Local-first by design · Riffl — personal expense tracker (Nigeria)
Last updated 26 July 2026 · Effective date 10 July 2026
Riffl is built to keep your money data on your phone. By default, your transactions, receipt and screenshot images, categories and informal-loan notes are stored only on your device, encrypted. Data leaves your device only when you choose an action that needs the internet — chiefly the optional AI capture, which sends an image to be read and then immediately discarded. We do not sell your data. Ever.
Riffl ("Riffl," "we," "us") is a local-first personal expense tracker operated by Riffl Ltd, a company registered in Nigeria (RC 9685707), acting as the data controller. For any privacy question or to exercise your rights, contact us at privacy@riffl.app. This Policy explains what personal data we process, why, the legal basis for it, and your rights under the Nigeria Data Protection Act (NDPA) 2023.
This Policy applies to the Riffl mobile app, the Riffl website and waitlist, and the supporting services (our extraction proxy and account/credit ledger). It does not apply to third-party services you reach through Riffl (such as your bank or a payment processor), which have their own policies.
The following is stored locally on your device in an encrypted database and is not transmitted to us unless you turn on a feature that requires it:
Why we keep the branch, plainly. A bag of rice does not cost the same in Lagos as it does in Kano, and a single national average describes nobody. For now that line stays on your phone and serves only your own figures. If we ever publish what Rifflers pay for everyday things, it will be opt-in, it will be an aggregate with no person in it, and we will ask you before anything of yours counts towards it. We are telling you now, at the start, rather than asking you to trust a change of mind later.
| Activity | What is sent | To whom | What happens to it |
|---|---|---|---|
| AI capture (on by default, switchable off) | The receipt or screenshot image | Our extraction proxy → Anthropic (Claude vision) | Read to produce structured fields, then discarded — not stored or logged by us. Only a scan count is kept. |
| Account & scan credits | A random device identifier (UUID); scan counts | Our ledger (Firebase / Google Cloud) | Used to track your credit balance. No name or email required. |
| Waitlist sign-up | Email; optional device type / interests | Our waitlist store (Firebase) | Used to contact you about access; kept until you ask us to delete it or the waitlist closes. |
| Payments (paid plans / credits) | None — you never enter payment details in Riffl | Google Play / Apple (they bill you directly) | Purchases happen inside your app store account, under their policies. Riffl receives only a confirmation that a purchase succeeded — never a card number, name or billing address. |
| Cloud backup & sync (optional, off by default) | Your records, each encrypted on your device before upload — plus unencrypted housekeeping labels: which table a record belongs to, its id, a version number, a device id and a timestamp | Your chosen cloud and/or our backup service | We hold ciphertext we cannot open: the key is derived from your passphrase and never sent to us. The housekeeping labels let us order and de-duplicate records without reading them — they reveal how many records exist and when they changed, never an amount, a merchant or an item. If you lose your passphrase, nobody can recover the backup, including us. |
We do not collect background location, contacts, or advertising identifiers, and Riffl contains no third-party advertising trackers. The branch printed on a receipt (3.1) is not location data in that sense: it is text from a document you chose to scan, it stays on your phone, and the only thing that ever reaches us is a count of how many receipts printed a branch at all — never which one.
AI reading is how Riffl reads a capture. When you scan a receipt or screenshot, we send the image to our proxy, which calls Anthropic's Claude vision model and returns suggested fields; it is what makes item-level detail possible. Nothing is read that you have not chosen to scan. The app also accepts expenses entered by hand, which send nothing off the device. You always review and confirm every result on the Confirm screen before it is saved — no transaction is recorded by automated processing alone. The image is processed and then discarded; we do not keep or train on it.
When you record a transfer or a loan, you may enter another person's name, account number, or the amount involved. You enter this for your own personal record-keeping, and it is stored on your device under your control. Please only record what you reasonably need, and respect others' privacy. Where this information is processed by us on your behalf (for example, transiently during AI capture), the protections in this Policy apply.
Some providers (e.g. Anthropic and Google) process data outside Nigeria. Where we transfer personal data abroad, we rely on a lawful mechanism under NDPA s.43 — your explicit consent (for AI capture), and/or appropriate safeguards such as standard contractual clauses with the provider. You can avoid international AI processing entirely by not using AI capture; the on-device capture and manual entry keep your data in-country on your phone.
No system is perfectly secure, but these measures reflect the sensitivity of financial data and our duty of care under applicable law.
Under the NDPA you have the right to: access your data; correct it; erase it; restrict or object to processing; data portability; and to withdraw consent at any time for anything we process on the basis of consent (the waitlist and marketing messages). Scanning is processed to perform the service you asked for — the equivalent control there is the choice to scan or not, which is always yours to make, capture by capture. Because most of your data lives on your device, you can exercise many of these rights directly in the app (view, edit, export, and delete). For data we hold (e.g. the scan ledger or waitlist), contact us at privacy@riffl.app and we will respond within the time required by law. You also have the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
Riffl is intended for users aged 18 and over and is not directed at children. We do not knowingly collect personal data from anyone under 18.
If a breach affecting personal data we hold occurs, we will notify the NDPC within 72 hours of becoming aware of it where required, and will inform affected individuals where there is a real risk of harm, in line with NDPA s.40.
We may update this Policy as Riffl evolves or the law changes. We will post the updated version with a new "Last updated" date and, for material changes, give in-app or email notice.
Operator: Riffl Ltd, Nigeria · RC 9685707. Email: privacy@riffl.app.
Regulator: Nigeria Data Protection Commission (NDPC) — you may contact the NDPC if you believe your data-protection rights have been infringed.
You can also reach us through the contact page.