---
title: "Safe for your team. Safe for your agents."
url: "https://riffads.com/security"
description: "Is RiffAds safe? How RiffAds protects your workspace, files and credits: private files, hashed API keys, spend limits for AI agents, and where your data goes."
updated: "2026-09-25"
source: "RiffAds"
---

# Safe for your team. Safe for your agents.

To keep your data safe, RiffAds keeps each workspace separate: our servers check that you belong to it before they show or change its data. Files are private and shared through links that expire. AI agents spend only within limits your team controls.

## Is RiffAds safe to use?

RiffAds is built to keep your data safe and your spend in check. Workspaces are kept separate, files are private and shared through links that expire, and passwords and API keys are stored as hashes. Content is checked before credits are held, AI agents are capped by limits your team sets, and RiffAds never posts to your social accounts.

Last reviewed: September 25, 2026.

**At a glance**

- Each workspace is kept separate
- Private files, links that expire
- API keys stored only as hashes
- Content checked before credits are held
- Agent spend capped by limits you set
- Never posts to your social or ad accounts

## How your workspace is protected

What RiffAds does today to keep your work, your keys and your credits safe. Each point describes how the product works now.

### Each workspace is kept separate

Your files, generations, API keys and credits belong to one workspace. Our servers, not your browser, decide which workspace a request is for, and check that you are a member before they show or change its data.

### Roles for your team

Each person is an owner, an admin or a member. Everyone in a workspace can see its content and usage. Only owners and admins manage API keys and agent spend limits, and only they see pending invitations.

### Verified email, hashed passwords

Sign in with email and password, or with Google. A new email address must be verified before it can sign in, and passwords are stored only as hashes, never in plain text.

### API keys with scopes

Every key belongs to a workspace. Its Read scope spends nothing, and spending needs a scope you add on purpose: Generate or Workflows. A key is shown once, stored only as a hash, and stops working when you revoke it.

### AI apps you approve

An AI app such as Claude or Cursor connects only after you approve it. Its token is checked on every call, you can set the connection to read only, and disconnecting it deletes its tokens.

### Spend limits for agents

Every agent job must name the most it may spend, and a job over that is refused, never trimmed. By default a workspace also caps agents at 600 credits a job and 2,000 credits a day.

### Private files, links that expire

Uploads and outputs are stored in private Cloudflare R2 storage. You open them through links that expire after a short time, and links given to an AI agent expire after 10 minutes.

### Signed webhooks

Each event is signed with HMAC SHA-256 in the webhook-signature header. The signing secret is shown once and stored encrypted with AES-256-GCM. Endpoints must be public https, and events carry ids, never file links.

### Card details stay with Dodo Payments

You pay on a checkout page run by Dodo Payments, the merchant of record, not on our site. RiffAds never sees or stores your full card number.

### Checked before credits are held

Scripts, prompts and uploaded images are checked before any credits are held or work starts. The same checks run in the app, the API, MCP, the CLI and workflows.

### Consent before a voice clone

Before a voice is cloned in the app, you confirm you have the right to clone it. We keep that confirmation with your user, workspace, IP address and the time, and the sample is safety checked first.

### Never touches your accounts

RiffAds does not connect to your social media or ad accounts, and it never posts anything. Every finished file comes back as a download link, and where it goes next is up to you.

### The four limits on agent spend

An agent's own number is only the first limit. Your workspace's owners and admins control the other three, and every agent job must fit under all four.

| Limit | Who sets it | Default | Measured over |
| --- | --- | --- | --- |
| The job's max_credits | The agent, on every call | Required, no default | One job |
| Workspace limit per job | Owner or admin | 600 credits | One job |
| API key budget | Owner or admin | No limit | Rolling 24 hours |
| Workspace daily limit | Owner or admin | 2,000 credits | Rolling 24 hours |

- The lowest limit wins, and a refused job says which limit stopped it.
- A limit set to 0 means agents may not spend at all.
- These limits apply to agents only, not to people working in the studio.

