Riffl
PRIVACY POLICY

How Riffl handles your data.

Local-first by design · Riffl — personal expense tracker (Nigeria)

Last updated 26 July 2026 · Effective date 10 July 2026

Plain-language summary

Riffl is built to keep your money data on your phone. By default, your transactions, receipt and screenshot images, categories and informal-loan notes are stored only on your device, encrypted. Data leaves your device only when you choose an action that needs the internet — chiefly the optional AI capture, which sends an image to be read and then immediately discarded. We do not sell your data. Ever.

1 · Who we are

Riffl ("Riffl," "we," "us") is a local-first personal expense tracker operated by Riffl Ltd, a company registered in Nigeria (RC 9685707), acting as the data controller. For any privacy question or to exercise your rights, contact us at privacy@riffl.app. This Policy explains what personal data we process, why, the legal basis for it, and your rights under the Nigeria Data Protection Act (NDPA) 2023.

2 · Scope

This Policy applies to the Riffl mobile app, the Riffl website and waitlist, and the supporting services (our extraction proxy and account/credit ledger). It does not apply to third-party services you reach through Riffl (such as your bank or a payment processor), which have their own policies.

3 · The data we process — and where it lives

3.1 · Stays on your device (default)

The following is stored locally on your device in an encrypted database and is not transmitted to us unless you turn on a feature that requires it:

  • Transactions you capture or enter (amount, date, merchant/recipient, category, account, notes, tags).
  • Receipt and bank/fintech screenshot images you capture or import, and any text read from them.
  • Informal-loan / "Money owed" records, including the names of people you transact with and amounts.
  • Your "self-identity" details (your own name variants and account numbers) used locally to tell whether a transfer is money in or out.
  • App-lock PIN / biometric settings (the biometric itself never leaves your device's secure hardware).
  • The branch or area a shop prints on its own receipt — “Ikeja”, “Ring Road”, “Kano” — kept exactly as printed, and only when the receipt prints it. Riffl holds no location permission and never asks your phone where you are.

Why we keep the branch, plainly. A bag of rice does not cost the same in Lagos as it does in Kano, and a single national average describes nobody. For now that line stays on your phone and serves only your own figures. If we ever publish what Rifflers pay for everyday things, it will be opt-in, it will be an aggregate with no person in it, and we will ask you before anything of yours counts towards it. We are telling you now, at the start, rather than asking you to trust a change of mind later.

3.2 · Sent off your device — only when you act

ActivityWhat is sentTo whomWhat happens to it
AI capture (on by default, switchable off)The receipt or screenshot imageOur extraction proxy → Anthropic (Claude vision)Read to produce structured fields, then discarded — not stored or logged by us. Only a scan count is kept.
Account & scan creditsA random device identifier (UUID); scan countsOur ledger (Firebase / Google Cloud)Used to track your credit balance. No name or email required.
Waitlist sign-upEmail; optional device type / interestsOur waitlist store (Firebase)Used to contact you about access; kept until you ask us to delete it or the waitlist closes.
Payments (paid plans / credits)None — you never enter payment details in RifflGoogle Play / Apple (they bill you directly)Purchases happen inside your app store account, under their policies. Riffl receives only a confirmation that a purchase succeeded — never a card number, name or billing address.
Cloud backup & sync (optional, off by default)Your records, each encrypted on your device before upload — plus unencrypted housekeeping labels: which table a record belongs to, its id, a version number, a device id and a timestampYour chosen cloud and/or our backup serviceWe hold ciphertext we cannot open: the key is derived from your passphrase and never sent to us. The housekeeping labels let us order and de-duplicate records without reading them — they reveal how many records exist and when they changed, never an amount, a merchant or an item. If you lose your passphrase, nobody can recover the backup, including us.

We do not collect background location, contacts, or advertising identifiers, and Riffl contains no third-party advertising trackers. The branch printed on a receipt (3.1) is not location data in that sense: it is text from a document you chose to scan, it stays on your phone, and the only thing that ever reaches us is a count of how many receipts printed a branch at all — never which one.

