Skip to content

Security

Safe for your team. Safe for your agents.

To keep your data safe, RiffAds keeps each workspace separate: our servers check that you belong to it before they show or change its data. Files are private and shared through links that expire. AI agents spend only within limits your team controls.

The short answer

Is RiffAds safe to use?

RiffAds is built to keep your data safe and your spend in check. Workspaces are kept separate, files are private and shared through links that expire, and passwords and API keys are stored as hashes. Content is checked before credits are held, AI agents are capped by limits your team sets, and RiffAds never posts to your social accounts.

Last reviewed

At a glance

  • Each workspace is kept separate
  • Private files, links that expire
  • API keys stored only as hashes
  • Content checked before credits are held
  • Agent spend capped by limits you set
  • Never posts to your social or ad accounts

Protections

How your workspace is protected

What RiffAds does today to keep your work, your keys and your credits safe. Each point describes how the product works now.

  • Each workspace is kept separate

    Your files, generations, API keys and credits belong to one workspace. Our servers, not your browser, decide which workspace a request is for, and check that you are a member before they show or change its data.

  • Roles for your team

    Each person is an owner, an admin or a member. Everyone in a workspace can see its content and usage. Only owners and admins manage API keys and agent spend limits, and only they see pending invitations.

  • Verified email, hashed passwords

    Sign in with email and password, or with Google. A new email address must be verified before it can sign in, and passwords are stored only as hashes, never in plain text.

  • API keys with scopes

    Every key belongs to a workspace. Its Read scope spends nothing, and spending needs a scope you add on purpose: Generate or Workflows. A key is shown once, stored only as a hash, and stops working when you revoke it.

  • AI apps you approve

    An AI app such as Claude or Cursor connects only after you approve it. Its token is checked on every call, you can set the connection to read only, and disconnecting it deletes its tokens.

  • Spend limits for agents

    Every agent job must name the most it may spend, and a job over that is refused, never trimmed. By default a workspace also caps agents at 600 credits a job and 2,000 credits a day.

  • Private files, links that expire

    Uploads and outputs are stored in private Cloudflare R2 storage. You open them through links that expire after a short time, and links given to an AI agent expire after 10 minutes.

  • Signed webhooks

    Each event is signed with HMAC SHA-256 in the webhook-signature header. The signing secret is shown once and stored encrypted with AES-256-GCM. Endpoints must be public https, and events carry ids, never file links.

  • Card details stay with Dodo Payments

    You pay on a checkout page run by Dodo Payments, the merchant of record, not on our site. RiffAds never sees or stores your full card number.

  • Checked before credits are held

    Scripts, prompts and uploaded images are checked before any credits are held or work starts. The same checks run in the app, the API, MCP, the CLI and workflows.

  • Consent before a voice clone

    Before a voice is cloned in the app, you confirm you have the right to clone it. We keep that confirmation with your user, workspace, IP address and the time, and the sample is safety checked first.

  • Never touches your accounts

    RiffAds does not connect to your social media or ad accounts, and it never posts anything. Every finished file comes back as a download link, and where it goes next is up to you.

The four limits on agent spend

An agent's own number is only the first limit. Your workspace's owners and admins control the other three, and every agent job must fit under all four.

The four limits on agent spend
LimitWho sets itDefaultMeasured over
The job's max_creditsThe agent, on every callRequired, no defaultOne job
Workspace limit per jobOwner or admin600 creditsOne job
API key budgetOwner or adminNo limitRolling 24 hours
Workspace daily limitOwner or admin2,000 creditsRolling 24 hours
  • The lowest limit wins, and a refused job says which limit stopped it.
  • A limit set to 0 means agents may not spend at all.
  • These limits apply to agents only, not to people working in the studio.

Your data

Where your data goes

RiffAds does not run its own AI models. To create your outputs, we send your inputs to third-party AI providers. They process the inputs and send back the result.

The service providers RiffAds uses, from the Privacy Policy
ProviderKindWhat it does for RiffAds
VercelHostingHosts our website, documentation site, app, API and MCP server.
NeonHostingDatabase.
Cloudflare R2HostingFile storage.
Trigger.devHostingBackground jobs that process media, and live progress updates.
fal.aiAICreates talking actor videos, other videos, images, music, voice changes, captions and other media.
OpenRouterAISends text and image requests to models from companies such as Google, Anthropic, OpenAI and xAI, to write and translate scripts, run chat tools, read pages you import and run safety checks.
ElevenLabsAITurns scripts into speech, clones voices from samples and designs voices from descriptions.
DeepgramAITurns voice clone samples into text so we can run a safety check.
Dodo PaymentsPaymentsCheckout, subscriptions and invoices, as the merchant of record.
ResendEmailSends account emails, such as email verification and password reset.
GoogleSign-inSign-in, if you choose to sign in with Google.
PostHog, Google Analytics, RB2B and Vercel Web AnalyticsAnalyticsMeasure how the site and the app are used, where turned on.
From our Privacy Policy

We do not train our own AI models on your content, and no-training is turned on with our AI providers. fal.ai, OpenRouter and the models it routes to, ElevenLabs and Deepgram do not use your content to train their models.

