This policy describes what Rift collects, what we do not collect, and how we handle your information. If you have questions, contact us at [email protected].
Rift collects almost nothing about you, by design. We don't ask for your email, phone, or government ID. We cannot read the plaintext content of your end-to-end encrypted direct messages. We don't hold the keys. Payments are processed by Stripe; we never see your card details. We don't store IP addresses, use behavioral tracking, or train AI on your content. The rest of this page explains the small amount of data we do handle and what we never collect.
What we collect
We collect only what is needed to operate Rift. That includes:
- Account identifiers: your username and the public key derived from your Rift Key. No email address, phone number, real name, or government ID is collected.
- Age attestation record: when you create an account, we store the date and time you confirmed that you meet our minimum age requirement (18+). This record exists solely to evidence your representation at signup; it is not used for any other purpose, is not shared with third parties, and is deleted when your account is deleted. We do not perform government ID verification.
- Profile information: display name, avatar, bio, status, and other profile fields you choose to provide are visible to other Rift users according to your privacy settings. Presence status (online, idle, do not disturb) is ephemeral and not permanently stored.
- Shard channel content: messages and media you post in Shard (community) channels are stored so members can see them. This content is encrypted at rest on our servers but is not end-to-end encrypted, since community channels require server-side delivery to multiple members.
- End-to-end encrypted direct messages: DM text payloads are encrypted on your device using the
Signal-style X3DH/Double Ratchet model (AES-256-GCM) before they leave. We
store only ciphertext. We cannot read the plaintext content of your E2EE DMs.
We do store routing metadata for DMs: who the participants are, when messages were sent, and delivery state, but not what the messages say. DM attachments (images, files) are encrypted at rest but are not currently end-to-end encrypted. - No stored IP addresses. All traffic to Rift is proxied through Cloudflare, which receives standard network metadata (IP addresses, request headers) as a routine part of routing traffic to our servers, governed by Cloudflare's privacy policy. Our backend never persists IP addresses. For abuse prevention and rate limiting we derive a one-way HMAC fingerprint from the connecting address using a salt that rotates daily and is destroyed within seven days. After rotation, the fingerprint can no longer be correlated to any IP, including by us. We do not maintain IP-to-account mappings, do not use IP data for advertising or behavioral profiling, and cannot identify users by IP address in response to law enforcement requests. Some abuse controls are keyed by account ID instead and never touch network metadata at all.
- Third-party connections: if you connect external services (such as Spotify or Twitch) to your profile, we store the OAuth tokens and provider display name needed to maintain the integration. You can disconnect these at any time.
How we use your information
We use the limited data we collect only to:
- Provide and operate Rift (including routing messages, hosting Shards, ephemeral lobbies, and voice).
- Enforce our Terms of Service and keep the platform safe (e.g., detecting CSAM or abuse).
- Comply with legal obligations.
- Improve the service, using only aggregate metrics (for example, total daily message counts or feature usage rates) that are never tied to individual accounts or identities.
We do not use your data for advertising, behavioral profiling, or sale to third parties.
How we share your information
We do not sell your personal data or share it for marketing or advertising.
We share the minimum necessary with trusted subprocessors under contracts that require them to protect your data at the same standard we do:
- Cloudflare: all traffic to Rift is proxied through Cloudflare's network for DDoS protection, application security, and content delivery. Cloudflare receives network metadata (IP addresses, request headers) as a routine part of routing traffic to our servers; this is governed by Cloudflare's own privacy policy. Cloudflare also provides our object storage (R2) for media uploads.
- Stripe: payment processing for paid subscriptions (see Payments below). Stripe collects and processes your payment details on its own infrastructure; Rift never sees them.
Our real-time voice and video infrastructure is built on open-source software that we self-host and operate entirely on our own servers. No third-party company receives or processes voice or video data on Rift's behalf.
We may also disclose information when required by law or to protect user safety (see Law enforcement below). We provide notice where legally permitted.
What we do not collect
Rift is not built to monetize your behavior. We do not:
- Run behavioral tracking or build advertising profiles from your activity.
- Embed third-party analytics in the application that follow you across sessions for marketing purposes.
- Sell your personal data.
- Collect or store your precise location or GPS coordinates.
- Use your messages, media, or profile data to train machine learning or AI models.
- Require an email address, phone number, or government ID to create an account.
- Respond differently to browser Do Not Track or Global Privacy Control (GPC) signals. We do not track you in the first place.
The public marketing website uses privacy-respecting, first-party analytics: aggregate page views with no cookies, no fingerprinting, and no stored IP addresses. The Rift app itself contains no analytics or tracking.
Children's privacy
Rift is strictly intended for individuals aged 18 and older. We do not knowingly collect or solicit personal information from anyone under the age of 18. Separately, consistent with the U.S. Children's Online Privacy Protection Act (COPPA), we do not knowingly collect personal information from children under 13 as defined by COPPA.
