PRIVACY POLICY
How Riffl handles your data.
Local-first by design · Riffl, personal expense tracker (Nigeria)
1 · Who we are
Riffl ("Riffl," "we," "us") is a local-first personal expense tracker operated by Riffl Ltd, a company registered in Nigeria (RC 9685707), acting as the data controller. For any privacy question or to exercise your rights, contact us at privacy@riffl.app. This Policy explains what personal data we process, why, the legal basis for it, and your rights under the Nigeria Data Protection Act (NDPA) 2023.
2 · Scope
This Policy applies to the Riffl mobile app, the Riffl website and waitlist, and the supporting services (our extraction proxy and account/credit ledger). It does not apply to third-party services you reach through Riffl (such as your bank or a payment processor), which have their own policies.
3 · The data we process, and where it lives
3.1 · Stays on your device (default)
The following is stored locally on your device in an encrypted database and is not transmitted to us unless you turn on a feature that requires it:
- Transactions you capture or enter (amount, date, merchant/recipient, category, account, notes, tags).
- Receipt and bank/fintech screenshot images you capture or import, and any text read from them.
- Informal-loan / "Money owed" records, including the names of people you transact with and amounts.
- Your "self-identity" details (your own name variants and account numbers) used locally to tell whether a transfer is money in or out.
- App-lock PIN / biometric settings (the biometric itself never leaves your device's secure hardware).
- The branch or area a shop prints on its own receipt (“Ikeja”, “Ring Road”, “Kano”), kept exactly as printed, and only when the receipt prints it. Riffl holds no location permission and never asks your phone where you are.
Why we keep the branch, plainly. A bag of rice does not cost the same in Lagos as it does in Kano, and a single national average describes nobody. For now that line stays on your phone and serves only your own figures. If we ever publish what Rifflers pay for everyday things, it will be opt-in, it will be an aggregate with no person in it, and we will ask you before anything of yours counts towards it. We are telling you now, at the start, rather than asking you to trust a change of mind later.
3.2 · Sent off your device, only when you act
| Activity | What is sent | To whom | What happens to it |
|---|---|---|---|
| AI capture (on by default, switchable off) | The receipt or screenshot image | Our extraction proxy → Anthropic (Claude vision) | Read to produce structured fields, then discarded, not stored or logged by us. Only a scan count is kept. |
| Account & scan credits | A random device identifier (UUID); scan counts | Our ledger (Firebase / Google Cloud) | Used to track your credit balance. No name or email required. |
| Waitlist sign-up | Email; optional device type / interests | Our waitlist store (Firebase) | Used to contact you about access; kept until you ask us to delete it or the waitlist closes. |
| Payments (paid plans / credits) | None. You never enter payment details in Riffl | Google Play / Apple (they bill you directly) | Purchases happen inside your app store account, under their policies. Riffl receives only a confirmation that a purchase succeeded, never a card number, name or billing address. |
| Cloud backup & sync (optional, off by default) | Your records, each encrypted on your device before upload, plus unencrypted housekeeping labels: which table a record belongs to, its id, a version number, a device id and a timestamp | Your chosen cloud and/or our backup service | We hold ciphertext we cannot open: the key is derived from your passphrase and never sent to us. The housekeeping labels let us order and de-duplicate records without reading them: they reveal how many records exist and when they changed, never an amount, a merchant or an item. If you lose your passphrase, nobody can recover the backup, including us. |
We do not collect background location, contacts, or advertising identifiers, and Riffl contains no third-party advertising trackers. The branch printed on a receipt (3.1) is not location data in that sense: it is text from a document you chose to scan, it stays on your phone, and the only thing that ever reaches us is a count of how many receipts printed a branch at all, never which one.
