Privacy Policy
Last updated: July 4, 2026
Who we are
Riffed is a job-search tool built for people who have recently been laid off. It helps you tailor your resume, draft cover letters, and shape your professional story. This policy explains what information we collect, how we use it, and the choices you have. It applies to the Riffed application at app.riffed.io.
Our approach to your data
We treat your resume and your employment situation as sensitive information, because they are. Two principles guide everything below: we collect only what we need to provide the service, and we never sell your personal information. Handling this information carefully is a core feature of Riffed, not an afterthought.
Information we collect
- Account information. Your email address, and, if you sign in with Google or LinkedIn, the basic profile information those providers share (name, email, profile identifier).
- Content you provide. Resume text you upload, job descriptions you paste, optional details about your job search, and any layoff-related information you choose to share.
- Generated content. The resume suggestions, cover letters, and other outputs the service produces from your inputs.
- Usage records. Limited technical records of your interactions with our AI features (such as timing and status of a request) so we can keep the service reliable. We do not sell or share this for advertising.
How we use your information
- To provide the core service: tailoring resumes, drafting cover letters, and related tools.
- To authenticate you and keep your account secure.
- To operate, maintain, debug, and improve the reliability of the service.
- To communicate with you about your account or important service changes.
AI processing
Riffed uses Anthropic’s Claude API to generate resume suggestions and cover letters. When you use these features, the content you provide is sent securely to Anthropic’s API to produce your result. We do not permit your inputs or outputs to be used to train AI models. AI processing happens server-side; our API keys are never exposed to your browser.
Service providers
We rely on a small number of infrastructure providers to run Riffed, each acting on our behalf:
- Supabase: authentication, database, and storage (where your account and content are held).
- Vercel: application hosting and content delivery.
- Anthropic: AI processing via the Claude API, as described above.
- Google and LinkedIn: only if you choose to sign in with them, for authentication.
How we protect your information
Your data is encrypted in transit and at rest. Access to your records is restricted at the database level so that, by default, only you can access your own information. Sensitive credentials are held server-side and are never sent to the browser.
Data retention and deletion
We keep your information for as long as your account is active. You can delete your account at any time, which removes your profile and associated records. If you need help deleting your data, contact us using the details below.
Your choices and rights
You can access and update your account information, request a copy of your data, or ask us to delete it. Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA, including the right to object to or restrict certain processing. We honor these requests as required by applicable law.
Cookies
We use cookies that are necessary to keep you signed in and to operate the service securely. We do not use advertising cookies or sell your information to advertisers.
Children
Riffed is intended for adults in the workforce and is not directed to anyone under 18. We do not knowingly collect information from children.
Changes to this policy
We may update this policy as the product evolves or as legal requirements change. When we do, we will revise the “Last updated” date above. Significant changes will be communicated through the service.
Contact
Questions about this policy or your data? Email privacy@riffed.io.
This policy is provided for transparency and does not constitute legal advice.