Privacy Policy

Last Updated: March 2026

1. Introduction

Riflet ("we," "us," "our," or "Company") is committed to protecting your privacy and ensuring transparency about how we collect, use, process, and safeguard your information. This Privacy Policy explains our practices regarding the collection and use of information when you use our Riflet application and related services. By downloading, installing, or using Riflet, you agree to the practices described in this Privacy Policy. If you do not agree with our practices, please do not use the Software. We encourage you to read this policy carefully and contact us if you have any questions.

2. Information We Collect

2.1 Local File Processing Data

Riflet is designed as a desktop application that primarily processes files locally on your device. When you select files and folders for processing, those files remain on your computer unless you explicitly choose to share them with external services. The Software reads and analyzes files stored on your system to combine them into a single document. This file data is processed entirely on your machine and is not transmitted to our servers unless you actively choose to utilize features that require internet connectivity, such as integration with AI services or cloud-based features.

2.2 Account Information (Future Beta and Paid Features)

If you create an account to access premium features or participate in our beta program, we may collect information such as your email address, name, and account preferences. This information is used to identify you, communicate with you about your account, and provide customer support. Account information is kept on secure servers and is only accessible to authorized personnel.

2.3 License and Activation Data

When paid licensing becomes available, we will collect information necessary to validate your license, including unique device identifiers and license keys. This information helps us prevent license abuse and unauthorized use. License validation occurs periodically through secure, encrypted connections. We do not store the contents of your files on our servers for license validation purposes.

2.4 Usage Analytics and Diagnostic Information

We collect anonymized usage analytics to improve the Software's performance, stability, and user experience. This may include information about which features you use, how frequently you use them, and whether the Software encounters errors or crashes. This data is aggregated and does not identify you personally. Diagnostic information may include your operating system version, device type, application version, and error logs. This information helps us identify bugs, optimize performance, and prioritize feature development. You may disable analytics collection through the Software's settings, though some critical diagnostic information may still be collected for security and stability purposes.

2.5 Update Check Information

Riflet automatically checks for software updates to ensure you have access to the latest features, security patches, and bug fixes. During these checks, we receive information about your current application version and operating system to determine which updates are applicable to your system. This information is used solely for delivering appropriate updates and is not used for marketing or profiling purposes.

2.6 Third-Party Service Integration Data

If you enable integration with third-party AI services or other external platforms (such as Claude, ChatGPT, or similar services), you are providing those services with access to the content you explicitly choose to share with them. Any data shared with third-party services is governed by their respective privacy policies. Riflet does not control how third-party services handle your data. You are responsible for reviewing the privacy policies of any third-party services you choose to integrate with and for understanding how those services will process your information.

2.7 Communication Data

If you contact us through email, support forms, or other communication channels, we collect your message content, email address, and any attachments you send for the purpose of responding to your inquiry and providing support. We may also collect information about the subject of your inquiry, its urgency, and any follow-up correspondence. This information is retained for a reasonable period to ensure we can provide adequate support and resolve your issues.

3. How We Use Your Information

We use the information we collect for the following purposes:

Service Delivery and Improvement: We use information to provide, operate, maintain, and improve the Software, including developing new features and services. We analyze usage patterns to understand how users interact with the Software and identify areas for enhancement. This helps us deliver better experiences and address technical issues.

Communication: We use your contact information to communicate with you about your account, respond to your inquiries, provide customer support, and send administrative notices. If you have opted in to marketing communications, we will use your information to send you promotional emails about new features, updates, and offers. You may opt out of marketing communications at any time by clicking the unsubscribe link in our emails or adjusting your communication preferences.

License Management: We use license and activation information to enforce license terms, prevent unauthorized use, and detect license fraud. This includes periodic checks to ensure your license remains valid and in compliance with our terms.

Security and Fraud Prevention: We use information to detect, prevent, and address fraud, abuse, and security issues. This includes monitoring for suspicious activity, unauthorized access attempts, and violations of our Terms of Service. We may use this information to protect the integrity and security of our systems and users.

