Legal

Privacy policy

This policy describes what Risha actually collects — not what it might collect one day. It was written to be read, not skipped.

Last updated: 10 September 2026.

First principle: your writing is yours

What you write in Risha belongs to you. We do not sell your writing or use it to train a Risha model. We process project content when you request cloud saving, syncing or sharing. If you choose to use the assistant, we send your request and the context it needs to the AI provider you selected, as explained in this policy.

In the desktop app, a local project file stays on your device unless you save it to your account or use a feature that needs to send it, such as co-writing or the assistant. Risha Online and cloud saving require project data to pass through our servers.

What we collect

We collect the minimum that makes accounts, sync and subscriptions work:

  • Account data: your name, email address and the date the account was created. If you signed up with a password, we store a derived hash rather than the password itself, so we can neither read nor recover it.
  • Sign in with Google or Apple: we store the stable identifier the provider sends, your email, and the name it makes available at sign-in. We never see your password with them, nor your contacts or files.
  • Your cloud projects: the project's title, content, size and revision number, if you choose to save to the cloud. If you don't, none of it is uploaded.
  • Sessions: a hash of the session token, the time it was last used, and the browser or app type — so you can see your active devices and end any session.
  • Subscription: your Stripe customer and subscription identifiers, your plan, its status and renewal date. Card numbers never pass through us and are never stored by us — they go straight to Stripe.
  • Security log: sign-ins, sign-outs and subscription changes, with the email connected to the event, the browser or app type, a country code and a hashed fingerprint of the network address. We do not store your raw IP address in this log. We use it to protect accounts and the service.
  • Download statistics: we record download-button clicks and requests to download links, including platform, country code and an estimated automated-traffic classification. Clicks are linked only to a tab session, never to your account. They do not tell us whether a download or installation completed. GitHub aggregate counters remain separate; GitHub and Cloudflare may process requests under their own policies.
  • Website page visits: we record the page, time, referring hostname, country code, device category, language, visible time and a boolean interaction signal without interaction details. This helps classify sessions as likely human, automated or unresolved. We store no raw IP, browser fingerprint or writing content, and use no tracking cookies. A random session ID stays within the browser tab. A temporary keyed network digest limits request rates; it expires after minutes and is never linked to accounts. This measurement does not run inside the editor.
  • Assistant: when you use it, we send OpenAI or Anthropic — depending on your choice — your request, recent conversation messages and relevant screenplay context. The context may include the full screenplay when a task requires reviewing or translating it. Your key is stored encrypted in your account, or on your device if account storage is unavailable, and decrypted only to fulfil your request. Risha does not store the assistant conversation in its database; the provider processes it under its terms and your account settings with that provider.
  • Service quality: we record daily summaries of signed-in account requests and successful cloud actions, service failures and affected accounts, without project content, titles or passwords. We do not monitor local writing or crashes that never reach the server. Detailed measurement events are retained for up to 90 days and daily summaries for up to 13 months. Open issues remain until resolved; affected-account identifiers are kept for no more than 90 days.

What we do not collect

We run no advertising, use no ad trackers, and neither sell nor rent your data. We do not ask for your phone number, age or precise location. We use no advertising cookies; the site or app may store your session token and preferences locally on your device to keep you signed in and remember your settings.

Where data is stored and who processes it

Account data and cloud projects are stored on Cloudflare infrastructure. The number of services that process your data depends on which features you choose to use:

  • Cloudflare — hosting and the database.
  • Stripe — payments and subscriptions. It alone handles your card details.
  • Resend — sending verification and password-reset emails.
  • OpenAI or Anthropic — processing assistant requests when you choose to use it, with your own account key for that provider.
  • GitHub — hosting desktop installers and updates, and providing aggregate download counts.

And if you sign in with Google or Apple, you deal with them directly under their own policies; we receive only the result.

How long data is kept

Your cloud projects and account data remain while your account exists. Sessions, verification tokens and password-reset tokens expire after their defined lifetimes. There is currently no automatic deletion period for the security audit log or site measurements; we keep them to protect and understand the service, and you may contact us about data linked to your account.

Your rights

At any time you may request a copy of your data, correct your email address, or delete your account together with all your cloud projects, permanently. Write to us at [email protected] and we respond within thirty days. Account deletion cannot be undone, so keep a copy of your files first — Risha exports your projects as files on your device at any time.

Children

Risha is not directed at anyone under thirteen, and we do not knowingly collect their data. If we learn of an account belonging to a child under that age, we delete it.

Changes to this policy

If we change anything material — such as collecting a new kind of data — we will notify you by email before the change takes effect, and update the last-updated date at the top of this page.

Contact

Risha is a product of Qasdeer. For any privacy question or a request concerning your data: [email protected].