Privacy Policy
Effective date: 5 June 2026 · Last updated: 5 June 2026
This policy explains what personal data we collect when you use Riposte, why we collect it,
who we share it with, and the rights you have over it. We keep it as short as we can while
still covering what the law — and you — deserve to know.
1.Who we are
Riposte is operated by Jakub Gierasimiuk, a sole proprietor
(jednoosobowa działalność gospodarcza) registered in Poland (“we”, “us”, “our”).
You can reach us at the addresses listed in section 13.
For the purposes of the EU General Data Protection Regulation (“GDPR”) and the UK GDPR,
Jakub Gierasimiuk is the data controller of the personal data described
below.
2.What we collect
Data you give us directly
- Email address — required to create and identify your account (handled via Firebase Authentication).
- Password — hashed by Firebase; we never see or store it in plain text.
- Display preferences — optional in-app settings that personalise your experience.
- Saved ripostes and optional private notes — the lines you save to your personal “Stash”, plus any note you attach to them.
We do not collect your real name, phone number, home address, or any government ID. Your email
is the only personal identifier we require.
Data generated by your use of the app
- Session data — which features you used, when, and for how long.
- Saved ripostes — the text of every line you save, with its optional note, source label, and tone tag.
- Swipe ratings (Cuts) — your keep / skip decisions on Daily Killer ripostes in the Cuts deck, used to rank lines and to build your “Liked” collection.
- SOS request inputs — the verbal attack you paste in for AI-generated comeback suggestions, plus any optional situation / who / where context.
- Sparring session results — your responses in mock-conversation practice and the AI persona’s reactions.
- Reviews activity — your spaced-repetition ratings (“Again”, “Good”, “Nailed”) on saved ripostes.
- Embeddings of your saved ripostes — a numeric “fingerprint” of each saved line, generated by an embedding model, used to surface relevant lines next time you paste a similar attack into SOS.
- Subscription status — whether you are on a free, trial, or paid plan.
- Voice input — audio captured during voice-to-text mode is transcribed on your device by your operating system and is never uploaded; only the resulting text is sent to us (see section 4).
Device & technical data (collected automatically)
- Device type and operating-system version, application version, language preference.
- Error and crash logs (these do not include your training input).
- IP address (used transiently for security, rate limiting, and fraud prevention).
We do not use advertising identifiers (IDFA / GAID). We do not track you across other apps or
websites.
Age. Riposte is intended for users 18 years of age or older —
the app contains verbal-conflict scenarios that are not appropriate for minors. We do not
knowingly collect data from anyone under 18. If you believe a minor has created an account,
contact us and we will delete it.
3.How we use your data & why
| Purpose | Legal basis (GDPR Art. 6) |
| Providing the app and its features (auth, sessions, saving, AI suggestions) |
Contract performance (Art. 6(1)(b)) |
| Processing payments and managing subscriptions |
Contract performance (Art. 6(1)(b)) |
| Sending transactional emails (e.g. password reset) |
Contract performance (Art. 6(1)(b)) |
| Improving app stability and fixing bugs |
Legitimate interests (Art. 6(1)(f)) |
| Security, fraud prevention, rate limiting |
Legitimate interests (Art. 6(1)(f)) |
| Complying with legal obligations (tax, consumer rights, law-enforcement requests) |
Legal obligation (Art. 6(1)(c)) |
We do not sell your data. We do not use it for third-party advertising, and we
do not train our own foundation models on your input.
4.AI processing — how it works
Riposte uses artificial intelligence (large language models) to generate comeback suggestions,
evaluate your Sparring responses, and surface lines you’ve already saved that match a new
attack. Here is exactly what happens with your text:
What you send to AI:
- The verbal attack you paste or type into SOS, including any optional situation / who / where context.
- Your typed or spoken responses during Sparring sessions.
How it is processed:
- Your input travels over an encrypted connection (HTTPS/TLS) from your device to our backend server (hosted on Railway).
- Our backend either calls OpenAI directly or routes the request through OpenRouter (an OpenAI-compatible routing layer that can dispatch to models from OpenAI, Google, or Anthropic). The default configuration uses OpenAI models.
- The AI returns a result (a comeback, an evaluation, or a similarity match) to our backend, which sends it to your device.
- What we store: for SOS we keep the attack text, the context fields, and the generated ripostes so we can show your history and so the retrieval cache (section 5) can serve repeat questions without a second AI call. For Sparring we keep your responses and the persona’s replies. For Reviews we keep the rating you give each saved line.
- What we do NOT store: the raw voice audio from your microphone is never sent to our servers — only the on-device transcript is. We never link AI inputs to advertising profiles or sell them.