4 · Why we process it (legal basis under the NDPA)

  • Performance of a contract — to provide the app and any paid features you buy, including metering scan credits, and to read a capture you ask Riffl to read. AI reading is how the scan feature works: when you scan a receipt, the image must be sent to be read, so this processing is necessary to deliver the thing you asked for rather than something we ask you to consent to separately. Scanning is always an act you take — Riffl reads nothing you have not pointed it at. (The app also lets you enter an expense by hand, which sends nothing.)
  • Your consent — for joining the waitlist and for any marketing messages. You can withdraw consent at any time.
  • Legitimate interests — to keep the service secure, prevent abuse/fraud, and improve reliability, balanced against your rights.
  • Legal obligation — to comply with applicable law, including responding to lawful requests and meeting our data-protection duties.

5 · AI extraction and automated processing

AI reading is how Riffl reads a capture. When you scan a receipt or screenshot, we send the image to our proxy, which calls Anthropic's Claude vision model and returns suggested fields; it is what makes item-level detail possible. Nothing is read that you have not chosen to scan. The app also accepts expenses entered by hand, which send nothing off the device. You always review and confirm every result on the Confirm screen before it is saved — no transaction is recorded by automated processing alone. The image is processed and then discarded; we do not keep or train on it.

6 · Information about other people

When you record a transfer or a loan, you may enter another person's name, account number, or the amount involved. You enter this for your own personal record-keeping, and it is stored on your device under your control. Please only record what you reasonably need, and respect others' privacy. Where this information is processed by us on your behalf (for example, transiently during AI capture), the protections in this Policy apply.

7 · Sharing and sub-processors

We do not sell your personal data and we do not share it for advertising. We use a small set of service providers strictly to run Riffl:

  • Anthropic — AI vision processing for capture (image/text processed and discarded).
  • Google / Firebase — the account/credit ledger, waitlist storage, and website hosting.
  • Google Play / Apple — they sell and bill Riffl Plus directly, and tell us only that a purchase cleared.

Each provider is bound by data-processing terms. We may also disclose data where required by law or to protect rights, safety, and security.

8 · International data transfers

Some providers (e.g. Anthropic and Google) process data outside Nigeria. Where we transfer personal data abroad, we rely on a lawful mechanism under NDPA s.43 — your explicit consent (for AI capture), and/or appropriate safeguards such as standard contractual clauses with the provider. You can avoid international AI processing entirely by not using AI capture; the on-device capture and manual entry keep your data in-country on your phone.

9 · Retention

  • On-device data is kept until you delete it or uninstall the app; deleting a transaction or using "delete all" removes it from your device.
  • AI-capture images are not retained after processing.
  • The scan-credit ledger is kept while your account/credits are active and for a reasonable period afterwards for accounting and abuse-prevention.
  • Waitlist records are kept until you ask us to delete them or the waitlist programme ends.

10 · How we protect your data

  • Local database and backups are encrypted (SQLCipher / AES-256); backup keys are derived from your passphrase and never sent to us.
  • App lock with biometric or PIN.
  • Encryption in transit (TLS) for anything that leaves the device.
  • A zero-knowledge proxy that processes images transiently and never stores or logs their contents.

No system is perfectly secure, but these measures reflect the sensitivity of financial data and our duty of care under applicable law.

11 · Your rights

Under the NDPA you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and to withdraw consent at any time for anything we process on the basis of consent (the waitlist and marketing messages). Scanning is processed to perform the service you asked for — the equivalent control there is the choice to scan or not, which is always yours to make, capture by capture. Because most of your data lives on your device, you can exercise many of these rights directly in the app (view, edit, export, and delete). For data we hold (e.g. the scan ledger or waitlist), contact us at privacy@riffl.app and we will respond within the time required by law. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).

12 · Children

Riffl is intended for users aged 18 and over and is not directed at children. We do not knowingly collect personal data from anyone under 18.

13 · Data breaches

If a breach affecting personal data we hold occurs, we will notify the NDPC within 72 hours of becoming aware of it where required, and will inform affected individuals where there is a real risk of harm, in line with NDPA s.40.

14 · Changes to this Policy

We may update this Policy as Riffl evolves or the law changes. We will post the updated version with a new "Last updated" date and, for material changes, give in-app or email notice.

15 · Contact

Operator: Riffl Ltd, Nigeria · RC 9685707. Email: privacy@riffl.app.

Regulator: Nigeria Data Protection Commission (NDPC) — you may contact the NDPC if you believe your data-protection rights have been infringed.

You can also reach us through the contact page.

© 2026 Riffl · RC 9685707 · Built in Lagos
TermsContact