Effective Date: August 30, 2026
This Privacy Policy explains how Risus collects, uses, discloses, stores, and protects information when you use the Risus mobile app, website, APIs, and related services, together called the "Service."
If you do not agree with this Privacy Policy, do not use the Service.
Data Protection Officer: For privacy-related questions, account deletion requests, data access requests, or other privacy concerns, contact our privacy team at privacy@risus.io.
This Privacy Policy applies to all users of the Risus mobile app, website, APIs, and related services (the "Service"). It covers the information we collect when you browse, register, post content, send messages, use AI-assisted features, or otherwise interact with the Service. It does not apply to third-party services that may be linked from our platform — those services have their own privacy policies.
We collect information you provide directly, content and activity you create or interact with, information collected automatically as you use the Service, and information we receive from other users and third parties.
Name, display name, username, email & profile details
Password credentials or authentication tokens (hashed where applicable)
Verification information (OTP, email verification, session security)
Google sign-in details, if you sign in with Google
Apple sign-in details, if you sign in with Apple
Posts, pings, reposts, captions, comments, reactions, likes & bookmarks
Chat rooms, direct messages, attachments, message status & related metadata
Uploaded images, videos, audio & documents
Reports, moderation requests, block/mute actions, appeals & support messages
AI prompts, generated outputs, feedback, moderation signals & usage logs
Device, network, app version & diagnostic logs
Notification tokens & delivery status
Media metadata (creation time, device info, embedded location)
When you sign in with Google, we use only the Google account identifier, name, email address, and profile image that you authorise. When you sign in with Apple, we use only the Apple user identifier, and the name and email address you authorise — including Apple’s private relay email if you choose to hide your email from us. With your permission, the Service may access your camera, microphone, selected photos, selected videos, or media files so you can create posts, send messages, upload profile content, scan codes, generate captions, or use media-related features. Risus may infer an approximate country or region from an IP address for security, fraud prevention, analytics, or localization where enabled. Uploaded images and videos may also contain creation time, device information, or location metadata embedded in the file. Risus does not collect device GPS or other precise location through Android location permissions unless a specific feature requires it, the permission is requested in context, and this Privacy Policy and the Data Safety declaration are updated. Risus seeks to avoid retaining or publicly exposing media location metadata when it is not needed. We may also receive information about you when other users message you, tag you, report your account or content, invite you to rooms, or interact with your content, and from service providers such as authentication, hosting, analytics, crash reporting, security, moderation, AI, email, SMS verification, and support providers.
Because Risus is a social and messaging platform, some content may be visible to other users depending on your settings, the feature used, and the way you share content on Risus.
Creating and authenticating your account, securing it, and delivering the core features of the platform.
Processing posts, pings, messages, media, and AI-assisted captions, suggestions, and enhancements.
Reviewing reports, enforcing policies, preventing abuse, protecting users, and meeting legal and child-safety obligations.
When you use AI features, or when content is screened for safety and moderation, Risus may process images, videos, captions, text prompts, editing instructions, reported content, and other content submitted to or analyzed by AI features; generated outputs, edits, feedback, usage logs, lyrics, music type, genre, style, mood, and related music-generation instructions; and moderation and safety signals needed to prevent abuse, spam, fraud, illegal content, child-safety violations, or other policy violations.
Risus uses third-party AI and automated-processing providers. These services support caption generation, image generation and editing, image and video analysis, content moderation, safety detection, and music generation.
Caption generation, content analysis, content suggestions, and safety classification.
Image generation and image editing.
Image and video analysis, content moderation, and safety detection.
Content moderation and safety detection across images and video.
Music and audio generation from lyrics, music type, genre, style, and mood instructions.
Depending on the feature used or safety process involved, Risus may transmit the information listed above to one or more of these providers. Processing is limited to providing the requested feature, analyzing or moderating content, detecting abuse or illegal activity, maintaining platform safety and reliability, and complying with applicable legal or safety obligations.
Risus shares only the minimum information reasonably required and does not intentionally include unrelated account, profile, contact, or precise-location information. Do not submit confidential, sensitive, illegal, or private information to optional AI features unless you are authorised to do so and understand the applicable processing.
Where third-party processing of personal or sensitive user data would not be reasonably expected, Risus provides a clear in-app disclosure describing the data, the purpose, and the type of service provider, and obtains affirmative consent before processing begins. You may decline optional AI processing by not using the relevant optional feature.
