Privacy Policy
Last updated: August 22, 2026
1. Introduction
Ryffar ("we", "us", "our") operates the Ryffar platform, which includes the website at ryffar.com, the web application at app.ryffar.com, and the Ryffar Chrome Extension (collectively, the "Service").
This Privacy Policy describes how we collect, use, store, and protect your personal information when you use our Service. By using Ryffar, you agree to the collection and use of information in accordance with this policy.
We are committed to protecting your privacy and handling your data with transparency. This policy is designed to comply with the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), and India's Digital Personal Data Protection Act, 2023 (DPDP Act).
2. Data We Collect
2.1 Account Data
When you create a Ryffar account, we collect:
| Data | Purpose |
|---|---|
| Email address | Account creation, login, and transactional notifications |
| Display name | Profile identification within the platform |
| Password | Authentication (stored as a bcrypt hash — we never store or have access to your plain-text password) |
| Avatar image | Profile display (stored securely in cloud storage) |
2.2 Authentication & Session Data
To secure your account and provide social login options, we may collect:
| Data | Purpose |
|---|---|
| Google account ID (if using Google Sign-In) | Social login authentication |
| LinkedIn account ID (if connecting LinkedIn) | LinkedIn integration features |
| Session tokens | Maintaining your logged-in state (JWT with expiration) |
| IP address | Session security, fraud prevention, and rate limiting |
| Browser user agent | Session identification and security |
2.3 User Content
When you use Ryffar's features, we store the content you create:
- Post drafts — text content and formatting for LinkedIn posts you compose
- AI chat conversations— messages exchanged with Ryffar's AI assistant during content creation
- Voice profiles — your writing tone, target audience, guidelines, restrictions, and professional context used to train the AI to write in your voice
- Voice writing samples — examples of your writing style used to improve AI voice matching
- Knowledge base items — reference materials you provide to give the AI additional context
- Media uploads — images attached to your posts (stored securely in cloud storage)
2.4 Billing Data
| Data | Purpose |
|---|---|
| Subscription plan and status | Managing your access to paid features |
| Payment gateway customer ID | Linking your account to the payment provider |
| Invoice records (amount, currency, date) | Billing history and tax compliance |
2.5 Waitlist Data
If you joined our waitlist before launch, we collected your email address, optional survey responses, and IP address for position tracking and fraud prevention.
3. Chrome Extension — Data Practices
The Ryffar Chrome Extension enhances your LinkedIn experience by enabling features such as post scheduling, self-commenting, self-reposting, and smart engagement. This section describes exactly what data the extension accesses and how it is handled.
3.1 Data the Extension Accesses
The Ryffar Chrome Extension accesses data from your active LinkedIn session to provide its features. This includes:
- Session authentication data, including LinkedIn cookies (li_at, JSESSIONID), used to obtain authorized access to LinkedIn data on your behalfand provide the extension's core features
- LinkedIn profile information — your name, profile photo URL, and LinkedIn identifier (URN), retrieved from your active session to identify your account within Ryffar
- LinkedIn feed content — post data visible on LinkedIn pages you visit, used to enable the smart engagement and feed discovery features
- Company page information — names and identifiers of LinkedIn company pages you administer, used to enable company page management features
- Extension preferences and cached state— stored locally in your browser using Chrome's storage API
3.2 How Extension Data Is Handled
- Locally stored:Extension preferences, settings, cached state, and authentication tokens are processed and stored locally in your browser using Chrome's storage API. This data never leaves your device unless explicitly synced (see below).
- Transmitted to our servers: If you are connected to a Ryffar account, some data is transmitted securely over HTTPSto Ryffar's servers, including: LinkedIn session authentication data (cookies), LinkedIn identity data (name, avatar, URN), company page information, and feature execution results (self-comment and self-repost outcomes).
- Purpose: This data is used exclusivelyto provide the extension's core features — post scheduling, self-commenting, self-reposting, analytics synchronization, and company page management. We do not use this data for advertising, profiling, or any purpose unrelated to the Service's functionality.
3.3 What the Extension Does NOT Access
To be clear about the boundaries of our data access:
- ❌ Your LinkedIn password — we never request, access, or store your LinkedIn login credentials
- ❌ Your LinkedIn private messages or inbox — the extension has no access to your messaging
- ❌ Your LinkedIn connection list — we do not scrape or store your connections
- ❌ Your browsing activity outside LinkedIn.com — the extension only operates on linkedin.com pages
- ❌ Cookies or data from any other website — our extension permissions are limited exclusively to linkedin.com
3.4 Your Control
You can disable or uninstall the Ryffar Chrome Extension at any time through Chrome's extension manager (chrome://extensions). Uninstalling the extension automatically removes all locally stored data. To request deletion of extension-related data stored on our servers, contact us at [email protected].
