Privacy Policy

1. Introduction

Ryffar ("we", "us", "our") operates the Ryffar platform, which includes the website at ryffar.com, the web application at app.ryffar.com, and the Ryffar Chrome Extension (collectively, the "Service").

This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our Service. By using Ryffar, you agree to the collection and use of information in accordance with this policy.

We are committed to protecting your privacy and handling your data with transparency. This policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and India's Digital Personal Data Protection Act, 2023 (DPDP Act).

2. Data We Collect

2.1 Account Data

When you create a Ryffar account, we collect:

DataPurpose
Email addressAccount creation, login, and transactional notifications
Display nameProfile identification within the platform
PasswordAuthentication (stored as a bcrypt hash — we never store or have access to your plain-text password)
Avatar imageProfile display (stored securely in cloud storage)

2.2 Authentication & Session Data

To secure your account and provide social login options, we may collect:

DataPurpose
Google account ID (if using Google Sign-In)Social login authentication
LinkedIn account ID (if connecting LinkedIn)LinkedIn integration features
Session tokensMaintaining your logged-in state (JWT with expiration)
IP addressSession security, fraud prevention, and rate limiting
Browser user agentSession identification and security

2.3 User Content

When you use Ryffar's features, we store the content you create:

2.4 Billing Data

DataPurpose
Subscription plan and statusManaging your access to paid features
Payment gateway customer IDLinking your account to the payment provider
Invoice records (amount, currency, date)Billing history and tax compliance

2.5 Waitlist Data

If you joined our waitlist before launch, we collected your email address, optional survey responses, and IP address for position tracking and fraud prevention.

3. Chrome Extension — Data Practices

The Ryffar Chrome Extension enhances your LinkedIn experience by enabling features such as post scheduling, self-commenting, self-reposting, and smart engagement. This section describes exactly what data the extension accesses and how it is handled.

3.1 Data the Extension Accesses

The Ryffar Chrome Extension accesses data from your active LinkedIn session to provide its features. This includes:

3.2 How Extension Data Is Handled

3.3 What the Extension Does NOT Access

To be clear about the boundaries of our data access:

3.4 Your Control

You can disable or uninstall the Ryffar Chrome Extension at any time through Chrome's extension manager (chrome://extensions). Uninstalling the extension automatically removes all locally stored data. To request deletion of extension-related data stored on our servers, contact us at [email protected].

4. How We Use Your Data

We use the data we collect for the following purposes:

  1. To provide and maintain the Service — delivering features, processing requests, and managing your account
  2. To generate AI-powered content in your voice — using your voice profile, writing samples, and knowledge base to produce LinkedIn content that matches your style
  3. To execute LinkedIn actions on your behalf — posting scheduled content, self-comments, and self-reposts using your LinkedIn session credentials
  4. To send transactional emails — OTP verification codes, password reset links, magic login links, and workspace invitation emails
  5. To process payments — managing subscriptions, credit pack purchases, and generating invoices
  6. To detect and prevent abuse — rate limiting, fraud detection, and enforcing acceptable use policies

4.1 AI & Automated Decision-Making

Ryffar uses artificial intelligence to generate content suggestions, analyze your writing voice, and assist in content creation. Here is how AI processes your data:

5. Third-Party Services

We use the following third-party services to operate Ryffar. Each service only receives the minimum data necessary for its function:

ServicePurposeData Shared
CloudflareInfrastructure (hosting, database, storage, CDN, AI gateway)All service data is processed on Cloudflare's global network
Anthropic (Claude)AI content generationUser prompts, voice profile context, knowledge base content
Google (Gemini)AI content generationSame as Anthropic
BrevoTransactional email deliveryRecipient email address and email content
Google OAuthSocial login (Sign in with Google)Email and name (authorized by you through Google)
StripePayment processing (global)Billing information (handled directly by Stripe)
PaddlePayment processing (EU, Merchant of Record)Billing information (handled directly by Paddle)
RazorpayPayment processing (India)Billing information (handled directly by Razorpay)

6. Data Security

We implement industry-standard security measures to protect your data:

While we take every reasonable precaution, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.

7. Data Retention

We retain your data only as long as necessary for the purposes described in this policy. Here are our specific retention periods:

Data TypeRetention Period
Account data (email, name, avatar)Retained while your account is active. Deleted within 30 days of account closure.
Post drafts and contentRetained until you delete them. Removed within 30 days of account closure.
AI chat conversationsRetained until you delete the thread. Removed within 30 days of account closure.
Voice profiles and writing samplesRetained until you delete them. Removed within 30 days of account closure.
LinkedIn session cookiesRefreshed and overwritten on each sync. Not accumulated over time.
Session data (JWT tokens)Automatically expires based on token TTL (time-to-live).
Invoice and billing recordsRetained for 7 years for tax and legal compliance.
Waitlist dataDeleted after account creation or upon request.

8. Your Rights

Depending on your location, you may have the following rights regarding your personal data:

Under GDPR (European Union)

Under CCPA (California, USA)

Under India DPDP Act, 2023

To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days.

9. Children's Privacy

Ryffar is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at [email protected].

10. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, providing notice through the Service or via email.

Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us: