Privacy policy
Last updated: June 2026
Riff ("we", "us", "our") is operated by Riff App Ltd, registered in England. This policy explains what personal data we collect, why, and your rights.
1. Data we collect
Account data. Email address, alias (display name), age, gender, and connection preferences. We do not require your real name.
Verification data. Selfie photos (for liveness checks), government ID images (processed by Veriff — we do not store your ID documents), and phone number (verified via Twilio). Selfie images are deleted after verification.
Questionnaire answers. Your responses to matching questions. These are used solely by the matching algorithm and are never displayed publicly.
Messages and voice messages. Encrypted in transit and at rest. We scan messages in real time for safety purposes (detecting harassment, explicit content, and crisis language) using automated systems. We do not read your messages manually unless responding to a safety report.
Usage data. App interactions, feature usage, and crash reports. No location tracking.
2. How we use your data
To match you with compatible people. To verify your identity and maintain platform safety. To send you messages from your matches. To improve the product. We never sell your data to advertisers or third parties.
3. Third-party processors
We share data with: Veriff (ID verification, EU data storage), Twilio (SMS verification), Stripe (payment processing), Anthropic (AI-powered chat bot for the demo, no user data shared), and Railway (hosting, EU). All processors are GDPR-compliant and bound by data processing agreements.
4. Data retention
Account data is retained while your account is active. Verification images are deleted after processing. Messages are retained for 12 months after the last activity in a conversation, then automatically deleted. You can request full data deletion at any time.
5. Your rights
Under UK GDPR and the Data Protection Act 2018, you have the right to: access your data, rectify inaccuracies, request deletion, restrict processing, data portability, and object to processing. Contact privacy@riff-app.co.uk to exercise any right. We respond within 30 days.
6. Security
All data is encrypted in transit (TLS 1.3) and at rest. Passwords are hashed with bcrypt. API keys are stored as environment variables, never in code. Our infrastructure is hosted in the EU.
7. Contact
Data controller: Riff App Ltd, Woking, England. Email: privacy@riff-app.co.uk.