Legal Compliance: We use information as required by law, court orders, or requests from government agencies. We may disclose information when we believe in good faith that disclosure is necessary to comply with applicable laws, enforce our agreements, protect our rights, or protect the safety of our users or the public.

Analytics and Research: We use aggregated and anonymized data to conduct research, generate reports, and understand usage trends. This information helps us make informed decisions about future development and helps us improve the Software for all users.

4. Data Sharing and Third Parties

We are committed to protecting your privacy and only share your information under specific circumstances. We do not sell, rent, or lease your personal information to third parties for marketing purposes.

Service Providers: We may share information with trusted service providers who assist us in operating the Software, processing payments, hosting data, performing analytics, and providing customer support. These service providers are contractually obligated to use your information only for the purposes we specify and are required to maintain the confidentiality and security of your information. Examples may include cloud hosting providers, email service providers, and analytics platforms.

Business Transfers: If Riflet is merged, acquired, or substantially all of its assets are transferred, your information may be transferred as part of that transaction. You will be notified of any such change and any choices you may have regarding your information.

Legal Obligations: We may disclose information when required by law, such as in response to subpoenas, court orders, or regulatory requests. We may also disclose information when we believe in good faith that such disclosure is necessary to enforce our Terms of Service, protect our rights or safety, or protect the rights and safety of others.

Third-Party Services You Choose: When you explicitly choose to integrate the Software with third-party services, Riflet transmits only the data you authorize. You are responsible for reviewing and accepting the privacy practices of those third parties. Riflet is not responsible for how third-party services handle your data.

Anonymized and Aggregated Data: We may share anonymized, aggregated information with partners and the public without restriction. This data cannot identify you and is used for research, marketing, analytics, and other purposes.

5. Data Security

We implement comprehensive security measures to protect your information from unauthorized access, alteration, disclosure, or destruction. Our security practices include encryption, secure communication protocols, access controls, and regular security assessments. However, no method of transmission over the internet or electronic storage is completely secure. While we strive to use industry-standard security measures, we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of any usernames and passwords associated with your account.

Since Riflet primarily processes files on your local device, the security of your files depends on the security of your own computer system. We recommend maintaining strong passwords, keeping your operating system and antivirus software up to date, and using a secure network connection, particularly when accessing any cloud-based features or integrations.

Data transmitted between the Software and our servers is encrypted using TLS/SSL protocols. License validation and update checks are performed through secure channels. Analytical data is transmitted with encryption and is stored on secure servers with restricted access. We conduct regular security audits and penetration testing to identify and address vulnerabilities.

6. Data Retention

We retain your information for as long as necessary to provide the Software, comply with legal obligations, enforce our agreements, and resolve disputes. The retention period varies depending on the type of information and the purposes for which we use it.

Account Information: Account information is retained for as long as your account is active and for a reasonable period afterward to ensure we can respond to inquiries and comply with legal obligations. If you request deletion of your account, we will delete your personal information within thirty days, except where retention is required by law.

Usage Analytics: Anonymized usage analytics are retained indefinitely for research and improvement purposes since they cannot identify you. Non-anonymized analytics and diagnostic information are typically retained for twelve months, after which they are deleted or anonymized.

Communication Records: Support communications and inquiries are retained for two years to ensure we can provide adequate follow-up support and for dispute resolution. Marketing communications records are retained for twelve months or until you opt out, whichever is earlier.

License and Activation Data: License activation information is retained for as long as your license is active and for twelve months afterward for audit and compliance purposes.

Backup and Archival Data: Even after deletion, information may persist in backup systems for an additional thirty days for security and disaster recovery purposes. We do not selectively restore information from backups for individual deletion requests.

7. Your Data Rights and Choices

Depending on your jurisdiction, you may have certain rights regarding your personal information. We are committed to honoring these rights to the extent required by applicable law.

