Claims

Each row is a sentence Rift publishes, the page it is on, and the page that qualifies it. Quotes are from the live site on 3 October 2026 unless a date is in the sentence. Nothing here is a pentest. Where a longer document already tells the truth, the row says so.

They say Where The record
Direct messages are encrypted end to end. "Not 'we promise not to,' we literally can't." Homepage Encryption page: 1:1 DM text, and 1:1 calls when both clients support it, are the end-to-end pieces. Attachments in those DMs, Splinters, and Shard channels use keys Rift holds. Shard voice is plaintext on their media server. Web and desktop clients load code from Rift. The threat model excludes "a malicious Rift that serves you modified client code."
"Even if one of your keys leaks later, the messages you already sent stay locked." Features, "Signal-style X3DH/Double Ratchet" Encryption page: stored DMs have a second ciphertext under long-lived identity keys. A leaked Rift Key or DM identity key decrypts history the server still holds, both directions. The signed prekey never rotates. Forward secrecy is described as a property of the live session.
Crack the servers and you get "a pile of unreadable gibberish that isn't attached to anybody." About, "Nothing here worth stealing" Features: "a worst-case breach leaks conversations, not identities." Usernames are the account identifier. Shard and Splinter messages are readable by anyone who holds Rift's keys, which the encryption page says Rift does.
"When you delete a message, the row leaves the database. It isn't archived somewhere or hidden behind a flag." Homepage Privacy policy: point-in-time backups cover seven days. A self-deleted account younger than a day leaves the username, Shard joins, and up to 20 recent Shard messages (300 characters each) visible to administrators for seven days. Reports outlive the account. Removed messages can sit in a Shard mod log for 14 days. Terms: CSAM evidence is preserved where the law requires it.
"No stored IP addresses." About Privacy policy: Cloudflare sees the IP as part of proxying. Rift derives an HMAC fingerprint with a salt that rotates daily and is destroyed within 48 hours. While the salt exists, they can test whether a fingerprint matches an IP someone supplies. Voice stats include country-level usage from the network edge. They also say Tor is not blocked.
Signup is a username and a password. "Nothing to identify you." No email, phone, or government ID. Homepage, FAQ, privacy policy The account is the username. They store an age-attestation timestamp. Optional YouTube, Twitch, and Apple Music connections store tokens. Push uses FCM or APNs device tokens. A subscription creates a Stripe customer token. The "we never had your email" line is about Rift's own form. Stripe still runs checkout.
No behavioral tracking, no ad pixel, no analytics SDK in the app. Messages never train AI. Homepage, FAQ, terms, privacy policy The no-ads and no-sale lines match the policy. The marketing homepage's CSP, checked 3 October 2026, allows scripts from the site itself and connections to therift.chat, api.therift.chat, and releases.therift.chat. The policy still describes first-party aggregate page views, aggregate feature-usage rates, 90 days of voice operations stats, and mobile crash reports to Sentry that are on by default. "Never train AI" is a clause in the contract. The client is closed, and there is no published audit.
"No investors, no board, no growth targets. There is no upstairs." Subscriptions are the only revenue, "now and always." About, plans Rift Communications LLC, Wyoming filing ID 2026-002029919. Registered agent: Registered Agents Inc, 30 N Gould St Ste R, Sheridan. The free record does not name members. The terms allow Rift to assign the agreement in a merger, acquisition, or sale of assets.
Three people. Pseudonymous "for the same reason we don't ask for your email." AI tooling, developer-reviewed. About, FAQ Same story from u/TheRiftChat on 22 July 2026, including "some parts are AI assisted." On that thread they also said AI helped write accessibility labels. No legal name on the about page, the DMCA page, or the free filing. About page sign-off: "Founder, primary engineer, husband."
Closed source today. Audits "on the list for later." You can check the work by signing up, exporting data, and reading the policy. FAQ They also write: "we would rather not be sued, which is a decent guarantee that it is true." Terms ban copying, decompiling, reverse engineering, scraping, and unofficial clients. Security page: report by email, no formal bug bounty, safe harbor if you follow that page.
18+ "unlocks the privacy features regulators don't permit" on platforms that allow minors. FAQ, about The stored proof is the date and time of a confirmation. No ID scan, which is also the sales point. The privacy policy still covers COPPA for children under 13 and tells people to report under-18 accounts. Terms: a false age is grounds for termination. Play listing: PEGI 18.
"Free is the whole product." Paid tiers "never gate the things that should have been free." Plans Free includes messaging, voice, video, and 1080p60 screen share, with 50 MB uploads. Rift+ is $7/month or $70/year: 1440p60, 300 MB uploads, a profile badge. Shard plans: $0, $10, and Shard Forge at $25/month (100 MB uploads per member, vanity invite on Forge). They say moderation stays free.
"A Shard is your community's home base, run by its own people." Homepage Features: if the owner deletes their account, is banned, or disappears for 60 days or more, ownership passes to the next member (admins, then highest role, then longest tenure). A Shard left untouched for 180 days or more can change hands while the owner still has an account.
Import from Discord rebuilds the server. Features The same section: structure only. Categories, channels, forum tags, roles, colors, and permissions that have a Rift equivalent. An editable preview first. Messages, members, and the Discord server stay where they are. No bot API. Incoming webhooks take Discord, GitHub, and Slack formats. u/TheRiftChat said the same about bots on 24 July 2026.
The iOS app "is built and in beta while App Store submission finishes." Download The next block on that page: store listing and TestFlight details appear "once submission is underway," and the status line is "Built, in beta, awaiting App Store." Android is on Google Play and is also offered as a sideload: "Download the APK," Beta 0.9.79, 124 MB, Android 7+, with instructions to allow installs from that source.
Windows client stays out of the way and uses a fraction of Discord's RAM, and it does not ship its own Chromium the way Electron does. Rift vs Discord, last updated June 2026 The same page says the chat UI runs in WebView2, Microsoft's shared Chromium runtime, counted separately from a 16 MB native shell. Their figure for one idle capture on one Windows 11 machine is about 250 MB total against about 1.8 GB for Discord. They call it one capture, not a benchmark.
Government requests, national security letters, compelled removals, DMCA notices: all zero. Transparency report, through 12 July 2026 They say this is the first report, the platform was in open beta, and zeros are the baseline. The report does not count ordinary moderation. The canary, updated 26 August 2026, still says no NSLs, no secret orders, no gag, no backdoor. They moved the update schedule from three months to six in that same update, and they wrote the change down.

The comparison numbers against Discord are Rift's, dated June 2026 on the vs page, with a line that Discord changes. This site does not re-test Discord's current upload cap or screen-share default.

Encryption · Privacy · Sources