Privacy Policy

Last updated: 3 October 2026

This policy explains how personal data is handled when you use Ripledd — both the website ripledd.com (the waitlist, the information and support pages, the internal admin area, and the read-only web viewer of public Ripledd content) and the Ripledd mobile app for iOS and Android. It is written to meet the EU General Data Protection Regulation (GDPR) and the ePrivacy rules on cookies.

The Ripledd mobile app is in closed testing (Apple TestFlight and Google Play testing) and is only available to invited testers. This policy already covers it in full. Some app features may still change before public launch.

On this page

1. Who is responsible

Ripledd is operated by an individual (a natural person) established in the European Union. That person is the "data controller" for the processing described here.

Controller: Elias Kofler, operating as "Ripledd". Contact for privacy matters and to exercise your rights: [email protected]. For content and abuse reports: [email protected]. A postal contact address is available on request.

We have not appointed a Data Protection Officer or an Art. 27 representative because we are not legally required to; the contact above reaches the person responsible.

2. What this policy covers

  • The website (ripledd.com): the waitlist, the information pages, the support form, the staff-only /admin area, and the anonymous read-only web viewer served at /app, /home, /post/… and /@handle.
  • The mobile app: the account-based iOS/Android client, where you sign in, build a profile, post images and text, follow people, and receive notifications.

Where a section applies to only one of the two, it says so.

3. What we collect and why

3.1 Website — joining the waitlist

When you submit the waitlist form we collect your email address, your device preference (iOS or Android), and the date and queue position assigned to you.

  • Purpose: to email you when Ripledd opens, and to understand demand.
  • Legal basis: your consent, given when you submit the form (Art. 6(1)(a) GDPR). You can withdraw it at any time — use the unsubscribe link in any waitlist email or write to [email protected] — without affecting processing done before you withdrew.

3.2 Website — contacting support

The support form collects your name, email address, an optional Ripledd handle, the topic you pick (report / technical / other), and the message you write. Please don't include special-category data (health, beliefs, and so on) or passwords and payment details in the message.

  • Purpose: to receive, answer, and keep a record of your request.
  • Legal basis: our legitimate interest in running a support function and answering people who contact us (Art. 6(1)(f) GDPR); where your request relates to a pre-contractual step, Art. 6(1)(b) also applies.

3.3 Website — browsing the web viewer

The viewer is read-only and anonymous — there is no account and no sign-in. When your browser loads content, requests go to our API ("ripledd-gateway"), which we self-host and expose to the internet through a Cloudflare tunnel. That server records standard technical log data: IP address, user-agent string, timestamp, and the resource requested; Cloudflare, as the proxy in front of it, processes the same connection data in transit (see section 6).

  • Purpose: to deliver the content you asked for, keep the service secure (abuse and rate-limit protection), and diagnose faults.
  • Legal basis: our legitimate interest in operating, securing, and maintaining the service (Art. 6(1)(f) GDPR).

3.4 Website — content shown in the viewer

Posts, images, handles, and profile details displayed in the viewer are published by Ripledd users and hosted on our infrastructure (see section 6). If content in the viewer is about you and you want it removed, contact [email protected] or [email protected].

3.5 Website — the internal admin area

/admin is staff-only. It is gated by a password and then a sign-in through Supabase Auth (Google, Apple, or email code), which processes the signing-in person's email, name, profile picture, and authentication tokens. Legal basis: our legitimate interest in securing internal tooling (Art. 6(1)(f) GDPR).

3.6 App — account and sign-in

You create an account with email and a password, or with Sign in with Google or Sign in with Apple.

  • Email sign-up: we store your email address and a securely hashed password (hashing is done by Supabase Auth — we never see the plain password). A 6-digit code is emailed to confirm the address. Before you enter a password, the app checks whether an email already has an account so it can send you to the right screen (sign in vs create account).
  • Google: we receive your email address, name, profile picture, and a Google account identifier.
  • Apple: we receive your name (only on the very first authorisation) and either your real email or Apple's private relay email, plus an Apple user identifier.
  • Sessions: after sign-in, authentication tokens (a JWT access token and a refresh token) are stored on your device. If you add more than one account to the in-app account switcher, each account's refresh token and a little profile chrome (name, handle, avatar URL) are kept in your device's storage so you can switch between them (up to six).

Purpose: to create and secure your account and keep you signed in. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR); for the "does this email have an account" check, our legitimate interest in a usable sign-in flow and in limiting blind credential-stuffing (Art. 6(1)(f)).