Right of Access: You have the right to request access to the personal information we hold about you. We will provide you with a copy of your information in a structured, commonly used, and machine-readable format within thirty days of your request, subject to verification of your identity.

Right to Correction: You have the right to request correction of inaccurate or incomplete personal information. You may update certain account information directly through your account settings, or you may contact us to request corrections to information we maintain.

Right to Deletion: You have the right to request deletion of your personal information, subject to certain exceptions. We will delete your information within thirty days unless we are required to retain it by law, for backup purposes, or to enforce our agreements. Note that deletion of account information does not delete your local files processed by the Software.

Right to Data Portability: You have the right to request your information in a portable, machine-readable format. We will provide your account information to you or transfer it to another service provider as directed, within thirty days of your request.

Right to Object: You have the right to object to our processing of your information for certain purposes, including direct marketing. You may opt out of marketing communications at any time by clicking the unsubscribe link in our emails or adjusting your preferences. You may also disable analytics collection through the Software's settings, though some diagnostic information may still be collected for security purposes.

Right to Withdraw Consent: Where we have obtained your consent for a specific processing activity, you have the right to withdraw that consent at any time. Withdrawal will not affect the lawfulness of processing conducted prior to your withdrawal.

Right to Lodge a Complaint: You have the right to lodge a complaint with your local data protection authority if you believe we have violated your privacy rights or failed to comply with applicable data protection laws.

To exercise any of these rights, please contact us using the information provided in the Contact section of this Policy. We will respond to all requests within the timeframe required by applicable law. To protect your privacy, we may request verification of your identity before fulfilling your request.

8. International Data Transfers and Compliance

GDPR Compliance (European Economic Area): If you are located in the European Economic Area, your personal information is protected under the General Data Protection Regulation (GDPR). We process your information lawfully based on one or more of the following legal bases: your consent, performance of a contract with you, compliance with legal obligations, protection of vital interests, performance of a task in the public interest, or our legitimate interests. Our legitimate interests include improving and securing the Software, preventing fraud, and analyzing usage patterns. We have implemented appropriate safeguards, including standard contractual clauses and adequacy decisions where applicable, to ensure that your information is protected when transferred outside the EEA.

CCPA Compliance (California): If you are a California resident, you are entitled to the following rights under the California Consumer Privacy Act (CCPA): the right to know what personal information is collected, used, shared, or sold; the right to delete personal information collected from you; the right to opt-out of the selling or sharing of your personal information; the right to correct inaccurate personal information; and the right to restrict use of sensitive personal information. We do not sell your personal information in the traditional sense, but we may share information with service providers for analytics and improvement purposes, which may be considered "sharing" under CCPA. You may submit a request to exercise these rights by contacting us. We will verify your identity and respond within forty-five days. You have the right to appeal our decision if you disagree.

PIPEDA Compliance (Canada): If you are a Canadian resident, your personal information is protected under the Personal Information Protection and Electronic Documents Act (PIPEDA). We collect and process your information with your knowledge and consent, except where otherwise permitted by law. You have the right to access your personal information, request correction of inaccurate information, and request deletion of your information, subject to legal exceptions. We will respond to all requests within thirty days. You may file a complaint with the Privacy Commissioner of Canada if you believe we have violated PIPEDA.

Other Jurisdictions: We are committed to complying with applicable data protection and privacy laws in all jurisdictions where we operate. If you are located in a jurisdiction with specific data protection laws (such as Brazil's LGPD, Australia's Privacy Act, or others), we will comply with those laws. Please contact us if you have questions about how your information is protected under your local laws.

Data Transfers: When we transfer information internationally, we use appropriate safeguards such as standard contractual clauses and adequacy decisions. Where applicable, we have obtained approval from relevant data protection authorities for our data transfer mechanisms. If you are in the EU and object to international transfers, you may contact us to discuss alternatives.