One exception worth knowing: when you create an actor, the analytics event we send includes the words you typed to describe the actor, and it goes to our analytics provider when analytics is turned on.

These providers may keep inputs and outputs for a time under their own terms. For example, ElevenLabs keeps a history of the speech it creates for us.

We and our service providers process data in the United States and other countries.

Read the full Privacy Policy

AI actors in ads

Using AI actors safely in ads

RiffAds makes the ad. You publish it, so the rules of each platform and each country apply to you as the advertiser. These are the ones that matter most for AI actors today.

Three rules to follow

Our records mark each output as AI generated, and webhook events about generated files carry a line that says so and asks you to disclose it where you publish.

  1. Say it is AI, in the ad itself

    On TikTok, turn on "This ad contains AI-generated content" in Ads Manager, or add your own clear label. In the EU, a realistic AI person can count as a deep fake, and the label must be visible or audible: an invisible watermark alone is not enough.

  2. Never present an AI actor as a real customer

    A line like "I used this and it worked" is a testimonial. The FTC says its rule does not ban AI avatars, but it does ban testimonials that misrepresent that the person exists or used the product.

  3. Use a real face or voice only with written consent

    Our Acceptable Use Policy requires written consent from any real person you show or clone, unless that person is you. TikTok also bans ads that misuse a public figure's likeness without permission.

Report

Report a security issue

Found a vulnerability? Email hello@riffads.com with the steps to reproduce it. This is the contact in our security.txt file, and we will confirm receipt.

Email hello@riffads.com

If you think your account or an API key is at risk, email hello@riffads.com right away. Revoke keys and remove app connections you no longer use, and set spending budgets on your API keys.

/.well-known/security.txt
Contact: mailto:hello@riffads.comPreferred-Languages: enCanonical: https://riffads.com/.well-known/security.txtPolicy: https://riffads.com/acceptable-use
View security.txt

FAQ

Security questions

Still unsure? Book a call

RiffAds is built to keep your work private and your spend under control. Each workspace is separate, files open only through links that expire, passwords and API keys are stored as hashes, content is checked before credits are held, and AI agents spend only within limits your team sets. No system is completely secure. Keep your keys safe and revoke the ones you no longer use.

No. We do not train our own AI models on your content, and no-training is turned on with our AI providers. fal.ai, OpenRouter and the models it routes to, ElevenLabs and Deepgram do not use your content to train their models. These providers may keep inputs and outputs for a time under their own terms. For example, ElevenLabs keeps a history of the speech it creates for us.

The members of your workspace. Files are private and open only through links that expire after a short time, and links given to an AI agent expire after 10 minutes. Anyone who has a link can open the file until the link expires, so share links with care. Authorized staff can access accounts, workspace content and generation details when needed to run the service, give support, investigate abuse or meet legal duties.

An agent can spend only up to your workspace's limits. Every agent job must name the most it may spend, and a job that costs more is refused. By default, agents may spend at most 600 credits a job and 2,000 credits a day in a workspace, and each API key can have its own 24 hour budget. A workspace owner or admin can change these limits, or set one to 0 so agents cannot spend at all.

No. RiffAds does not connect to your social media or ad accounts, and it never posts anything. You get a download link to each finished file, and you decide where it goes. When you publish an ad with an AI actor, label it as AI where the platform or the law asks you to.

Email hello@riffads.com from the email address on your account and ask us to delete your data. We will delete or anonymize your personal data, except what we must keep for legal, tax, billing and safety reasons, and tell you what we keep and why. The Privacy Policy lists how long each kind of record is kept.

Email hello@riffads.com with the steps to reproduce the issue, and the page, URL or API endpoint where you found it. It is the contact listed in our security.txt file at riffads.com/.well-known/security.txt, and we will confirm receipt.

Stop waiting on creators. Ship the ad today.

Book a call for a walkthrough, or log in and make your first ad.

New here? Try Growth for $1