Working draft — pending final legal review. Contact support@riky.ai with any questions.
Riky AI

Privacy Policy

Version 1.0 (beta draft) · RIKY LIMITED

Riky AI Privacy Policy · Effective: 31 July 2026 · Version 1.0 (beta)

Riky AI ("Riky", "we") is operated by RIKY LIMITED, a company registered in England and Wales (company no. 16331323). We are the data controller for the personal information described here. ICO registration: application submitted — registration number to follow. Contact: support@riky.ai — for privacy requests, questions, and reporting content.

Riky is an AI assistant. This policy tells you plainly what we collect, what we do with it, who else touches it, and the controls you have. It is written to be read.

1. What we collect

Teams: if you join a team, your teammates can see what is shared with the team — shared projects, team agents and their schedules, and team check-in activity (like streaks). Your chats are never visible to teammates.

What we deliberately don't do: voice transcription happens on your device — your audio never reaches our servers or any cloud service. We don't run ads, and we do not sell or "share" your personal information as those terms are defined by the California Consumer Privacy Act — with anyone.

2. Chat history — how it actually works

Chat history is a setting, on by default so your conversations are there when you return. You can turn it off any time in Settings → Privacy. With history off, your chats are ephemeral: messages are processed to generate the reply and are not stored. You can also delete any individual conversation permanently, at any time. A copy of your conversations is also kept on your device for offline speed; deleting a conversation (or the app) removes it there too.

Even with history off, some things you create are stored until you delete them or your account: scheduled-agent run outputs, check-in notes, extracted text from documents you upload, your onboarding profile, and Studio prompts and creations. Request telemetry (no message bodies) is also kept for cost and abuse control.

3. What we use your information for

Purpose Basis (UK/EU)
Providing Riky: chat, agents, Studio, projects, coach Contract
Personalising your coach and suggestions from your profile and activity Contract
Sending push notifications you enable Contract / consent
Security, abuse prevention, rate-limiting, cost control (telemetry) Legitimate interests
Crash & error diagnostics (Sentry, EU) — on by default, opt-out in Settings Legitimate interests
Product usage analytics (PostHog, EU) — off by default, opt-in only Consent
Connected calendars — creating the events you ask for (§4A) Contract / consent
Reply feedback — evaluating and improving service quality Legitimate interests
Payments, when paid plans launch (Stripe) Contract / legal obligation

We do not use your conversations, uploads, or generated content to train AI models.

4. AI processing — who sees your messages

To generate replies, your messages and relevant context are sent to large-language-model providers:

These providers process your content to generate a response and are not permitted to use it for training. We will update this policy and tell you in the app before we start sending your content to any new category of AI provider or any new processing region.

Live web search. When you ask Riky something that needs current information from the web, Riky can run a live web search. Search queries are processed by Brave Software Inc. (USA) using the Brave Search API. We send Brave only the text of the search query — never your name, email, account ID, device ID, or any other identifier. Brave retains a record of queries made through Riky's account for up to 90 days for billing and troubleshooting, and states that it cannot link any query to an individual person or device. You can turn live web search off at any time in Settings → Integrations → Web search; Riky then answers from its own knowledge only. Because Brave is a US company, search-query text leaves the UK/EEA when this feature is used.

Riky is an AI. Its replies — including the Coach — are machine-generated. Riky is not a human, and it is not a licensed therapist, medical professional, lawyer, or financial adviser; its output is not professional advice of any kind.

4A. Connected calendars (Google and Microsoft)

You can optionally connect your Google Calendar or Microsoft (Outlook) calendar so Riky can add events for you — for example putting a scheduled agent run on your calendar. When you connect:

5. Studio creations — read this one

Images and videos you generate in Studio — and character, reference, or start-frame images you upload to it — are currently stored at unlisted but publicly accessible URLs: anyone who has the link can view them. Links are not guessable and are not listed anywhere, but treat creations and uploaded Studio images as shareable, not private. Do not include personal or confidential information in generation prompts, and think twice before uploading images of real people. We plan to move creations to private storage before public launch and will update this policy when we do.

6. Where your data lives and travels

Our backend runs on Fly.io in London, United Kingdom. Our database and authentication (Supabase) are hosted in the United Kingdom/EEA region shown in your app's data settings [to be confirmed]. AI providers and some service providers (Google, OpenRouter, Anthropic, Replicate, Brave Search, Expo push notifications, Apple, Stripe when enabled, and Microsoft if you connect an Outlook calendar) process data in the United States.

Where data leaves the UK/EEA, we rely on recognised safeguards: the UK–US Data Bridge / EU–US Data Privacy Framework for certified recipients, and the UK International Data Transfer Agreement / EU Standard Contractual Clauses otherwise. You can ask us at support@riky.ai for details of the safeguard applying to any transfer.

7. How long we keep things

Data Kept
Chats (history on) Until you delete the conversation or your account
Chats (history off) Not stored
Agent run outputs, check-ins, projects/tasks, knowledge text, onboarding profile Until deleted / account deletion
Studio creations Until account deletion
Coach photos Until removed or account deletion
Request telemetry (no content) Kept for cost/abuse control
Crash & error diagnostics (Sentry, EU) Retained per Sentry's default retention (≈90 days)
Usage analytics (PostHog, EU) — only if opted in Retained per PostHog's retention; stops on withdrawal
Push tokens Until sign-out or account deletion
Studio character / reference images Until deleted / account deletion
Reply feedback (rating + reason) Until the conversation or your account is deleted
Calendar access tokens (encrypted) Until you disconnect the calendar / account deletion

Deleting your account erases your data — including coach photos, creations, and profile — not just deactivates it. Settings → Account → Delete.

8. Your rights and controls

Wherever you are, you can: export your data (Settings → Privacy → Export — a complete machine-readable copy), delete your account, delete any conversation, correct your profile, turn chat history off, and withdraw any consent you've given. Email support@riky.ai to exercise anything you can't reach in-app; we respond within one month.

9. Children

Riky is not directed at children. You must be at least 16 to use Riky (and 18 to make purchases, when billing launches — see the Terms of Use). We do not knowingly collect information from anyone under 16; if we learn an account belongs to someone under the minimum age, we will delete it and its data.

10. Closed beta specifics

Riky is currently an invite-only beta. If you join via Apple TestFlight, Apple collects your email, name, device information, usage data, crash logs, and any feedback you send through TestFlight, and shares them with us — see Apple's TestFlight terms. Beta features, data structures, and this policy may change as the product develops; we may reset or delete beta data before public launch with notice in the app. Invite codes control account creation; we don't currently offer Riky in mainland China.

11. Security

All traffic is encrypted in transit (HTTPS only — the app refuses insecure connections). Sessions are stored in your device's secure keystore. Server-side access is scoped by row-level security and ownership checks on every request. Stored provider keys you add are encrypted and never shown again. No security is perfect; we notify affected users and regulators of any breach as required by law.

12. Changes and contact

We'll post changes here and set a new effective date; for material changes — especially any new AI provider category or processing region — we'll tell you in the app first.

RIKY LIMITED · England and Wales · support@riky.ai · https://riky.ai/privacy