Privacy Policy
Effective date: 10 October 2026 App: Riya (the AI companion app with the companion Riya) Who we are: Riya is made and run by Manoj Kumar, an individual developer based in India ("we", "us"). For Indian data-protection law, Manoj Kumar is the Data Fiduciary (the person who decides how your data is used). Postal address for notices: H. No. 86-260-1, Somappa Colony, Near NCC Canteen, B-Camp, Kurnool, Andhra Pradesh 518002, India Contact: riyaapp@proton.me · Privacy questions and requests: riyaapp@proton.me (see section 11)
This policy explains what we collect when you use Riya, why, who helps us run the service, and the choices you have. We've tried to keep it short and plain. If anything is unclear, write to us at riyaapp@proton.me.
The short version
- Your companion is an AI, not a person. Her replies, voice notes and pictures are AI-generated. To reply to you, your messages are sent to AI providers who process them for us.
- We keep your chat history in your account so the conversation continues. You can delete your account at any time, and that deletes your chats and memories.
- Memory is optional. You can switch it off, use "This chat only", or forget single items in Controls.
- Health things are only remembered if you say yes when asked. You can change this anytime.
- We don't sell your data, we don't show ads, and we don't use third-party analytics or advertising trackers in the app. We count a few basic usage events ourselves (like app opens and purchases), never your messages.
- The app is for adults (18+) only.
1. What we collect
Account information
- Google sign-in. You sign in with your Google account. We receive your email address and basic profile information Google shares (such as your name and profile picture link), plus a unique account ID.
- Age confirmation. Before you sign in, you confirm you are 18 or older. We record when you confirmed it with your account.
Your conversations
- Messages you send and the companion's replies, with times and message type (text or voice).
- Voice messages you choose to record. The recording is stored in private storage in your account and is turned into text so your companion can reply.
- Reactions (the emoji you put on her messages). They are stored so they survive a new phone; they are not sent to the AI.
- Reminders and follow-ups you ask for (for example "remind me to call the dentist tomorrow"), including the topic and time.
Memory (optional)
If memory is on, your companion keeps short notes about things you've told her, like a thoughtful friend would: your name and basics, people and pets in your life, likes and dislikes, routines, plans and how they turned out, and the inside jokes and moments you share. See section 4 for what is never stored and how long things are kept.
Device and settings information
- Region, time zone and language settings from your phone (not GPS location). We use these to show the right crisis helplines, time reminders and limits to your local day, and reply in your language.
- Push notification token, if you allow notifications, so we can deliver messages and reminders.
- Your Controls choices (memory on/off, "This chat only", health memory, which messages your companion may send you).
Purchases
If you subscribe, Apple or Google handles the payment. We do not receive your card or bank details. Our subscription service provider (RevenueCat) and the stores tell us your subscription status, product, and renewal or expiry dates, linked to your account ID.
Usage events
We record a few basic events about how the app is used, linked to your account: when you open the app (at most once a day), when you finish signing up, when you reach a plan limit, when the upgrade screen is shown, and when a purchase starts, completes or fails. Each event can carry a few simple details, such as the plan or product, where the upgrade screen was opened from, your phone's platform, the app version and your region. They never include your messages, voice, memories or anything you write. We keep them in our own database (no third-party analytics service) and use them only to understand how the app is used and to improve it.
Safety information
To keep conversations safe we record limited safety signals, for example that a message needed a crisis response, or that someone said they were under 18 (see section 6). We also keep short technical records of safety decisions (such as "allowed" or "blocked" and a reason code). If you report one of her replies, we keep the report, the reported message and a little surrounding conversation so we can review it.
Technical logs
Our servers keep technical logs (for example request times, error messages and counts) to run and fix the service.
What we don't collect
- No precise location (GPS).
- No contacts, calendar or photo library access.
- Photos: sending photos to your companion is not offered at launch.
- No advertising IDs, and no third-party analytics or advertising SDKs.
2. How we use it
- To run the chat: generate your companion's replies and voice notes, send her pictures, and keep your conversation history.
- To remember (if memory is on): so she can ask how things went, remember what you like and keep your shared jokes.
- To send messages you've allowed: reminders you asked for, occasional check-ins and "how did it go?" follow-ups. You can switch each of these off in Controls.
- For safety: to detect crisis situations and show helplines, to keep the experience non-romantic for anyone who says they are under 18, and to prevent abuse.
- For your plan: to apply free and Premium limits and unlock Premium after purchase.
- To improve the app: from the usage events above, we see things like how many people come back the next day, how often limits are reached, and how many people upgrade. We look at these as counts, not to profile you.
- To support you when you contact us, to look into replies you report, and to keep the service working and secure.
- To meet legal duties, for example keeping security logs, handling data breaches, and counting (without names or message content) how often crisis helplines were shown, where a law requires us to report that number.
We do not use your conversations for advertising, and we do not sell or rent your personal information.