Risus reviews the privacy, data-retention, security, human-review, and model-training terms applicable to each provider and service configuration. Risus also keeps this Privacy Policy and its Google Play Data Safety declaration aligned with the collection, transmission, processing, and sharing performed through these services.
Where required by law, we process personal data under one or more of the following legal bases:
To provide the Service and the features you request.
Where you grant permission for camera, microphone, media access, notifications, optional AI features, or similar controls.
Such as safety, security, fraud prevention, service improvement, analytics, reliability, and moderation.
Such as responding to lawful requests and preventing or reporting child sexual abuse, exploitation, or other illegal activity where required.
Personal information is stored in secure servers located in Cloud infrastructure operated by trusted hosting providers.
Your information may be processed in countries other than where you live. Where required, we use appropriate safeguards for international data transfers.
Risus uses trusted third-party providers for hosting and cloud infrastructure, storage, authentication (including Google Sign-In and Sign in with Apple), analytics, crash reporting, performance monitoring, push notifications, AI processing, email delivery, SMS verification, content delivery networks, media processing, moderation, trust and safety, security, abuse prevention, and support. Providers are expected to implement appropriate security measures and may process information only for contracted, disclosed, or legally permitted purposes. Risus remains responsible for evaluating third-party practices, limiting data use to app functionality and policy-conforming purposes, and preventing the sale or unrelated use of personal and sensitive user data. Risus does not sell personal information. If this changes, this Privacy Policy and the required privacy disclosures will be updated before the change takes effect.
Information may be shared in the following ways:
Content you post, send, or make visible may be shown to other users according to your use of the Service and your privacy settings.
Providers that help us host, secure, analyse, moderate, deliver, and support the Service, acting on our behalf.
Where required by law, to protect rights and safety, to investigate abuse, to prevent harm, or to report illegal content.
In a merger, acquisition, financing, restructuring, or asset sale, subject to appropriate safeguards.
When you direct us to share information or use features that intentionally share content.
Data transmitted between your device and our servers is protected using modern cryptography such as HTTPS/TLS.
Access to personal data is restricted to authorised personnel on a need-to-know basis, with monitoring of unusual activity.
We conduct regular security reviews and monitoring. No system is completely secure, and we cannot guarantee absolute security.
We keep information only as long as needed to provide the Service and meet legal, safety, and dispute obligations. Reports and enforcement records may be kept longer, and backups persist for a limited time during normal backup cycles.
We may disclose information when required by law, to protect rights and safety, to investigate abuse, to prevent harm, or to report illegal content. If Risus is involved in a merger, acquisition, financing, restructuring, or asset sale, information may be transferred as part of that transaction, subject to appropriate safeguards.
We keep information for as long as needed to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain safety, prevent abuse, and protect the integrity of the Service.
Generally kept while your account is active.
Kept until deleted by you or removed under our policies, unless retention is required for safety, legal, backup, abuse-prevention, or dispute reasons.
Kept for a limited period needed for debugging, security, and reliability.
May be kept longer to protect users and prevent repeat abuse.
Retained for the period needed to provide the feature, investigate abuse, maintain safety and reliability, resolve disputes, or satisfy legal duties. Third-party retention is governed by the applicable provider service, configuration, and contract reviewed by Risus.
May persist for a limited time during normal backup and disaster-recovery cycles.
If you created an account, you may request account deletion in the app and through our public web deletion page.
Settings > Account > Delete Account.
https://risus.io/delete-request — available without signing in to the app.
privacy@risus.io
When deletion is completed, Risus deletes or anonymizes personal data associated with your account unless limited retention is required or permitted for legal, security, fraud-prevention, moderation, dispute, backup, or safety reasons.
Temporary deactivation, freezing, or hiding an account is not the same as account deletion.
Depending on your location, you may have rights to access, correct, download, delete, restrict, or object to the processing of your personal data. You may withdraw consent for optional permissions through device settings and may decline optional AI processing by not using the relevant feature. To make a privacy request, contact us at privacy@risus.io. We may need to verify your identity before responding, and we aim to respond within the timeframes required by applicable law.
Art. 15 GDPR / CCPA
Request a copy of the personal data we hold about you and information about how we process it.
Art. 16 GDPR
Request correction of inaccurate or incomplete personal information we hold about you.
Art. 17 GDPR / CCPA
Request deletion of your account and associated personal data, subject to legal and safety retention requirements.
Art. 18 GDPR
Request that we restrict processing of your personal data under certain conditions.
Art. 20 GDPR
Receive your personal data in a structured, commonly used, machine-readable format.