3.7 App — your profile

Your profile holds a username / handle, a display name, an optional bio (up to 160 characters), an optional avatar image, one optional external link with a label, and public counts (followers, following, posts, likes). Your profile and these fields are public — visible in the app and in the website's read-only viewer at /@handle.

Purpose: to give you an identity other people can find and follow. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).

3.8 App — content you create

When you post, we process the images you choose, any text / caption or "thought", comments and replies, and @-mentions of other users.

  • Images you pick are uploaded to our API and re-encoded server-side into three JPEG sizes (thumbnail, medium, full). Re-encoding removes embedded file metadata, including camera EXIF data and any GPS location tags — we do not read, keep, or attach that data.
  • Finished images are stored in Cloudflare R2 object storage and delivered through a CDN (cdn.ripledd.com). Anything you post publicly is public: it can be viewed in the app and on the website by its public URL (ripledd.com/post/…), and other users can reply to it.
  • Text-only "thoughts" and comments skip the image steps.

Purpose: to store, display, and distribute the content you publish. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).

3.9 App — follows, likes, bookmarks

We record who you follow, the posts you like, and the posts you bookmark (bookmarks are private to you). Follows and likes are visible to others as counts and, for follows, as connection lists.

Purpose: to build your feed, show interaction counts, and let people see their followers. Legal basis: performance of our contract with you (Art. 6(1)(b) GDPR).

3.9.1 App — blocking and abuse reports

When you block an account, we store your account ID, the blocked account ID, the time of the block, and, if applicable, the source post or comment ID. We use this relationship to hide content, prevent interactions, remove existing follows, and manage your blocked-users list. A copy of your safety settings is cached on your device to keep blocked content hidden when offline.

Blocking also creates a private support/moderation report containing the reporter’s account ID, name and handle, the blocked account’s ID and handle, and the source content ID when provided. Reporting a post or comment similarly identifies the reporter and content, and includes the reporter’s account email if available. These records are available to Ripledd for abuse review; we do not send a block notification to the blocked account or publish your blocked-users list.

Purpose and legal basis: providing account safety controls as part of our service (Art. 6(1)(b) GDPR) and our legitimate interests in investigating abuse and protecting users (Art. 6(1)(f) GDPR). Blocks remain until you unblock the account or either account is deleted. Moderation reports follow the support request retention period in section 8; unblocking does not withdraw a report.

3.10 App — search and automated image understanding

To power search, every post's image(s) and caption are processed by our own CLIP model (running on the self-hosted "ripledd-inference" service) to produce numeric vector embeddings. The embeddings, plus each image's pixel dimensions, are stored alongside the post. When you run a search, the text you type is sent to our API and turned into a vector so it can be compared against post vectors; search text is not stored beyond ordinary server logs. Recent searches are kept only on your device.

There is no third-party AI provider involved and this processing does not make any decision that has a legal or similarly significant effect on you.

Purpose: semantic and similarity search of public posts. Legal basis: performance of our contract with you and our legitimate interest in a useful search feature (Art. 6(1)(b) and (f) GDPR).

3.11 App — post views

While you are signed in, opening a post records a view: the post ID, your user ID, which screen it was seen on (feed, detail, or thought), the carousel slide index, and a timestamp. Views are rate-limited to one per post per minute and capped at 100 per post per user. They drive the public view count on a post.

Purpose: to show creators how much reach a post has. Legal basis: our legitimate interest in basic post analytics for creators (Art. 6(1)(f) GDPR).

3.12 App — notifications and push

When someone likes, comments on, replies to, follows, or @-mentions you, we create a notification record (type, who did it, which post, read state, timestamps). You can turn each category on or off in settings; those preferences are stored server-side.

If you grant the OS notification permission, we register an Expo push token and your platform (iOS or Android) so we can send phone push notifications. The push token is deleted when you sign out, when you use "Reset App", or when the push provider reports it as no longer valid. A push message sent to your device contains the other person's name, a short preview of the post text, and the other person's avatar image. Push is delivered via Expo's push service and then Apple's or Google's push transport (see section 6).

Purpose: to tell you about activity involving you. Legal basis: performance of our contract with you for the in-app notification list (Art. 6(1)(b) GDPR); your device-level permission (consent) for OS push notifications, which you can withdraw at any time in your device settings or in the app.

3.13 App — device permissions

  • Photo library: requested so you can pick images to post or set an avatar. The app only reads the specific photos you select — it does not scan or index your library. On iOS, a picked photo stored in iCloud may be downloaded to a local file so it can be uploaded.
  • Notifications: requested so we can send push notifications (see 3.12).