- [Set agent limits](https://app.riffads.com/connections)
- [Manage API keys](https://app.riffads.com/api-keys)
- [How to connect an agent](https://riffads.com/connect)

## Where your data goes

RiffAds does not run its own AI models. To create your outputs, we send your inputs to third-party AI providers. They process the inputs and send back the result.

| Provider | Kind | What it does for RiffAds |
| --- | --- | --- |
| Vercel | Hosting | Hosts our website, documentation site, app, API and MCP server. |
| Neon | Hosting | Database. |
| Cloudflare R2 | Hosting | File storage. |
| Trigger.dev | Hosting | Background jobs that process media, and live progress updates. |
| fal.ai | AI | Creates talking actor videos, other videos, images, music, voice changes, captions and other media. |
| OpenRouter | AI | Sends text and image requests to models from companies such as Google, Anthropic, OpenAI and xAI, to write and translate scripts, run chat tools, read pages you import and run safety checks. |
| ElevenLabs | AI | Turns scripts into speech, clones voices from samples and designs voices from descriptions. |
| Deepgram | AI | Turns voice clone samples into text so we can run a safety check. |
| Dodo Payments | Payments | Checkout, subscriptions and invoices, as the merchant of record. |
| Resend | Email | Sends account emails, such as email verification and password reset. |
| Google | Sign-in | Sign-in, if you choose to sign in with Google. |
| PostHog, Google Analytics, RB2B and Vercel Web Analytics | Analytics | Measure how the site and the app are used, where turned on. |

From our Privacy Policy ([How AI processing works](https://riffads.com/privacy#ai-processing)):

> **We do not train our own AI models on your content, and no-training is turned on with our AI providers. fal.ai, OpenRouter and the models it routes to, ElevenLabs and Deepgram do not use your content to train their models.** One exception worth knowing: when you create an actor, the analytics event we send includes the words you typed to describe the actor, and it goes to our analytics provider when analytics is turned on.

These providers may keep inputs and outputs for a time under their own terms. For example, ElevenLabs keeps a history of the speech it creates for us.

We and our service providers process data in the United States and other countries.

[Read the full Privacy Policy](https://riffads.com/privacy)

## Using AI actors safely in ads

RiffAds makes the ad. You publish it, so the rules of each platform and each country apply to you as the advertiser. These are the ones that matter most for AI actors today.

- **AIGC**: TikTok allows ads with AI-generated media only with its AIGC label or your own clear disclaimer. Ads that do not disclose it are rejected or restricted. Source: [TikTok Advertising Policies](https://ads.tiktok.com/help/article/tiktok-ads-policy-misleading-and-false-content), April 2026.
- **Jun 1, 2026**: Since this date, Meta uses automated detection to find ad media made or edited with third-party AI tools, and adds an "AI info" label in "About this ad". Source: [Meta Transparency Center](https://transparency.meta.com/policies/ad-standards/SIEP-advertising/SIEP/), read 2026-09-25.
- **Aug 2, 2026**: EU AI Act Article 50 applies from this date. A business that uses AI to make a deep fake must disclose that it is AI generated. Source: [European Commission](https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations), 2026-08-06.
- **$53,088**: The most a US court can fine per knowing violation of an FTC rule, such as the rule against fake testimonials. Source: [eCFR, 16 CFR 1.98](https://www.ecfr.gov/current/title-16/section-1.98), current 2026-09-22.

### Three rules to follow

1. **Say it is AI, in the ad itself.** On TikTok, turn on "This ad contains AI-generated content" in Ads Manager, or add your own clear label. In the EU, a realistic AI person can count as a deep fake, and the label must be visible or audible: an invisible watermark alone is not enough. Sources: [TikTok Business Help Center](https://ads.tiktok.com/help/article/add-disclaimers-to-ads), September 2025; [EU AI Act, Article 50(4)](https://publications.europa.eu/resource/celex/32024R1689), OJ 2024-07-12; [European Commission, Article 50 Q&A](https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act), 2026-07-24.
2. **Never present an AI actor as a real customer.** A line like "I used this and it worked" is a testimonial. The FTC says its rule does not ban AI avatars, but it does ban testimonials that misrepresent that the person exists or used the product. Sources: [eCFR, 16 CFR 465.2](https://www.ecfr.gov/current/title-16/part-465), current 2026-09-22; [FTC, rule Q&A](https://www.ftc.gov/business-guidance/resources/consumer-reviews-testimonials-rule-questions-answers), 2024-11-08, modified 2025-05-01.
3. **Use a real face or voice only with written consent.** Our Acceptable Use Policy requires written consent from any real person you show or clone, unless that person is you. TikTok also bans ads that misuse a public figure's likeness without permission. Sources: [TikTok Advertising Policies](https://ads.tiktok.com/help/article/tiktok-ads-policy-misleading-and-false-content), April 2026.

