Privacy Policy

Effective Date: August 30, 2026

01

Introduction

This Privacy Policy explains how Risus collects, uses, discloses, stores, and protects information when you use the Risus mobile app, website, APIs, and related services, together called the "Service."

If you do not agree with this Privacy Policy, do not use the Service.

Our Primary Goals:

  • Create, authenticate, secure, and manage accounts
  • Provide posts, pings, chat rooms, messaging, media upload, notifications, search, profiles, bookmarking, and AI features
  • Personalise the Service and improve usability
  • Moderate content, investigate reports, and enforce our policies
  • Prevent spam, fraud, abuse, illegal activity, and security incidents
  • Provide customer support and respond to user requests
  • Analyse performance, diagnose crashes, debug problems, and improve reliability
  • Comply with legal obligations, court orders, regulator requests, child-safety duties, and lawful requests
  • Communicate with you about your account, security, policy updates, and service changes

Data Protection Officer: For privacy-related questions, account deletion requests, data access requests, or other privacy concerns, contact our privacy team at privacy@risus.io.

02

Scope and Application

This Privacy Policy applies to all users of the Risus mobile app, website, APIs, and related services (the "Service"). It covers the information we collect when you browse, register, post content, send messages, use AI-assisted features, or otherwise interact with the Service. It does not apply to third-party services that may be linked from our platform — those services have their own privacy policies.

03

What We Collect

We collect information you provide directly, content and activity you create or interact with, information collected automatically as you use the Service, and information we receive from other users and third parties.

Types of Personal Information:

Name, display name, username, email & profile details

Password credentials or authentication tokens (hashed where applicable)

Verification information (OTP, email verification, session security)

Google sign-in details, if you sign in with Google

Apple sign-in details, if you sign in with Apple

Posts, pings, reposts, captions, comments, reactions, likes & bookmarks

Chat rooms, direct messages, attachments, message status & related metadata

Uploaded images, videos, audio & documents

Reports, moderation requests, block/mute actions, appeals & support messages

AI prompts, generated outputs, feedback, moderation signals & usage logs

Device, network, app version & diagnostic logs

Notification tokens & delivery status

Media metadata (creation time, device info, embedded location)

When you sign in with Google, we use only the Google account identifier, name, email address, and profile image that you authorise. When you sign in with Apple, we use only the Apple user identifier, and the name and email address you authorise — including Apple’s private relay email if you choose to hide your email from us. With your permission, the Service may access your camera, microphone, selected photos, selected videos, or media files so you can create posts, send messages, upload profile content, scan codes, generate captions, or use media-related features. Risus may infer an approximate country or region from an IP address for security, fraud prevention, analytics, or localization where enabled. Uploaded images and videos may also contain creation time, device information, or location metadata embedded in the file. Risus does not collect device GPS or other precise location through Android location permissions unless a specific feature requires it, the permission is requested in context, and this Privacy Policy and the Data Safety declaration are updated. Risus seeks to avoid retaining or publicly exposing media location metadata when it is not needed. We may also receive information about you when other users message you, tag you, report your account or content, invite you to rooms, or interact with your content, and from service providers such as authentication, hosting, analytics, crash reporting, security, moderation, AI, email, SMS verification, and support providers.

Because Risus is a social and messaging platform, some content may be visible to other users depending on your settings, the feature used, and the way you share content on Risus.

How We Use Your Information:

Account & Service Provision

Creating and authenticating your account, securing it, and delivering the core features of the platform.

Content, Messaging & AI Features

Processing posts, pings, messages, media, and AI-assisted captions, suggestions, and enhancements.

Safety, Moderation & Legal Compliance

Reviewing reports, enforcing policies, preventing abuse, protecting users, and meeting legal and child-safety obligations.

04

AI Features and Automated Moderation

When you use AI features, or when content is screened for safety and moderation, Risus may process images, videos, captions, text prompts, editing instructions, reported content, and other content submitted to or analyzed by AI features; generated outputs, edits, feedback, usage logs, lyrics, music type, genre, style, mood, and related music-generation instructions; and moderation and safety signals needed to prevent abuse, spam, fraud, illegal content, child-safety violations, or other policy violations.