Both permissions are optional, are asked for during onboarding (and again at the point of use), and can be declined or later changed in your device settings. The app does not request or use your location, contacts, microphone, or camera roll beyond the photos you explicitly choose.

3.14 App — data stored on your device

The app keeps a local cache to work quickly and offline: an on-device SQLite database (cached profiles, follow states, your own user row) and key–value storage (your session tokens, theme and accent choice, the onboarding-complete flag, your recent searches, a notification-badge preference, the multi-account switcher vault, and your anonymous-analytics choice). This data stays on your device; "Reset App" in Advanced settings clears all of it and signs you out.

3.15 Website and app — technical log data

Our self-hosted API ("ripledd-gateway") logs the IP address, user-agent, request path, and timestamp of requests; the self-hosted embedding service logs the calling IP for rate-limiting. The app also periodically contacts Expo's update servers to check for over-the-air JavaScript updates, which involves basic device and app-runtime information. The mobile app has no crash-reporting SDK. Its optional PostHog analytics is described separately in section 4.3 and does not capture exceptions or logs.

  • Purpose: delivering requests, security and abuse prevention, rate limiting, debugging, and shipping fixes.
  • Legal basis: our legitimate interest in operating and securing the service (Art. 6(1)(f) GDPR).

4. Analytics and advertising

Ripledd runs no advertising, on the website or in the app. There is no Google Analytics, Google AdSense, cross-site advertising, or advertising SDK. The website and mobile app use only the limited measurement tools below.

4.1 Vercel Speed Insights (website)

Every website page loads Vercel Speed Insights, which reports aggregate performance metrics (Core Web Vitals). It sets no cookies, does not build a profile, and does not identify you. Legal basis: our legitimate interest in a fast site (Art. 6(1)(f) GDPR).

4.2 PostHog (website)

PostHog analytics is off by default and starts only if you select “Allow analytics” in the website banner. The staff-only /admin area is excluded. We use PostHog Cloud EU, hosted in Frankfurt, to understand in aggregate which parts of the website are useful and where something fails.

If you consent, the website can send these deliberately coarse events:

  • the general page area viewed (for example “support”, “viewer feed”, or “privacy”), never the exact URL, handle, post ID, or query string;
  • broad navigation and call-to-action choices, such as opening the support page, an external social channel, or the “Get the app” prompt;
  • waitlist success and the selected device category, but not the email;
  • successful support-form submission and its topic category, but not the name, email, handle, or message;
  • broad viewer interactions, such as content type shared, a disabled action prompt opened, profile section selected, carousel use, audio-preview start, pagination, and coarse search-result state — never search words, profile handles, content IDs, titles, captions, or audio names; and
  • a coarse error area and error category, without exception messages, stack traces, form values, or page URLs.

PostHog receives a random anonymous identifier held only in browser memory for the current page/tab lifetime. We do not call PostHog's identify function, do not create person profiles, and do not persist its identifier in cookies, local storage, or session storage. Autocapture, session replay, heatmaps, surveys, feature flags, campaign/referrer collection, automatic page and page leave events, web-vitals capture, structured logs, network telemetry, and automatic exception capture are disabled. A final data filter removes exact URLs, referrers, identifiers, free text, and other unexpected properties before an event is sent. GeoIP enrichment is also disabled. Like any internet service, PostHog receives the IP address needed to accept the HTTPS connection. Every event carries PostHog's GeoIP-disable instruction, so the service does not add location properties derived from that address.

  • Purpose: aggregate website usage, conversion, and reliability measurement.
  • Legal basis: your consent (Art. 6(1)(a) GDPR). No PostHog request is made before consent. You can decline without losing any site feature and withdraw at any time through Analytics choices in the footer. Withdrawal stops future events and clears the in-memory identifier. We also respect the browser's Do Not Track setting.

4.3 PostHog (mobile app)

PostHog analytics in the iOS and Android app is off by default. On first use, no analytics banner interrupts the app. You can turn analytics on with the separate, unchecked Share anonymous usage analytics (optional) control in the short confirmation sheet shown only when you continue with sign-in/account creation, or later in Settings. The PostHog client is not created and makes no request unless you actively enable that control. We use the same PostHog Cloud EU project, hosted in Frankfurt, to understand aggregate feature use and improve the app.

