Privacy Policy
Last updated 24 August 2026
The short version
Raff keeps your shop's data on your own device. There is no Raff server, no account to create, and no advertising or analytics tracking of any kind. We cannot read your inventory, your sales, or your customers — because that information never reaches us.
What Raff stores, and where
Everything you enter — products, stock levels, locations, orders, suppliers, sales, refunds, customers and their phone numbers, and your shop's own settings — is stored in Raff's database on your iPhone or iPad.
Raff also keeps a copy in your personal iCloud account, so that your data is backed up and stays in step across your own Apple devices. That copy belongs to your Apple ID, is held on Apple's infrastructure under Apple's own privacy terms, and may be stored outside your country. It is not shared with us and not shared with other Raff users. You can stop it at any time in the iOS Settings app under your Apple Account → iCloud, by turning iCloud off for Raff.
If you use Raff's team feature to share a shop with staff, the shared data travels through that same Apple iCloud sharing mechanism, between the Apple IDs you invite — never through a server of ours.
AI runs on your device
Raff's assistant — the Iris models that read your spoken stock notes, your product photos and your supplier invoices — runs entirely on your device. What you say, type or photograph is processed locally. It is not uploaded to us, and it is not sent to any third-party AI service.
Camera, microphone and photos
- Camera — scanning barcodes, reading product labels and photographing invoices.
- Microphone — capturing spoken stock commands and questions.
- Photo library — only the individual pictures you choose.
Everything captured is processed on the device and saved only inside your own Raff data. Nothing is streamed to us. You can revoke any of these permissions in iOS Settings, and Raff keeps working without them (with those features unavailable).
Payments
Raff never sees, handles or stores card numbers. When you connect a payment provider, the customer enters their card on that provider's own secure payment page, over an encrypted connection to the provider. Raff receives only the result of the payment: whether it succeeded, and a reference plus the card brand and last four digits to print on the receipt.
Your provider's own privacy policy governs what they do with that payment data. The credentials you enter to connect a provider are stored in the device Keychain, never in a backup file or an export.
Your customers' data
If you record customers to track credit or send receipts, you are the one responsible for that information under your local data-protection law — in Saudi Arabia, the Personal Data Protection Law (PDPL). Raff's role is to store it on your device and, if iCloud is on, in your own iCloud account. Collect only what you need, tell your customers what you keep, and delete a customer from the app when they ask.
What we receive
Nothing automatic. Raff has no analytics SDK, no advertising SDK, no crash reporter that sends us your content, and no telemetry. If you email us for support, we receive whatever you choose to put in that email — and if you attach a data export, that file contains your shop's records, so please send one only when you mean to.
Apple may give us anonymous, aggregated App Store statistics (downloads, crash counts) as it does for every app. Those contain no shop or customer data.
Your controls
- Export everything as CSV files or one JSON backup — Settings › Data.
- Delete everything from the same screen; deleting the app removes its data from the device, and the iCloud copy can be removed in iOS iCloud settings.
- Lock the app behind Face ID or your passcode — Settings › App Lock.
- Turn off iCloud for Raff in iOS Settings to keep everything on the one device.
Children
Raff is a business tool for shop owners and staff. It is not directed at children and we do not knowingly collect any data from them.
Changes and contact
If this policy changes, the updated version appears on this page with a new date. Material changes will also be noted in the app's release notes.
Questions, or a request about your data: [email protected].