Privacy Policy
How NineGate handles your data.
In effect since 2026-08-08 · PT Digital Reka Inovasi (DRITECH)
1. Who we are
PT Digital Reka Inovasi (DRITECH), a company registered in Indonesia, operates NineGate — a subscription AI assistant and the metered API gateway that serves it.
Registered address: Tower Riviera 60007 2D Lantai 37, Meikarta District 2, Cibatu, Cikarang Selatan, Kab. Bekasi, Jawa Barat 17530
Privacy enquiries: admin@dritech.co.id · +62 851-5627-3045
2. Architecture: what runs where
Understanding this section explains the whole document. There are two distinct places:
- The NineGate application runs entirely on your own computer. It keeps its configuration, your notes, and the credentials for the accounts you connect locally, on that machine.
- The NineGate gateway is our server. It forwards your language model requests to the model providers, and counts token usage so your subscription allowance can be enforced.
3. Your Google data
If you connect a Google account, NineGate requests the following permissions:
| Service | OAuth scope | What it is used for |
|---|---|---|
| Gmail | gmail.readonly, gmail.send, gmail.modify | Read and search your mail, send and reply on your explicit instruction, and add or remove labels on a message when you ask. |
| Google Drive | drive | Search your Drive, and open, upload, download, share or delete the files you ask about. This is full Drive access: searching means listing files across your Drive, which a narrower scope cannot do. |
| Google Docs | documents | Draft and edit the documents you ask for. |
| Google Sheets | spreadsheets | Read and write spreadsheets for data tasks you ask for. |
| Google Contacts | contacts.readonly | Look up a recipient's address when you ask for mail to be sent to someone by name. |
| Google Calendar | calendar | Read what is scheduled, and create or move events on your request. |
Your Google tokens are never sent to our servers. Signing in happens on your computer, the tokens are stored on your computer, and NineGate calls Google’s APIs directly from there. We cannot reach your Google account, and revoking access at myaccount.google.com/permissions cuts it off immediately.
What you should understand, though: if you ask NineGate to do something with the contents of your Google data — “summarise this email”, “tidy up this spreadsheet” — then those contents become part of the request sent to the language model, and that request passes through our gateway on its way to the model provider. We do not store it (see section 4), but it does transit. We state this plainly so you can decide what you hand to the assistant.
We do not use your Google data to train any model, do not sell it, and do not share it with anyone other than the model provider processing your request.
4. What we store on the server
For each request that passes through the gateway, we record:
- An identifier for your API key (not the key itself — we store only a hash of it)
- The model called and the endpoint it went to
- Token counts (prompt and response), timestamp, duration, and success or failure
- The IP address the request came from
We do not store the content of your conversations — not the prompts, not the model’s replies. What we record is the metadata needed to enforce your allowance and bill your subscription.
One honest exception: a diagnostic mode exists that stores request contents in order to trace a fault. It is off, is only switched on if you ask for technical help and agree to it, and is switched off again afterwards.
5. Other accounts you connect
NineGate can be connected to WhatsApp, Telegram, GitHub and other services. All of those sign-ins happen on your computer and their credentials are stored there. Our servers do not receive them, do not store them, and cannot use them.
6. Model providers
Your requests are forwarded to language model providers — among them OpenAI, Anthropic, Google and others, depending on the model you choose. Those providers process the contents of your request under their own policies. You choose the model, and in doing so you choose which provider receives that data.
7. Retention
Request logs are kept for at most 60 days and are then deleted automatically by a job that runs on our gateway. Daily usage summaries (token counts per day, with no content) are kept for as long as the account is active, for billing.
8. Your rights
- Request a copy of the data we hold about your account
- Request deletion of your account together with all of its logs and usage history
- Revoke Google access at any time, directly from your Google account settings
- Erase all local data by deleting the NineGate installation folder
Send requests to admin@dritech.co.id. We respond within 30 days.
9. Security
Traffic to the gateway is encrypted with TLS. Account passwords are stored as Argon2id hashes and cannot be recovered by anyone, including us. Administrative access is limited to DRITECH personnel.
API keys are stored twice: as a SHA-256 hash, which the gateway uses to recognise the key on each request, and as an encrypted copy (AES-256-GCM) so that you can see your key again in the portal. The encryption key is held separately from the database.
We say so openly because it affects you: unlike a password, an API key can technically be recovered by anyone holding both the database and the encryption key. Treat an API key like a password, and delete keys you no longer use from the portal — deletion takes effect immediately.
No system is completely secure. If an incident affects your data, we will tell you by email.
10. Changes
If this policy changes materially, we notify active users by email before the change takes effect. The effective date is shown at the top of this page.