Third-Party AI Providers

Risus uses third-party AI and automated-processing providers. These services support caption generation, image generation and editing, image and video analysis, content moderation, safety detection, and music generation.

Google Gemini

Caption generation, content analysis, content suggestions, and safety classification.

Google Imagen

Image generation and image editing.

Google Cloud Vision

Image and video analysis, content moderation, and safety detection.

Sightengine

Content moderation and safety detection across images and video.

ElevenLabs

Music and audio generation from lyrics, music type, genre, style, and mood instructions.

Depending on the feature used or safety process involved, Risus may transmit the information listed above to one or more of these providers. Processing is limited to providing the requested feature, analyzing or moderating content, detecting abuse or illegal activity, maintaining platform safety and reliability, and complying with applicable legal or safety obligations.

Data Minimisation

Risus shares only the minimum information reasonably required and does not intentionally include unrelated account, profile, contact, or precise-location information. Do not submit confidential, sensitive, illegal, or private information to optional AI features unless you are authorised to do so and understand the applicable processing.

Disclosure and Consent

Where third-party processing of personal or sensitive user data would not be reasonably expected, Risus provides a clear in-app disclosure describing the data, the purpose, and the type of service provider, and obtains affirmative consent before processing begins. You may decline optional AI processing by not using the relevant optional feature.

Risus reviews the privacy, data-retention, security, human-review, and model-training terms applicable to each provider and service configuration. Risus also keeps this Privacy Policy and its Google Play Data Safety declaration aligned with the collection, transmission, processing, and sharing performed through these services.

06

How We Store, Share & Protect Your Data

Data Storage

Personal information is stored in secure servers located in Cloud infrastructure operated by trusted hosting providers.

Your information may be processed in countries other than where you live. Where required, we use appropriate safeguards for international data transfers.

Risus uses trusted third-party providers for hosting and cloud infrastructure, storage, authentication (including Google Sign-In and Sign in with Apple), analytics, crash reporting, performance monitoring, push notifications, AI processing, email delivery, SMS verification, content delivery networks, media processing, moderation, trust and safety, security, abuse prevention, and support. Providers are expected to implement appropriate security measures and may process information only for contracted, disclosed, or legally permitted purposes. Risus remains responsible for evaluating third-party practices, limiting data use to app functionality and policy-conforming purposes, and preventing the sale or unrelated use of personal and sensitive user data. Risus does not sell personal information. If this changes, this Privacy Policy and the required privacy disclosures will be updated before the change takes effect.

How Information Is Shared

Information may be shared in the following ways:

With other users

Content you post, send, or make visible may be shown to other users according to your use of the Service and your privacy settings.

With service providers

Providers that help us host, secure, analyse, moderate, deliver, and support the Service, acting on our behalf.

For legal and safety reasons

Where required by law, to protect rights and safety, to investigate abuse, to prevent harm, or to report illegal content.

Business transfers

In a merger, acquisition, financing, restructuring, or asset sale, subject to appropriate safeguards.

With your consent or direction

When you direct us to share information or use features that intentionally share content.

Data Protection Measures

1

Encryption in Transit

Data transmitted between your device and our servers is protected using modern cryptography such as HTTPS/TLS.

2

Access Controls

Access to personal data is restricted to authorised personnel on a need-to-know basis, with monitoring of unusual activity.

3

Security Review

We conduct regular security reviews and monitoring. No system is completely secure, and we cannot guarantee absolute security.

4

Limited Retention

We keep information only as long as needed to provide the Service and meet legal, safety, and dispute obligations. Reports and enforcement records may be kept longer, and backups persist for a limited time during normal backup cycles.

Data Processing Agreements

We may disclose information when required by law, to protect rights and safety, to investigate abuse, to prevent harm, or to report illegal content. If Risus is involved in a merger, acquisition, financing, restructuring, or asset sale, information may be transferred as part of that transaction, subject to appropriate safeguards.

07

Data Retention

We keep information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain safety, prevent abuse, and protect the integrity of the Service.

Account information

Generally kept while your account is active.

