Privacy Policy
Riky AI Privacy Policy · Effective: 31 July 2026 · Version 1.0 (beta)
Riky AI ("Riky", "we") is operated by RIKY LIMITED, a company registered in England and Wales (company no. 16331323). We are the data controller for the personal information described here. ICO registration: application submitted — registration number to follow. Contact: support@riky.ai — for privacy requests, questions, and reporting content.
Riky is an AI assistant. This policy tells you plainly what we collect, what we do with it, who else touches it, and the controls you have. It is written to be read.
1. What we collect
- Account: email address and sign-in identity (email/password, Google Sign-In, or Sign in with Apple), managed by our authentication provider Supabase.
- Onboarding profile: answers you give our onboarding interview — about your work, goals, and background — including a short bio. If you give us your business website address, we fetch and analyse its public pages to personalise Riky for you.
- Your content: chat messages, uploaded documents (we extract and store the text, not the original file), projects, tasks, goals, check-in ratings and notes, agent instructions and memories, and Studio prompts.
- Generated content: replies, agent run outputs, and Studio images/videos.
- Coach photos: only if you explicitly upload one and tick the consent box; used solely to style your coach. Deleted with your account.
- Studio character and reference images: images you upload to Studio as reusable characters, reference images, or video start frames. Only upload images you have the right to use; images of a real person need that person's consent (see the Terms of Use). Deleted when you delete them or your account.
- Reply feedback: if you rate a reply (thumbs up/down) and optionally give a reason, we store that rating and reason linked to the conversation, and use it to evaluate and improve service quality — not to train AI models (§3).
- Connected calendars (optional): if you connect a Google or Microsoft calendar, we store an encrypted access token so Riky can act on your calendar when you ask (§4A). We do not store your Google or Microsoft password.
- Technical data: push-notification tokens, and per-request telemetry (which AI model served you, token counts, response time, error codes). Telemetry contains no message content.
- Crash reports: crash and error diagnostics (via Sentry, EU-hosted), on by default to help us fix bugs. Reports are scrubbed to stack traces only and contain no personal content. You can turn this off any time in Settings → Privacy.
- Usage analytics: only if you opt in (off by default). Anonymous, aggregated product-usage events — which screens and features you use, and whether actions succeed — via PostHog (EU-hosted). Never your chats, uploads, or personal content. You can withdraw any time in Settings → Privacy.
- Consent and acceptance records: when you create an account we record the terms version you accepted and when, your invite code if you used one, and the data-handling preferences you choose (kept as proof of your choices).
Teams: if you join a team, your teammates can see what is shared with the team — shared projects, team agents and their schedules, and team check-in activity (like streaks). Your chats are never visible to teammates.
What we deliberately don't do: voice transcription happens on your device — your audio never reaches our servers or any cloud service. We don't run ads, and we do not sell or "share" your personal information as those terms are defined by the California Consumer Privacy Act — with anyone.
2. Chat history — how it actually works
Chat history is a setting, on by default so your conversations are there when you return. You can turn it off any time in Settings → Privacy. With history off, your chats are ephemeral: messages are processed to generate the reply and are not stored. You can also delete any individual conversation permanently, at any time. A copy of your conversations is also kept on your device for offline speed; deleting a conversation (or the app) removes it there too.
Even with history off, some things you create are stored until you delete them or your account: scheduled-agent run outputs, check-in notes, extracted text from documents you upload, your onboarding profile, and Studio prompts and creations. Request telemetry (no message bodies) is also kept for cost and abuse control.
3. What we use your information for
| Purpose | Basis (UK/EU) |
|---|---|
| Providing Riky: chat, agents, Studio, projects, coach | Contract |
| Personalising your coach and suggestions from your profile and activity | Contract |
| Sending push notifications you enable | Contract / consent |
| Security, abuse prevention, rate-limiting, cost control (telemetry) | Legitimate interests |
| Crash & error diagnostics (Sentry, EU) — on by default, opt-out in Settings | Legitimate interests |
| Product usage analytics (PostHog, EU) — off by default, opt-in only | Consent |
| Connected calendars — creating the events you ask for (§4A) | Contract / consent |
| Reply feedback — evaluating and improving service quality | Legitimate interests |
| Payments, when paid plans launch (Stripe) | Contract / legal obligation |
We do not use your conversations, uploads, or generated content to train AI models.
4. AI processing — who sees your messages
To generate replies, your messages and relevant context are sent to large-language-model providers:
- OpenRouter, Inc. (USA) — the routing layer for Riky's multi-model engine, which serves every paid tier's everyday requests. Through OpenRouter your content reaches the engine's models (currently from Meta, DeepSeek, and Qwen). We pin routing to US/EU-hosted providers configured for zero data retention and no training on your content.
- Anthropic (USA) — Claude models handle harder work on Pro and Studio, and a small Anthropic model classifies each request to pick the right brain. Under the Anthropic API terms we use, your content is not used to train Anthropic's models.
- Google (Gemini) — free-tier chat, onboarding, free agent runs, image generation, and Studio video (Veo). We use Google's paid API tier, under which Google does not use your content to train or improve its models.
- Replicate, Inc. (USA) — runs the open-weight Wan video model that renders Studio's silent draft clips. Your video prompt (and a start-frame image if you attach one) is sent to Replicate to generate the clip; Replicate deletes inputs after processing and does not use your content to train models.
- Mistral (France) — only if you explicitly select a Mistral model.
These providers process your content to generate a response and are not permitted to use it for training. We will update this policy and tell you in the app before we start sending your content to any new category of AI provider or any new processing region.
