such as /disconnect).

Requesting Complete Deletion: You may request complete deletion of any stored metadata associated with your account by emailing mraflym46@gmail.com. Requests are fulfilled within 7 business days.

7. Contact Information

If you have any questions, concerns, or requests regarding this Privacy Policy or your data, please contact:

Developer: Muhammad Rafly Mubarak (rafylabs)

Email: mraflym46@gmail.com

Location: Jakarta, Indonesia

Website: https://rafylabs.com