Riposte

Privacy Policy

Effective date: 5 June 2026 · Last updated: 5 June 2026

This policy explains what personal data we collect when you use Riposte, why we collect it, who we share it with, and the rights you have over it. We keep it as short as we can while still covering what the law — and you — deserve to know.

1.Who we are

Riposte is operated by Jakub Gierasimiuk, a sole proprietor (jednoosobowa działalność gospodarcza) registered in Poland (“we”, “us”, “our”). You can reach us at the addresses listed in section 13.

For the purposes of the EU General Data Protection Regulation (“GDPR”) and the UK GDPR, Jakub Gierasimiuk is the data controller of the personal data described below.

2.What we collect

Data you give us directly

We do not collect your real name, phone number, home address, or any government ID. Your email is the only personal identifier we require.

Data generated by your use of the app

Device & technical data (collected automatically)

We do not use advertising identifiers (IDFA / GAID). We do not track you across other apps or websites.

Age. Riposte is intended for users 18 years of age or older — the app contains verbal-conflict scenarios that are not appropriate for minors. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us and we will delete it.

3.How we use your data & why

PurposeLegal basis (GDPR Art. 6)
Providing the app and its features (auth, sessions, saving, AI suggestions) Contract performance (Art. 6(1)(b))
Processing payments and managing subscriptions Contract performance (Art. 6(1)(b))
Sending transactional emails (e.g. password reset) Contract performance (Art. 6(1)(b))
Improving app stability and fixing bugs Legitimate interests (Art. 6(1)(f))
Security, fraud prevention, rate limiting Legitimate interests (Art. 6(1)(f))
Complying with legal obligations (tax, consumer rights, law-enforcement requests) Legal obligation (Art. 6(1)(c))

We do not sell your data. We do not use it for third-party advertising, and we do not train our own foundation models on your input.

4.AI processing — how it works

Riposte uses artificial intelligence (large language models) to generate comeback suggestions, evaluate your Sparring responses, and surface lines you’ve already saved that match a new attack. Here is exactly what happens with your text:

What you send to AI:

How it is processed:

Voice input specifically: audio captured via the in-app voice button is transcribed on your device by your operating system’s speech-recognition service. Only the resulting text transcript — not the audio — is sent to our servers for AI processing.

The AI providers we use act as data processors under our instructions. They are contractually prohibited from using your data to train their models in a way that could identify you. We use commercial API endpoints (not consumer chat products), so your inputs are not added to public training corpora.

5.Who we share it with (data processors)

We use a short list of carefully selected processors, bound by data-processing agreements:

ServicePurposePrivacy policy
Firebase Auth (Google) Login and authentication firebase.google.com
Supabase (EU — Frankfurt) Database: account data, saved ripostes, swipe ratings, SOS requests, Sparring sessions, Reviews state, embeddings supabase.com
Railway (US) Backend application hosting railway.app
Upstash Redis (EU — Frankfurt) Daily-limit counters, short-lived session tokens, the SOS retrieval cache (24-hour expiry) upstash.com
OpenAI (default AI provider) Comeback generation, Sparring evaluation, saved-line embeddings openai.com
OpenRouter (optional routing layer) Routes AI requests to OpenAI / Google / Anthropic models openrouter.ai
RevenueCat (US) Subscription state management revenuecat.com
Apple App Store / Google Play Payment processing (we never see your card number) apple.com · google.com

We do not share your data with any party not listed above, and we do not sell your data under any circumstances.

International transfers

Some processors may process data outside the EEA. We rely on the European Commission’s Standard Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework to safeguard those transfers.

6.Where your data is stored

7.How long we keep it

8.Your rights

Under GDPR and equivalent laws, you can:

To exercise any of these rights, email support@getriposte.app. We reply within 30 days.

9.California privacy rights (CCPA)

If you are a California resident, you have the right to:

To exercise California rights, email support@getriposte.app with the subject line “CCPA Request”.

10.Children’s privacy

Riposte is intended for users 18 years of age or older. We do not knowingly collect personal data from anyone under 18. If we become aware that a user is under 18, we will delete their account and all associated data. If you believe a minor has created an account, contact us at support@getriposte.app.

11.How we keep it safe

No system is ever 100% secure. If a breach occurs that affects your rights, we will notify you and the relevant supervisory authority as required by GDPR Art. 33–34.

12.Changes to this policy

If we change this policy in a way that affects you, we will notify you through the app and / or by email at least 14 days before the change takes effect. The “effective date” at the top of this page always reflects the current version.

13.Contact

Jakub Gierasimiuk (sole proprietorship registered in Poland)

NIP (tax ID): 5422866210

Privacy & general enquiries: support@getriposte.app

Website: getriposte.app