Skip to content
Riff← Back to Riff

Riff / Legal & trust

Privacy Policy

What Riff learns from your content, why it needs that information, and the choices that stay yours.

Draft updated September 7, 2026

PrivacyTermsSecurityData deletion
Draft for review

These pages are being prepared for Riff’s launch. The operating entity, public contact details, and production data practices still need confirmation. They are not yet final policies or a statement of Meta approval.

On this page

  1. Who we are & what this covers
  2. Information Riff processes
  3. How information is used
  4. Instagram access & publishing
  5. AI processing & service providers
  6. Cookies & local storage
  7. Retention & deletion
  8. Your choices & privacy rights
  9. Legal grounds & international processing
  10. Children & security
  11. Changes & contact

At a glance

Your content and connected-account information help Riff work for your business. This policy explains that processing, the providers involved, and how to request access or deletion.

01Who we are & what this covers

Riff helps businesses understand their content, plan marketing, create media, and publish to supported social accounts. This draft describes the website and development workspace, together with the intended handling of connected-account data when those features become available.

Riff’s legal operating person or entity and business contact details must be confirmed before this policy takes effect. Where Riff decides how personal information is used to operate its service, it acts as a controller. Where it processes a business’s content on that business’s instructions, its role depends on the service and the applicable agreement. A business’s own privacy notice may also apply to information it provides.

02Information Riff processes

  • Information you provide. Business and website details, brand preferences, prompts, conversations, plans, drafts, captions, uploaded images, video, audio, transcripts, and messages you send to the team. Voice features can process recordings and consent materials you supply.
  • Website and brand sources. Content from the website URLs you provide, including text, images, and business information used to build your brand context.
  • Connected Instagram information. Where authorized and supported, professional-account identifiers, usernames, profile information, media identifiers, captions, media and thumbnails, timestamps, links, and available account and post performance metrics. Metrics can include views, reach, likes, comments counts, saves, shares, and aggregated audience information. Availability depends on your account, permissions, and Meta’s API.
  • Connection and publishing records. Access tokens, token expiry and connection status, selected account, publishing instructions, scheduled times where scheduling is enabled, media containers, publish results, and error information.
  • Technical information. Requests to the service can include IP address, browser and device information, request times, and error logs. The workspace also uses essential browser storage to remember selections and preferences.

The development workspace does not yet offer public customer registration. Account contact information and billing information will need to be described here when those services are introduced. Permissions to read message contents or moderate comments are not implied by access to post statistics.

03How information is used

Riff uses information to provide the features you request: learn your brand context, analyze your content’s performance, suggest ideas, generate and edit media, maintain your workspace, and carry out publishing instructions. Information can also be used to answer support requests, diagnose failures, protect the service, and meet legal obligations.

Connected Instagram data is used for the account owner’s requested experience. It must not be repurposed for another customer’s marketing, sold or licensed, used for surveillance or eligibility decisions, or used to identify people behind aggregated audience statistics. These restrictions also apply to information derived from Meta data.

Riff does not currently include third-party advertising trackers in its website code. Introducing advertising, unrelated profiling, or a materially different use of information would require an updated notice and any permission required by law or Meta’s rules.

04Instagram access & publishing

Instagram features depend on authorization from an account you are entitled to manage and on the permissions Meta makes available. Riff’s development integration supports authorized professional accounts; a public Instagram connection flow is still being prepared. Riff does not ask for your Instagram password.

Where publishing is available, Riff sends selected media, captions, and publishing settings to Meta at your direction. Where scheduled publishing becomes available, approval of a schedule authorizes the corresponding publishing attempt. A plan or content suggestion alone is not permission to publish.

You can remove Riff’s access through the connected app controls in Instagram or Facebook, depending on how you connected. Removing access prevents subsequent authorized API access; it does not itself erase all information previously stored by Riff. To request that deletion, follow the data deletion instructions. Content already published on Instagram is also subject to Meta’s policies and controls.

05AI processing & service providers

Riff uses OpenAI APIs for features including text and visual analysis, content generation, transcription, and speech. Depending on the feature, relevant prompts, business context, connected-account content or insights, images, audio, video, and transcripts may be sent for processing. This is processing to produce an answer or media for your workspace; it is distinct from training a general-purpose model.