9. Children and Minors

Riflet is not intended for children under the age of thirteen (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If we discover that we have collected personal information from a child without verifiable parental consent, we will immediately delete such information and terminate the child's account if applicable. Parents or guardians who believe their child has provided information to us should contact us immediately.

For users between thirteen and eighteen (or the applicable age of majority in your jurisdiction), we provide additional privacy protections. We limit the collection of information from minors to what is necessary to provide the Software and will not use such information for marketing or profiling purposes without explicit parental consent. Minors have all the data rights described in this Policy and may request deletion of their information at any time.

10. Cookies and Tracking Technologies

Riflet's desktop application does not use traditional cookies in the same manner as web applications. However, the Software may use local storage mechanisms to save your preferences, recent files, settings, and other user-specific information on your device. This information is stored locally and is not transmitted to our servers unless you explicitly enable cloud features or integrations.

If you access Riflet through a web-based portal or dashboard (if available in future versions), we may use cookies and similar tracking technologies to improve your experience, remember your preferences, and analyze usage. These technologies help us understand how you interact with the service and allow us to tailor features to your needs. You may control cookie settings through your browser preferences, though disabling cookies may limit certain functionality.

11. Third-Party Links and Services

Riflet may contain links to third-party websites, applications, and services that are not operated by us. This Privacy Policy applies only to information collected through Riflet. When you access third-party services, you are subject to their privacy policies and terms of service. We encourage you to review the privacy policies of any third-party services before providing them with your information. We are not responsible for the privacy practices of third-party services, and your use of such services is at your own risk.

12. Marketing Communications

We may use your email address to send you promotional communications about new features, updates, special offers, and other information we think may be of interest to you. You may opt out of marketing communications at any time by clicking the unsubscribe link in our emails or by adjusting your communication preferences in your account settings. Opting out of marketing communications will not affect transactional emails such as account confirmations, support responses, or important security notices.

We will never sell or share your email address with third parties for their marketing purposes without your explicit consent. If we use a third-party email service provider, they are contractually obligated to use your information only for sending messages on our behalf and to maintain its confidentiality.

13. Policy Updates and Changes

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. We will notify you of any material changes by posting the updated Privacy Policy in the Software and updating the "Last Updated" date at the top of this document. Your continued use of the Software following the posting of an updated Privacy Policy constitutes your acceptance of the changes. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information. If we make significant changes that materially alter how we use your information, we will provide additional notice, such as through email to registered account holders.

14. Contact Us

If you have questions about this Privacy Policy, concerns about how we handle your information, or if you wish to exercise any of your rights under applicable data protection laws, please contact us using the information below. We will respond to all inquiries within thirty days.

Support Email: You may reach our privacy and support team through the contact form on our website or via email at the address provided in the Software's support section. When contacting us, please provide as much detail as possible about your inquiry and include your email address so we can respond to you.

Mailing Address: You may also submit written inquiries to the address listed on our website or within the Software's documentation.

Data Protection Officer: If you are located in the EU or have GDPR-related inquiries, you may contact our Data Protection Officer through the contact information provided on our website.

Response Times: We are committed to responding to all privacy-related inquiries promptly. For data access requests, corrections, deletions, or other rights requests, we will respond within the timeframe required by applicable law, typically within thirty days. If we cannot fulfill your request, we will explain the reason and advise you of your rights.

15. Definitions

Personal Information: Any information that identifies you or could reasonably be used to identify you, including but not limited to your name, email address, account information, usage information linked to your account, and any information you provide through communications with us.

Processing: Any operation performed on personal information, including collection, recording, organization, structuring, storage, adaptation, retrieval, consultation, use, disclosure, combination, or erasure.

Anonymized Information: Information that has been processed or modified such that it cannot identify you and cannot be reasonably connected back to you, even with additional information. Anonymized information is not subject to this Privacy Policy.

Aggregated Information: Information about groups of users that has been combined and summarized so that it does not identify any individual. This information is not subject to this Privacy Policy.