1. Who we are
Rafii (“we”, “us”) operates the service at https://postriff-phase2-private.vercel.app. [Legal entity name, registered address and registration number — to be confirmed by counsel.] We are the controller of the account and workspace data described below.
2. What we collect
Account data
Your email address and, if you sign in with Google, the name and profile image your provider shares. Authentication is handled by Supabase Auth. We do not store passwords.
Workspace content
Sources you paste or upload, the drafts generated from them, your edits, approvals, scheduling times, media you upload, and the receipts produced when a post is published. This content belongs to you.
Connected-account data
When you connect a social account through its official login, we receive an access token, the account’s identity (id and handle), and — only for capabilities you enable — the ids of posts published through Rafii, their native metrics, and comments on those posts. Tokens are encrypted at the application layer before storage and are decrypted only by authorized server operations for the enabled capability.
Billing data
If you subscribe, Stripe processes your payment. We store your Stripe customer and subscription identifiers and the plan you chose. Card numbers never reach our systems.
Operational data
Request logs with timestamps, IP-derived throttling counters, session identifiers and a content-free audit trail of actions in your workspace (for example “invitation.created”). Application audit events omit prompts, post bodies, tokens and files. Hosting and error-tracking configuration still requires verification before public launch.
3. How we use it
- To run the service: drafting, previews, approvals, scheduling and publishing on your instruction.
- To send transactional email: invitations, a welcome message, trial reminders and billing notices. We do not send marketing email.
- To keep the service safe: rate limiting, abuse prevention, session revocation and the audit trail.
- To bill you, if you subscribe.
We do not sell your data, and we do not use your content or your audience’s data for advertising.
4. AI processing
The deterministic preview makes no model request. When a configured cloud writer is selected, your instruction and permitted source context are sent to that writer through the configured model route. A local CLI can also send data to its cloud provider. Sources require the applicable egress consent; writing samples require separate purpose and exact writer-route permission. Only bounded style observations are used for sample-based drafting. Workspace memory reaches a cloud writer only when its owner allows it. When you ask for a reply suggestion, the comment, the commenter’s public handle and the post it answers are sent to the managed writer with facts from sources you cleared for public use and the memory you allowed; nothing is sent to the platform until you approve the reply. Paid routes use a workspace reservation and record reported or estimated usage; unknown usage remains reserved until reconciled. Provider contracts, data retention and processing regions require review before a paid beta.
Web research is off for every hosted workspace until its owner turns it on. When it is on and a draft needs facts you have not supplied, we send a search query derived from your message to Exa and fetch the public pages it finds through Jina Reader; a link you paste is fetched the same way. Your sources, memory files and drafts are never sent, facts found this way are marked in the draft for you to check, and turning research off stops it immediately. Both services are listed under Subprocessors.
5. Connected platforms
Rafii connects to LinkedIn, Threads, Instagram and other platforms only through your own authorisation, requesting the minimum permissions for the capability you enable. Data received from a platform (account identity, post ids, metrics, comments) is used solely to provide the service to you — showing your results, letting you reply, and reconciling publications. It is not sold, shared with third parties, or combined across customers. When you disconnect an account, the stored token is wiped and revoked with the platform where supported, and platform data for that account stops being collected. Your use of each platform remains subject to that platform’s own terms and privacy policy.