Voice input specifically: audio captured via the in-app voice button is
transcribed on your device by your operating system’s speech-recognition service. Only the
resulting text transcript — not the audio — is sent to our servers for AI processing.
The AI providers we use act as data processors under our instructions. They are contractually
prohibited from using your data to train their models in a way that could identify you. We use
commercial API endpoints (not consumer chat products), so your inputs are not added to public
training corpora.
5.Who we share it with (data processors)
We use a short list of carefully selected processors, bound by data-processing agreements:
| Service | Purpose | Privacy policy |
| Firebase Auth (Google) |
Login and authentication |
firebase.google.com |
| Supabase (EU — Frankfurt) |
Database: account data, saved ripostes, swipe ratings, SOS requests, Sparring sessions, Reviews state, embeddings |
supabase.com |
| Railway (US) |
Backend application hosting |
railway.app |
| Upstash Redis (EU — Frankfurt) |
Daily-limit counters, short-lived session tokens, the SOS retrieval cache (24-hour expiry) |
upstash.com |
| OpenAI (default AI provider) |
Comeback generation, Sparring evaluation, saved-line embeddings |
openai.com |
| OpenRouter (optional routing layer) |
Routes AI requests to OpenAI / Google / Anthropic models |
openrouter.ai |
| RevenueCat (US) |
Subscription state management |
revenuecat.com |
| Apple App Store / Google Play |
Payment processing (we never see your card number) |
apple.com · google.com |
We do not share your data with any party not listed above, and we do not sell your data under
any circumstances.
International transfers
Some processors may process data outside the EEA. We rely on the European Commission’s Standard
Contractual Clauses (SCCs) and, where applicable, the EU-US Data Privacy Framework to safeguard
those transfers.
6.Where your data is stored
- Account data, saved ripostes, swipe ratings, SOS requests, Sparring sessions, Reviews state, embeddings — Supabase, EU (Frankfurt, Germany;
eu-central-1).
- Cache (daily limits, SOS retrieval cache) and short-lived session tokens — Upstash Redis, EU (Frankfurt, Germany).
- Authentication records — Firebase Auth (Google Cloud).
- Backend processing — Railway.
7.How long we keep it
- Account data (email, preferences) — until you delete your account.
- Saved ripostes, private notes, swipe ratings, and embeddings — until you delete the saved line, or until you delete your account.
- Sparring history, Reviews state, and SOS request history — until you delete your account.
- SOS retrieval cache — 24 hours, then automatically expires.
- Voice audio — not retained; transcription happens on your device and is never uploaded.
- Payment and subscription records — up to 7 years, as required by Polish accounting law.
- Server logs (IP, error logs) — 90 days, then automatically deleted.
- Deleted account data — permanently removed within 30 days of the deletion request.
8.Your rights
Under GDPR and equivalent laws, you can:
- Access — request a copy of the personal data we hold about you.
- Correct — ask us to fix inaccurate data.
- Erase — delete your account and all associated data, in-app from Settings → Account → Delete Account, or by writing to us.
- Restrict or object — to processing based on legitimate interest.
- Port — receive your data in a machine-readable format.
- Withdraw consent — where processing is based on consent, at any time.
-
Lodge a complaint with a supervisory authority — in Poland, the
Urząd Ochrony Danych Osobowych (uodo.gov.pl).
To exercise any of these rights, email support@getriposte.app. We reply within 30 days.
9.California privacy rights (CCPA)
If you are a California resident, you have the right to:
- Know what personal information we collect and how we use it (sections 2 and 3).
- Delete your personal information (section 8).
- Opt out of sale — we do not sell personal information, period.
- Non-discrimination — exercising your privacy rights will not change your service or pricing.
To exercise California rights, email support@getriposte.app with the subject line “CCPA Request”.
10.Children’s privacy
Riposte is intended for users 18 years of age or older. We do not knowingly
collect personal data from anyone under 18. If we become aware that a user is under 18, we will
delete their account and all associated data. If you believe a minor has created an account,
contact us at support@getriposte.app.
11.How we keep it safe
- Transport encryption (TLS 1.2+) for all traffic between the app, our backend, and our processors.
- Hashed passwords — we never store your password in plain text (handled by Firebase Auth).
- Encryption-at-rest for databases and authentication tokens (OS-level secure storage on-device).
- Least-privilege access controls; only our backend service can query user data.
- Rate limiting, input sanitisation, and HTTPS-only tokens.
No system is ever 100% secure. If a breach occurs that affects your rights, we will notify you
and the relevant supervisory authority as required by GDPR Art. 33–34.
12.Changes to this policy
If we change this policy in a way that affects you, we will notify you through the app and / or
by email at least 14 days before the change takes effect. The “effective date” at the top of
this page always reflects the current version.
13.Contact