Last updated September 14, 2026
Privacy Policy
Riki is a product of Upward Wealth, Inc. In this policy, “Riki,” “we,” and “us” refer to Upward Wealth, Inc. This policy explains how we handle information when you visit meetriki.com, use the Riki mobile app, or contact us. The website is a public information site and does not provide account sign-in.
Service measurement and campaign measurement
Riki measures service usage and reliability by default using aggregate daily counts of selected API operations, success and failure categories, and response-time buckets. These metrics help us improve sign-in, bank connections, and app features. The metric records contain no account or device identifiers, IP addresses, advertising identifiers, request content, financial values, or chat messages. We keep these aggregate records for 90 days. Normal service processing and security logs are separate from these metrics.
Optional campaign measurement uses AppsFlyer to help us understand how people find Riki. It is off by default and can be changed under Privacy in the app settings. When enabled, AppsFlyer may receive an install identifier, approximate location derived from IP, device and app technical information, and install or app-open interactions. We do not send your Riki account identity, financial information, authentication data, or chat content to AppsFlyer. Advertising identifiers and advertising-partner sharing remain disabled. Accepting these terms does not grant permission for cross-app advertising tracking or replace any separately required permission.
Information you provide
We collect information you choose to provide in the app or to our support team. Depending on the features you use, this may include your name, email address, financial goals, answers about your circumstances, support messages, chat messages, and details related to a report or potential lending conversation. Please do not send passwords, one-time codes, full account numbers, or a full Social Security number by email or in chat.
Sign in with Apple or Google
The Riki app supports Sign in with Apple and Google Sign-In. We receive an identifier from the provider and, depending on your choices and the provider, may receive your name and email address. We use that information to create, locate, and protect your Riki account. Riki does not offer a separate password sign-in. Apple and Google process information under their own terms and privacy policies.
Financial accounts connected through Plaid
Connecting a financial institution is optional. When you choose to connect through Plaid, the connection occurs in Plaid's experience rather than a bank-credential form created by Riki. Plaid may provide Riki with institution and account identifiers, account names and types, masked account details, balances, transactions, categories, recurring-activity information, and available history. Plaid and the financial institutions you select also process information under their own terms and privacy notices.
We use connected-account information to organize cash-flow activity, identify patterns, and prepare or update a Riki report. Institution data may be delayed, incomplete, duplicated, or categorized incorrectly, so a report may change as additional information becomes available or your account choices change.
Optional credit-range lookup through Array
If you expressly ask Riki to look up a credit range, Riki sends Array your first and last name, current address, any previous address you provide, and any date of birth or Social Security number you choose to provide. We also send the IP address supplied to us by our trusted hosting network, the time of your request, and the URL of this privacy notice as a record of your authorization. Array processes that information under its applicable terms and privacy notice and returns a broad score range rather than a full credit report.
Riki does not place the name, address, date of birth, Social Security number, or raw Array response from that request into its credit-range database records. We retain the normalized range and limited security and consent metadata for up to one year and treat a returned range as fresh for 30 days. The Array range is separate from a Riki cash-flow report or Riki score. It is not added to a Riki report or sent to a lender unless a later, clearly identified flow asks for and receives separate authorization.
Riki reports and chat
We use information you provide and permissioned financial data to create cash-flow summaries, educational estimates, and Riki reports. These outputs may include available months of data, income patterns, recurring obligations, spending patterns, cash-flow capacity, payment signals, and a Riki score.
Riki chat uses artificial intelligence. When you use it, we process your message and may provide an AI service provider with the minimum relevant report, profile, and recent conversation context needed to generate a response. Chat is separate from the goal journeys and lender-bidding workflows used by earlier Riki products. We may save conversations so you can return to them and for security, quality, and support.
To verify the name you confirm in your profile, we send that name and account-owner names from your connected banks to our AI provider for comparison. We retain the comparison result and confidence, rather than the bank-owner names or an AI explanation. We also refresh your Riki report automatically when updated bank data arrives.
Device keys and authorized report sharing
Riki is designed to use device-based cryptographic keys to help protect report data that you choose to share. Before a report handoff, the app is intended to show the named recipient, purpose, included data, and any expiration and ask for your explicit authorization. Encryption reduces risk but cannot guarantee absolute security, and device-key availability may vary by device, operating system, and release.
Riki does not operate a lender marketplace or bid system. We are exploring a direct, consent-based report workflow with loanDepot, but its data fields, delivery method, retention rules, and other requirements have not been finalized. As of the date above, this policy does not represent that a loanDepot integration is active. If we enable one, the app will identify the recipient and the information to be shared before you authorize it. A recipient then handles information it receives under its own privacy notice and legal obligations.
How we use information
We use information to operate and secure Riki; authenticate accounts; provide the features you request; connect the institutions you select; prepare reports; respond in chat; record sharing choices; provide support; detect and prevent misuse; measure and improve performance; and meet legal, accounting, security, and recordkeeping obligations. We do not use the public website to accept loan applications.
Service providers and storage
We use providers that support hosting, databases, authentication, financial-data connections, AI, monitoring, security, and customer support. The current architecture uses Vercel to host the website and application programming interfaces and MongoDB Atlas for database services. Plaid supports financial account connections, Array supports optional credit-range lookup, and Apple and Google support authentication. These providers process information for us under contracts and their applicable terms.
We may also disclose information when reasonably necessary to comply with law or valid legal process, protect people or Riki, investigate misuse, enforce agreements, or complete a corporate transaction. If ownership or control changes, information may transfer as part of that transaction subject to applicable law.
Website analytics and browser storage
The website uses necessary browser storage to remember your analytics choice. If a Google Analytics measurement ID is configured, Google Analytics loads only after you choose “Allow analytics.” It may receive page, browser, device, and general usage information; Riki configures it to anonymize IP addresses. Choosing “Only necessary” prevents that analytics script from loading. You can clear the saved choice through your browser's site-data controls.
Retention and deletion
We keep information for as long as needed to provide Riki and for the purposes in this policy. Retention depends on the type of data, your choices, legal requirements, and security needs. The app provides account-deletion and connection controls. If you cannot access the app, use our public account-deletion page to submit a request without reinstalling Riki. Some limited records may remain where reasonably needed for security, fraud prevention, legal compliance, or dispute resolution. Deleting Riki data does not automatically delete data already sent to a third party with your authorization.
Your choices and requests
You can choose whether to connect a financial institution, which supported accounts to include, whether to use chat, and whether to authorize a report handoff. Depending on where you live, you may have rights to ask about, access, correct, delete, or obtain a portable copy of personal information, or to object to or limit certain processing. We may need to verify your identity before completing a request. Email hello@meetriki.com for help.
Security
We use administrative, technical, and organizational safeguards designed to protect information. These include scoped access, encryption in transit and at rest where appropriate, provider-issued authentication tokens, audit records for sensitive operations, and device-key protections where supported. No online service, device, or storage method is completely secure. Contact us promptly if you believe your account or device has been compromised.
Children
Riki is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. Contact us if you believe a child provided information to Riki so we can review it.
Changes to this policy
We may update this policy as Riki changes. We will post the revised policy here and update the date above. If a change requires additional notice or consent under applicable law, we will provide it before the change applies.
Contact us
Questions or privacy requests can be sent to hello@meetriki.com.