Our records mark each output as AI generated, and webhook events about generated files carry a line that says so and asks you to disclose it where you publish.

- [Read our AI Disclosure](https://riffads.com/ai-disclosure)
- [Read the Acceptable Use Policy](https://riffads.com/acceptable-use)

## Report a security issue

Found a vulnerability? Email hello@riffads.com with the steps to reproduce it. This is the contact in our security.txt file, and we will confirm receipt.

Security contact: hello@riffads.com. [View security.txt](https://riffads.com/.well-known/security.txt):

```
Contact: mailto:hello@riffads.com
Preferred-Languages: en
Canonical: https://riffads.com/.well-known/security.txt
Policy: https://riffads.com/acceptable-use
```

If you think your account or an API key is at risk, email hello@riffads.com right away. Revoke keys and remove app connections you no longer use, and set spending budgets on your API keys.

## Security questions

### Is RiffAds safe?

RiffAds is built to keep your work private and your spend under control. Each workspace is separate, files open only through links that expire, passwords and API keys are stored as hashes, content is checked before credits are held, and AI agents spend only within limits your team sets. No system is completely secure. Keep your keys safe and revoke the ones you no longer use.

### Does RiffAds train AI on my videos?

No. We do not train our own AI models on your content, and no-training is turned on with our AI providers. fal.ai, OpenRouter and the models it routes to, ElevenLabs and Deepgram do not use your content to train their models. These providers may keep inputs and outputs for a time under their own terms. For example, ElevenLabs keeps a history of the speech it creates for us.

### Who can see my files?

The members of your workspace. Files are private and open only through links that expire after a short time, and links given to an AI agent expire after 10 minutes. Anyone who has a link can open the file until the link expires, so share links with care. Authorized staff can access accounts, workspace content and generation details when needed to run the service, give support, investigate abuse or meet legal duties.

### Can an AI agent spend all my credits?

An agent can spend only up to your workspace's limits. Every agent job must name the most it may spend, and a job that costs more is refused. By default, agents may spend at most 600 credits a job and 2,000 credits a day in a workspace, and each API key can have its own 24 hour budget. A workspace owner or admin can change these limits, or set one to 0 so agents cannot spend at all.

### Does RiffAds post to my social accounts?

No. RiffAds does not connect to your social media or ad accounts, and it never posts anything. You get a download link to each finished file, and you decide where it goes. When you publish an ad with an AI actor, label it as AI where the platform or the law asks you to.

### How do I delete my data?

Email hello@riffads.com from the email address on your account and ask us to delete your data. We will delete or anonymize your personal data, except what we must keep for legal, tax, billing and safety reasons, and tell you what we keep and why. The Privacy Policy lists how long each kind of record is kept.

### How do I report a vulnerability?

Email hello@riffads.com with the steps to reproduce the issue, and the page, URL or API endpoint where you found it. It is the contact listed in our security.txt file at riffads.com/.well-known/security.txt, and we will confirm receipt.

## Stop waiting on creators. Ship the ad today.

Book a call for a walkthrough, or log in and make your first ad.

- [Book a call](https://cal.com/ravisojitra/30min)
- [Log in](https://app.riffads.com/sign-in)
- [New here? Try Growth for $1](https://app.riffads.com/sign-up?redirect=%2Fpricing%3Fplan%3Dgrowth%26interval%3Dmonth)