6. Retention
| Data | Kept | Notes |
|---|---|---|
| Verified phone identity | Until you revoke the number or delete the account | The number is encrypted at rest; notifications and diagnostics do not include the full number. |
| Phone sessions | Until you delete the account or workspace | No audio recording. Call lifecycle, bounded costs and text transcript follow the Rafii voice conversation policy. |
| Phone sign-in | Codes expire after five minutes. Expired code digests older than one day and caller rate-limit digests older than two days are removed on the next incoming-call or enabled phone-maintenance pass. | Single-use codes are stored only as keyed hashes and belong to your account, workspace and chosen conversation. Caller ID alone does not authenticate. No private context or AI session before authentication. |
| Drafts and revision history | Until you delete them | Revision history is kept with the draft. |
| Sources you add | Until retraction or deletion | Retraction blocks future use and dependent drafts; deletion removes the text and derived chunks. |
| Generated media | Until you delete it | Immutable renditions; provenance kept as hashes. |
| Provider tokens (OAuth) | Until disconnect or revocation | Encrypted at rest; the ciphertext is wiped on disconnect. |
| Approval receipts | Retained as records after publication | Limited deletion, trial and audit records remain after account deletion; workspace publication records are removed. |
| Post metrics | Until workspace deletion; release policy pending review | Native metric observations; never sold or aggregated across customers with content. |
| Audience comments | Until the provider or you delete them | Tombstones are preserved when a provider requires deletion. |
| Time back estimates | Until you delete your account or the workspace | Estimated minutes saved per completed task, your answers about how long tasks usually take, and seconds of active use in Rafii. No text, keystrokes, pointer positions or browsing outside Rafii. |
| Logs and traces | 30 days — candidate | Sanitised: no prompts, post bodies, tokens or files by default. |
| Backups | 30-day rotation — candidate | Database and object-storage backup coverage must be verified separately for the release environment. |
7. Subprocessors
| Provider | Purpose | Region | Status |
|---|---|---|---|
| Dial | Optional phone verification and inbound/outbound PSTN transport for Self-Hosted Phone Mode | Provider route to be verified | Only when Dial Phone Mode is configured and you explicitly enable callbacks or create a one-time dial-in code; no audio recording |
| Twilio | Optional SMS notifications or legacy phone verification and PSTN transport | Provider route to be verified | Only when the corresponding service is configured and you consent |
| OpenAI GPT-Live | Browser and optional phone voice conversations delegated to the same Rafii runtime | Provider route to be verified | Only when configured; session storage is disabled and the text transcript remains in Rafii |
| Vercel | Hosting and API runtime | Release region to be verified | Configured hosting provider |
| Supabase | Authentication, PostgreSQL database, private object storage | Release region to be verified | Configured identity, database and storage provider |
| Vercel Web Analytics; Sentry when configured | Website usage and sanitised error diagnostics | Release settings to be verified | Analytics is integrated; error delivery depends on configuration |
| Stripe | Subscription billing and invoices (card details never touch Rafii) | Global | When you subscribe |
| Resend | Transactional email (invitations, trial and billing notices) | To be verified | Only when a reviewed email sender is configured |
| Social providers (LinkedIn, Threads, Instagram) | Publishing and metrics for accounts you connect | Provider’s own | Only through your own OAuth grant |
| Vercel AI Gateway and the selected model provider; configured CLI provider | Drafting posts and reply suggestions from the instruction and permitted context | Provider route and contract to be verified | Cloud routes require the applicable consent; deterministic preview makes no model call |
| Exa (exa.ai) | Web search for facts when you ask for research: receives a search query derived from your message, never your sources, memory files or drafts | To be verified for release | Only after the workspace owner turns web research on |
| Jina Reader (r.jina.ai) | Fetches the public pages found by that search, or a page whose link you paste, as plain text | To be verified for release | Only after the workspace owner turns web research on |
8. Your rights
Wherever you live, you can exercise these from the app (Account → Privacy & data) or by emailing us:
- Export your workspace (drafts, sources, approvals, receipts) with a receipt
- Disconnect any provider at any time
- Retract or delete any source
- Delete your account and workspace
- Request a sanitised diagnostics package — only with your explicit consent
Deleting your account removes your workspace and media; content-free receipts may survive as tombstones where audit rules require it. The full procedure is on the data deletion page. If you are in the EEA, UK or Switzerland you also have the right to lodge a complaint with your supervisory authority.
9. International transfers
Database, storage and authentication use the configured Supabase project; API functions run on Vercel. Actual processing regions and any international transfers must be confirmed for the release environment. [Transfer mechanism (for example Standard Contractual Clauses) — to be confirmed by counsel.]
10. Security
Row-level security on every workspace table, application-layer encryption of provider tokens with a server-held key, minimum OAuth scopes, session revocation, step-up authentication for sensitive actions, and a content-free audit log. Details are on the security page.
11. Children
Rafii is not directed at anyone under 18 and we do not knowingly collect data from them.
12. Changes
We will post changes here with a new “last updated” date and, for material changes, email account holders before they take effect.
13. Contact
Privacy questions and requests: privacy@postriff.app.