Introduction
Larasin is a social network for students, university students, and alumni in Indonesia. This Privacy Policy explains what data we collect, how we use it, and the rights you have.
We do not sell your personal data. This policy applies to the Larasin web app (web.larasin.com), the Larasin mobile apps, and this website larasin.com.
Google User Data
Larasin uses Google Sign-In (OAuth 2.0) so you can create an account and log in. We request only the basic Google Sign-In scopes: OpenID, email, and profile. We do not request access to Gmail, Google Drive, Calendar, Contacts, or any other Google product data.
- Access: When you sign in with Google, we receive your Google account name, email address, and profile photo.
- Use: We use this Google user data solely to create and authenticate your Larasin account, display your name and photo on Larasin, and communicate with you about your account. We do not use Google user data for advertising, remarketing, credit decisions, or any purpose unrelated to providing Larasin.
- Store: We store your Google name, email address, profile photo, Google account identifier, and OAuth identity record on our servers for as long as your Larasin account remains active. See retention and account deletion below.
- Share: We do not sell, rent, or share Google user data with third parties for their advertising or marketing. We share data only with processors that host and operate Larasin, and only as needed to provide the service, comply with law, or investigate security or abuse.
Limited Use: User data obtained from Google APIs is used only to provide or improve user-facing features that are prominent in Larasin (account creation and sign-in). Humans do not read this data except with your consent, for security or abuse investigation, to comply with law, or in aggregated form for internal operations. Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
Account and identity data
When you register or sign in, we process the data needed to manage your account:
- Email, display name, and username
- Google Sign-In identity (name, email, profile photo) if you use OAuth — new accounts are currently created with Google. See Google User Data for how we access, use, store, and share Google data
- Password (stored as a bcrypt hash) if you add a password after OAuth
- Email verification status, account role, and active/inactive status
- Linked OAuth identity (provider, provider ID, email, avatar from the provider)
Optional profile data
You may add extra profile information. All of it is optional except the minimum data needed for an account:
- Bio, phone number, date of birth, and gender
- Profile photo and banner (stored as media files on our infrastructure)
- Education history (school/university, major, period, grades/GPA, description), organizations, certificates, work experience, skills, and awards
- University/program reference data from a public catalog (PDDIKTI) — this is institutional data, not your personal data
Content you create
Content you upload or send through Larasin may include:
- Posts, thread replies, reposts, bookmarks, and polls
- Media attachments (images, video, audio, files) on posts, profiles, or direct messages
- Drafts and scheduled posts before they are published
- Link previews from URLs you share
Direct messages
Text messages, media attachments, emoji reactions, and sent/read status are stored on our servers so conversations can sync across devices.
Direct messages are not end-to-end encrypted. Content is protected with TLS in transit (HTTPS), but can be accessed by our systems to operate the service and review reports you submit — the same disclosure as in the mobile app.
Conversations with people you do not yet follow each other can start through a message-request flow.
Devices and push notifications
When you sign in from a new device, we register device information for account security and notification delivery:
- Client device ID (client_device_id), platform (web/iOS/Android), OS version
- App version and build, device model, device name (if you provide one)
- Push tokens (FCM for Android, APNs for iOS) and the push provider
- IP address, user agent, and last-seen time — updated while you use the service. An IP address can indicate a coarse network location (for example city or ISP) and is used only for session security and abuse prevention, not for maps, movement tracking, or ads
Session data
- On the web: `larasin_session` cookie (httpOnly, secure in production, lasts about 30 days) holding access and refresh tokens
- On mobile: tokens are stored in the device secure store (SecureStore), not cookies
- Refresh tokens are stored as hashes in the database; when we issue them we also store IP and user agent for security
- Access tokens (JWT) are short-lived (about 1 hour) and refresh automatically while the session is active
- Client device ID in web localStorage to bind the device session
Reports and moderation
If you report a post, profile, or conversation, we store the report reason (spam, harassment, inappropriate content, other) and any optional details you provide.
Block data (who blocked whom) is stored so blocked users cannot send you DMs or follow you.