Live web search. When you ask Riky something that needs current information from the web, Riky can run a live web search. Search queries are processed by Brave Software Inc. (USA) using the Brave Search API. We send Brave only the text of the search query — never your name, email, account ID, device ID, or any other identifier. Brave retains a record of queries made through Riky's account for up to 90 days for billing and troubleshooting, and states that it cannot link any query to an individual person or device. You can turn live web search off at any time in Settings → Integrations → Web search; Riky then answers from its own knowledge only. Because Brave is a US company, search-query text leaves the UK/EEA when this feature is used.
Riky is an AI. Its replies — including the Coach — are machine-generated. Riky is not a human, and it is not a licensed therapist, medical professional, lawyer, or financial adviser; its output is not professional advice of any kind.
4A. Connected calendars (Google and Microsoft)
You can optionally connect your Google Calendar or Microsoft (Outlook) calendar so Riky can add events for you — for example putting a scheduled agent run on your calendar. When you connect:
- We access your calendar only to do what you ask in the app (creating the events you approve). We do not read your existing events, and we never see your Google or Microsoft password — connection uses the provider's own sign-in (OAuth).
- Access tokens are stored encrypted on our servers and are deleted when you disconnect the calendar or delete your account. You can disconnect at any time in Settings, or revoke Riky's access from your Google or Microsoft account settings.
- The events Riky creates live in your calendar under the provider's own terms and privacy policy.
- Google API disclosure: Riky's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
5. Studio creations — read this one
Images and videos you generate in Studio — and character, reference, or start-frame images you upload to it — are currently stored at unlisted but publicly accessible URLs: anyone who has the link can view them. Links are not guessable and are not listed anywhere, but treat creations and uploaded Studio images as shareable, not private. Do not include personal or confidential information in generation prompts, and think twice before uploading images of real people. We plan to move creations to private storage before public launch and will update this policy when we do.
6. Where your data lives and travels
Our backend runs on Fly.io in London, United Kingdom. Our database and authentication (Supabase) are hosted in the United Kingdom/EEA region shown in your app's data settings [to be confirmed]. AI providers and some service providers (Google, OpenRouter, Anthropic, Replicate, Brave Search, Expo push notifications, Apple, Stripe when enabled, and Microsoft if you connect an Outlook calendar) process data in the United States.
Where data leaves the UK/EEA, we rely on recognised safeguards: the UK–US Data Bridge / EU–US Data Privacy Framework for certified recipients, and the UK International Data Transfer Agreement / EU Standard Contractual Clauses otherwise. You can ask us at support@riky.ai for details of the safeguard applying to any transfer.
7. How long we keep things
| Data | Kept |
|---|---|
| Chats (history on) | Until you delete the conversation or your account |
| Chats (history off) | Not stored |
| Agent run outputs, check-ins, projects/tasks, knowledge text, onboarding profile | Until deleted / account deletion |
| Studio creations | Until account deletion |
| Coach photos | Until removed or account deletion |
| Request telemetry (no content) | Kept for cost/abuse control |
| Crash & error diagnostics (Sentry, EU) | Retained per Sentry's default retention (≈90 days) |
| Usage analytics (PostHog, EU) — only if opted in | Retained per PostHog's retention; stops on withdrawal |
| Push tokens | Until sign-out or account deletion |
| Studio character / reference images | Until deleted / account deletion |
| Reply feedback (rating + reason) | Until the conversation or your account is deleted |
| Calendar access tokens (encrypted) | Until you disconnect the calendar / account deletion |
Deleting your account erases your data — including coach photos, creations, and profile — not just deactivates it. Settings → Account → Delete.
8. Your rights and controls
Wherever you are, you can: export your data (Settings → Privacy → Export — a complete machine-readable copy), delete your account, delete any conversation, correct your profile, turn chat history off, and withdraw any consent you've given. Email support@riky.ai to exercise anything you can't reach in-app; we respond within one month.
- UK/EU: you also have rights to restriction, objection, and portability, and to complain to the ICO (ico.org.uk) or your local supervisory authority.
- United States: we do not sell or share personal information; there is nothing to opt out of. State-specific rights will be honoured through the same controls above.
- Canada / Quebec: RIKY LIMITED is accountable for your information; the person in charge of the protection of personal information is the CEO, reachable at support@riky.ai. Your information is processed outside Quebec/Canada (UK and US) with contractual protections. You may request access, rectification, or withdraw consent, and complain to the OPC or CAI.
- Other regions: the purposes in §3 are the complete list of what we use your information for; contact us to exercise any local right.
9. Children
Riky is not directed at children. You must be at least 16 to use Riky (and 18 to make purchases, when billing launches — see the Terms of Use). We do not knowingly collect information from anyone under 16; if we learn an account belongs to someone under the minimum age, we will delete it and its data.
10. Closed beta specifics
Riky is currently an invite-only beta. If you join via Apple TestFlight, Apple collects your email, name, device information, usage data, crash logs, and any feedback you send through TestFlight, and shares them with us — see Apple's TestFlight terms. Beta features, data structures, and this policy may change as the product develops; we may reset or delete beta data before public launch with notice in the app. Invite codes control account creation; we don't currently offer Riky in mainland China.
11. Security
All traffic is encrypted in transit (HTTPS only — the app refuses insecure connections). Sessions are stored in your device's secure keystore. Server-side access is scoped by row-level security and ownership checks on every request. Stored provider keys you add are encrypted and never shown again. No security is perfect; we notify affected users and regulators of any breach as required by law.
12. Changes and contact
We'll post changes here and set a new effective date; for material changes — especially any new AI provider category or processing region — we'll tell you in the app first.
RIKY LIMITED · England and Wales · support@riky.ai · https://riky.ai/privacy