Riff Apps

Governance

How we handle data, how we use AI, and what we commit to on every build. Written for clients doing due diligence on us — and for anyone using a product we made.


Our commitments on AI

These apply to everything we build, including our own products. If a client asks us to break one, we say no.

Nobody is fooled about who they’re talking to

AI participants and generated content are labelled in the interface at the point of use, not disclosed once in a policy page. In Riff, for example, AI companions are identified as AI throughout the experience.

A human decides anything that matters

Where an output affects someone’s money, safety, employment, learning or access to a service, a person reviews it before it takes effect and can overturn it. The route to that person is part of the design.

Explainable outputs

If a model ranks, scores or matches someone, the product shows the basis for it in terms they can understand.

Measured, not assumed

Every AI feature ships with an evaluation set, recorded failure modes and monitoring in production.

Your data is not training data

We do not use client or end‑user content to train third‑party models, and we select providers whose terms match that.


Data protection

We act as a processor on client projects and a controller for our own products and enquiries. Both are documented.

Lawful basis first

Identified and recorded before a feature is built, not reverse‑engineered before an audit.

Minimised by design

A feature gets the fields it needs and no more, with a retention period set at the same time.

Impact assessed

A DPIA for anything involving special category data, children, large‑scale profiling or automated decisions.

Rights that work

Access, correction, deletion, portability and objection built as functioning product features.

Transfers documented

Where data leaves the UK or EEA, the safeguard relied on is recorded and reviewed.

Breach ready

A tested response plan with the 72‑hour regulator notification window built into it.

Read the full GDPR statement


Security

Proportionate to the data a product holds, and reviewed as that changes.

Encryption everywhere

TLS in transit and encryption at rest as standard, including user media and voice. Secrets held in a managed store, never in source control.

Least privilege access

Named accounts, multi‑factor authentication, role‑based permissions and access reviews when people join or leave a project.

Dependencies watched

Automated vulnerability scanning on every build, with a defined window for patching by severity.

Tested independently

Third‑party penetration testing before launch on products handling sensitive data, and periodically after.


Accessibility

WCAG 2.2 AA is the floor for everything we deliver, not an upgrade.

Interfaces are built to work with a keyboard alone, with a screen reader, at 200% zoom and with reduced motion enabled. Colour is never the only way meaning is conveyed, contrast is checked against the standard, and forms carry real labels and error messages that say what to fix. We test with assistive technology rather than relying on an automated checker alone.

If you find something on this site or in one of our products that you cannot use, email Contact@Riff-Apps.com and we will treat it as a defect.

Doing due diligence on us?

We’ll complete your security questionnaire, sign a DPA and walk your team through how a product handles data.