If you consent, the app can send these deliberately coarse events:

  • an app session starting, the app returning to the foreground, and the general screen area viewed (for example “feed”, “composer”, “search”, or “settings”), never a route containing a handle, user ID, post ID, or other object ID;
  • onboarding steps and the broad sign-in method and outcome (for example email, Google, or Apple; succeeded, failed, or cancelled), never an email, account ID, token, or error message;
  • creating, deleting, reporting, or sharing a broad content type; creation may also include whether media or a music track was attached and a coarse media count (“none”, “one”, or “multiple”), never the image, caption, comment, title, track, content ID, or recipient;
  • interaction categories and state, such as like/bookmark on or off, follow or unfollow, opening comments, block or unblock, and opening a notification by its broad type — never the affected account or content;
  • search area and a result-count range, never the search words, results, handles, or content IDs;
  • the profile field edited (for example “bio” or “avatar”), never its old or new value; and
  • coarse app choices such as notification category on/off, theme or navigation preference, and whether audio started from content or a profile track, never a device push token, track ID, or track title.

PostHog receives a fresh random anonymous identifier held only in app memory for the current app process. It is not your Ripledd account ID and is not persisted across app launches. We never call PostHog's identify function and never send names, emails, handles, authentication tokens, profile values, content, search text, object IDs, push tokens, or precise device details. The only basic app context allowed is the app version, operating-system family, and analytics-library version.

Person profiles, persistent analytics identifiers, automatic touch and screen capture, automatic lifecycle capture, session replay, surveys, feature flags, push-token capture, structured logs, console capture, network telemetry, and automatic exception/crash capture are disabled. A final event-and-property allowlist drops any unapproved event or field before sending it. GeoIP enrichment is disabled. Like any internet service, PostHog receives the IP address needed to accept the HTTPS connection. Every event carries PostHog's GeoIP-disable instruction, so the service does not add location properties derived from that address.

  • Purpose: aggregate app usage and feature adoption measurement.
  • Legal basis: your consent (Art. 6(1)(a) GDPR). No PostHog request is made before consent. Declining does not remove any app feature. You can withdraw or grant consent at any time through the optional analytics checkbox in the sign-in/account-creation confirmation sheet or under Settings → Advanced → Anonymous Analytics. Withdrawal stops future events and clears the in-memory identifier.

5. Cookies and local storage

CategoryExamplesSet whenLifetime
Strictly necessary (website)Your theme choice (browser local storage, not cookies); Supabase auth session (only on /admin); hosting/load-balancing cookies from Vercel.Always — the site needs them.Session to ~1 year.
Analytics choice (website)Your “allow” or “decline” selection, its date, and policy version in browser local storage; it contains no account or analytics identifier.When you make a choice.Up to 6 months, then we ask again; removable sooner through browser storage controls.
Analytics choice (app)Your “allow” or “decline” selection, its date, and policy version in device key–value storage; it contains no account or analytics identifier.When you make a choice.Up to 6 months; removable sooner from the sign-in/account-creation confirmation sheet, Settings → Advanced, or with “Reset App”.
App device storageSession tokens, theme, onboarding flag, recent searches, notification-badge preference, multi-account vault, SQLite cache.On the app while signed in / in use.Until you clear it, use "Reset App", or uninstall.

The website sets no analytics or advertising cookies. PostHog has no persistent analytics identifier on either surface; the website banner and app store only the necessary record of your choice. The mobile app uses your device's own storage, not cookies, so a browser cookie banner is not relevant inside the native app; its separate optional analytics controls serve that choice.

6. Who we share data with

The API (ripledd-gateway) and the embedding service (ripledd-inference) run on hardware we operate ourselves in Austria; they are not outsourced to a hosting provider. Apart from that, we do not sell personal data and share it only with the service providers below — each acting as our processor under a data-processing agreement — or where the law requires disclosure.

ProviderWhat it does for usLocation
SupabasePostgreSQL database (accounts, profiles, posts, media references, social graph, notifications, push tokens, view records, support and waitlist records, embeddings), authentication, transactional email (verification and password-reset codes), and realtime updates.Data hosted in Supabase's Central EU region (Frankfurt, Germany).
CloudflareObject storage (R2) for images and avatars; CDN delivery of media; Cloudflare Tunnel, DNS, and bot/DDoS protection in front of the self-hosted API.Cloudflare global network; company in the USA.
Expo (Expo Application Services)Over-the-air app updates, and relaying push notifications from us to Apple/Google push transport.USA.
Apple"Sign in with Apple"; app distribution via TestFlight/App Store; Apple Push Notification service.USA / Ireland.
Google"Sign in with Google"; app distribution via Google Play; Firebase Cloud Messaging push transport.Google Ireland Ltd. (EU) and Google LLC (USA).
VercelHosting and CDN for the website; Speed Insights performance metrics.Global edge network; company in the USA.
PostHogConsent-based, anonymous website and mobile-app event analytics with person profiles and persistent analytics identifiers disabled.PostHog Cloud EU, Frankfurt, Germany.

