Privacy
The privacy policy is dated September 2026 and is much longer than the homepage. Several of the sharpest limits are in it. The homepage keeps the short version. The data controller named at the bottom is Rift Communications LLC.
The IP they don't store
About page: "no stored IP addresses." Policy: all traffic is proxied through Cloudflare, which receives IP addresses and request headers under Cloudflare's own policy. Rift says its backend never persists IP addresses and keeps no IP-to-account map.
Abuse control uses a one-way HMAC of the connecting address. The salt rotates daily and is destroyed within 48 hours. The policy says the quiet part:
While a day's salt still exists, we could check whether a fingerprint matches an IP address someone supplies. Once that salt is destroyed, no fingerprint computed under it can be tied to any IP by anyone, including us.
So "we cannot identify users by IP in response to law enforcement" is true, on their telling, only after the salt is gone, and only for records Rift itself holds. They note that compelling Cloudflare is a separate legal process. A same-day request, with the address in hand, is a check they say they are able to run.
Other network facts in the same policy:
- Signup puzzles, when enabled, are counted against that fingerprint. The puzzle runs on Rift's servers, not a third-party captcha. Nothing from the check is stored on the account.
- Several brand-new accounts from the same connection deleting themselves in a day pauses new signups from that connection for the rest of the day.
- Voice operations collect country-level call usage, region, aggregate connection quality, and media traffic totals. Country hints come from the network edge and may be a VPN exit. Lookups tied to a live call expire within ten minutes of the last refresh. Pseudonymous caller keys last up to two UTC days. Aggregate stats last 90 days. They say audio and video are not retained in this feature, and the reports go to Rift, not a third-party analytics product.
- Tor is not blocked or degraded, by their policy.
On 3 October 2026 the marketing homepage responded with a content security policy that allows scripts from the site itself (including unsafe-inline) and connections to therift.chat, api.therift.chat, and releases.therift.chat. That matches the "no third-party ad pixel on the marketing site" claim for that response. It does not speak to the app, to Cloudflare, or to Sentry.
Delete means gone, after a week, with a list of exceptions
Homepage: the row leaves the database and is not archived. Policy: "When you delete a message, it is permanently purged from the database. It is not soft deleted or hidden." Then the backup paragraph. The database keeps rolling point-in-time backups of the previous seven days. Deleted data can live in a backup until that backup ages out. They say seven days is the whole window, and that they do not keep long-term archival backups.
More retention, all from the same policy:
- Account deletion diagnostics: a rolling five-minute trail, capped at 64 API actions, of route names, methods, status codes, and times. Not message bodies, passwords, or IPs. A completed self-service deletion saves an encrypted copy that administrators can read for 24 hours. Daily cleanup removes it, "normally within 48 hours."
- A separate receipt keeps account ID, deletion source and time, client platform, and account age for seven days.
- If the account is less than a day old, that receipt also keeps an encrypted copy of the username, the Shards joined and when, and up to 20 of the most recent Shard messages, first 300 characters each. Direct messages are excluded. Administrators can see it. It is deleted with the receipt after seven days. This exists, they say, to investigate abuse of brand-new accounts.
- Reports and the evidence captured with them are kept after the reported account, or the reporter's account, is deleted. A deleted reporter is unlinked from their reports. Messages a moderator removed stay in that Shard's mod log for up to 14 days.
- Lobby rooms are deleted when the room dissolves, "typically after 30 minutes."
- The terms, separately, say CSAM is preserved and reported where the law requires it.
The encryption page says deleting a DM removes the row and that there is no moderation retention copy of encrypted DM text, because the server could not read it. Attachments are removed from storage once nothing references them. That sentence lives next to the seven-day backup window in the privacy policy. A backup is an archive. The homepage says it isn't archived somewhere.
What an account actually is
Collected, by the policy: username, the public key derived from the Rift Key, the age-attestation timestamp, profile fields you fill in, Shard content (encrypted at rest, not end to end), DM ciphertext plus routing metadata, and the attachment exception described on the encryption page.
Also optional, and easy to miss under "we never had your email":
- YouTube, if you connect an account: OAuth tokens, stored encrypted, and the channel name. Read-only access to subscriptions, liked videos, and channel name. Feeds are fetched when opened and not stored. Disconnect revokes the token. Searching YouTube without connecting uses Rift's own key.
- Apple Music and Twitch, if connected: tokens and the provider display name. Apple Music may include a music user token.
- Push tokens (APNs or FCM) plus platform, app version, and an optional device label and locale. Removed on logout, revoke, or when notifications are denied. Push for encrypted DMs cannot include the text.
- Two-factor secrets, if you turn 2FA on, encrypted at rest. No phone number required.
- Stripe, if you pay: Rift says checkout happens on Stripe, and Rift stores an opaque customer token and subscription state (active, past due, cancelled, period dates). Rift says it does not receive the card, the billing address, or "financial identity." Stripe does receive whatever Stripe Checkout collects. Payments are how a username becomes a customer of a second company.
Sentry, on the phone, by default
The FAQ says the app carries no analytics SDK, and that the mobile app can send crash reports you can switch off. The policy is more specific. The mobile app sends crash and error reports to Sentry: the error, the stack, device model, OS version, app version, and a short trail of recent activity (log lines, screens opened, and network requests) from just before the failure. Reports are not tied to the account and are not supposed to include messages. Crash reporting and the activity trail are on by default, each with a switch under Settings, Privacy, Diagnostics. Web and desktop send Sentry nothing.
"No analytics SDK" and "Sentry is on unless you find the switch" are both on the site. Sentry is an error tracker. It is also a third party receiving a trail of what the app was doing.
The 18+ theory
FAQ:
Being adults-only also unlocks the privacy features regulators don't permit on platforms that allow minors: no email, no phone number, no government ID, and deleted messages actually leave the database.
The implementation is a checkbox. The policy stores "the date and time you confirmed" you are 18, uses it only as evidence of that representation, and deletes it with the account. There is no government ID check. The about page calls this a lounge: "Sorry, kids. This one isn't for you." The same policy then has a children's section. Rift is "strictly intended" for 18 and older, and, "separately, consistent with" COPPA, they do not knowingly collect personal information from children under 13. They ask people to report both under-13 and under-18 accounts. If they learn an account is under 18, they say they will terminate it and delete the data, subject to obligations such as CSAM reporting.
COPPA is an under-13 statute. The FAQ's "regulators don't permit" sentence is broader than that statute, and the policy they wrote still has to mention it. The age gate is a timestamp of a click. A minor who clicks through gets the same no-email, short IP memory, and hard-delete design that the FAQ is selling as the point of keeping minors out. The terms say a false age is a material misrepresentation and a permanent bar. Catching it depends on someone noticing.
Play lists the app as PEGI 18. That is a store questionnaire, not an ID check inside Rift.
Law enforcement, in their words
They say they will comply with valid process, review it, and push back when they believe it is overbroad. What they say they can provide: account creation date, username, Shard metadata, and DM routing metadata (participants, timestamps, delivery state). What they say they cannot provide: plaintext of end-to-end DM text, and an IP-to-account answer from Rift's own systems once the salt is gone. Emergency disclosure is allowed for an imminent threat of death or serious physical injury. Notice to the user when the law allows it.
The warrant canary and the transparency report are the institutional half of this. Both are covered on the company page. As of the August 2026 canary and the July 2026 report, every counter they publish is zero. A zero report from a young beta is a baseline, which is what they call it. It is not evidence about the next request.