3. Who processes your data for us
We use trusted service providers. They process data on our behalf to provide the service.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, file storage, sign-in and server functions | All account, chat, memory, voice-recording and settings data described above |
| Google (Google Sign-In) | Signs you in | Your sign-in request; Google shares your email and basic profile with us |
| OpenAI | Writes your companion's chat replies and the messages she starts (check-ins, reminders, follow-ups); creates search "embeddings" so she can find relevant memories | Recent conversation, relevant memory notes and instructions for each reply; memory note text and your latest message (for memory search) |
| Google (Gemini API) | Decides what is worth remembering and writes memory notes; settles privacy checks the classifier is unsure about; writes your companion's first hello | Recent conversation text, existing memory notes |
| Jev (Typesafe, api.typesafe.ai) | Classifies messages for safety and memory (for example, whether a message is a crisis, or whether something is private) and helps pick relevant memories | Message text, recent conversation, and candidate memory notes to choose from |
| Deepgram | Turns your voice messages into text | Your voice recording (we have opted out of Deepgram's model-improvement program) |
| ElevenLabs | Creates your companion's voice notes | The text of her reply (not your voice) |
| RevenueCat | Manages subscriptions with Apple and Google | Your account ID, subscription and purchase status |
| Expo push service, Google Firebase Cloud Messaging, Apple Push Notification service | Deliver notifications to your phone | Your push token and the notification (a short preview such as "You have a new message", titled with your companion's name) |
| Apple App Store / Google Play | Payments and subscription billing | Handled under Apple's or Google's own privacy policies |
Providers may keep data for a limited time under their own terms, for example for abuse monitoring. We may also disclose information if required by law, to protect someone's safety, or as part of a merger or sale of the business (we would tell you first).
4. Memory: what is kept, what never is, and for how long
What memory never stores
- Crisis or self-harm details.
- Sexuality, religious identity or beliefs, caste, or politics. (Festivals and plans, like "Diwali at the in-laws'", may be remembered as events, never as a label about you.)
- Money amounts, salary, debts, balances or account details. (What happened, like "got a raise", may be remembered.)
- Phone numbers, emails, ID numbers (such as Aadhaar), card or bank numbers, or home addresses.
- A child's health, school name, location or route. (An adult's child's class, tests and school events may be remembered as part of your life.)
- Sensitive details about other people.
- Hypotheticals, role-play, or things only the companion said about you.
Health things: only with your consent
The first time you mention something health-related, your companion asks: "Can Riya remember health things you tell her?" Until you tap Yes, remember, nothing health-related is saved (she still responds warmly in the moment). If you tap No thanks, she won't ask again. You can change this anytime with the Remember health things switch in Controls; turning it off also forgets health things already saved.
With your consent: everyday illness, injuries, hospital stays and appointments are kept as short-lived moments (about 2–3 weeks), and she may ask in chat how you're feeling. Ongoing conditions (including mental-health conditions) and medicines are kept only in your own plain words, with no doses and nothing guessed, and come up only when you bring up something related. Health things never appear in notifications or in messages she starts. A child's health is never stored. Reminders you ask for (like calling the dentist) are always saved so they can be delivered.
How long memories last
- Feelings around an everyday event fade after about 3 weeks; small everyday events after a few months.
- Near-term plans close a few days after their date. Life goals stay until done or dropped.
- Important life events (a new job, a move, a breakup, a loss) are kept while your account is active.
- When you correct something, the old version is kept for about 30 days, then removed.
- If you don't use the app for 12 months, we may erase your memories (we'll try to let you know beforehand).
Your memory controls
In Controls (tap the Controls button at the top of the chat; it's also in Settings) you can:
- see a plain list of what your companion remembers and Forget any item;
- switch Remember things about me off (this erases saved memories and reminders that depend on them);
- choose This chat only (nothing is saved);
- switch health memory on or off;
- choose whether she may send reminders, check-ins and follow-ups.
You can also say "forget that" in chat. Forgetting a memory does not delete your chat history.
How memory works: memory looks at your chats, including her replies, to remember things about you and your shared moments. It only saves what you said about yourself, plus your shared jokes and moments.
5. How long we keep your data
| Data | How long |
|---|---|
| Account, chat history, reactions, voice recordings | Until you delete your account |
| Memories | As described in section 4, and always deleted when you delete your account |
| Reminders | Until delivered, stopped or expired |
| Safety signals | A minor-age guard lasts 24 hours; a crisis check-in flag is cleared after one check-in. Safety decision records are kept with your account. |
| Subscription status | While your account exists |
| Usage events | 13 months, then deleted automatically; always deleted when you delete your account |
| Technical and security logs | Our hosting provider keeps routine server logs for about 7 days; security logs are kept for up to 1 year where Indian law requires us to keep logs to detect and investigate unauthorised access (DPDP Rules 2025, rules 6 and 8) |
| Reports you send about her replies | Until reviewed, then up to 1 year |
| Grievance and rights-request correspondence | Up to 3 years, so we can show how we handled it |
When you delete your account, we immediately delete your account, chats, reactions, memories, reminders, voice recordings and voice notes from our live systems. Any copies left in backups are removed within 30 days. Limited logs about the account's activity (not your messages) may be kept for up to one year where the law requires it. Our service providers keep data only under their own terms (section 3). Apple, Google and our subscription provider (RevenueCat) keep their own records of purchases under their own terms. See our Delete your account page.