We may also disclose data if required by law, to enforce our Terms, or to protect the rights, safety, and security of Ripledd, our users, or the public — including reporting content that sexualises minors to the competent authorities.

7. International transfers

Some providers are established outside the European Economic Area, mainly in the United States (Cloudflare, Expo, Vercel, Google, Apple). PostHog analytics data is sent to its EU Cloud region in Germany. Where other data is transferred there, it is protected by the EU–US Data Privacy Framework (for certified recipients) and/or the European Commission's Standard Contractual Clauses, together with additional technical and organisational safeguards. You can ask us for a copy of the relevant safeguard.

8. How long we keep data

  • Account and profile: until you delete your account (see section 9).
  • Posts, images, captions, comments, and their embeddings: until you delete them or your account. Deleting a post removes the database rows immediately; the stored image files are purged on a short cycle and may persist briefly in CDN caches and routine backups.
  • Blocks: until you unblock or either account is deleted; related moderation reports follow the support-request retention period below.
  • Follows, likes, bookmarks: until you undo them or delete your account.
  • Notifications: on a rolling window of up to about 12 months, then pruned; an emptied placeholder row may be kept for like entries to enforce push cool-downs.
  • Push tokens: until you sign out, use "Reset App", or the token becomes invalid.
  • Post-view records: up to about 12 months, then aggregated or deleted.
  • Support requests: up to 24 months after the request is resolved, then deleted or anonymised.
  • Server and API logs: normally 30–90 days, then rotated and deleted, unless an entry is needed longer to investigate an incident.
  • PostHog analytics: anonymous website and app events for no longer than 12 months, then deleted; no persistent visitor or user profile is created. The local consent choice expires after 6 months.
  • Waitlist entries: until Ripledd launches plus a short transition period, or until you ask to be removed — whichever comes first.
  • On-device data: until you clear it, use "Reset App", or uninstall.

9. Deleting your account

You can delete your account in Settings → Danger Zone → Delete Account. This removes your account and associated profile, posts, comments, likes, bookmarks, follows, blocks, notifications, push tokens, and embeddings. Stored media may remain briefly in CDN caches or routine backups. Limited support and moderation records may be retained for abuse investigations and according to section 8.

You can also request deletion by emailing [email protected] from the account’s email address (or providing your handle). We respond to deletion requests within 30 days, subject to applicable legal retention requirements.

Signing out, or using "Reset App" in Settings → Danger Zone, only clears data from your device — it does not delete your account or your content.

To have a waitlist entry, support records, or analytics data deleted, email the same address. Because analytics uses only a short-lived anonymous identifier and no account details, we may be unable to locate a past event as yours; turning analytics off always stops future collection.

10. Your rights

Under the GDPR you have the right to:

  • access the personal data we hold about you, and get a copy;
  • have inaccurate data corrected;
  • have your data erased;
  • restrict processing, or object to it — including to any processing we base on legitimate interests, and at any time to direct marketing;
  • receive data you gave us in a portable, machine-readable format;
  • withdraw consent at any time, without affecting processing carried out beforehand.

To exercise any of these, email [email protected]. We reply within one month. You also have the right to complain to your local data protection authority — for EEA authorities see edpb.europa.eu.

11. Children

Ripledd is not directed at people under 16 (or the higher digital-consent age set by your country, where applicable). We do not knowingly process the personal data of children below that age. If you believe a child has given us data, contact [email protected] and we will delete it.

12. Security

We use transport encryption (HTTPS) everywhere, signed-token (JWT) authentication, password hashing handled by Supabase Auth, per-user scoping of stored files, rate limiting, and access controls on our self-hosted infrastructure. Our backend embedding service is reachable only from our own API, protected by a shared secret and network isolation. No method of transmission or storage is completely secure, but we take reasonable steps to protect your data and to notify you and the authorities of a breach where the law requires.

13. Changes to this policy

We may update this policy. We will change the "last updated" date above, and for material changes we will take reasonable steps to notify you — on the website or in the app.

14. Contact

See also our Terms of Service.