RIFFL

Privacy Policy

Last updated: July 29, 2026

This Privacy Policy explains what information we collect, how we use it, how we protect it, and your choices.

RIFFL (“we”, “us”, “our”) operates the RIFFL mobile application and website at riffl.ai. This Privacy Policy explains what information we collect, how we use it, how we protect it, and your choices.

1. Who we are

Data controller: [Legal entity name, address]
Contact: privacy@riffl.ai

2. Information we collect

2.1 Information you provide

DataPurpose
Email addressAccount creation, login (OTP), support, premium invitations
Name / display nameProfile, personalization
UsernameAccount identity
Password (optional)Email login if you set one
Google profile infoIf you sign in with Google: name, email, profile picture URL, locale
Avatar choiceProfile display (preset or uploaded photo)
Feedback & support messagesRespond to tickets and ratings
Payment-related infoProcess subscriptions (handled by Apple App Store or Razorpay; we store transaction references, plan, amounts — not full card numbers)

2.2 Information collected automatically

DataPurpose
Device identifierSession management, push notifications, analytics
Push notification tokenSend push notifications you opt into
Platform (iOS/Android), app versionCompatibility, analytics, experiments
Country (from device/network)Content and pricing localization
Listening progress & historyResume playback, recommendations, product improvement
Bookmarks & playlist savesYour library
Likes / dislikes on contentPersonalization
Product analytics eventsUnderstand usage, fix bugs, improve features (first-party analytics)

We do not collect precise GPS location, contacts, or microphone audio for core app features.

2.3 Information from others

If another RIFFL user invites you to shared Premium access, we process your email address to deliver the invitation.

3. How we use information

  • Provide and operate the RIFFL service (audio content, feeds, library, search)
  • Authenticate you and secure your account
  • Process subscriptions and restore purchases
  • Send transactional email (OTP, receipts, invitation, support)
  • Send push notifications if you grant permission
  • Improve content, features, and performance
  • Comply with law and enforce our Terms

Legal bases (where applicable): contract performance, legitimate interests, consent (e.g. push notifications), legal obligation.

4. How we share information

We share data only with service providers who help us operate RIFFL:

ProviderRole
Amazon Web Services (AWS)Hosting, storage (S3), queues
GoogleGoogle Sign-In; Firebase Cloud Messaging (push delivery)
AppleIn-app purchases (iOS)
RazorpayPayments (where applicable)
Email delivery providerTransactional email (OTP, subscription emails)
First-party analyticsProduct analytics on RIFFL infrastructure

We do not sell your personal information.

5. Data retention

  • Active account: We retain your information while your account is active and you use RIFFL.
  • Deleted account: When you delete your account in the app, we close your account and you lose access to your profile, bookmarks, listening history, and Premium benefits. We sign you out on all devices and stop sending push notifications to that account. We may retain certain information for a limited period where required by law (for example, payment and tax records), to prevent fraud, or for other legitimate purposes described in this policy. Deleted accounts cannot be restored through the app.
  • Signing up again: You may create a new account with the same email address after deletion. That new account is separate and does not include data from your previous account.
  • Verification codes: Login codes sent by email are automatically removed after they expire (typically within about 15 minutes).

6. Your rights and choices

Depending on your region, you may have rights to access, correct, delete, or port your data, and to object or restrict processing.

  • Delete account: Settings → Account → Delete account (in app), or Data Deletion Request
  • Push notifications: revoke in device Settings; optional in RIFFL Settings
  • Marketing: RIFFL v1 uses transactional + product notifications; adjust OS notification settings

Contact privacy@riffl.ai for requests. We respond within applicable legal timeframes.

7. Security

We use industry-standard measures including encrypted connections (HTTPS/TLS), secure password storage, and access controls on our systems. No method of transmission or storage is completely secure.

8. Children

RIFFL is not directed at children under 13 (or higher age where required). We do not knowingly collect data from children.

9. International transfers

Your data may be processed in India and other countries where our providers operate. We use appropriate safeguards where required.

10. Changes

We may update this policy. We will post the new version at riffl.ai/privacy with an updated date. Material changes may be notified in-app.

11. Contact

privacy@riffl.ai
[Company address]