Posts, messages & media

Kept until deleted by you or removed under our policies, unless retention is required for safety, legal, backup, abuse-prevention, or dispute reasons.

Crash logs & diagnostics

Kept for a limited period needed for debugging, security, and reliability.

Reports & enforcement records

May be kept longer to protect users and prevent repeat abuse.

AI inputs, outputs & moderation signals

Retained for the period needed to provide the feature, investigate abuse, maintain safety and reliability, resolve disputes, or satisfy legal duties. Third-party retention is governed by the applicable provider service, configuration, and contract reviewed by Risus.

Backup copies

May persist for a limited time during normal backup and disaster-recovery cycles.

08

Account Deletion and Data Deletion

If you created an account, you may request account deletion in the app and through our public web deletion page.

In the app

Settings > Account > Delete Account.

Public web page

https://risus.io/delete-request — available without signing in to the app.

By email

privacy@risus.io

When deletion is completed, Risus deletes or anonymizes personal data associated with your account unless limited retention is required or permitted for legal, security, fraud-prevention, moderation, dispute, backup, or safety reasons.

Deactivation Is Not Deletion

Temporary deactivation, freezing, or hiding an account is not the same as account deletion.

09

Your Rights and Choices

Depending on your location, you may have rights to access, correct, download, delete, restrict, or object to the processing of your personal data. You may withdraw consent for optional permissions through device settings and may decline optional AI processing by not using the relevant feature. To make a privacy request, contact us at privacy@risus.io. We may need to verify your identity before responding, and we aim to respond within the timeframes required by applicable law.

Right of Access

Art. 15 GDPR / CCPA

Request a copy of the personal data we hold about you and information about how we process it.

Right to Rectification

Art. 16 GDPR

Request correction of inaccurate or incomplete personal information we hold about you.

Right to Erasure

Art. 17 GDPR / CCPA

Request deletion of your account and associated personal data, subject to legal and safety retention requirements.

Right to Restriction

Art. 18 GDPR

Request that we restrict processing of your personal data under certain conditions.

Right to Data Portability

Art. 20 GDPR

Receive your personal data in a structured, commonly used, machine-readable format.

Right to Object

Art. 21 GDPR

Object to the processing of your personal data, including for direct marketing purposes.

Withdraw Consent

Art. 7(3) GDPR

Withdraw optional permissions (camera, microphone, notifications, media access) at any time through your device settings. Withdrawing consent does not affect prior lawful processing.

Right to Lodge a Complaint

Art. 77 GDPR

Lodge a complaint with a supervisory authority if you believe our processing violates applicable data protection laws.

Exercising Your Rights

Contact us at privacy@risus.io to exercise any of these rights. You can also control app permissions, and withdraw optional consents such as camera, microphone, notifications, or media access, through your device settings.

10

Permissions and Device Controls

You can control app permissions through your device settings. Disabling permissions may limit features such as posting photos, recording videos, sending media, scanning codes, receiving notifications, or using AI media features.

Risus requests sensitive permissions only when needed and in context. Where collection or sharing would not be reasonably expected, Risus provides a prominent in-app disclosure and obtains affirmative consent before access or processing begins. Permissions that are not necessary for a current user-facing feature are removed from the app.

11

Cookies and Tracking Technologies

Our website (risus.io) may use cookies, local storage, server logs, and similar technologies to provide essential website functions, protect forms from abuse, remember preferences, measure performance, and improve the website. Where required by law, Risus obtains consent before placing or using non-essential analytics, preference, advertising, or similar technologies.

Cookies are small data files stored on your device. The mobile app does not use browser cookies but may use equivalent on-device storage. See our Website and Cookie Notice for more detail.

Essential

Required for security, form submission, account deletion requests, and basic website operation. These cannot be disabled without breaking site functionality.

Preference

Remember language or display choices to provide a consistent experience across sessions.

Analytics

Help us understand website visits and errors, where enabled, so we can fix issues and improve the experience.

Security

Help detect spam, abuse, bots, and fraudulent requests. May be set by our security service providers.