6. Safety, crisis support and age
- Adults only. Riya is only for people aged 18 and over. Companion chatbots like this one are not suitable for minors. We don't knowingly collect data from anyone under 18.
- If someone tells the companion they are under 18, she stays friendly but not romantic for 24 hours, even if they then say it was a joke. During that time she doesn't send pictures or voice notes, and check-ins and follow-ups pause; reminders the person asked for still arrive, in a non-romantic tone.
- We may suspend or close accounts we reasonably believe belong to someone under 18, and we may ask for confirmation of age. When we close such an account, we delete its data as described in section 5.
7. Where your data is processed
We are based in India. Our database is hosted by Supabase in Singapore. Our AI and other service providers are mainly in the United States and may process data in other countries. When data moves across borders, we rely on the safeguards available under applicable law (such as standard contractual clauses in the EU/UK).
8. Security
Data travels between the app, our servers and our providers over encrypted connections (HTTPS). Voice recordings and voice notes are kept in private storage that only your account can access, and other users cannot read your chats. We limit who can access our systems and keep security logs so we can spot and investigate misuse. No system is perfectly secure. If a personal data breach affects you, we will tell you without delay, in the app or by email: what happened, what it may mean for you, what we are doing about it, what you can do to protect yourself, and who to contact. We will also report it to the authorities as the law requires (in India, the Data Protection Board).
9. Your rights and choices
Wherever you live, you can:
- see and delete memories in Controls;
- switch off memory, health memory, reminders, check-ins, follow-ups and notifications;
- delete your account in Settings → Delete account, or by email;
- ask us for a copy of your data, to correct it, or to stop a use you object to, by writing to riyaapp@proton.me.
We'll reply within the time your local law requires, and in any case within 30 days. We may need to confirm it's you, for example by asking you to write from the email you sign in with.
India (Digital Personal Data Protection Act, 2023)
- What we process and why: the personal data listed in section 1, for the purposes in section 2, to provide the companion chat service described in section 2.
- Your rights: you can ask for a summary of the personal data we process and the service providers we share it with (section 3). You can also ask for it to be corrected, completed, updated or erased, and you can nominate someone to exercise your rights if you die or can't act yourself.
- Withdrawing consent: this is as easy as giving it. Switch memory, health memory, reminders or notifications off in Controls, or delete your account in Settings → Delete account. Withdrawing consent doesn't affect anything we did before you withdrew, but some features (like memory) stop working.
- Grievances: write to our Grievance Officer (below). We acknowledge within 48 hours and reply within 30 days, and never later than the period allowed by law.
- Complaints to the Data Protection Board of India: if you're not satisfied with our reply, you may complain to the Data Protection Board of India through its official complaint process. Indian law asks you to use our grievance process first.
Grievance Officer and contact person for privacy questions (India): Manoj Kumar — riyaapp@proton.me — H. No. 86-260-1, Somappa Colony, Near NCC Canteen, B-Camp, Kurnool, Andhra Pradesh 518002, India
European Union, UK
Riya is not offered in the European Union, the wider EEA (Iceland, Liechtenstein, Norway), the United Kingdom or Switzerland at this time. If that changes, we will update this policy first.
United States
We don't sell or share personal information for cross-context behavioural advertising. Residents of some states have rights to know, delete and correct their data; contact us to use them. We won't treat you differently for using your rights. Some states have laws for AI companion apps (for example New York and California): the app tells you that your companion is an AI and not a human, and it follows the crisis protocol described on our Help & support page.
Canada, Australia, Japan
You can ask to access or correct your information, and complain to your regulator (the Office of the Privacy Commissioner of Canada, the OAIC in Australia, or Japan's Personal Information Protection Commission) if you're unhappy with our response.
10. Changes
If we change this policy in a meaningful way, we'll tell you in the app before the change takes effect. The date at the top shows the latest version.
11. Contact
Riya is run by Manoj Kumar, an individual developer in India. Postal address for notices: H. No. 86-260-1, Somappa Colony, Near NCC Canteen, B-Camp, Kurnool, Andhra Pradesh 518002, India General support: riyaapp@proton.me Privacy questions, data requests and grievances: Manoj Kumar (Grievance Officer and contact person for questions about how your personal data is used) — riyaapp@proton.me
When we answer a request about your data, we will include these contact details in our reply.