4. How We Use Your Data
We use the data we collect for the following purposes:
- To provide and maintain the Service — delivering features, processing requests, and managing your account
- To generate AI-powered content in your voice — using your voice profile, writing samples, and knowledge base to produce LinkedIn content that matches your style
- To execute LinkedIn actions on your behalf — posting scheduled content, self-comments, and self-reposts using your LinkedIn session credentials
- To send transactional emails — OTP verification codes, password reset links, magic login links, and workspace invitation emails
- To process payments — managing subscriptions, credit pack purchases, and generating invoices
- To detect and prevent abuse — rate limiting, fraud detection, and enforcing acceptable use policies
4.1 AI & Automated Decision-Making
Ryffar uses artificial intelligence to generate content suggestions, analyze your writing voice, and assist in content creation. Here is how AI processes your data:
- AI models used:We process your prompts, voice profiles, and knowledge base content through third-party AI models, including Anthropic (Claude), Google (Gemini), and Cloudflare Workers AI, accessed via Cloudflare's AI Gateway.
- What AI does: The AI generates suggested content (post drafts, comments, rewrites) based on your instructions and voice profile. It does not make decisions with legal or significant effects on you.
- Model training: Your content is not used to train our AI models or any third-party AI models. Your data is processed solely to generate responses for you and is not retained by AI providers beyond the duration of the API request.
5. Third-Party Services
We use the following third-party services to operate Ryffar. Each service only receives the minimum data necessary for its function:
| Service | Purpose | Data Shared |
|---|---|---|
| Cloudflare | Infrastructure (hosting, database, storage, CDN, AI gateway) | All service data is processed on Cloudflare's global network |
| Anthropic (Claude) | AI content generation | User prompts, voice profile context, knowledge base content |
| Google (Gemini) | AI content generation | Same as Anthropic |
| Brevo | Transactional email delivery | Recipient email address and email content |
| Google OAuth | Social login (Sign in with Google) | Email and name (authorized by you through Google) |
| Stripe | Payment processing (global) | Billing information (handled directly by Stripe) |
| Paddle | Payment processing (EU, Merchant of Record) | Billing information (handled directly by Paddle) |
| Razorpay | Payment processing (India) | Billing information (handled directly by Razorpay) |
6. Data Security
We implement industry-standard security measures to protect your data:
- All data transmitted between your browser and our servers is encrypted using HTTPS/TLS
- Passwords are hashed using bcrypt — we never store or transmit plain-text passwords
- Session management uses JWT tokens with expiration, automatically invalidated after the set period
- LinkedIn session cookies are stored securely and transmitted only over encrypted connections
- Our infrastructure runs on Cloudflare's global edge network, which provides built-in DDoS protection, Web Application Firewall (WAF), and bot management
- API endpoints are protected by rate limiting to prevent abuse
While we take every reasonable precaution, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.
7. Data Retention
We retain your data only as long as necessary for the purposes described in this policy. Here are our specific retention periods:
| Data Type | Retention Period |
|---|---|
| Account data (email, name, avatar) | Retained while your account is active. Deleted within 30 days of account closure. |
| Post drafts and content | Retained until you delete them. Removed within 30 days of account closure. |
| AI chat conversations | Retained until you delete the thread. Removed within 30 days of account closure. |
| Voice profiles and writing samples | Retained until you delete them. Removed within 30 days of account closure. |
| LinkedIn session cookies | Refreshed and overwritten on each sync. Not accumulated over time. |
| Session data (JWT tokens) | Automatically expires based on token TTL (time-to-live). |
| Invoice and billing records | Retained for 7 years for tax and legal compliance. |
| Waitlist data | Deleted after account creation or upon request. |
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data:
Under GDPR (European Union)
- Right to access — request a copy of your personal data
- Right to rectification — request correction of inaccurate data
- Right to erasure— request deletion of your data ("right to be forgotten")
- Right to data portability — receive your data in a structured, machine-readable format
- Right to restrict processing — limit how we use your data
- Right to object — object to processing based on legitimate interests
- Right to withdraw consent — withdraw previously given consent at any time
Under CCPA (California, USA)
- Right to know — what personal information we collect and how it is used
- Right to delete — request deletion of your personal information
- Right to opt-out — opt out of the sale of personal information (we do not sell your data)
- Right to non-discrimination — we will not discriminate against you for exercising your privacy rights
Under India DPDP Act, 2023
- Right to access — obtain a summary of your personal data and processing activities
- Right to correction and erasure — request correction of inaccurate data or erasure of data no longer necessary
- Right to grievance redressal — raise grievances regarding data processing
- Right to nominate — nominate another individual to exercise your rights in case of death or incapacity
To exercise any of these rights, contact us at [email protected]. We will respond to your request within 30 days.
9. Children's Privacy
Ryffar is not directed at individuals under the age of 16. We do not knowingly collect personal data from children under 16. If we become aware that we have collected data from a child under 16, we will take steps to delete that information promptly. If you believe a child has provided us with personal data, please contact us at [email protected].
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. When we make material changes, we will notify you by updating the "Last updated" date at the top of this page and, where appropriate, providing notice through the Service or via email.
Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
11. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: [email protected]
- Website: ryffar.com