Rift is designed for adults. No marketing, content, design choices, or features are directed at, designed for, or intended to attract children, and the service does not target users under the age of 18.
If we learn that we have inadvertently collected personal information from a person under 18, we will terminate their account and delete associated data as quickly as possible, subject to any legal obligations such as mandatory CSAM reporting. If you believe that a child under 13 or a person under 18 has created an account, please contact us at [email protected].
Non-consensual intimate imagery (NCII)
In compliance with the TAKE IT DOWN Act, we provide a process for the removal of non-consensual intimate imagery. If you find imagery of yourself posted without your consent, contact [email protected]. We will review and, if verified, remove such content within 48 hours of a valid request.
How data is stored
We use industry-standard protections, including encryption at rest for data we control. Media files are stored using Cloudflare R2 and delivered via CDN with short-lived signed URLs, so your IP is never exposed to the storage origin. EXIF metadata is automatically stripped from uploaded images before storage.
When you upload a file, the content is processed and written to storage at the network edge. Our application servers authorize the transfer and record the file reference, but do not receive or handle the file bytes themselves. This means our central infrastructure has no mechanism to log, inspect, or build behavioral profiles from the content of what you share. We store what's needed to deliver your file. Not a shadow record of it.
When messages contain links, our servers fetch the preview metadata and proxy the preview images so your IP address is never sent to the linked site.
We are based in the United States and use global infrastructure. Your data may be processed and stored in the U.S. or other jurisdictions. Where required, we rely on standard contractual clauses or equivalent safeguards for international transfers.
Data retention
We retain information only as long as needed to provide the service, comply with law, resolve disputes, and enforce our agreements. When you delete content or your account, we delete or anonymize associated data within 30 days, subject to legal holds and backup cycles. When you delete a message, it is permanently purged from the database. It is not soft deleted or hidden.
Ephemeral Rift Lobby rooms and their content are automatically and permanently deleted when the room dissolves (typically after 30 minutes of creation).
Law enforcement and legal requests
We prioritize user privacy, but we will comply with valid legal process (such as subpoenas or court orders) when required by law. We review requests for validity and push back on requests we believe are overbroad where possible.
- What we can provide: account creation date, username, metadata for Shard channels, and the limited routing metadata we hold for direct messages (such as participants, timestamps, and delivery state). We do not have the content of those messages.
- What we cannot provide: we cannot provide the plaintext content of end-to-end encrypted direct messages, as we do not hold the decryption keys. We also cannot identify users by IP address; we do not retain IP-to-account mappings, and the daily fingerprint salts that transiently correlate them are automatically destroyed within seven days of creation.
- Emergency disclosure: we may disclose information to authorities if we have a good-faith belief that there is an imminent threat of death or serious physical injury.
Where legally permitted, we will attempt to notify affected users before complying with a request.
Your rights
We provide the same high standard of privacy to all users regardless of location. Depending on where you live, you may have additional rights under laws such as the EU General Data Protection Regulation (GDPR) or the California Consumer Privacy Act (CCPA), including the right to access, correct, delete, or export personal data we hold.
You can request account or data deletion and data export by contacting [email protected]. We will respond in line with applicable law.
If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local data protection supervisory authority (for example, your national data protection authority in the EEA, or the Information Commissioner's Office in the UK). We would welcome the chance to address your concern directly first, but you may contact a supervisory authority at any time.
For the purposes of applicable data protection law, we process your data on the following bases: contractual necessity (to provide the service), legitimate interests (security and abuse prevention), legal obligation (e.g., CSAM reporting), and consent (optional data you choose to provide, such as third-party service connections).
Cookies
For the Rift web application, we use cookies and similar technologies primarily to keep you signed in (for example, carrying an authentication JWT). We do not use cookies to sell your data or build cross-site ad profiles within the app.
Payments
Payments are processed exclusively by Stripe, Inc. When you upgrade, you are redirected to Stripe's hosted checkout, where your payment information is collected and processed entirely on Stripe's systems. Rift never receives or stores your payment card information, billing address, or financial identity. We retain only an opaque Stripe customer token and your subscription state (active, past due, cancelled, billing period dates). Stripe's privacy policy governs their handling of your payment data: https://stripe.com/privacy.
Security
We take security seriously. If you discover a vulnerability, please report it to [email protected].
In the event of a data breach affecting your personal information, we will notify affected users and relevant authorities as required by applicable law.
Changes to this policy
We may update this policy from time to time. If we make material changes, we will notify you via a notice within the Rift application. Your continued use of Rift after changes take effect constitutes acknowledgment of the updated policy. The "Last updated" date at the top reflects the most recent revision.
Contact
Rift is operated by Rift Communications LLC, a Wyoming (USA) limited liability company, which is the data controller for the personal data described in this policy.
For privacy requests and questions: [email protected]