Art. 21 GDPR
Object to the processing of your personal data, including for direct marketing purposes.
Art. 7(3) GDPR
Withdraw optional permissions (camera, microphone, notifications, media access) at any time through your device settings. Withdrawing consent does not affect prior lawful processing.
Art. 77 GDPR
Lodge a complaint with a supervisory authority if you believe our processing violates applicable data protection laws.
Contact us at privacy@risus.io to exercise any of these rights. You can also control app permissions, and withdraw optional consents such as camera, microphone, notifications, or media access, through your device settings.
You can control app permissions through your device settings. Disabling permissions may limit features such as posting photos, recording videos, sending media, scanning codes, receiving notifications, or using AI media features.
Risus requests sensitive permissions only when needed and in context. Where collection or sharing would not be reasonably expected, Risus provides a prominent in-app disclosure and obtains affirmative consent before access or processing begins. Permissions that are not necessary for a current user-facing feature are removed from the app.
Risus is not directed to children under 13 and is intended only for users who are at least 13 years old, or the higher minimum age required in their country. In compliance with the Children's Online Privacy Protection Act (COPPA), Risus does not knowingly collect, use, or disclose personal information from children under 13 without legally valid authorization.
You must be at least 13 years old (or the higher minimum age required in your country) to create an account. Certain features may have a higher age requirement and may be unavailable to minors. If you are under the age of legal majority in your jurisdiction, you confirm that you have parental or guardian consent where required by law. Accounts determined to belong to users below the applicable minimum age may be suspended, restricted, or permanently removed.
If we discover that a user under the age of 13 has created an account or provided personal information, we will take appropriate steps to remove the account and delete the associated data, subject to legal, safety, security, moderation, and backup retention requirements.
Parents or legal guardians who believe their child has provided personal information to Risus may contact us at privacy@risus.io. Risus also prohibits content or conduct that exploits, endangers, sexualizes, abuses, or harms children — see our Child Safety and CSAE Standards for more information and for the child safety reporting contact.
Risus maintains a strict, zero-tolerance policy against Child Sexual Abuse and Exploitation (CSAE). We explicitly prohibit any content, behavior, or activity that sexually exploits, abuses, or endangers children — including grooming, sextortion, trafficking, and the sharing of exploitative material.
Any user found violating our child safety standards will face immediate and permanent account termination and may be reported to the appropriate authorities, including NCMEC and local law enforcement.
Child Sexual Abuse Material is immediately removed, the offending account disabled, and the incident reported to NCMEC and relevant law enforcement.
Users can report suspicious behavior or content by visiting the post or profile, selecting "Report" or "Flag", and choosing the appropriate safety category.
Dedicated Child Safety Contact
For safety enforcement questions or severe escalations, contact our Child Safety Point of Contact directly.
For residents of the United States, the following rights may apply under the California Consumer Privacy Act (CCPA), the California Privacy Rights Act (CPRA), and other applicable state privacy laws.
Request disclosure of the categories and specific pieces of personal information we have collected, the sources, our purposes, and any third parties with whom we share it.
Request deletion of personal information we have collected, subject to exceptions for legal compliance, safety, and fraud prevention.
Request correction of inaccurate personal information we hold about you.
Risus does not sell personal information and does not share personal information for cross-context behavioural advertising.
Request that we limit our use of sensitive personal information to what is necessary to provide the Services.
We will not discriminate against you for exercising any of your privacy rights.
Submit requests by emailing privacy@risus.io. We will verify your identity by comparing the information you provide with our records before processing your request.
We maintain security measures designed to protect your personal data. In the event of a data breach that poses a risk to your rights and freedoms, we have procedures to promptly identify, assess, and respond.
Security monitoring helps detect anomalous activity. Upon detection, we work to contain the breach and assess its scope and impact.
Where required by applicable law (for example, the GDPR 72-hour rule), we notify the relevant supervisory authority within the legally required timeframe.
Where a breach is likely to result in high risk to your rights and freedoms, we will notify affected users promptly with information about what happened and what steps to take.
We take steps to remediate the breach and provide guidance to affected individuals on how to protect themselves.
If you have questions about a potential breach or believe your account may have been compromised, contact us immediately at privacy@risus.io.
We may update this Privacy Policy as the Service, our providers, or legal requirements change. We will update the date shown at the top of this page and provide additional notice where required.
If a material change requires renewed consent, Risus will request that consent before the affected processing begins.
Have questions about our privacy policy? We're here to help.