Privacy Policy
Last updated: October 2, 2026
How Riffi handles your information while helping your brand create content and keep showing up.
Who this policy covers
Riffi operates in Canada. This policy covers Riffi’s website, accounts, creative workspace, brand imports, AI features and social publishing tools. Riffi is the service responsible for the account and service information described here. Contact support@riffi.com with privacy questions. When you upload information about other people for your business, you are responsible for having permission and providing any required notices.
Information we collect
We collect information you provide, information needed to operate the service, and information from providers you choose to connect.
- Account information: name, email, timezone, password hash for password accounts, and sign-in provider identifier for connected login methods. We do not store your password as readable text.
- Brand and content information: business details, website URLs, audience, products, brand voice, colors, fonts, logos, uploaded assets, prompts, generated content, drafts, revisions and schedules.
- Public website information: publicly available page text, images, logos and styling from links you submit. Some imports use a rendered browser to read public pages. This does not give Riffi access to a private website account.
- Connected account information: platform, account identifier, username, connection status, profile image where supplied, publishing permissions and publication results.
- Billing information: plan, subscription state, payment-provider identifiers and available invoice details. Payment card entry and processing are handled by the payment provider.
- Operational information: service requests, security events, rate-limit records, timestamps, browser/network information available to our hosting providers, and messages you send to support.
How we use information
We use information to create and secure accounts; import and remember branding; generate and edit requested content; store your workspace; schedule and publish posts you authorize; confirm publication results; administer subscriptions where available; answer support requests; and investigate errors, fraud or misuse. We do not promise audience growth or use your unpublished drafts as public examples without permission.
AI generation and service providers
When you request AI features, relevant prompts, brand context and selected assets are sent to the configured AI provider, including OpenAI. Outputs may contain errors or resemble other outputs. Avoid including sensitive personal information that is unnecessary for the task. AI providers have their own processing and retention terms.
Cloudflare provides hosting, database, file storage and browser rendering. Post for Me manages social connections and publication requests. Google processes Google sign-in when configured. Stripe processes payments when enabled. An email delivery provider may handle requested account messages when email delivery is configured. Only features you use and providers enabled for those features receive the relevant information.
- OpenAI privacy information: https://openai.com/policies/privacy-policy/
- Cloudflare privacy information: https://www.cloudflare.com/privacypolicy/
- Post for Me privacy information: https://www.postforme.dev
- Google privacy information: https://policies.google.com/privacy
- Stripe privacy information: https://stripe.com/privacy
Social publishing and access tokens
Connecting an account authorizes the permissions shown during the platform connection flow. When you publish or schedule a post, Riffi sends its media, captions and destination account identifiers to Post for Me and the selected social platforms. The platforms may make that content public according to your selected settings.
Social tokens for Post for Me connections remain with that provider. Legacy direct connections, where used, store encrypted tokens in Riffi. Disconnecting prevents future use through that connection; it does not remove posts already published or necessarily revoke all permissions at the social platform. You can also revoke access in the platform’s own settings.
Sharing and disclosures
We share information with service providers to perform the functions above, with social platforms for authorized posting, and when required by applicable law or reasonably necessary to protect accounts and the service. Information may also be transferred as part of a business transaction, subject to applicable privacy obligations. We do not sell your personal information or use it for cross-context behavioral advertising.
Storage, retention and security
We keep account and workspace records while needed to provide the service. You can remove unused assets and drafts in the app. Contact support@riffi.com to request account deletion or an export. Security, billing, legal or dispute records may need to be retained after a request; backups and third-party records may follow separate retention cycles. We will explain applicable limits when handling your request. We do not promise instant deletion from every backup or connected provider.
Access checks, password hashing, secure session cookies, token protections and temporary signed media links help protect your workspace. No online service is completely secure. Media links used for publishing can be accessed by whoever possesses a valid link until it expires. Do not share those links unnecessarily.
Your choices and privacy rights
You can edit your profile and business details, remove drafts and assets, disconnect social accounts and request assistance with access, correction, export or deletion at support@riffi.com. We may verify account ownership before acting. Depending on where you live, you may also have rights to object to or restrict processing, withdraw consent, or complain to your local privacy regulator. We respond within applicable legal requirements and do not penalize you for exercising rights.
Where applicable law requires a legal basis, service delivery relies on contractual necessity; security and service operations on legitimate interests; required records on legal obligations; and optional uses requiring permission on consent. Information may be processed in countries different from yours through our providers. Applicable transfer requirements must be respected.
Canadian privacy rights and accountability
Riffi handles personal information under applicable Canadian privacy law, including the Personal Information Protection and Electronic Documents Act (PIPEDA) where it applies, and applicable provincial requirements. Direct privacy requests and complaints to support@riffi.com, for the person responsible for privacy at Riffi. You may request access to information about you, correction of inaccuracies, an explanation of its use and disclosures, or withdrawal of consent subject to legal or contractual restrictions. Withdrawing information necessary for a feature may prevent us from providing that feature.
We explain relevant purposes when collecting information and obtain consent where required. We do not treat agreement to these terms as blanket consent for unrelated uses. If a privacy issue remains unresolved, you can contact the Office of the Privacy Commissioner of Canada or the applicable provincial privacy commissioner. PIPEDA access requests are generally answered within 30 days, subject to legally permitted extensions and exceptions.
Our providers may process information outside Canada, including in the United States. Information processed abroad may be subject to that jurisdiction’s laws and access by its courts or authorities. We remain accountable for personal information transferred for processing and use appropriate contractual and other safeguards. If a breach triggers notification or reporting obligations under applicable law, we will notify affected people and the relevant authority as required.
- Canadian privacy information and complaint guidance: https://www.priv.gc.ca/en/report-a-concern/guide/
Children and policy changes
Riffi is intended for adult business users and creators, not children under 18. Do not submit a child’s personal information without appropriate authority. If you believe a child has provided account information, contact support@riffi.com. We may update this policy as the service changes, update the date, and provide additional notice for material changes where required.
Contact
Questions about this page? Email support@riffi.com.