Skip to content
riffraff

Legal

privacy policy.

What riffraff does with personal data, who it is shared with, and how long it is kept. Written to be read rather than to be survived.

In effect from 9 September 2026

Who we are

riffraff is a spam scoring service operated by Registered company name to be confirmed , a company registered in England and Wales, company number Company number to be confirmed , registered office Registered address to be confirmed .

We are registered with the Information Commissioner's Office under registration ICO registration number to be confirmed .

Controller or processor

We act in two different capacities, and it matters which one applies.

For your account, we are the controller. That is your name, your email address, your team, your billing record and how you use the service.

For the submissions you send us to score, we are a processor and you are the controller. Those submissions come from people filling in forms on your website, not from you, and we only handle them on your instructions. If you are an agency running riffraff on behalf of a client, that client is usually the controller and you should say so in your own contract with them.

What we handle

As controller, for your account:

  • Your name and email address, and your password stored as a hash
  • Your team, your role in it, and any invitations you send
  • Two-factor authentication secrets and recovery codes, encrypted, if you turn it on
  • Your subscription and payment records, held by our payment processor rather than by us
  • API tokens you create, stored as hashes

As processor, for each submission you send to be scored, we keep a record containing:

  • The sender's email address, if your integration sends one
  • The subject line, if your integration sends one
  • The score, the verdict, and the reasons the rules gave
  • The time, the team and the API token used

You decide what reaches us. If your form collects a phone number, a postcode or anything else and your integration puts it in the message it sends us, it is scored and then discarded with the rest of the message body, as described below.

What we do not keep

We do not store the body of the messages you send us. It is held in memory long enough for the rules to score it, and then it is gone. It is not written to our database, and it is not used to train anything, because there is nothing to train: the rules are deterministic and hand written, with a published reason for every point they award.

This is a deliberate design decision rather than a promise about intent. It is also why the evaluations list shows you a sender and a score but never the message itself.

Why we may do it

For your account data, our lawful basis is performance of our contract with you, and our legitimate interest in securing the service and keeping proper records.

For submissions, we process on your documented instructions as your processor. Establishing your own lawful basis for scoring your form submissions, and telling the people filling in those forms that you do it, is your responsibility as controller. Our advice is to name riffraff in your own privacy notice.

How long we keep it

Evaluation records are deleted 1 year after they are created. This runs automatically every day, so the figure describes what happens rather than what we intend to happen.

Account data is kept while your account is open. Close it and we delete your account and its evaluation records, other than anything we are required to keep for tax and accounting, which is six years for billing records.

Who else sees it

We do not sell personal data and we do not share it for anyone else's marketing. We use these sub-processors:

Who What for Where
Laravel Forge and its underlying hosting provider Application hosting and the database holding evaluation records Region to be confirmed
Mailgun Sending account, digest and alert email European Union, when the EU endpoint is configured
Stripe Subscription billing and payment processing United States, under its own transfer safeguards

If you have configured a webhook, we send evaluation records to the address you gave us. Where that data then goes is yours to control.

If you have turned on borderline alerts, we email the addresses you nominated, and those emails contain the sender address and subject of the submission concerned. Only nominate people who should see that.

Security

  • Everything is served over TLS. The API refuses plain HTTP
  • Passwords are hashed, API tokens are stored as hashes, and two-factor secrets are encrypted at rest
  • Two-factor authentication is available on every account and we recommend it
  • Access to production is limited to staff who need it
  • Not storing message bodies is itself a security control: what is not kept cannot be lost

Your rights

Under UK GDPR you can ask for a copy of your data, ask us to correct or delete it, object to or restrict what we do with it, and ask for it in a portable form. Write to [email protected] and we will answer within one month.

If your request is about a submission scored on someone else's website, that site's owner is the controller and we will pass your request to them rather than acting on it ourselves.

Contact and complaints

Email [email protected] about anything on this page.

If we do not put something right, you can complain to the Information Commissioner's Office at ico.org.uk. We would rather you told us first.