Last updated July 27, 2026
Privacy Policy
Riidact exists to keep sensitive information on your device, so this policy is short and concrete: what runs locally, the little we store when you have an account, and how to erase all of it.
The short version
- Everything you type is checked on your device. The text, the files you attach, and the screenshots you paste are scanned locally and never sent to us.
- Without an account, nothing is sent at all. The extension runs entirely locally and sends no telemetry of any kind. Syncing starts only when you link the extension to an account, or your organisation enrolls your browser through managed settings.
- With an account or an enrolled device, only receipts sync. When something is caught, the record that reaches the dashboard is metadata: time, site, category, severity, action, and rule id. Never the text itself.
- Deletion is real deletion. Events expire on your retention schedule, and deleting your account erases everything, including your sign-in and billing profile.
What runs on your device
All detection happens inside the browser extension on your machine: the built-in pattern rules, the checksum validators, the on-device language model, and the file and image scanning (including OCR). Detection models are downloaded to your device and run there. Your message content, attachments, and the pages you visit are never transmitted to Riidact and never leave your computer through us.
Because detection runs entirely on your device and we never see your content, we cannot confirm that any particular thing was caught or redacted. Detection is best-effort: it can miss sensitive information or flag harmless text, so always review a message before you send it. The Terms of Service set out the full disclaimer.
What we store when you have an account
Creating an account, or having your organisation enroll your device, stores the minimum needed to run the service:
- Account details. Your email address and, if you sign in with Google, Apple, Facebook, or Microsoft, the identity reference those providers give us for sign-in. We do not receive your passwords for those services.
- Your rules. The watchlist rules you write, so they can sync to your devices (and to your team, if you share them).
- Linked devices.A name like "Chrome on macOS", a hashed link token (we store only the hash), and when the device last synced. For devices enrolled by an organisation, the name can be a label your IT team sets.
- Catch receipts. For each catch: timestamp, site, category, severity, action taken, and the rule id. That is the whole record.
- Team records. If you create or join a team: membership, invites, and a change log of who edited shared rules and settings.
What we never collect
- The text you type, anywhere, ever.
- The contents of your files, images, or screenshots.
- Your browsing history or the contents of pages you visit.
- Anything for advertising. We show no ads, run no ad trackers, and sell no data.
Teams and visibility
On a team, the owner can see members' catch receipts (the metadata above) in the team dashboard. The same applies when your organisation enrolls your browser through managed settings: the receipts from that device sync to the organisation's team dashboard. Teams can switch on aggregation, which strips member attribution before storage so the dashboard shows team-level counts only. Personal rules stay private to their author: teammates and owners cannot read them. If you leave a team, your personal rules travel with you.
Retention and deletion
Catch receipts expire automatically after your retention window (30 days to 2 years, set in Settings) and are then deleted from the dashboard and exports. Deleting your account removes your rules, devices, receipts, sign-in identity, and billing profile. These are hard deletes, not soft flags.
Billing
Payments are processed by Stripe. Your card details go directly to Stripe and never touch our servers; we keep a customer reference and the subscription records needed to run your plan. Deleting your account also deletes your billing profile with the payment processor.
Service providers
We use a small number of providers to run the service:
- Supabase hosts our database and authentication.
- Stripe processes payments and stores payment details.
- Resend delivers our emails, such as sign-up confirmations and team invites, and receives the recipient address and message for each send.
- Google, Apple, Facebook, and Microsoft handle sign-in only if you choose to sign in with them.
Each receives only what its role requires. None of them receive the content you type.
Security
Device link tokens are stored as hashes, access to workspace data is scoped per account and team at the database layer, and the extension only runs on sites you point it at. No system is perfectly secure, but the design keeps the most sensitive data, your actual words, off our servers entirely.
Changes and contact
If this policy changes in a way that matters, we will note it here and in the dashboard before it takes effect. Questions or requests, including data deletion, reach us at support@riidact.com.