4 · Why we process it (legal basis under the NDPA)
- Performance of a contract: to provide the app, including metering scan credits, and to read a capture you ask Riffl to read. AI reading is how the scan feature works: when you scan a receipt, the image must be sent to be read, so this processing is necessary to deliver the thing you asked for rather than something we ask you to consent to separately. Scanning is always an act you take: Riffl reads nothing you have not pointed it at. (The app also lets you enter an expense by hand, which sends nothing.)
- Your consent: for joining the waitlist and for any marketing messages. You can withdraw consent at any time.
- Legitimate interests: to keep the service secure, prevent abuse/fraud, and improve reliability, balanced against your rights.
- Legal obligation: to comply with applicable law, including responding to lawful requests and meeting our data-protection duties.
5 · AI extraction and automated processing
AI reading is how Riffl reads a capture. When you scan a receipt or screenshot, we send the image to our proxy, which calls Anthropic's Claude vision model and returns suggested fields; it is what makes item-level detail possible. Nothing is read that you have not chosen to scan. The app also accepts expenses entered by hand, which send nothing off the device. You always review and confirm every result on the Confirm screen before it is saved. No transaction is recorded by automated processing alone. The image is processed and then discarded; we do not keep or train on it.
6 · Information about other people
When you record a transfer or a loan, you may enter another person's name, account number, or the amount involved. You enter this for your own personal record-keeping, and it is stored on your device under your control. Please only record what you reasonably need, and respect others' privacy. Where this information is processed by us on your behalf (for example, transiently during AI capture), the protections in this Policy apply.
8 · International data transfers
Some providers (e.g. Anthropic and Google) process data outside Nigeria. Where we transfer personal data abroad, we rely on a lawful mechanism under NDPA s.43: the transfer being necessary to perform the contract you have asked us to perform (reading a capture requires sending it to be read), and/or appropriate safeguards such as standard contractual clauses with the provider. You can avoid international processing entirely by entering expenses by hand. Manual entry sends nothing off your phone and keeps your data in-country.
9 · Retention
- On-device data is kept until you delete it or uninstall the app; deleting a transaction or using "delete all" removes it from your device.
- AI-capture images are not retained after processing.
- The scan-credit ledger is kept while your account/credits are active and for a reasonable period afterwards for accounting and abuse-prevention.
- Waitlist records are kept until you ask us to delete them or the waitlist programme ends.
10 · How we protect your data
- Local database and backups are encrypted (SQLCipher / AES-256); backup keys are derived from your passphrase and never sent to us.
- App lock with biometric or PIN.
- Encryption in transit (TLS) for anything that leaves the device.
- A zero-knowledge proxy that processes images transiently and never stores or logs their contents.
No system is perfectly secure, but these measures reflect the sensitivity of financial data and our duty of care under applicable law.
11 · Your rights
Under the NDPA you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and to withdraw consent at any time for anything we process on the basis of consent (the waitlist and marketing messages). Scanning is processed to perform the service you asked for, and the equivalent control there is the choice to scan or not, which is always yours to make, capture by capture. Because most of your data lives on your device, you can exercise many of these rights directly in the app (view, edit, export, and delete). For data we hold (e.g. the scan ledger or waitlist), contact us at privacy@riffl.app and we will respond within the time required by law. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
12 · Children
Riffl is intended for users aged 18 and over and is not directed at children. We do not knowingly collect personal data from anyone under 18.
13 · Data breaches
If a breach affecting personal data we hold occurs, we will notify the NDPC within 72 hours of becoming aware of it where required, and will inform affected individuals where there is a real risk of harm, in line with NDPA s.40.
14 · Changes to this Policy
We may update this Policy as Riffl evolves or the law changes. We will post the updated version with a new "Last updated" date and, for material changes, give in-app or email notice.
15 · Contact
Operator: Riffl Ltd, Nigeria · RC 9685707. Email: privacy@riffl.app.
Regulator: Nigeria Data Protection Commission (NDPC). You may contact the NDPC if you believe your data-protection rights have been infringed.
You can also reach us through the contact page.