What we do not collect
- GPS location, geographic coordinates, or device location permission
- Advertising ID
- Third-party product analytics (for example Mixpanel, Google Analytics, Sentry) — not installed in the Larasin web or mobile apps today
How we use data
- Provide and operate features (feed, profile, DMs, notifications)
- Authenticate accounts, prevent abuse, and keep sessions secure
- Send push notifications according to your preferences (you can turn off specific types)
- Show content according to the visibility settings you choose
- Handle reports, blocks, and community-rule enforcement
- Maintain, improve, and develop the service
Legal basis (Indonesian PDP Law)
Under Indonesia’s Personal Data Protection Law (Law No. 27 of 2022), we process personal data based on:
- Your consent when you register and use certain features
- Performance of the service agreement (providing the account and features you request)
- Our balanced legitimate interests, such as platform security, abuse prevention, and handling reports — without overriding your privacy rights
- Compliance with legal obligations, where applicable
Service providers & data processors
We use trusted service providers to run Larasin. They process data on our behalf and may not use it for other purposes:
- Google — OAuth / Google Sign-In authentication (name, email, profile photo; see Google User Data)
- Google Firebase Cloud Messaging (FCM) — Android push notifications
- Apple Push Notification service (APNs) — iOS push notifications
- Hosting, database, and object-storage (media) providers
- Email providers — sending OTP codes (verification, password reset, account deletion)
We do not sell or rent your personal data to third parties for their marketing.
Device permissions (mobile app)
The mobile app may request the following system permissions — only for features you use:
- Camera — scan a web login QR code and attach photos in chat or posts
- Microphone — voice notes and audio in chat
- System photo/video picker — you choose files for your profile, posts, or message attachments. Larasin does not request full gallery access on the device
- Notifications — likes, replies, follows, and incoming messages
Data security
- TLS/HTTPS encryption for data in transit between your device and our servers
- Passwords stored as bcrypt hashes; refresh tokens stored as hashes
- Internal access controls and operational environment separation — we do not publish technical details for security reasons
Larasin has not undergone an independent security audit (for example MASA). No system is 100% secure; if you suspect account misuse, change your password and revoke devices in Settings immediately.
Storage and retention
- Active account — data is kept while your account is active and as needed to operate the service
- Account deletion — 30-day grace period after the request; then data is permanently deleted from production (except what the law requires us to keep)
- Notifications — read items older than 30 days or unread items older than 90 days may be cleaned up automatically
- Devices you revoke — permanently removed from the system after about 1 day
- Posts you delete — marked deleted; content is hidden in the app but a data row may remain for thread integrity
Your privacy settings
You can control most data visibility through Settings:
- Private profile — only followers see the full profile
- Hide profile-visit history (stealth)
- Post visibility: public, followers only, or community
- Manage blocked users
- Turn off specific push notification types (in-app notifications may still appear)
- View and revoke devices connected to your account
Your rights
Under the PDP Law, you may request access, correction, deletion, and restriction of processing of your personal data, and withdraw consent insofar as that does not conflict with our legal obligations.
Most corrections can be made directly in your profile and Settings. For other requests (not self-serve account deletion), contact contact@larasin.com.
Automatic data export (data portability) is not available yet — we will process manual requests where feasible.
Account deletion
You can delete your account yourself at any time — you do not need to contact us:
- Mobile app: Settings → Delete account
Web app: Profile settings → Danger zone → Delete account
After confirmation (email OTP plus identity verification), the account is deactivated and enters a 30-day grace period. During that time you can still sign in to cancel deletion.
After 30 days, your profile, posts, messages, media, and account-related data are permanently deleted from our production systems, except data we are required by law to keep.
Children
Larasin is for Larasiners, not for children under 16. We do not knowingly collect data from children under 16.
If you believe an account belongs to a child under 16, contact contact@larasin.com so we can close it.
Policy changes
We may update this policy as the product or legal requirements evolve. Material changes will be announced on this site or in the app. The last-updated date is shown above.
Contact
Privacy questions (not self-serve account deletion): contact@larasin.com.
See also the Terms of Service and Contact us.
Social activity