Riposte is a LinkedIn engagement assistant for teams that runs inside Claude as an MCP connector. It watches public social media posts, ranks them by engagement velocity, and drafts replies that a human reviews and posts. This policy explains what data Riposte handles, why, and what your rights are.
The short version. We store your work email and name (for sign-in), the content your workspace creates (voice samples, tracked lists, engagement logs), cached public social media posts, and usage metering. We never ask for social media passwords, never post on anyone's behalf, never read private messages, and never sell data.
When you sign in, our authentication provider (Clerk) shares your name and work email address with us. We use these to match you to a seat in your team's workspace. Sign-in is OAuth 2.0 — we never see or store your password.
A small number of workspaces created before OAuth was added still connect using a secret link containing a per-seat token. That token is the credential, so the link should be treated like a password. We are retiring this path; if your workspace uses one, we will move you to OAuth sign-in.
Riposte fetches publicly available posts, profiles, and comment threads via a licensed third-party data provider, and caches them in our database so your feed loads quickly and repeat lookups don't re-fetch. We do not access private profiles, direct messages, or any content behind a login.
When you tell Riposte you posted a reply — or when the daily check described in §3 finds one on a post Riposte drafted for — we store the comment text, the post it was on, and a link to the comment, so your engagement reports are about what actually happened. Each record notes whether you confirmed it or we detected it.
We meter tool calls, data-provider calls, and drafting tokens per seat and per workspace. This powers budgets, fair-use limits, and billing. Your workspace admin can see the same usage report we bill from.
We do not sell personal data, share it with advertisers, or use it for any purpose beyond operating Riposte.
| Provider | Purpose |
|---|---|
| Clerk | Authentication (OAuth 2.0 sign-in) |
| Supabase | Database (encrypted at rest) |
| Vercel | Application hosting |
| Anthropic | AI draft generation and, on request, web search for target companies (API; not used for model training) |
| RapidAPI | Marketplace we call the social-data provider through |
LinkedIn Scraper API (linkedin-scraper-api-real-time-fast-affordable.p.rapidapi.com) | The licensed provider that retrieves public LinkedIn content. Configurable, so this page names the one in use; if we change provider we will update this page and the effective date. |
| GitHub | Scheduled jobs (GitHub Actions) that trigger our refresh and sync endpoints |
Within your workspace, shared activity (contacts, engagement history, briefs) is visible to your teammates by design — that team awareness is the product. The contact watchlist is workspace-wide: it is shared by everyone on the team, not private to whoever added someone. Voice profiles are visible at workspace level too, but only their creator or a workspace admin can change or delete one — a voice is somebody's own writing. Drafts are never written to Riposte's database — but they are produced by Anthropic's API and returned into your assistant conversation, so your host's retention policy and Anthropic's apply to them exactly as they do to the rest of that conversation.
Riposte processes publicly available social media content, which includes posts and profile details of people our customers choose to track. If you believe your public content is being processed and want it removed, contact us at the address below. We will remove your cached posts, your entry on any customer's watchlist, and your rows as a commenter on their posts — in every workspace that holds them, not just one. Three limits worth stating plainly, because we would rather be exact than reassuring. Where someone replied to a post and we did not capture a usable link to their profile, we hold a name and the text of the reply with nothing that identifies whose it is; we cannot single those out on request, and we will not guess, because guessing means deleting a stranger's words from a customer's record. We keep no suppression list, so if a customer tracks you again afterwards your public posts can be fetched afresh. And where a customer has recorded that they replied to one of your posts, that record is their own business activity, which we handle with them rather than delete unilaterally.
Depending on where you live (including under UK and EU GDPR), you may have the right to access, correct, export, or delete your personal data, and to lodge a complaint with a supervisory authority. Email us and we will respond within 30 days.
The riposte.chat website sets no analytics or advertising cookies. Signing in sets strictly necessary session cookies from our authentication provider.
Riposte is a business tool intended for users 18 and over. If we make material changes to this policy we will update this page and note the new effective date. Questions, or any request under this policy: hello@riposte.chat.