For more detailed information about cookies, visit our Cookie Policy at https://risus.io/cookies-policy

12

Children's Privacy (COPPA)

Risus is not directed to children under 13 and is intended only for users who are at least 13 years old, or the higher minimum age required in their country. In compliance with the Children's Online Privacy Protection Act (COPPA), Risus does not knowingly collect, use, or disclose personal information from children under 13 without legally valid authorization.

Age Requirements

You must be at least 13 years old (or the higher minimum age required in your country) to create an account. Certain features may have a higher age requirement and may be unavailable to minors. If you are under the age of legal majority in your jurisdiction, you confirm that you have parental or guardian consent where required by law. Accounts determined to belong to users below the applicable minimum age may be suspended, restricted, or permanently removed.

If we discover that a user under the age of 13 has created an account or provided personal information, we will take appropriate steps to remove the account and delete the associated data, subject to legal, safety, security, moderation, and backup retention requirements.

Parental Rights

Parents or legal guardians who believe their child has provided personal information to Risus may contact us at privacy@risus.io. Risus also prohibits content or conduct that exploits, endangers, sexualizes, abuses, or harms children — see our Child Safety and CSAE Standards for more information and for the child safety reporting contact.

🛡️

Child Safety Standards

Risus maintains a strict, zero-tolerance policy against Child Sexual Abuse and Exploitation (CSAE). We explicitly prohibit any content, behavior, or activity that sexually exploits, abuses, or endangers children — including grooming, sextortion, trafficking, and the sharing of exploitative material.

Zero Tolerance Policy

Any user found violating our child safety standards will face immediate and permanent account termination and may be reported to the appropriate authorities, including NCMEC and local law enforcement.

CSAM Reporting

Child Sexual Abuse Material is immediately removed, the offending account disabled, and the incident reported to NCMEC and relevant law enforcement.

In-App Reporting

Users can report suspicious behavior or content by visiting the post or profile, selecting "Report" or "Flag", and choosing the appropriate safety category.

Dedicated Child Safety Contact

For safety enforcement questions or severe escalations, contact our Child Safety Point of Contact directly.

childsafety@risus.io
13

Compliance with United States Privacy Laws

For residents of the United States, the following rights may apply under the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other applicable state privacy laws.

Right to Know

Request disclosure of the categories and specific pieces of personal information we have collected, the sources, our purposes, and any third parties with whom we share it.

Right to Delete

Request deletion of personal information we have collected, subject to exceptions for legal compliance, safety, and fraud prevention.

Right to Correct

Request correction of inaccurate personal information we hold about you.

Right to Opt-Out of Sale/Sharing

Risus does not sell personal information and does not share personal information for cross-context behavioural advertising.

Right to Limit Sensitive Data Use

Request that we limit our use of sensitive personal information to what is necessary to provide the Services.

Right to Non-Discrimination

We will not discriminate against you for exercising any of your privacy rights.

Submitting Requests

Submit requests by emailing privacy@risus.io. We will verify your identity by comparing the information you provide with our records before processing your request.

14

Data Breach Notification

We maintain security measures designed to protect your personal data. In the event of a data breach that poses a risk to your rights and freedoms, we have procedures to promptly identify, assess, and respond.

1

Detection and Containment

Security monitoring helps detect anomalous activity. Upon detection, we work to contain the breach and assess its scope and impact.

2

Regulatory Notification

Where required by applicable law (for example, the GDPR 72-hour rule), we notify the relevant supervisory authority within the legally required timeframe.

3

Individual Notification

Where a breach is likely to result in high risk to your rights and freedoms, we will notify affected users promptly with information about what happened and what steps to take.

4

Remediation and Support

We take steps to remediate the breach and provide guidance to affected individuals on how to protect themselves.

If you have questions about a potential breach or believe your account may have been compromised, contact us immediately at privacy@risus.io.

15

Changes to This Privacy Policy

We may update this Privacy Policy as the Service, our providers, or legal requirements change. We will update the date shown at the top of this page and provide additional notice where required.

If a material change requires renewed consent, Risus will request that consent before the affected processing begins.

Get in Touch

Have questions about our privacy policy? We're here to help.

© 2026 Risus. All rights reserved.

Your privacy is our priority.