Riff does not train a general-purpose AI model on connected Meta data. Before production use, provider agreements and settings must be verified to restrict Meta data to processing on Riff’s behalf for the applicable customer’s requested purpose. This draft does not promise zero retention by providers or claim that those contractual checks are complete.

The current implementation supports local file storage and Cloudflare R2 object storage. Publishing can create a separate, publicly retrievable copy of selected media so Meta can fetch it. Anyone with that media URL may be able to retrieve it while it remains available. Cleanup is attempted after publishing; a production expiry and cleanup process still needs verification.

Service providers may process information needed for hosting, storage, AI, and support. Their production identities, processing locations, retention settings, and contracts must be confirmed before launch. Riff may disclose information to comply with law or address a legal request, subject to applicable restrictions. Meta data is subject to the narrower sharing rules in Meta’s Platform Terms; a general business purpose does not override them.

06Cookies & local storage

The workspace uses an essential cookie to remember the selected project and browser storage for preferences such as media-generation choices. Blocking or clearing this storage may reset selections or affect functionality. The marketing website does not currently set advertising cookies through its application code.

Hosting infrastructure may maintain operational request logs. Any additional analytics or non-essential tracking introduced for the public service must be reflected in this policy and accompanied by consent controls where required.

07Retention & deletion

Workspace content remains stored until it is removed or the workspace is deleted; the development build does not yet enforce a comprehensive automatic retention schedule. The final schedule must cover original media, generated files, connected-account records, derived brand context and insights, logs, provider copies, and backups.

For Meta data, the intended policy is to keep information only while needed for an authorized purpose and to delete it as soon as reasonably possible when it is no longer needed, the account is closed, the service stops, or you or Meta request deletion. If law requires retention, only the required information may be retained for the required period and purpose.

Deletion requests must also cover relevant derived data and service-provider copies. Backups must expire under a documented schedule and must not reintroduce deleted data into active use. No fixed completion or backup-expiry period is asserted in this draft because that operational process has not been verified. See Data deletion for the proposed request process and current contact status.

08Your choices & privacy rights

You can choose what you upload, edit or remove supported workspace content, and revoke connected-account permissions. You may request access, correction, or deletion of your information. Depending on your location, you may also have rights to a portable copy, to restrict or object to processing, withdraw consent, appeal a decision, or complain to your local data protection authority. Riff’s intended deletion request process is available to all users, regardless of location.

We may need proportionate information to verify a request and your authority over an account. Do not send passwords, access tokens, or unnecessary identity documents. Where Riff handles information on behalf of a business, we may need to coordinate with that business to fulfill the request.

Contact: A public contact address has not been confirmed yet. If you already work with the Riff team, use your existing contact to make this request. A monitored public address must be added before these pages are finalized.

09Legal grounds & international processing

Where applicable privacy law requires a legal basis, processing must be based on providing the agreed service, a legitimate interest such as protecting the service where that interest is not overridden by your rights, compliance with law, or consent where required. Withdrawing consent does not affect processing that was lawful before withdrawal.

Riff and its providers may process information outside your country. The production locations and legally required transfer safeguards, including contractual safeguards where applicable, must be confirmed before the public service launches. This draft does not claim a particular data residency or transfer certification.

10Children & security

Riff is intended for adults using it for business purposes, not for children. Do not provide children’s personal information or sensitive personal information that is unnecessary for the feature you are using. Contact the team if you believe a child has supplied personal information.

See the Security page for the current safeguards, development limitations, and how to report a concern. No service can guarantee absolute security.

11Changes & contact

The date above identifies the latest draft. Before this policy is adopted, Riff’s operator and public contact details must be supplied and the policy checked against the production service. Future material changes should be communicated through the service or another appropriate channel before they take effect, with consent obtained where required.

A public contact address has not been confirmed yet. If you already work with the Riff team, use your existing contact to make this request. A monitored public address must be added before these pages are finalized.

Riff

An AI head of marketing for people who don’t have one.

Product
How it worksPricing
Company
AboutCareersContact
Legal
PrivacyTermsSecurityData deletion
© 2026 Riff